ASCON Hardware Architecture for Side-Channel Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptosystems face challenges in achieving efficient execution and robust side-channel resistance, particularly in resource-constrained applications like IoT devices, due to limitations in hardware implementations of lightweight cryptographic algorithms.
Innovation Solution
The proposed hardware architecture for ASCON cryptographic operations includes optimized scheduling and datapath design, merging of absorption and permutation steps, efficient masked S-box implementations, and optional unrolling, which enhance performance and side-channel protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If masking schemes are implemented to protect against side-channel attacks, then security against side-channel attacks is improved, but device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing sensitive variables into multiple randomized shares (d+1 shares for security order d). The masking circuit is segmented into multiple independent paths that operate on these shares, preventing attackers from correlating physical side-channel information with original secret variables while maintaining manageable complexity through modular design
Solution Approach 2:
The patent introduces random masks as intermediary elements that mediate between sensitive data and physical implementations. These masks act as buffers that prevent direct correlation between physical side-effects and secret variables, adding security without requiring fundamental redesign of the cryptographic core
2Productivity
If hardware implementations are optimized for high performance, then productivity is improved, but use of energy increases
Solution Approach 1:
The patent implements dynamic operation modes that can adapt between different performance and power consumption levels. The hardware can operate in high-performance mode when speed is critical or in low-power mode for resource-constrained applications, allowing optimization based on specific operational requirements rather than fixed design constraints
Solution Approach 2:
The patent utilizes parameter changes by varying the security order d and the number of permutation rounds to balance performance and power consumption. By adjusting these parameters, the implementation can be optimized for either high speed or low power consumption depending on the specific application requirements
3Reliability
If masking circuits are designed with higher security order, then security against side-channel attacks is improved, but device complexity increases
Solution Approach 1:
The patent segments the masking circuit into modular components that can be independently implemented and verified. Each module operates on a subset of shares, allowing higher security orders to be achieved through composition of simpler, verified building blocks rather than monolithic complex circuits
Solution Approach 2:
The patent designs universal masking gadgets that can be reused across different cryptographic operations and security orders. These multi-functional components reduce overall circuit complexity by eliminating redundant logic that would otherwise be needed for each specific operation or security level
Data Source
AI summary
A hardware architecture configured to implement ASCON cryptographic algorithms and protect against side-channel attacks that includes a co-processor having a controller, a logic gate operably configured to receive a data input and ASCON state memory data in an initial cycle of permutation iterations, a multiplexor operably configured to direct data input from the logic gate based on a signal received from the controller and in the initial cycle of permutation iterations, an ASCON state memory operably configured to receive the processed data in the initial cycle of permutation iterations, and that is operably configured to implement a permutation round configured to receive the data input directly from the logic gate through the multiplexor and process the data input utilizing a permutation function to generate processed data and in the initial cycle of permutation iterations.


