← 返回 JSSC 论文列表JSSC 2022第1期Power ManagementEqualizer
Syn-STELLAR: An EM/Power SCA-Resilient AES-256 With Synthesis-Friendly Signature Attenuation Archisman Ghosh , Debayan Das , Student Member , IEEE, Josef Danial , Student Member , IEEE
Syn-STELLAR提出了一种抗侧信道攻击的AES-256加密技术,通过数字友好的电流源和反馈机制提升安全性。
MTD从10M提升至250M
侧信道攻击AES-256数字控制环形振荡器时变传递函数
▸创新点1:数字友好的电流源和数字控制回路(电路创新)。采用全数字设计的电流源和控制回路,显著提高了技术节点的可扩展性,使MTD(最大耐受攻击次数)从10M提升至250M,实现了25倍的性能提升。
▸创新点2:环形振荡器(RO)作为局部和全局反馈(系统创新)。RO不仅作为泄漏旁路路径,还通过频率调节实现AES节点电压的动态调整,集成了局部负反馈(LNFB)和全局反馈功能,增强了安全性和适应性。
▸创新点3:时变传递函数(TVTF)技术(方法创新)。通过消除电流域均衡器的直流偏置需求,并采用开关电容电路实现时域混淆,显著提升了安全性,使MTD达到>1.25B,比现有技术高出25%。
▸创新点4:合成友好的签名衰减嵌入式加密(系统创新)。结合DSAC和TVTF技术,首次实现了可综合的高安全性防护方案,支持低层金属布线,为实际应用提供了更高的灵活性和可扩展性。
Abstract
Mathematically secure cryptographic algorithms leak meaningful side-channel information in the form of corre- lated power and electromagnetic (EM) signals, leading to physical side-channel analysis (SCA) attacks. Circuit-level countermea- sures against power/EM SCA include a current equalizer, IVR, non-linear LDOs, enhancing protection up to 10M traces, and current-domain signature atte nuation (CDSA), and randomized NL-LDO cascaded with arithmetic countermeasures achieved p r o t e c t i o nu pt o>1B. This work embraces the concept of analog CDSA but makes it easily scalable over technology nodes with digital-friendly current sources, digital control loop, and digital bleed path to increase the MTD from 10M to 250M (25× improvement, using a single digital countermeasure). Ring oscillator (RO) used as the bleed path to bypass encryption- dependent leakage acts as local negative feedback (LNFB). Besides, based on RO oscillation frequency, AES node voltage can be tuned at startup, PVT, or frequency variation. Thus, RO acts as integrated LNFB and global feedback for the digital signature attenuation circuit (DSAC). Another circuit technique, namely, the time-varying transf er function (TVTF), removes the requirement of dc bias in the current-domain equalizer (best switch capacitor-based countermeasure till date) to make it digital and utilizes switch cap-based circuit for time-domain obfuscation to achieve enhanced security. This work, namely, Syn-STELLAR: SYNthesis-friendly Sig