The Experts below are selected from a list of 2208 Experts worldwide ranked by ideXlab platform

Ingrid Verbauwhede - One of the best experts on this subject based on the ideXlab platform.

  • aes based security coprocessor ic in 0 18 muhbox m cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18- $muhbox m$ CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • aes based security coprocessor ic in 0 18 μm cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18-μm CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • an interactive codesign environment for domain specific Coprocessors
    2006
    Co-Authors: Patrick Schaumont, Doris Ching, Ingrid Verbauwhede
    Abstract:

    Energy-efficient embedded systems rely on domain-specific Coprocessors for dedicated tasks such as baseband processing, video coding, or encryption. We present a language and design environment called GEZEL that can be used for the design, verification and implementation of such coprocessor-based systems.The GEZEL environment creates a platform simulator by combining a hardware simulation kernel with one or more instruction-set simulators. The hardware part of the platform is programmed in GEZEL, a deterministic, cycle-true and implementation-oriented hardware description language. GEZEL designs are scripted, allowing the hardware configuration of the platform simulator to be changed quickly without going through lengthy recompiles. For this reason, we call the environment interactive. We present the execution ladder as an optimization framework to balance interactivity against simulation speed.We demonstrate our approach using several designs including an AES encryption coprocessor and a Viterbi decoding coprocessor. We discuss the advantages of our approach as opposed to more conventional approaches using SystemC and Verilog/VHDL.

  • aes based cryptographic and biometric security coprocessor ic in 0 18 spl mu m cmos resistant to side channel power analysis attacks
    2005
    Co-Authors: Kris Tiri, D D Hwang, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    This paper describes an embedded security coprocessor that consists of four components: an advanced encryption standard (AES) based cryptographic engine, a fingerprint matching oracle, template storage, and an interface unit. Two functionally-identical Coprocessors are fabricated using a TSMC 6M 0.18-/spl mu/m process. The first coprocessor uses standard cells and encrypts at 3.84 Gb/s. The second coprocessor uses wave dynamic differential logic (WDDL) combined with differential routing to combat side-channel information leakage through power analysis attacks. It encrypts at 0.99 Gb/s. The coprocessor is part of a security-partitioned embedded system called ThumbPod.

  • a side channel leakage free coprocessor ic in 0 18 spl mu m cmos for embedded aes based cryptographic and biometric processing
    2005
    Co-Authors: Kris Tiri, D D Hwang, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption and other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC and its design techniques. The IC has been fabricated in 0.18/spl mu/m CMOS. The coprocessor, which is used for embedded cryptographic and biometric processing, consists of four components: an advanced encryption standard (AES) based cryptographic engine, a fingerprint-matching oracle, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first, 'secure', coprocessor is implemented using a logic style called wave dynamic digital logic (WDDL) and a layout technique called differential routing. The second, 'insecure', coprocessor is implemented using regular standard cells and regular routing techniques. Measurement-based experimental results show that a differential power analysis (DPA) attack on the insecure coprocessor requires only 8,000 acquisitions to disclose the entire 128b secret key. The same attack on the secure coprocessor still does not disclose the entire secret key at 1,500,000 acquisitions. This improvement in DPA resistance of at least 2 orders of magnitude makes the attack de facto infeasible. The required number of measurements is larger than the lifetime of the secret key in most practical systems.

Patrick Schaumont - One of the best experts on this subject based on the ideXlab platform.

  • optimizing the hw sw boundary of an ecc soc design using control hierarchy and distributed storage
    2009
    Co-Authors: Xu Guo, Patrick Schaumont
    Abstract:

    Hardware/Software codesign of Elliptic Curve Cryptography has been extensively studied in recent years. However, most of these designs have focused on the computational aspect of the ECC hardware, and not on the system integration into a SoC architecture. We study the impact of the communication link between CPU and coprocessor hardware for a typical ECC design, and demonstrate that the SoC may become performance-limited due to coprocessor data- and instruction-transfers. A dual strategy is proposed to remove the bottleneck: introduction of local control as well as local storage in the coprocessor. We quantify the impact of this strategy on a prototype implementation for Field Programmable Gate Arrays (FPGA) and measured an average speed-up in the resulting design of 9.4 times over the baseline ECC system, while the resulting system area increases by a factor of 1.6. The optimal area-time product improvement of our ECC coprocessor is 4.3 times compared to that of the baseline ECC coprocessor. Using design space exploration of a large number of system configurations using the latest FPGA technology and tools, we show that the optimal choice of ECC coprocessor parameters is strongly dependent on the efficiency of system-level communication.

  • energy and performance evaluation of an fpga based soc platform with aes and present Coprocessors
    2008
    Co-Authors: Xu Guo, Zhimin Chen, Patrick Schaumont
    Abstract:

    Hardware implementations of block ciphers have been intensively evaluated for years. The hardware profile, including the performance, area and power of a block cipher, only considers the block cipher as a standalone component, and does not consider it as a coprocessor in a system design. In this paper we consider system integration of AES and PRESENT crypto Coprocessors, and analyze the system profile in a co-simulation environment and then on an actual FPGA-based SoC platform. Energy, performance and implementation results for both the AES- and PRESENT-based systems are presented. Our research emphasizes the need to consider energy efficiency and performance at system-level when evaluating a block cipher for real embedded systems. Simulation results reveal that the hardware/software interfaces, as the communication bottleneck, have major impact on the system performance. Experimental results further demonstrate that the PRESENT, a power-efficient light-weight block cipher with lower security level, becomes less energy-efficient than AES when system-integration overhead is included.

  • aes based security coprocessor ic in 0 18 muhbox m cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18- $muhbox m$ CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • aes based security coprocessor ic in 0 18 μm cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18-μm CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • an interactive codesign environment for domain specific Coprocessors
    2006
    Co-Authors: Patrick Schaumont, Doris Ching, Ingrid Verbauwhede
    Abstract:

    Energy-efficient embedded systems rely on domain-specific Coprocessors for dedicated tasks such as baseband processing, video coding, or encryption. We present a language and design environment called GEZEL that can be used for the design, verification and implementation of such coprocessor-based systems.The GEZEL environment creates a platform simulator by combining a hardware simulation kernel with one or more instruction-set simulators. The hardware part of the platform is programmed in GEZEL, a deterministic, cycle-true and implementation-oriented hardware description language. GEZEL designs are scripted, allowing the hardware configuration of the platform simulator to be changed quickly without going through lengthy recompiles. For this reason, we call the environment interactive. We present the execution ladder as an optimization framework to balance interactivity against simulation speed.We demonstrate our approach using several designs including an AES encryption coprocessor and a Viterbi decoding coprocessor. We discuss the advantages of our approach as opposed to more conventional approaches using SystemC and Verilog/VHDL.

Kris Tiri - One of the best experts on this subject based on the ideXlab platform.

  • aes based security coprocessor ic in 0 18 muhbox m cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18- $muhbox m$ CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • aes based security coprocessor ic in 0 18 μm cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18-μm CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • aes based cryptographic and biometric security coprocessor ic in 0 18 spl mu m cmos resistant to side channel power analysis attacks
    2005
    Co-Authors: Kris Tiri, D D Hwang, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    This paper describes an embedded security coprocessor that consists of four components: an advanced encryption standard (AES) based cryptographic engine, a fingerprint matching oracle, template storage, and an interface unit. Two functionally-identical Coprocessors are fabricated using a TSMC 6M 0.18-/spl mu/m process. The first coprocessor uses standard cells and encrypts at 3.84 Gb/s. The second coprocessor uses wave dynamic differential logic (WDDL) combined with differential routing to combat side-channel information leakage through power analysis attacks. It encrypts at 0.99 Gb/s. The coprocessor is part of a security-partitioned embedded system called ThumbPod.

  • a side channel leakage free coprocessor ic in 0 18 spl mu m cmos for embedded aes based cryptographic and biometric processing
    2005
    Co-Authors: Kris Tiri, D D Hwang, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption and other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC and its design techniques. The IC has been fabricated in 0.18/spl mu/m CMOS. The coprocessor, which is used for embedded cryptographic and biometric processing, consists of four components: an advanced encryption standard (AES) based cryptographic engine, a fingerprint-matching oracle, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first, 'secure', coprocessor is implemented using a logic style called wave dynamic digital logic (WDDL) and a layout technique called differential routing. The second, 'insecure', coprocessor is implemented using regular standard cells and regular routing techniques. Measurement-based experimental results show that a differential power analysis (DPA) attack on the insecure coprocessor requires only 8,000 acquisitions to disclose the entire 128b secret key. The same attack on the secure coprocessor still does not disclose the entire secret key at 1,500,000 acquisitions. This improvement in DPA resistance of at least 2 orders of magnitude makes the attack de facto infeasible. The required number of measurements is larger than the lifetime of the secret key in most practical systems.

D D Hwang - One of the best experts on this subject based on the ideXlab platform.

  • aes based security coprocessor ic in 0 18 muhbox m cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18- $muhbox m$ CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • aes based security coprocessor ic in 0 18 μm cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18-μm CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • aes based cryptographic and biometric security coprocessor ic in 0 18 spl mu m cmos resistant to side channel power analysis attacks
    2005
    Co-Authors: Kris Tiri, D D Hwang, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    This paper describes an embedded security coprocessor that consists of four components: an advanced encryption standard (AES) based cryptographic engine, a fingerprint matching oracle, template storage, and an interface unit. Two functionally-identical Coprocessors are fabricated using a TSMC 6M 0.18-/spl mu/m process. The first coprocessor uses standard cells and encrypts at 3.84 Gb/s. The second coprocessor uses wave dynamic differential logic (WDDL) combined with differential routing to combat side-channel information leakage through power analysis attacks. It encrypts at 0.99 Gb/s. The coprocessor is part of a security-partitioned embedded system called ThumbPod.

  • a side channel leakage free coprocessor ic in 0 18 spl mu m cmos for embedded aes based cryptographic and biometric processing
    2005
    Co-Authors: Kris Tiri, D D Hwang, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption and other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC and its design techniques. The IC has been fabricated in 0.18/spl mu/m CMOS. The coprocessor, which is used for embedded cryptographic and biometric processing, consists of four components: an advanced encryption standard (AES) based cryptographic engine, a fingerprint-matching oracle, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first, 'secure', coprocessor is implemented using a logic style called wave dynamic digital logic (WDDL) and a layout technique called differential routing. The second, 'insecure', coprocessor is implemented using regular standard cells and regular routing techniques. Measurement-based experimental results show that a differential power analysis (DPA) attack on the insecure coprocessor requires only 8,000 acquisitions to disclose the entire 128b secret key. The same attack on the secure coprocessor still does not disclose the entire secret key at 1,500,000 acquisitions. This improvement in DPA resistance of at least 2 orders of magnitude makes the attack de facto infeasible. The required number of measurements is larger than the lifetime of the secret key in most practical systems.

Shenglin Yang - One of the best experts on this subject based on the ideXlab platform.

  • aes based security coprocessor ic in 0 18 muhbox m cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18- $muhbox m$ CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • aes based security coprocessor ic in 0 18 μm cmos with resistance to differential power analysis side channel attacks
    2006
    Co-Authors: D D Hwang, Kris Tiri, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption or other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC fabricated in 0.18-μm CMOS consisting of an Advanced Encryption Standard (AES) based cryptographic engine, a fingerprint-matching engine, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first coprocessor was implemented using standard cells and regular routing techniques. The second coprocessor was implemented using a logic style called wave dynamic differential logic (WDDL) and a layout technique called differential routing to combat the differential power analysis (DPA) side-channel attack. Measurement-based experimental results show that a DPA attack on the insecure coprocessor requires only 8000 encryptions to disclose the entire 128-bit secret key. The same attack on the secure coprocessor does not disclose the entire secret key even after 1 500 000 encryptions.

  • aes based cryptographic and biometric security coprocessor ic in 0 18 spl mu m cmos resistant to side channel power analysis attacks
    2005
    Co-Authors: Kris Tiri, D D Hwang, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    This paper describes an embedded security coprocessor that consists of four components: an advanced encryption standard (AES) based cryptographic engine, a fingerprint matching oracle, template storage, and an interface unit. Two functionally-identical Coprocessors are fabricated using a TSMC 6M 0.18-/spl mu/m process. The first coprocessor uses standard cells and encrypts at 3.84 Gb/s. The second coprocessor uses wave dynamic differential logic (WDDL) combined with differential routing to combat side-channel information leakage through power analysis attacks. It encrypts at 0.99 Gb/s. The coprocessor is part of a security-partitioned embedded system called ThumbPod.

  • a side channel leakage free coprocessor ic in 0 18 spl mu m cmos for embedded aes based cryptographic and biometric processing
    2005
    Co-Authors: Kris Tiri, D D Hwang, A Hodjat, Bocheng Lai, Shenglin Yang, Patrick Schaumont, Ingrid Verbauwhede
    Abstract:

    Security ICs are vulnerable to side-channel attacks (SCAs) that find the secret key by monitoring the power consumption and other information that is leaked by the switching behavior of digital CMOS gates. This paper describes a side-channel attack resistant coprocessor IC and its design techniques. The IC has been fabricated in 0.18/spl mu/m CMOS. The coprocessor, which is used for embedded cryptographic and biometric processing, consists of four components: an advanced encryption standard (AES) based cryptographic engine, a fingerprint-matching oracle, template storage, and an interface unit. Two functionally identical Coprocessors have been fabricated on the same die. The first, 'secure', coprocessor is implemented using a logic style called wave dynamic digital logic (WDDL) and a layout technique called differential routing. The second, 'insecure', coprocessor is implemented using regular standard cells and regular routing techniques. Measurement-based experimental results show that a differential power analysis (DPA) attack on the insecure coprocessor requires only 8,000 acquisitions to disclose the entire 128b secret key. The same attack on the secure coprocessor still does not disclose the entire secret key at 1,500,000 acquisitions. This improvement in DPA resistance of at least 2 orders of magnitude makes the attack de facto infeasible. The required number of measurements is larger than the lifetime of the secret key in most practical systems.