42
T. Oder et al.
where μ F , σ 2
F , and n F (resp. μ R , σ 2
R , and n R ) denote the mean, variance, and
number of measurements set with fixed input (resp. random input). If the value
exceeds the threshold |t| > 4.5, the test has detected leakage. For more information,
we refer the interested reader to further literature related to this side-channel
evaluation methodology [51].
We measured the computation of the butterfly during the NTT for two coefficients, the addition of the two shares during the masked re-encryption as described
in Sect. 2.3.2 for one coefficient, the remasking and decoding as described in
Sect. 2.3.2 for four coefficients (that encode one bit), the masked χ -step of KECCAK
for five bytes, point-wise multiplication and addition for two coefficients, two
bits for the sampler, and 12 bytes for the comparison. To reduce the number of
measured sample points per trace, we split the decoding into one measurement of the
modulus transformation (Algorithm 1) and one measurement of the final operations
as described in Algorithm 2. Figure 2.4 depicts the results for each module. The
lower (resp. upper) curve shows the maximum absolute value of the first-order (resp.
second-order) test as a function of the total number of measurements considered in
the evaluation. It is noticeable that indeed no first-order leakage could be measured
up to 100,000 traces. There is also no obvious increase of the t-values. Thus, the
implementation showed first-order protection as expected. Additionally, the secondorder evaluation shows leakage early on for every module and displays an upward
trend with higher number of measurements. This is also expected given that we
implemented first-order masking.
2.6 Results and Comparison
We evaluate the performance of our implementation using Keil μVision V5.17
and use -O3 optimization for compiling. We took special care to prevent effects
that the compiler optimization itself could induce side-channel leakage, e.g., by
overwriting one shared value in a register with the second share. Cycle counts are
measured using the on-board cycle count register (DWT_CYCCNT). To measure the
dynamic memory consumption we used the callgraph feature of the Keil IDE. We
present the cycle counts of our implementation in Table 2.1. The CCA2-secured
encryption takes 4,176,684 cycles which translates to 25 ms when operating at a
clock frequency of 168 MHz. The key generation takes 16 ms at 168 MHz.
Applying the CCA2-conversion to the decryption causes a much higher overhead
due to the necessary re-encryption. In the unmasked case, it requires 27 times
more cycles and in the masked case 46 times more cycles. Thus, the masked
CCA2-decryption takes 25,334,493 cycles which is an overhead factor of 5.7
compared to the CCA2-secured decryption without masking. The overhead cost for
the masking of the CCA2-secured decryption is mainly due to the high cost of the
sampling. The sampling in turn heavily depends on the performance of the PRNG.
A suitable replacement for SHAKE-128 would therefore drastically improve the
Précédent

- 50/268

Suivant