Multiplicative Masking for AES in Hardware

Hardware masked AES designs usually rely on Boolean masking and perform the computation of the S-box using the tower-field decomposition. On the other hand, splitting sensitive variables in a multiplicative way is more amenable for the computation of the AES S-box, as noted by Akkar and Giraud. Howe...

Full description

Bibliographic Details
Main Authors: Lauren De Meyer, Oscar Reparaz, Begül Bilgin
Format: Article
Language:English
Published: Ruhr-Universität Bochum 2018-08-01
Series:Transactions on Cryptographic Hardware and Embedded Systems
Subjects:
Online Access:https://tches.iacr.org/index.php/TCHES/article/view/7282