Skip to main navigation Skip to search Skip to main content

Principles on the security of AES against first and second-order differential power analysis

  • Jiqiang Lu*
  • , Jing Pan
  • , Jerry Den Hartog
  • *Corresponding author for this work
  • Eindhoven University of Technology
  • Riscure

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The Advanced Encryption Standard (AES) is a 128-bit block cipher that is currently being widely used in smartcards. Differential Power Analysis (DPA) is a powerful technique used to attack a cryptographic implementation in a resource-limited application environment like smartcards. Despite the extensive research on DPA of AES, it seems none has explicitly addressed the fundamental issue: How many rounds of the beginning and end parts of an AES implementation should be protected in order to resist practical DPA attacks, namely first and second-order DPA attacks? Implementation designers may think that it is sufficient to protect the first and last one (or one and a half) rounds of AES, leaving the inner rounds unprotected or protected by simple countermeasures. In this paper, we show that power leakage of some intermediate values from the more inner rounds of AES can be exploited to conduct first and/or second-order DPA attacks by employing techniques such as fixing certain plaintext/ciphertext bytes. We give five general principles on DPA vulnerability of unprotected AES implementations, and then give several general principles on DPA vulnerability of protected AES implementations. These principles specify which positions of AES are vulnerable to first and second-order DPA. To justify the principles, we attack two recently proposed AES implementations that use two kinds of countermeasures to achieve a high resistance against power analysis, and demonstrate that they are even vulnerable to DPA. Finally, we conclude that at least the first two and a half rounds and the last three rounds should be secured for an AES implementation to be resistant against first and second-order DPA in practice.

Original languageEnglish
Title of host publicationApplied Cryptography and Network Security - 8th International Conference, ACNS 2010, Proceedings
PublisherSpringer Verlag
Pages168-185
Number of pages18
ISBN (Print)3642137075, 9783642137075
DOIs
StatePublished - 2010
Externally publishedYes

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume6123 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Keywords

  • Advanced Encryption Standard
  • Differential power analysis
  • Side channel cryptanalysis

Fingerprint

Dive into the research topics of 'Principles on the security of AES against first and second-order differential power analysis'. Together they form a unique fingerprint.

Cite this