The invention discloses a low-overhead anti-
power analysis AES (
advanced encryption standard)
algorithm mask protection method. According to the method, two shares of a
plaintext and a secret key are received in a
clock period 0, ten rounds of round functions are executed from the
clock period 0 to the
clock period 30, each round needs three clock periods, and two shares of a
ciphertext are output in a clock period 31; in the implementation of a
round function and key expansion, the calculation of an
S box (not including input linear mapping) needs three clock periods; in the third clock period after
S box calculation is completed, a round of residual operation (wherein the residual operation of a
round function comprises a multiplication module of the
S box, S box output linear mapping, row shifting, column
confusion and round key addition, and the residual operation of key expansion comprises key word XOR generation of a next round of round key) and the next round of S box input linear mapping calculation are completed at the same time. According to the
mask, the side channel security capability of first-order
power consumption analysis resistance can be provided for the AES
algorithm, and the requirements on random numbers and
chip area are remarkably reduced.