2021
DOI: 10.1007/978-3-030-92518-5_12
|View full text |Cite
|
Sign up to set email alerts
|

Improving First-Order Threshold Implementations of SKINNY

Abstract: Threshold Implementations have become a popular generic technique to construct circuits resilient against power analysis attacks. In this paper, we look to devise efficient threshold circuits for the lightweight block cipher family SKINNY. The only threshold circuits for this family are those proposed by its designers who decomposed the 8-bit S-box into four quadratic S-boxes, and constructed a 3-share byte-serial threshold circuit that executes the substitution layer over four cycles. In particular, we revisi… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
6
0

Year Published

2021
2021
2022
2022

Publication Types

Select...
3

Relationship

1
2

Authors

Journals

citations
Cited by 3 publications
(6 citation statements)
references
References 28 publications
0
6
0
Order By: Relevance
“…As can be seen that this output bit of S 2 is constructed by a standalone AND gate, and correction terms have to be added to construct a 3-input/3-output share TI of the SKINNY S-box. In the supplementary material [8], we present explicit algebraic expressions for all 3 shares of the S-boxes F , G and H. While noncompleteness and correctness are easy to argue, we additionally argue uniformity of our construction too.…”
Section: This Allows Us To Decompose the S-box Intomentioning
confidence: 91%
See 4 more Smart Citations
“…As can be seen that this output bit of S 2 is constructed by a standalone AND gate, and correction terms have to be added to construct a 3-input/3-output share TI of the SKINNY S-box. In the supplementary material [8], we present explicit algebraic expressions for all 3 shares of the S-boxes F , G and H. While noncompleteness and correctness are easy to argue, we additionally argue uniformity of our construction too.…”
Section: This Allows Us To Decompose the S-box Intomentioning
confidence: 91%
“…Since we also have that S = S Red • S Blue , this also gives us the cubic decomposition required to construct a first order TI using 4 input/output shares that can evaluate the shared S-box in just 2 cycles. In the supplementary material [8], we present explicit algebraic expressions for all 4 shares of the S-boxes S Red , S Blue , where we additionally argue uniformity of our construction too.…”
Section: Decomposition Into Two Cubic S-boxesmentioning
confidence: 92%
See 3 more Smart Citations