Lightweight Ciphers and their Side-channel Resilience

Journal Article (2020)
Author(s)

Annelie Heuser (INRIA/IRISA)

Stjepan Picek (TU Delft - Cyber Security)

Sylvain Guilley (Telecom Paris Tech)

Nele Mentens (Katholieke Universiteit Leuven)

Research Group
Cyber Security
Copyright
© 2020 Annelie Heuser, S. Picek, Sylvain Guilley, Nele Mentens
DOI related publication
https://doi.org/10.1109/TC.2017.2757921
More Info
expand_more
Publication Year
2020
Language
English
Copyright
© 2020 Annelie Heuser, S. Picek, Sylvain Guilley, Nele Mentens
Research Group
Cyber Security
Issue number
10
Volume number
69
Pages (from-to)
1434-1448
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Side-channel attacks represent a powerful category of attacks against cryptographic devices. Still, side-channel analysis for lightweight ciphers is much less investigated than for instance for AES. Although intuition may lead to the conclusion that lightweight ciphers are weaker in terms of side-channel resistance, that remains to be confirmed and quantified. In this paper, we consider various side-channel analysis metrics which should provide an insight on the resistance of lightweight ciphers against side-channel attacks. In particular, for the non-profiled scenario we use the theoretical confusion coefficient and empirical optimal distinguisher. Our study considers side-channel attacks on the first, the last, or both rounds simultaneously. Furthermore, we conduct a profiled side-channel analysis using various machine learning attacks to recover 4-bit and 8-bit intermediate states of the cipher. Our results show that the difference between AES and lightweight ciphers is smaller than one would expect, and even find scenarios in which lightweight ciphers may be more resistant. Interestingly, we observe that the studied 4-bit S-boxes have a different side-channel resilience, while the difference in the 8-bit ones is only theoretically present.

Files

40613695_08053814.pdf
(pdf | 5.22 Mb)
License info not available