A secure and highly efficient first-order masking scheme for AES linear operations

来源 :网络空间安全科学与技术(英文版) | 被引量 : 0次 | 上传用户:heguojing514
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Due to its provable security and remarkable device-independence,masking has been widely accepted as a noteworthy algorithmic-level countermeasure against side-channel attacks.However,relatively high cost of masking severely limits its applicability.Considering the high tackling complexity of non-linear operations,most masked AES implementations focus on the security and cost reduction of masked S-boxes.In this paper,we focus on linear operations,which seems to be underestimated,on the contrary.Specifically,we discover some security flaws and redundant processes in popular first-order masked AES linear operations,and pinpoint the underlying root causes.Then we propose a provably secure and highly efficient masking scheme for AES linear operations.In order to show its practical implications,we replace the linear operations of state-of-the-art first-order AES masking schemes with our proposal,while keeping their original non-linear operations unchanged.We implement four newly combined masking schemes on an Intel Core i7-4790 CPU,and the results show they are roughly 20%faster than those original ones.Then we select one masked implementation named RSMv2 due to its popularity,and investigate its security and efficiency on an AVR ATMega1 63 processor and four different FPGA devices.The results show that no exploitable first-order side-channel leakages are detected.Moreover,compared with original masked AES implementations,our combined approach is nearly 25%faster on the AVR processor,and at least 70%more efficient on four FPGA devices.
其他文献
肠内营养是重症病人临床治疗不可或缺部分,权威指南均指出早期启动肠内营养是改善疾病预后的关键。将指南理论落实到具体临床实践中,是提高和推动重症病人规范化肠内营养实施的关键。基于多年危重病人肠内营养实施的临床实践及理论基础,笔者团队在“5W1H”思维框架下总结出“一患一策,循环评估,通道基础,质量兼顾,爬坡达标”的肠内营养实施策略。“,”Enteral nutrition is an indispensable part of the treatment for critically ill patients
球头销是汽车的安保件,关系到驾乘人员的生命安全,如有缺陷,尤其是裂纹缺陷,将严重影响汽车的安全状态,进而影响人的生命安全,因此严格控制球头销出现裂纹显得愈加重要.rn我公司生产的40Cr材质球头销楔横轧件,毛坯图如图1所示,外委调质时发现批量裂纹,更换调质厂家仍有批量裂纹出现(图2),经过大量分析验证,找到了裂纹原因.
期刊
重症病人早期肠内营养至关重要,然而其临床实践仍充满挑战。中国腹腔重症协作组9家医院25位专家,针对重症病人胃肠功能障碍的病因及评估、早期肠内营养实施策略,以及各种临床实践中的具体方案进行讨论,并提出18项临床最为关注的问题,综合循证医学证据及临床经验,最终制订该共识,旨在为临床医师提供参考及指导,以期改善病人预后。“,”Early enteral nutrition plays an important role in the management of critically ill patients,
随着汽车更新迭代周期不断缩短,对冲压模具新车型调试周期提出了更高的考验,从模具加工制造后回厂至实现量产的周期逐渐压缩至三个月,因此如何最大化利用冲压生产线的调试工时便是重中之重.冲压生产线调试阶段主要包含自动化调试、面品改善、试制装车、精度改善等.其中自动化调试阶段作为首个关卡,其效率直接影响整个模具调试周期的效率及人员积极性.自动化调试阶段可归纳为端拾器制作(工时约占70%)、机器人轨迹调试(工时约占25%)、程序配方调试(工时约占5%)三个步骤.
期刊
鉴于锻造行业不断增加的成本压力,锻造生产线的制造商也被要求发展创新,以节约现有资源.这些概念必须提供机会,以满足许多代加工厂商在减少二氧化碳排放方面的要求.因此,提高感应加热系统的能效至关重要,是感应加热系统持续进一步发展的关键环节.rn德国每年生产约230万吨热成形锻件,加热锻造材料的能耗需求约为每年1000GWh,这意味着:即使能源成本仅为0.10欧元/kWh时,每年总计花费也要达到1亿欧元.现有数据表明,感应加热装置的制造商尤其被要求进行智能概念的节能型感应加热系统开发.
期刊
翼子板工艺面优化设计rn针对上述五大危害,如何采取措施消除?rn过拉延设计rn与保险杠匹配的棱线R角,一般为R3mm,不足以支持拉延.拉延造型设计扩大到R5mm~R6mm,侧立面扩张2,0 ~ 2.5mm,后工序整形到产品R3mm,如图6所示,翼子板头部拉延工艺设计(翼子板头部截面图,来源于图5(a)中的A-A截面),图6(a)所示为翼子板头部拉延工艺设计,图6(b)所示为翼子板棱线过拉延局部放大.
期刊
C 70E下侧门板生产工序为:裁料→校平→剪切→压形→落料,其产品质量已处于铁路行业的中游,有必要重新审视,设计复合模具,提高整机产品质量的档次.rn工艺分析rn生产现状rnC70E下侧门压形模具(C103-1807-00-00)原在4000t水压机(现已报废)上使用,现在2600t油压机上使用,详见图1,需要4名操作者,落料模具(C107-1763-00-00)在2000t冲床上使用,详见图2,需要4名操作者,2600t油压机和2000t冲床分布在2个厂房,压形和落料两道工序之间需要4次跨厂房物料倒运,
期刊
While consumers use the web to perform routine activities,they are under the constant threat of attack from malicious websites.Even when visiting\'trusted\'sites,there is always a risk that site is compromised,and,hosting a malicious script.In this sc
营养支持治疗可改善消化道恶性肿瘤病人术后营养状况和生命质量。国内外临床指南建议对恶性肿瘤手术病人术前施行早期以口服营养补充为主的营养支持治疗,以减少营养不良风险。肠内营养粉剂是胃肠道功能基本正常病人围手术期的主要营养支持方法。目前众多Meta分析结果显示:术后早期肠内营养能有效增强机体免疫功能、减少术后并发症和缩短住院时间,但近期结局指标分析不全面,且目前尚无关于中国病人的汇总分析结果。笔者查阅相关文献,采用Meta分析评价肠内营养粉剂对中国消化道恶性肿瘤病人术后近期疗效的影响。“,”Nutritiona
Gradual increase in the number of successful attacks against Industrial Control Systems(ICS)has led to an urgent need to create defense mechanisms for accurate and timely detection of the resulting process anomalies.Towards this end,a class of anomaly det