Polynomial direct sum masking to protect against both SCA and FIA

Claude Carlet,Abderrahman Daif,Sylvain Guilley,Cédric Tavernier
DOI: https://doi.org/10.1007/s13389-018-0194-9
2018-08-31
Journal of Cryptographic Engineering
Abstract:Side-channel attacks (SCAs) and fault injection attacks (FIAs) allow an opponent to have partial access to the internal behavior of the hardware. Since the end of the 1990s, many works have shown that this type of attacks constitutes a serious threat to cryptosystems implemented in embedded devices. In the state of the art, there exist several countermeasures to protect symmetric encryption (especially AES-128). Most of them protect only against one of these two attacks (SCA or FIA). A method called ODSM has been proposed to withstand SCA and FIA, but its implementation in the whole algorithm is a big open problem when no particular hardware protection is possible. In the present paper, we propose a practical masking scheme specifying ODSM which makes it possible to protect the symmetric encryption against these two attacks.
computer science, theory & methods
What problem does this paper attempt to address?