A Table-Lookup Threshold Implementation Method for PRESENT Encryption and Decryption

ThePRESENT encryption and decryption threshold implementation scheme addresses vulnerabilities to side-channel attacks by employing input selection layers and non-linear transformations, ensuring secure operations on hardware platforms.

CN119513894BActive Publication Date: 2025-07-15NANJING UNIV OF SCI & TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411647218.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2025-07-15
Estimated Expiration
2044-11-18

AI Technical Summary

Technical Problem

In the prior art, the decryption part of the PRESENT algorithm lacks an effective threshold implementation solution, cannot resist side channel attacks, and there is no phenotype threshold implementation solution for hardware implementation, resulting in security risks in application scenarios where two-way encryption and decryption operations are required.

Method used

A PRESENT cryptographic decryption threshold implementation scheme is proposed, and a phenotype threshold implementation method is adopted, including input selection layer, first layer to fifth layer of the wheel function, and nonlinear operations of encryption and decryption are implemented in parallel. The threshold implementation of the nonlinear function F-1 of the decrypted part is derived through the S-box quadratic decomposition, and the register layer is added to avoid information leakage.

Benefits of technology

It realizes side channel attack protection for encryption and decryption of the PRESENT algorithm, and is suitable for FPGA and ASIC hardware platforms. It can resist first-order side channel attacks and higher-order zero-offset side channel attacks, improving hardware security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119513894B_ABST
    Figure CN119513894B_ABST
Patent Text Reader

Abstract

The present invention discloses a look-up table type threshold implementation method for PRESENT encryption and decryption, belonging to the field of cryptographic hardware design. The present invention includes an input selection layer, a first layer of round function, a second layer of round function, a third layer of round function, a fourth layer of round function, and a fifth layer of round function; first, based on the secondary decomposition of the S-box in the encryption part, the secondary decomposition derivation of the S-box inverse is carried out; then the threshold implementation of the non-linear function F in the decryption part is derived. ‑1 Based on the S-box decomposition in the encryption part, the present invention gives the inverse decomposition of the S-box in the decryption part, and also gives the look-up table type encryption and decryption threshold implementation method, which is applicable to the application scenarios that require both encryption and decryption for two-way operations; this method can be applied to various hardware platforms such as FPGA and ASIC to implement PRESENT.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cryptographic hardware design, and particularly relates to a look-up table type threshold implementation method for PRESENT encryption and decryption. Background Art

[0002] During the operation of cryptographic hardware, various forms of information leakage such as energy consumption, electromagnetic radiation, execution time, cache access pattern, etc. will occur. The analysis methods for using this information leakage to recover sensitive information such as keys are collectively referred to as side-channel attacks (or side-channel analysis). After nearly 30 years of development, side-channel attacks have been proven to be applicable to attacking all or most symmetric and asymmetric cryptographic algorithm implementations on various types of hardware platforms such as FPGAs, smart cards, processors, and graphics processing units, posing a serious threat to the security of chips. Therefore, the design of cryptographic hardware resistant to side-channel attacks is essential. With the development of side-channel attack technology, the security threats caused by side-channel attacks are becoming increasingly large, attracting the attention of international scholars in the academic and industrial circles. In 2012, the international standard cryptographic ISO / IEC 19790 "Security Technical Requirements for Cryptographic Modules" promulgated by the International Organization for Standardization (ISO) separately regarded non-invasive attacks mainly based on side-channel attacks as a security domain and gave a distinction of four security levels. Affected by the actual attack security threats and the common security requirements of international national standards, whether it can resist side-channel attacks has become one of the problems that cryptographic hardware must face.

[0003] The ultra-lightweight block cipher algorithm PRESENT in the prior art is designed specifically for resource-constrained environments (such as RFID tags and sensor networks). In 2019, the PRESENT algorithm was selected as a lightweight cipher algorithm, and its corresponding international standard is ISO / IEC 29192-2:2019.

[0004] Based on the design idea of multi-party secure computation in the prior art, a mask scheme resistant to Glithch-Free, Threshold Implementation (TI) is proposed. Threshold implementation does not provide a definite algorithm, but clarifies three core constraints: correctness, non-completeness, and uniformity. In other words, any construction that satisfies these conditions can be regarded as a threshold implementation scheme. In threshold implementation, the number of sharing factors is determined by t(d + 1), where t is the algebraic degree of the non-linear function and d is the order of resistance to side-channel attacks. Threshold Implementation (TI) well solves the problem of glitches in mask hardware design and can avoid first-order leakage.

[0005] In the prior art, for PRESENT encryption, an affine computation-based threshold implementation scheme is given by combining a masking scheme and a hiding scheme, and this scheme is suitable for hardware implementation. For PRESENT encryption in the prior art, a look-up table-based threshold implementation scheme is given by pre-computing the look-up table results corresponding to the non-linear part, and this scheme is suitable for software implementation. In the above prior art, only the threshold implementation of PRESENT encryption is given, and the threshold implementation of PRESENT decryption is not given, and there is no look-up table-based threshold implementation scheme for hardware implementation.

[0006] However, the threshold implementation scheme for PRESENT decryption is also essential. On the one hand, since the PRESENT algorithm adopts the SPN structure, the non-linear function of its decryption part is different from that of the encryption part. Therefore, the protection scheme for the decryption part cannot be directly obtained from the protection scheme for the encryption part. On the other hand, from the perspective of algorithm integrity, the decryption part is also vulnerable to side-channel attacks. For the integrity and availability of data, in most scenarios such as secure communication, data storage, user authentication, security protocols, key distribution, and end-to-end encryption, two-way operations of encryption and decryption are involved. Therefore, the present invention provides an encryption and decryption threshold implementation scheme for the PRESENT cryptographic algorithm, including two implementation methods: computation-based and look-up table-based. Summary of the Invention

[0007] In view of the problems mentioned in the background art, the present invention proposes an encryption and decryption threshold implementation scheme for the PRESENT cryptographic algorithm, which solves the problem that the existing PRESENT only gives the encryption threshold implementation, is applicable to application scenarios that require two-way operations of both encryption and decryption, and can resist first-order side-channel attacks and high-order zero-offset side-channel attacks.

[0008] Technical Solution: To solve the above technical problems, the technical solution adopted by the present invention is as follows:

[0009] A look-up table-based threshold implementation method for PRESENT encryption and decryption includes an input selection layer, a first round function layer, a second round function layer, a third round function layer, a fourth round function layer, and a fifth round function layer;

[0010] The input selection layer: parallelly implements the input selection of three shared factors;

[0011] The first round function layer: implements the function of adding round key;

[0012] The second round function layer: parallelly implements the T layer of encryption, the P -1 layer of decryption, and the A''' -1 layer of decryption;

[0013] The third layer of the round function: The encrypted A”’ layer, the encrypted P layer, and the decrypted 2:1 MUX layer are implemented in parallel;

[0014] The fourth layer of the round function: The encrypted 2:1 MUX layer and the decrypted T -1 layer;

[0015] The fifth layer of the round function: The output selection of three shared factors is implemented;

[0016] First, based on the quadratic decomposition of the S-box in the encryption part, the quadratic decomposition derivation of the S-box inverse is carried out;

[0017] Then, the threshold implementation of the decryption part non-linear function F -1 is derived.

[0018] Preferably, the specific content of the quadratic decomposition derivation of the S-box inverse based on the quadratic decomposition of the S-box in the encryption part is as follows:

[0019] The known quadratic decomposition based on the S-box in the encryption part;

[0020] Based on the S-box decomposition function of PRESENT, the decomposed S-box is expressed as: where A”, A', and A are all 4-bit affine transformations, specifically as follows:

[0021] A = 01AB892345EFCD67, A' = 0B835ED61A924FC7, A” = C98D6327AFEB0541 Let Then the S-box is expressed as:

[0022]

[0023] where A”' = 8FDACB9E43160752, Q 12 The expression is:

[0024]

[0025] where a, b, c, and d are the input 4-bit data, and each letter represents 1-bit data; e, f, g, and h are the output 4-bit data, and each letter represents 1-bit data;

[0026] The quadratic decomposition derivation of the S-box inverse is carried out, specifically as:

[0027] Since From Q 12 F is derived, and the transformation corresponding to F is expressed as C905AF8D63EB4127;

[0028] The decomposition result of the S-box inverse is derived from formula (1), specifically as:

[0029]

[0030] Among them, S -1 represents the inverse of the S-box; F -1 represents the inverse of the F function; A -1 represents the inverse of the affine transformation A; A” -1 represents the inverse of the affine transformation A”;

[0031] Derive Q 12 from Q 12 to obtain the inverse function Q 12 -1 , specifically:

[0032]

[0033] Calculate F -1 corresponding to the transformation 2DE9C38F614B07A5 according to formulas (3) and (4).

[0034] Preferably, the specific content of the threshold implementation of the decryption part non-linear function F -1 is as follows:

[0035] The threshold implementation of the encryption part non-linear function F is expressed as T(x i , x j ) = A”((Q 12 )) i,j (A(x i ), A(x j )));

[0036]

[0037] The inputs of T(x i , x j ) are xi and xj, where xi and xj respectively represent the 4-bit inputs of the i-th and j-th sharing factors; first, through the affine transformation A, A(x i ), A(x j ) are obtained and used as the two inputs of (Q 12 ) i,j for the operation of (Q 12 ) i,j ; then, through the affine transformation A”, a corresponding 4-bit shared output T is obtained;

[0038] Derive the threshold implementation T -1 of the decryption part non-linear function F -1 , and the formula is T -1 (x i , x j ) = A -1 (Q12 -1 (A” -1 (x i ),A” -1 (x j ))),specifically:

[0039] Give Q according to formula (4) and formula (5) 12 -1 The corresponding threshold implementation:

[0040]

[0041] where x i ,x j respectively represent the 4-bit inputs of the i-th and j-th sharing factors; first, through the affine transformation A” -1 ,obtain A” -1 (x i ),A” -1 (x j ), and use them as the two inputs of (Q 12 -1 ) i,j for the operation of (Q 12 -1 ) i,j ,and then through the affine transformation A -1 ,obtain a 4-bit shared output T -1 .

[0042] Preferably, in the first cycle, perform the input selection layer operation; the input selection layer includes 3 2:1 MUX layers, and the control signal of the 2:1 MUX layer is the initial round valid signal f2. In the initial state, f2 = 1, and the initial inputs P1, P2, and P3 are respectively selected as the outputs dreg1, dreg2, and dreg3; in the next 1 - 62 cycles, f2 = 0, and the round function inputs dat10_1, dat10_2, and dat10_3 are respectively selected as the outputs dreg1, dreg2, and dreg3.

[0043] Preferably, the first layer of the round function includes 3 registers, 1 round key addition addRK, and 1 2:1 MUX layer; the outputs of the 3 registers are the 3 outputs of the input selection layer; addRK is the round key addition operation, indicating the exclusive OR operation between the round key rk[i], i ∈ [1, 2,..., 32] and the output dreg1 of the first register;

[0044] The control signal of the 2:1 MUX layer is the odd-cycle valid signal f1. When executed in the even-numbered cycles, f1 = 1, and the data after the round key addition addRK is selected as the output dat1_1. When executed in the odd-numbered cycles, f1 = 0, and dreg1 is directly selected as the output dat1_1. In the 1st to 62nd cycles, dat1_2 is directly equal to dreg2, and dat1_3 is directly equal to dreg3.

[0045] Preferably, the second layer of the round function includes 3 T layers, 3 P -1 layers and 3 A''' -1 layers;

[0046] The T layer represents 2 64-bit inputs, which are respectively divided into 16 4-bit inputs, and then operate according to the T function;

[0047] P -1 The layer represents that the 64-bit input is successively divided into 16 4-bit inputs, and then operates according to the P -1 function;

[0048] A''' -1 The layer represents that the 64-bit input is successively divided into 16 4-bit inputs, and then operates according to A''' -1 = CAF98EBD06354271 function;

[0049] Preferably, the third layer of the round function includes 3 A''' layers, 3 P layers and 3 2:1 MUX layers;

[0050] The A''' layer represents that the 64-bit input is successively divided into 16 4-bit inputs, and then operates according to A''' = 8FDACB9E43160752 function;

[0051] The P layer represents that the 64-bit input is successively divided into 16 4-bit inputs, and then operates according to the P function;

[0052] The control signal of the 2:1 MUX layer is the odd-cycle valid signal f1. When executed in the even-numbered cycles, f1 = 1, and dat5_1, dat5_2, dat5_3 are selected as the outputs dat7_1, dat7_2, dat7_3. When executed in the odd-numbered cycles, f1 = 0, and dat6_1, dat6_2, dat6_3 are selected as the outputs dat7_1, dat7_2, dat7_3.

[0053] Preferably, the fourth layer of the round function includes 3 2:1 MUX layers, 3 T -1 layers;

[0054] 2. The control signal of the 2:1 MUX layer is the odd-cycle valid signal f1. When executed in the even-numbered cycle, f1 = 1, and dat3_1, dat3_2, and dat3_3 are selected as the outputs dat9_1, dat9_2, and dat9_3. When executed in the odd-numbered cycle, f1 = 0, and dat4_1, dat4_2, and dat4_3 are selected as the outputs dat9_1, dat9_2, and dat9_3.

[0055] T -1 The layer represents 2 64-bit inputs, which are respectively divided into 16 4-bit inputs, and then operate according to the T -1 (a,b) function.

[0056] Preferably, the fifth layer of the round function includes 3 2:1 MUX layers;

[0057] The control signals of the 3 2:1 MUX layers are the encryption valid signal f. When encrypting, f = 1, and dat9_1, dat9_2, and dat9_3 are selected as the outputs dat10_1, dat10_2, and dat10_3. When decrypting, f = 0, and dat8_1, dat8_2, and dat8_3 are selected as the outputs dat10_1, dat10_2, and dat10_3.

[0058] Advantageous effects: Compared with the prior art, the present invention has the following advantages:

[0059] (1) The present invention proposes a look-up table-based threshold implementation method for PRESENT encryption and decryption, which uses 64 cycles to complete the encryption threshold implementation and 96 cycles to complete the decryption threshold implementation. This method can provide side-channel attack protection for the encryption and decryption of the PRESENT algorithm and can be applied to hardware platforms such as FPGA and ASIC.

[0060] (2) Compared with the software look-up table-based threshold implementation method for the encryption part given only in the reference prior art [SBM2018], the present invention focuses on giving the threshold implementation method for the decryption part and adds a register layer. In the same cycle, it is ensured that there is only one non-linear operation, avoiding glitch leakage attacks and being suitable for hardware side-channel attack protection.

[0061] (3) The present invention gives the PRESENT-TI implementation, which uses 1693 LUTs and 289 Reg on the Kintex7 device, and the encryption / decryption throughput reaches 316.46 Mbps, and the throughput per unit area is 186.92 Kbps / LUT.

[0062] (4) Perform side-channel security evaluation on the power traces implemented by the PRESENT-TI IP core of the present invention collected on the SAKURA-X development board. Use 3 million power traces for test vector leakage evaluation detection. The results show that there is no first-order information leakage and second-order to fourth-order zero-offset information leakage in the PRESENT-TI IP core proposed by the present invention. Therefore, the PRESENT-TI IP core proposed by the present invention can resist first-order side-channel attacks and high-order zero-offset side-channel attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 It is a schematic circuit design diagram of the look-up table type threshold implementation of PRESENT encryption and decryption of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0064] The following further clarifies the present invention in conjunction with specific embodiments. The embodiments are implemented on the premise of the technical solution of the present invention. It should be understood that these embodiments are only used to illustrate the present invention and not to limit the scope of the present invention.

[0065] The look-up table type threshold implementation method of PRESENT encryption and decryption provided in this embodiment is mainly applied to the field of cryptographic hardware design, and has bidirectional operations including encryption and decryption; at the same time, it can resist side-channel attacks. This method can be applied to various hardware platforms such as FPGA and ASIC to implement PRESENT. Its specific implementation content includes:

[0066] S1: First, based on the quadratic decomposition of the S-box in the encryption part, perform the derivation of the quadratic decomposition of the S-box inverse.

[0067] S11: The known quadratic decomposition of the S-box in the encryption part;

[0068] Taking the quadratic decomposition of as an example, based on the S-box decomposition function of PRESENT, the decomposed S-box can be expressed as:

[0069] where A”, A', and A are all 4-bit affine transformations, specifically as follows: Let

[0070]

[0071] where A''' = 8FDACB9E43160752, Q 12 The expression is:

[0072]

[0073] Among them, a, b, c, and d are the 4-bit data inputs, and each letter represents 1-bit data; e, f, g, and h are the 4-bit data outputs, and each letter represents 1-bit data.

[0074] S12: Conduct the second decomposition derivation of the inverse S-box.

[0075] Since Therefore, F can be derived from Q 12 The corresponding transformation of F can be expressed as C905AF8D63EB4127.

[0076] The decomposition result of the inverse S-box can be derived from formula (1), specifically:

[0077]

[0078] Among them, S -1 represents the inverse S-box; F -1 represents the inverse F function; A -1 represents the inverse of the affine transformation A; A” -1 represents the inverse of the affine transformation A”.

[0079] From Q 12 the inverse function Q 12 can be derived, specifically as shown in formula (4): 12 -1

[0080]

[0081] According to formulas (3) and (4), the transformation corresponding to F -1 can be calculated as 2DE9C38F614B07A5.

[0082] S2: Give the threshold implementation method of the decryption part non-linear function F -1 ;

[0083] S21: The threshold implementation of the known encryption part non-linear function F;

[0084] The threshold implementation of the encryption part non-linear function F is expressed as T(x i , x j ) = A”(Q 12 (A(x i ), A(x j ))).

[0085]

[0086] T(x i , x j) The inputs are xi and xj, where xi and xj respectively represent the 4-bit inputs of the i-th and j-th sharing factors; first, through an affine transformation A, we get A(x i ), A(x j ), and use them as the two inputs of (Q 12 ) i,j to perform the operation of (Q 12 ). The specific calculation process is shown in formula (5); then, through an affine transformation A”, we get a corresponding 4-bit shared output T. This is the calculation process corresponding to T(x i,j , x i , x j ) = A”(Q 12 (A(x i ), A(x j )). Based on this, the truth table of 8-bit input and 4-bit output can be deduced.

[0087] S22: Deduce the threshold implementation T -1 of the decryption part non-linear function F -1 , and the formula is T -1 (x i , x j ) = A -1 (Q 12 -1 (A” -1 (x i ), A” -1 (x j )), specifically:

[0088] According to formula (4) and formula (5), give the threshold implementation (Threshold Implementation, TI) corresponding to Q 12 -1 :

[0089]

[0090] Among them, x i , x j respectively represent the 4-bit inputs of the i-th and j-th sharing factors. First, through an affine transformation A” -1 , we get A” -1 (x i ), A” -1 (x j ), and use them as the two inputs of (Q 12 -1 ) i,j to perform the operation of (Q 12 -1 ), and then through an affine transformation A i,j operation, and then through an affine transformation A -1, a 4-bit shared output T is obtained -1 . This is T -1 (x i , x j ) = A -1 (Q 12 -1 (A” -1 (x i ), A” -1 (x j ))) corresponding calculation process, by which the truth table of 8-bit input and 4-bit output can be deduced;

[0091] A -1 = 016789EF4523CDAB

[0092] A” -1 = CF65ED47218B03A9

[0093] A”' -1 = CAF98EBD06354271

[0094] To avoid information leakage caused by input correlation, register operations are added after the non-linear operation. S3: Give a complete table-lookup type threshold implementation method for PRESENT encryption and decryption.

[0095] A”' -1 = CAF98EBD06354271

[0096] Table 1 PRESENT Encryption and Decryption Threshold Implementation

[0097]

[0098]

[0099] Among them, rk[i] ← KeySchedule(k) represents the key generation of PRESENT, which is consistent with the traditional key generation. The difference is that each round key maintains 2 cycles, and Register represents adding a register layer to the output of the previous step.

[0100] In this embodiment, taking Taking the secondary decomposition as an example, the S-box decomposition function based on PRESENT is prior art. The publicly published literature for reference is as follows: [SMG2015] Pascal Sasdrich, Amir Moradi, Tim Güneysu. Affine Equivalence and Its Application to Tightening Threshold Implementations. SAC 2015: 263 - 276.

[0101] In this embodiment, T(x i ,x j ) = A”(Q 12 (A(x i ), A(x j ))) The corresponding truth table is prior art. The publicly published literature for reference is as follows: [SBM2018] Pascal Sasdrich, René Bock, Amir Moradi. Threshold Implementation in Software - Case Study of PRESENT. COSADE 2018: 227 - 244.

[0102] The threshold implementation includes an input selection layer, the first layer of the round function, the second layer of the round function, the third layer of the round function, the fourth layer of the round function, and the fifth layer of the round function. As Figure 1 shown.

[0103] Input selection layer: Three input selections with shared factors are implemented in parallel.

[0104] The first layer of the round function: Implements the function of adding the round key.

[0105] The second layer of the round function: Implements the encrypted T layer, the decrypted P -1 layer, and the decrypted A”’ -1 layer in parallel.

[0106] The third layer of the round function: Implements the encrypted A”’ layer, the encrypted P layer, and the decrypted 2:1 MUX layer in parallel.

[0107] The fourth layer of the round function: Implements the encrypted 2:1 MUX layer and the decrypted T -1 layer in parallel.

[0108] The fifth layer of the round function: Implements the output selection of three shared factors.

[0109] Input selection layer: In the first cycle, the input selection layer operation is performed. The input selection layer includes three 2:1 MUXes (2-to-1 multiplexers). The control signal of the 2:1 MUX is the initial round valid signal f2. In the initial state, f2 = 1, and the left initial inputs P1, P2, and P3 are respectively selected as the outputs dreg1, dreg2, and dreg3. In the following cycles from the 1st to the 62nd, f2 = 0, and the right-round function inputs dat10_1, dat10_2, and dat10_3 are respectively selected as the initial round outputs dreg1, dreg2, and dreg3. P1, P2, and P3 are respectively the three shared factor inputs of the threshold implementation circuit. Among them, P2 and P3 are 64-bit random numbers, P is a 64-bit plaintext, represents the XOR operation; dat10_1, dat10_2, and dat10_3 are the inputs of the round function.

[0110] In the 2nd to the 63rd cycles, in each cycle, the first layer of the round function, the second layer of the round function, the third layer of the round function, the fourth layer of the round function, the fifth layer of the round function, and the input selection layer are sequentially executed.

[0111] First layer of the round function: It includes three registers, one round key addition addRK, and one 2:1 MUX. The outputs of the three registers are the three outputs of the input selection layer, namely dreg1, dreg2, and dreg3. The control signal of the 2:1 MUX is the odd cycle valid signal f1. When executed in the 2nd, 4th, 6th, ……, 62nd cycles, f1 = 1, and the data processed by the round key addition addRK is selected as the output dat1_1. When executed in the 3rd, 5th, ……, 63rd cycles, f1 = 0, and dreg1 is directly selected as the output dat1_1. In the first to the 62nd cycles, dat1_2 is directly equal to dreg2, and dat1_3 is directly equal to dreg3.

[0112] addRK is the round key addition operation, which represents the XOR operation between the round key rk[i], i ∈ [1, 2, …, 32] and the output dreg1 of the first register.

[0113] Second layer of the round function: It includes three T layers, three P -1 layers, and three A''' -1 layers, and the specific inputs are as Figure 1 shown.

[0114] The T layer represents two 64-bit inputs, which are respectively divided into 16 4-bit inputs, and then operated 16 times according to the T function to obtain 16 4-bit outputs, which are merged into a 64-bit output after merging. T is a truth table with 8-bit inputs and 4-bit outputs. The specific content is as follows.

[0115] As shown in Table 2, the input of the T function is 4-bit a and 4-bit b, with a total of 8-bit input. The values in the table are the 4-bit outputs for different values of a and b. The numbers in the table are all represented in hexadecimal.

[0116] Table 2 Truth table of the T function

[0117]

[0118]

[0119] P -1 The P layer means that the 64-bit input is sequentially divided into 16 4-bit inputs, and then operated according to the P -1 function.

[0120] P -1 The calculation of the P function is shown in Table 3, which means moving the 1-bit data corresponding to the input position x to the position corresponding to the output P -1 (x).

[0121] Table 3 Results corresponding to the P -1 function

[0122] x 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 <![CDATA[P -1 (x)]]> 0 4 8 12 16 20 24 28 32 36 40 44 48 52 56 60 x 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 <![CDATA[P -1 (x)]]> 1 5 9 13 17 21 25 29 33 37 41 45 49 53 57 61 x 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 <![CDATA[P -1 (x)]]> 2 6 10 14 18 22 26 30 34 38 42 46 50 54 58 62 x 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 <![CDATA[P -1 (x)]]> 3 7 11 15 19 23 27 31 35 39 43 47 51 55 59 63

[0123] A”’ -1 The A”’ layer means that the 64-bit input is sequentially divided into 16 4-bit inputs, and then operated according to A”' -1 = CAF98EBD06354271 function. The specific table is as follows.

[0124] Table 4 Truth table of the A”' -1 function

[0125] x 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 <![CDATA[A”' -1 (x)]]> C A F 9 8 E B D 0 6 3 5 4 2 7 1

[0126] The third layer of the round function: contains 3 A”’ layers, 3 P layers and 3 2:1 MUXs. The specific input is as Figure 1 shown.

[0127] The A”’ layer means that the 64-bit input is sequentially divided into 16 4-bit inputs, and then operated according to A”' = 8FDACB9E43160752 function. The specific table is as follows.

[0128] Table 5 Truth table of the A”' function

[0129] x 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 A”'(x) 8 F D A C B 9 E 4 3 1 6 0 7 5 2

[0130] The P layer means that the 64-bit input is sequentially divided into 16 4-bit inputs, and then operated according to the P function.

[0131] The calculation of the P function is shown in Table 6, which means moving the 1-bit data corresponding to the input position x to the position corresponding to the output P(x).

[0132] Table 6 Truth table of the P function

[0133] x 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 P(x) 0 16 32 48 1 17 33 49 2 18 34 50 3 19 35 51 x 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 P(x) 4 20 36 52 5 21 37 53 6 22 38 54 7 23 39 55 x 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 P(x) 8 24 40 56 9 25 41 57 10 26 42 58 11 27 43 59 x 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 P(x) 12 28 44 60 13 29 45 61 14 30 46 62 15 31 47 63

[0134] The control signals of the 3 2:1 MUXes are the odd-cycle valid signal f1. When executed in the 2nd, 4th, 6th,..., 62nd cycles, f1 = 1, and dat5_1, dat5_2, dat5_3 are selected as the outputs dat7_1, dat7_2, dat7_3; when executed in the 3rd, 5th,..., 63rd cycles, f1 = 0, and dat6_1, dat6_2, dat6_3 are selected as the outputs dat7_1, dat7_2, dat7_3.

[0135] The fourth layer of the round function: contains 3 2:1 MUXes and 3 T -1 layers, and the specific input and output are as Figure 1 shown.

[0136] The control signals of the 3 2:1 MUXes are the odd-cycle valid signal f1. When executed in the 2nd, 4th, 6th,..., 62nd cycles, f1 = 1, and dat3_1, dat3_2, dat3_3 are selected as the outputs dat9_1, dat9_2, dat9_3; when executed in the 3rd, 5th,..., 63rd cycles, f1 = 0, and dat4_1, dat4_2, dat4_3 are selected as the outputs dat9_1, dat9_2, dat9_3.

[0137] T -1 The T -1 layer means that 2 64-bit inputs are respectively divided into 16 4-bit inputs, and then operated 16 times according to the T -1 (a, b) function to obtain 16 4-bit outputs, which are combined into 64-bit outputs after merging. T -1 (a, b) is a function with 2 4-bit inputs and 4-bit outputs. The specific implementation by looking up the table is as follows.

[0138] As shown in Table 6, the input of the T -1 function is 4-bit a and 4-bit b, with a total of 8-bit inputs. The values in the table are the 4-bit outputs for different values of a and b. The numbers in the table are all represented in hexadecimal.

[0139] Table 7: Truth table of the T -1 function

[0140]

[0141] The fifth layer of the round function: It contains three 2:1 MUXes, and the specific input and output are as Figure 1 shown.

[0142] The control signals of the three 2:1 MUXes are the encryption valid signal f. When encrypting, f = 1, and dat9_1, dat9_2, and dat9_3 are selected as the outputs dat10_1, dat10_2, and dat10_3; when decrypting, f = 0, and dat8_1, dat8_2, and dat8_3 are selected as the outputs dat10_1, dat10_2, and dat10_3.

[0143] In the 64th cycle, the input selection layer and the first layer of the round function are executed. At this time, dat1_1, dat1_2, and dat1_3 of the first layer of the round function are used as the outputs dout1, dout2, and dout3.

[0144] In the key generation part, it is similar to the traditional key generation. The difference is that each round key is maintained for two cycles. Specifically, in the 2nd - 3rd cycles, rk[1] is used; in the 4th - 5th cycles, rk[2] is used;..., in the 60th - 61st cycles, rk

[30] is used, and in the 62nd - 63rd cycles, rk

[31] is used. In the last 64 cycles, rk

[32] is used.

[0145] Experimental results:

[0146] Xilinx ISE Design Suite 14.4 software is used for synthesis and implementation. For fairness, when synthesizing, the design goal and strategy are selected as Balanced, the optimization goal is Speed, the optimization effort is Normal, and the KeepHierarchy is No. The PRESENT hardware implementation performance evaluation is carried out on four FPGA devices: Xilinx Kintex7 XC7K160T (using 28nm process), Virtex5 XC5VLX50 (using 65nm process), Xilinx Spartan6 (using 45nm process), and Xilinx Spartan3E XC3S50 (using 90nm process).

[0147] Tables 8 - 11 give the synthesis results of the PRESENT encryption threshold implementation and the encryption and decryption threshold implementation on the four devices of Kintex7, Virtex5, Spartan6, and Spartan3E. The results include the corresponding key generation.

[0148] Table 8 Synthesis Results of PRESENT Implementation on Kintex7

[0149]

[0150] Table 9 Synthesis Results of Five PRESENT Implementations on Virtex5

[0151]

[0152] Table 10 Synthesis Results of Five PRESENT Implementations on Spartan6

[0153]

[0154] Table 11 Synthesis Results of Five PRESENT Implementations on Spartan3

[0155]

[0156] Table 12 gives the ratio of the PRESENT encryption / decryption threshold implementation to the encryption threshold implementation. For the look-up table-based threshold implementation, compared with the PRESENT encryption implementation, the area of the PRESENT encryption / decryption implementation increases by 0.84 - 1.10 times, the throughput rate decreases by 7% - 16%, and the throughput rate per unit area decreases by 53% - 60%.

[0157] Table 12 Ratio of PRESENT Encryption / Decryption Threshold Implementation to Encryption Threshold Implementation

[0158]

[0159]

[0160] The threshold of TVLA (Test Vector Leakage Assessment, for detecting information leakage) is set to 4.5. As shown in Table 13, when there are 100,000 energy traces, 1 million energy traces, and 3 million energy traces, the maximum value of TVLA of PRESENT-TI is less than 4.5, and it passes the first-order TVLA test, the second-order / third-order / fourth-order zero-offset TVLA tests. The PRESENT-TI scheme can resist first-order side-channel attacks and high-order zero-offset side-channel attacks. The reason for being able to resist side-channel attacks is that the threshold implementation scheme satisfies three properties: correctness, uniformity, and non-completeness, and these properties can ensure that the hardware implementation resists glitch leakage attacks.

[0161] Table 13 Maximum Value of TVLA Test for PRESENT Threshold Implementation

[0162]

[0163] Based on the S-box decomposition of the encryption part, the present invention gives the inverse decomposition of the S-box in the decryption part and proposes a look-up table-based threshold implementation method for PRESENT encryption and decryption. The present invention provides a look-up table-based encryption and decryption threshold implementation method, which is applicable to application scenarios that require both encryption and decryption for two-way operations. This method can be applied to various hardware platforms such as FPGA and ASIC to implement PRESENT.

[0164] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A look-up table type threshold implementation method for PRESENT encryption and decryption, characterized in that: It includes an input selection layer, the first layer of the round function, the second layer of the round function, the third layer of the round function, the fourth layer of the round function, and the fifth layer of the round function; The input selection layer: Parallelly implements the input selection of three shared factors; The first layer of the round function: Implements the function of round key addition; The second layer of the round function: The encrypted T layer, the decrypted P -1 layer, and the decrypted A''' -1 layer are implemented in parallel; The third layer of the round function: Parallelly implements the encrypted A''' layer, the encrypted P layer, and the decrypted 2:1 MUX layer; The fourth layer of the round function: The 2:1 MUX layer for encryption and the T layer for decryption are implemented in parallel. -1 layer; The fifth layer of the round function: Implements the output selection of three shared factors; First, based on the quadratic decomposition of the S-box in the encryption part, the quadratic decomposition derivation of the S-box inverse is carried out; Based on the quadratic decomposition of the S-box in the encryption part, specifically: The S-box is expressed as: wherein, A''' = 8FDACB9E43160752, Q 12 The expression is: Where a, b, c, d are the input 4-bit data, and each letter represents 1-bit data; e, f, g, h are the output 4-bit data, and each letter represents 1-bit data; Carry out the quadratic decomposition derivation of the S-box inverse, specifically: Since derived from Q 12 F is derived, and the corresponding transformation of F is represented as C905AF8D63EB4127; Derive the decomposition result of the S-box inverse from formula (1), specifically: Among them, S -1 represents the inverse of the S-box; F -1 represents the inverse of the F function; A -1 represents the inverse of the affine transformation A; A” -1 represents the inverse of the affine transformation A”. Derived from Q 12 Derive Q 12 Inverse function Q 12 -1 , specifically: Calculate F according to formulas (3) and (4). -1 The corresponding transformation is 2DE9C38F614B07A5; Then, the threshold implementation of the decryption part of the non-linear function F is derived. -1 is derived.

2. The table - look - up type threshold implementation method for PRESENT encryption and decryption according to claim 1, characterized in that: Derive the specific content of the threshold implementation of the decryption part of the non - linear function F -1 which is as follows: The threshold implementation of the encryption part of the non-linear function F is expressed as T(x i ,x j ) = A”((Q 12 ) i,j (A(x i ),A(x j ))); T(x i ,x j ) has an input of x i 、x j , x i 、x j Represent the 4-bit input of the i-th and j-th shared factors respectively; first, after affine transformation A, we get A(x i ),A(x j ), and as (Q 12 ) i,j The two inputs are (Q 12 ) i,j After the affine transformation A", a corresponding 4-bit shared output T is obtained; Derive the threshold implementation T of the decryption part non - linear function F -1 , where the formula for T is -1 T -1 (x i , x j ) = A -1 (Q 12 -1 (A” -1 (x i ), A” -1 (x j ))), specifically: Give Q according to formula (4) and formula (5). 12 -1 The corresponding threshold implementation: where x i and x j respectively represent the 4-bit inputs of the i-th and j-th shared factors; first, through the affine transformation A” -1 , we get A” -1 (x i ), A” -1 (x j ), and use them as the two inputs of (Q 12 -1 ) i,j for the (Q 12 -1 ) i,j operation. After that, through the affine transformation A -1 , we get a 4-bit shared output T -1 .

3. The method for implementing PRESENT encryption and decryption by look-up table threshold according to claim 1, characterized in that: In the first cycle, the input selection layer operation is executed; The input selection layer includes 3 2:1 MUX layers, and the control signal of the 2:1 MUX layer is the initial round valid signal f2. In the initial state, f2 = 1, and the initial inputs P1, P2, and P3 are respectively selected as the outputs dreg1, dreg2, and dreg3; In the next 1st to 62nd cycles, f2 = 0, and the round function inputs dat10_1, dat10_2, and dat10_3 are respectively selected as the outputs dreg1, dreg2, and dreg3.

4. The PRESENT encryption / decryption look-up table type threshold implementation method according to claim 1, characterized in that: The first layer of the round function contains 3 registers, 1 round key addition addRK, and 1 2:1 MUX layer; The outputs of the 3 registers are the 3 outputs of the input selection layer; addRK is the round key addition operation, indicating the exclusive OR operation between the round key rk[i], i ∈ [1, 2, …, 32] and the output dreg1 of the first register; The control signal of the 2:1 MUX layer is the odd cycle valid signal f1. When executed in the even cycle, f1 = 1, and the data processed by the round key addition addRK is selected as the output dat1_1; When executed in the odd cycle, f1 = 0, and dreg1 is directly selected as the output dat1_1; In the 1st to 62nd cycles, dat1_2 is directly equal to dreg2, and dat1_3 is directly equal to dreg3.

5. The PRESENT encryption / decryption table lookup type threshold implementation method according to claim 1, characterized in that: The second layer of the round function contains three T-layers, three P -1 -layers, and three A''' -1 -layers; The T layer represents 2 64-bit inputs, which are respectively divided into 16 4-bit inputs and then operated according to the T function; P -1 The layer represents dividing the 64-bit input into 16 4-bit inputs in sequence, and then operating according to the P -1 function; A”’ -1 The layer indicates that a 64-bit input is sequentially divided into 16 4-bit inputs, and then operated according to the -1 =CAF98EBD06354271 function.

6. The table - look - up type threshold implementation method for PRESENT encryption and decryption according to claim 5, characterized in that: The third layer of the round function contains 3 A''' layers, 3 P layers, and 3 2:1 MUX layers; The A''' layer represents dividing the 64-bit input into 16 4-bit inputs in sequence and then operating according to the function A''' = 8FDACB9E43160752; The P layer represents dividing the 64-bit input into 16 4-bit inputs in sequence and then operating according to the P function; The control signal of the 2:1 MUX layer is the odd-cycle valid signal f1. When executed in the even-numbered cycle, f1 = 1, and dat5_1, dat5_2, and dat5_3 are selected as the outputs dat7_1, dat7_2, and dat7_3; when executed in the odd-numbered cycle, f1 = 0, and dat6_1, dat6_2, and dat6_3 are selected as the outputs dat7_1, dat7_2, and dat7_3.

7. The PRESENT encryption / decryption look-up table type threshold implementation method according to claim 6, characterized in that: The fourth layer of the round function contains three 2:1 MUX layers and three T -1 layers; The control signal of the 2:1 MUX layer is the odd-cycle valid signal f1. When executed in the even-numbered cycle, f1 = 1, and dat3_1, dat3_2, and dat3_3 are selected as the outputs dat9_1, dat9_2, and dat9_3; when executed in the odd-numbered cycle, f1 = 0, and dat4_1, dat4_2, and dat4_3 are selected as the outputs dat9_1, dat9_2, and dat9_3; T -1 The layer represents two 64-bit inputs, which are respectively divided into 16 4-bit inputs, and then operate according to the -1 (a, b) function.

8. The look-up table type threshold implementation method for PRESENT encryption and decryption according to claim 7, characterized in that: The fifth layer of the round function contains three 2:1 MUX layers; The control signals of the three 2:1 MUX layers are the encryption valid signal f. When encrypting, f = 1, and dat9_1, dat9_2, and dat9_3 are selected as the outputs dat10_1, dat10_2, and dat10_3; when decrypting, f = 0, and dat8_1, dat8_2, and dat8_3 are selected as the outputs dat10_1, dat10_2, and dat10_3.

Citation Information

Patent Citations

  • Shared encryption and decryption AES hardware implementation method based on polynomial basis

    CN118473645A