EP2928112B1

Encryption device of a substitution-box type, and corresponding encryption method and computer program product

Abstract

This record has no abstract on file.

EP2928112B1, drawing sheet 1
Sheet 1 of 70

Term

8.5 yearsleft in the term

Expires 24 March 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

13 claims: 3 independent, 10 dependent

  1. 1
    A device of a Substitution-Box, S-Box, type, which is suitable for operating in a symmetric-key AES, Advanced Encryption Standard, encryption apparatus, and includes at least one module (11) configured for carrying out a non-linear operation in a finite field ( GF (2 8 )) of an AES encryption method implemented by said encryption apparatus, said module (11) comprising at least one reprogrammable look-up table (50), wherein said module (11) comprises a plurality of flip-flop memory structures defining memory registers configured to implement a plurality of reprogrammable composite look-up tables (40;41) that implement said non-linear operation in a composite field of finite subfields ( GF (2 4 ) 2 ;GF ((2 2 ) 2 ) 2 ) deriving from said finite field ( GF (2 8 )), each of said composite look-up tables (40) being smaller than a single re-programmable look-up table (50) that is able to implement autonomously said non-linear operation in a finite field ( GF (2 8 )), each of the look-up tables (40) that implement non-linear operations being masked at least by a respective pair of input and output masks.
  2. 2
    The device according to Claim 1, characterized in that said non-linear operation is an operation of multiplicative inversion of a SubBytes operation of an AES encryption procedure, and in that said device (10) comprises a module (12) for performing an affine transformation.
  3. 3
    The device according to Claim 1 or to Claim 2, characterized in that said encryption apparatus is comprised in a set-top box and/or in a smart card.
  4. 4
    The device according to any one of the preceding claims, characterized in that said composite field of finite subfields ( GF (2 4 ) 2 ; GF ((2 2 ) 2 ) 2 ) is obtained via a procedure comprising the operations of:- mapping all the elements of the finite field ( GF (2 8 )) of the non-linear operation by decomposing them over the composite field of finite subfields ( GF (2 4 ) 2 ;GF ((2 2 ) 2 ) 2 ) using an isomorphism;- computing the non-linear operation to be implemented, in the composite field of finite subfields ( GF (2 4 ) 2 ;GF ((2 2 ) 2 ) 2 );and - mapping the results of said operation of computation over the field of the non-linear operation, applying the inverse of the isomorphism used for the decomposition over the composite field of finite subfields ( GF (2 4 ) 2 ;GF ((2 2 ) 2 ) 2 ).
  5. 5
    The device according to Claim 4, characterized in that , given the decomposition over the composite field of finite subfields ( GF (2 4 ) 2 ;GF ((2 2 ) 2 ) 2 ), it comprises implementing at least part of the linear operations, in particular the additions, resulting from said decomposition via combinational logic and implementing the remaining operations, including the non-linear operations, resulting from said decomposition via said composite look-up tables (40).
  6. 6
    An AES symmetric-key encryption method that comprises carrying out a non-linear operation in a finite field ( GF (2 8 )) and providing an apparatus comprising a Substitution-Box, S-Box, device for carrying out said AES non-linear operation, wherein an S-Box device (10) is provided comprising a plurality of flip-flop memory structures defining memory registers configured for implementing a plurality of reprogrammable composite look-up tables (40;41) that implement said non-linear operation in a composite field of finite subfields ( GF (2 4 ) 2 ;GF ((2 2 ) 2 ) 2 ) deriving from said finite field ( GF (2 8 )), sizing each of said composite look-up tables (40) as smaller than a single re-programmable look-up table (50) that is able to implement autonomously said non-linear operation in a finite field ( GF (2 8 )), masking each of the look-up tables (40) that implement non-linear operations at least by a respective pair of input and output masks.
  7. 7
    The method according to Claim 6, characterized in that one or more of said look-up tables (40) are accessed via access operations (210) that include an operation of initialization (100) of the look-up table (40), which comprises writing initialization values ( dout ) in said look-up table (40), by applying (110, 120) an input mask ( R 1 ) to input data ( din ;din ref , din mask ) that identify a location of said look-up table (40) and an output mask ( R 2 ) to data (dout ;dout ref , dout mask ) at output from a location of said look-up table (40).
  8. 8
    The method according to Claim 7, characterized in that at least one second step of initialization (120) of said look-up table (50) is carried out, which comprises:providing at least one second input mask R 1 ′ and one second output mask R 2 ′ ;and computing corresponding initialization values as a function of a logic combination (Δ 1 ) of said first input mask ( R 1 ) and second input mask R 1 ′ and of a logic combination (Δ 2 ) of said first output mask R 2 ′ and second output mask R 2 ′ .
  9. 9
    The method according to Claim 8, characterized in that said logic combination (Δ 1 , Δ 2 ) is an operation of exclusive OR (XOR) between the values of said first input mask ( R 1 ) and said second input mask R 1 ′ and, respectively, between the values of a logic combination of said first output mask ( R 2 ) and said second output mask R 2 ′ .
  10. 10
    The method according to Claim 8 or Claim 9, characterized in that it comprises repeating the step of computation for a given number of times, supplying each time a further input mask R 1 " and a further output mask R 2 " , and computing said logic combinations as a function of said further input mask R 1 " or output mask R 2 " and of the input mask R 1 ′ or output mask R 2 ′ supplied previously.
  11. 11
    The method according to Claim 10, characterized in that said given number of times is chosen, in particular at run-time, for regulating the performance or level of protection of the encryption method (200) in regard to side-channel attacks.
  12. 12
    The method according to Claim 11, characterized in that it is configured for carrying out said operations of initialization in one clock cycle.
  13. 13
    A computer program product that can be loaded into the memory of at least one computer, the computer program product comprising portions of software code that are adapted to implement the steps of the method when the program is run on at least one computer according to any one of Claims 6 to 12.