Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
|
 |
On Highly Nonlinear S-Boxes and Their Inability to Thwart DPA Attacks
| |
|
Boolean Function and S-Box
On Highly Nonlinear S-Boxes and Their Inability to Thwart DPA Attacks
Claude Carlet1 
| (1) |
INRIA, Projet CODES, BP 105 - 78153, Le Chesnay Cedex, France, University of Paris 8 (MAATICAH), |
Abstract
Prouff has introduced recently, at FSE 2005, the notion of transparency order of S-boxes. This new characteristic is related
to the ability of an S-box, used in a cryptosystem in which the round keys are introduced by addition, to thwart single-bit
or multi-bit DPA attacks on the system. If this parameter has sufficiently small value, then the S-box is able to withstand
DPA attacks without that ad-hoc modifications in the implementation be necessary (these modifications make the encryption
about twice slower). We prove a lower bound on the transparency order of highly nonlinear S-boxes. We show that some highly
nonlinear functions, and in particular the S-box of AES, have very bad transparency orders.
Fulltext Preview (Small, Large)
|
|
|
|
|
|