{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T20:33:33Z","timestamp":1770842013053,"version":"3.50.1"},"reference-count":70,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2020,1,22]],"date-time":"2020-01-22T00:00:00Z","timestamp":1579651200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2020,1,22]],"date-time":"2020-01-22T00:00:00Z","timestamp":1579651200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100006254","name":"Ruhr-Universit\u00e4t Bochum","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100006254","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2020,7]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The effort in reducing the area of AES implementations has largely been focused on application-specific integrated circuits (ASICs) in which a tower field construction leads to a small design of the AES S-box. In contrast, a naive implementation of the AES S-box has been the status-quo on field-programmable gate arrays (FPGAs). A similar discrepancy holds for masking schemes\u2014a well-known side-channel analysis countermeasure\u2014which are commonly optimized to achieve minimal area in ASICs. In this paper, we demonstrate a representation of the AES S-box exploiting rotational symmetry which leads to a 50% reduction in the area footprint on FPGA devices. We present new AES implementations which improve on the state-of-the-art and explore various trade-offs between area and latency. For instance, at the cost of increasing 4.5 times the latency, one of our design variants requires 25% less look-up tables (LUTs) than the smallest known AES on Xilinx FPGAs by Sasdrich and G\u00fcneysu at ASAP\u00a02016. We further explore the protection of such implementations against side-channel attacks. We introduce a generic methodology for masking any<jats:italic>n<\/jats:italic>-bit Boolean functions of degree<jats:italic>t<\/jats:italic>with protection order<jats:italic>d<\/jats:italic>. The methodology is exact for first-order and heuristic for higher orders. Its application to our new construction of the AES S-box allows us to improve previous results and introduce the smallest first-order masked AES implementation on Xilinx FPGAs, to date.<\/jats:p>","DOI":"10.1007\/s00145-019-09342-y","type":"journal-article","created":{"date-parts":[[2020,1,22]],"date-time":"2020-01-22T19:02:32Z","timestamp":1579719752000},"page":"1114-1155","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["Spin Me Right Round Rotational Symmetry for FPGA-Specific AES: Extended Version"],"prefix":"10.1007","volume":"33","author":[{"given":"Felix","family":"Wegener","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lauren","family":"De Meyer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amir","family":"Moradi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,1,22]]},"reference":[{"key":"9342_CR1","unstructured":"T. Beyne, B. Bilgin, Uniform first-order threshold implementations. in R. Avanzi and H.M. Heys, editors, Selected Areas in Cryptography\u2014SAC 2016\u201323rd International Conference, St. John\u2019s, NL, Canada, August 10\u201312, 2016, Revised Selected Papers, Lecture Notes in Computer Science, vol. 10532 (Springer, 2016), pp. 79\u201398."},{"key":"9342_CR2","doi-asserted-by":"crossref","unstructured":"G. Barthe, F. Dupressoir, S. Faust, B. Gr\u00e9goire, F. Standaert, P.-Y. Strub, Parallel implementations of masking schemes and the bounded moment leakage model. in J.-S. Coron and J.B. Nielsen, editors, Advances in Cryptology\u2013EUROCRYPT 2017\u201336th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Paris, France, April 30\u2013May 4, 2017, Proceedings, Part I, Lecture Notes in Computer Science, vol. 10210 pp. 535\u2013566 (2017)","DOI":"10.1007\/978-3-319-56620-7_19"},{"issue":"3","key":"9342_CR3","doi-asserted-by":"publisher","first-page":"16:1","DOI":"10.1145\/2629552","volume":"8","author":"Shivam Bhasin","year":"2015","unstructured":"S. Bhasin, J.-L. Danger, S. Guilley, W. He, Exploiting FPGA block memories for protected cryptographic implementations. TRETS, 8(3), 16:1\u201316:16 (2015)","journal-title":"TRETS"},{"key":"9342_CR4","doi-asserted-by":"crossref","unstructured":"S. Bhasin, S. Guilley, J.-L. Danger, From cryptography to hardware: Analyzing embedded xilinx BRAM for cryptographic applications. in 45th Annual IEEE\/ACM International Symposium on Microarchitecture, MICRO 2012, Workshops Proceedings, Vancouver, BC, Canada, December 1\u20135, 2012 (IEEE Computer Society, 2012), pp. 1\u20138","DOI":"10.1109\/MICROW.2012.11"},{"issue":"7","key":"9342_CR5","doi-asserted-by":"publisher","first-page":"1188","DOI":"10.1109\/TCAD.2015.2419623","volume":"34","author":"Beg\u00fcl Bilgin","year":"2015","unstructured":"B. Bilgin, B. Gierlichs, S. Nikova, V. Nikov, V. Rijmen, Trade-offs for threshold implementations illustrated on AES. IEEE Trans. on CAD of Integrated Circuits and Systems, 34(7), 1188\u20131200 (2015)","journal-title":"IEEE Trans. on CAD of Integrated Circuits and Systems"},{"key":"9342_CR6","doi-asserted-by":"crossref","unstructured":"S. Bhasin, S. Guilley, Y. Souissi, T. Graba, J.-L. Danger, Efficient dual-rail implementations in FPGA using block rams. in P.M. Athanas, J. Becker, and R. Cumplido, editors, 2011 International Conference on Reconfigurable Computing and FPGAs, ReConFig 2011, Cancun, Mexico, November 30\u2013December 2, 2011 (IEEE Computer Society, 2011), pp. 261\u2013267","DOI":"10.1109\/ReConFig.2011.32"},{"key":"9342_CR7","doi-asserted-by":"crossref","unstructured":"A. Brouwer, W. Haemers, Spectra of Graphs, chapter Chapter 12: Distance-Regular Graphs (Springer New York, 2012), p. 178","DOI":"10.1007\/978-1-4614-1939-6"},{"key":"9342_CR8","first-page":"922","volume":"2018","author":"Dusan Bozilov","year":"2018","unstructured":"D. Bozilov, M. Knezevic, V. Nikov, Optimized threshold implementations: Securing cryptographic accelerators for low-energy and low-latency applications. IACR Cryptology ePrint Archive, 2018, 922 (2018)","journal-title":"IACR Cryptology ePrint Archive"},{"issue":"2","key":"9342_CR9","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/s00145-012-9124-7","volume":"26","author":"Joan Boyar","year":"2013","unstructured":"J. Boyar, P. Matthews, R. Peralta, Logic minimization techniques with applications to cryptology. J. Cryptol., 26(2), 280\u2013312 (2013)","journal-title":"J. Cryptology"},{"key":"9342_CR10","doi-asserted-by":"crossref","unstructured":"B. Bilgin, S. Nikova, V. Nikov, V. Rijmen, G. St\u00fctz, Threshold implementations of all 3x3 and 4x4 s-boxes. in E. Prouff and P. Schaumont, editors, Cryptographic Hardware and Embedded Systems\u2013CHES 2012\u201314th International Workshop, Leuven, Belgium, September 9\u201312, 2012. Proceedings, Lecture Notes in Computer Science vol. 7428 (Springer, 2012), pp. 76\u201391","DOI":"10.1007\/978-3-642-33027-8_5"},{"key":"9342_CR11","doi-asserted-by":"crossref","unstructured":"A. Bogdanov, Multiple-differential side-channel collision attacks on AES. in E. Oswald and P. Rohatgi, editors, Cryptographic Hardware and Embedded Systems\u2013CHES 2008, 10th International Workshop, Washington, D.C., USA, August 10\u201313, 2008. Proceedings, Lecture Notes in Computer Science, vol. 5154 (Springer, 2008), pp. 30\u201344","DOI":"10.1007\/978-3-540-85053-3_3"},{"key":"9342_CR12","doi-asserted-by":"crossref","unstructured":"P. Bulens, F.-X. Standaert, J.-J. Quisquater, P. Pellegrin, G. Rouvroy, Implementation of the AES-128 on Virtex-5 FPGAs. in S. Vaudenay, editor, Progress in Cryptology\u2013AFRICACRYPT 2008, First International Conference on Cryptology in Africa, Casablanca, Morocco, June 11\u201314, 2008. Proceedings, Lecture Notes in Computer Science, vol. 5023 (Springer, 2008), pp. 16\u201326","DOI":"10.1007\/978-3-540-68164-9_2"},{"key":"9342_CR13","doi-asserted-by":"crossref","unstructured":"D. Canright, A very compact s-box for AES. in Rao and Sunar [RS05], pp. 441\u2013455.","DOI":"10.1007\/11545262_32"},{"key":"9342_CR14","doi-asserted-by":"crossref","unstructured":"D. Canright, L. Batina, A very compact \u201cperfectly masked\u201d S-Box for AES. in S.M. Bellovin, R. Gennaro, A.D. Keromytis, and M. Yung, editors, Applied Cryptography and Network Security, 6th International Conference, ACNS 2008, New York, NY, USA, June 3\u20136, 2008. Proceedings, Lecture Notes in Computer Science, vol. 5037 pp. 446\u2013459 (2008)","DOI":"10.1007\/978-3-540-68914-0_27"},{"key":"9342_CR15","doi-asserted-by":"crossref","unstructured":"J. Chu, M. Benaissa, Low area memory-free FPGA implementation of the AES algorithm. in D. Koch, S. Singh, and J. T\u00f8rresen, editors, 22nd International Conference on Field Programmable Logic and Applications (FPL), Oslo, Norway, August 29\u201331, 2012 (IEEE, 2012), pp. 623\u2013626","DOI":"10.1109\/FPL.2012.6339250"},{"key":"9342_CR16","unstructured":"J. Cooper, E. D. Mulder, G. Goodwill, J. Jaffe, G. Kenworthy, P. Rohatgi, Test Vector Leakage Assessment (TVLA) Methodology in Practice. in International Cryptographic Module Conference (2013)"},{"key":"9342_CR17","doi-asserted-by":"crossref","unstructured":"T. D. Cnudde, M. Ender, A. Moradi, Hardware masking, revisited. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2018(2), (2018). to appear.","DOI":"10.46586\/tches.v2018.i2.123-148"},{"key":"9342_CR18","unstructured":"C. Chen, M. Farmani, T. Eisenbarth, A tale of two shares: Why two-share threshold implementation seems worthwhile - and why it is not. in J.H. Cheon and T. Takagi, editors, Advances in Cryptology - ASIACRYPT 2016\u201322nd International Conference on the Theory and Application of Cryptology and Information Security, Hanoi, Vietnam, December 4\u20138, 2016, Proceedings, Part I, Lecture Notes in Computer Science, vol. 10031, pp. 819\u2013843 (2016)"},{"key":"9342_CR19","doi-asserted-by":"crossref","unstructured":"P. Chodowiec, K. Gaj, Very compact FPGA implementation of the AES algorithm. in C.D. Walter, C.K. Ko\u00e7, and C. Paar, editors, Cryptographic Hardware and Embedded Systems\u2013CHES 2003, 5th International Workshop, Cologne, Germany, September 8-10, 2003, Proceedings, Lecture Notes in Computer Science, vol. 2779 (Springer, 2003), pp. 319\u2013333","DOI":"10.1007\/978-3-540-45238-6_26"},{"key":"9342_CR20","doi-asserted-by":"crossref","unstructured":"S. Chari, C. S. Jutla, J. R. Rao, P. Rohatgi, Towards sound approaches to counteract power-analysis attacks. In Wiener [Wie99], pp. 398\u2013412","DOI":"10.1007\/3-540-48405-1_26"},{"key":"9342_CR21","doi-asserted-by":"crossref","unstructured":"T.D. Cnudde, O. Reparaz, B. Bilgin, S. Nikova, V. Nikov, V. Rijmen, Masking AES with d+1 shares in hardware. in B. Gierlichs and A.Y. Poschmann, editors, Cryptographic Hardware and Embedded Systems\u2013CHES 2016\u201318th International Conference, Santa Barbara, CA, USA, August 17\u201319, 2016, Proceedings, Lecture Notes in Computer Science, vol. 9813 (Springer, 2016), pp. 194\u2013212","DOI":"10.1007\/978-3-662-53140-2_10"},{"key":"9342_CR22","unstructured":"T. D. Cnudde, Cryptography Secured against Side-Channel Attacks. PhD thesis (KU Leuven, 2018)"},{"key":"9342_CR23","doi-asserted-by":"crossref","unstructured":"L. De Meyer, A. Moradi, F. Wegener, Spin me right round: Rotational symmetry for FPGA-specific AES. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2018(3) (2018)","DOI":"10.46586\/tches.v2018.i3.596-626"},{"key":"9342_CR24","doi-asserted-by":"crossref","unstructured":"M. Ender, S. Ghandali, A. Moradi, C. Paar, The first thorough side-channel hardware trojan. In T. Takagi and T. Peyrin, editors, Advances in Cryptology\u2013ASIACRYPT 2017\u201323rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3\u20137, 2017, Proceedings, Part I, Lecture Notes in Computer Science, vol. 10624 (Springer, 2017), pp. 755\u2013780","DOI":"10.1007\/978-3-319-70694-8_26"},{"key":"9342_CR25","doi-asserted-by":"crossref","unstructured":"T. Eisenbarth, T. Kasper, A. Moradi, C. Paar, M. Salmasizadeh, M.T.M. Shalmani, On the power of power analysis in the real world: A complete break of the keeloqcode hopping scheme. In D.A. Wagner, editor, Advances in Cryptology\u2013CRYPTO 2008, 28th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 17\u201321, 2008. Proceedings, Lecture Notes in Computer Science, vol. 5157 (Springer, 2008), pp. 203\u2013220","DOI":"10.1007\/978-3-540-85174-5_12"},{"key":"9342_CR26","unstructured":"A. Francillon, B. Danev, S. Capkun, Relay attacks on passive keyless entry and start systems in modern cars. In Proceedings of the Network and Distributed System Security Symposium, NDSS 2011, San Diego, California, USA, 6th February\u20139th February 2011 (The Internet Society, 2011)"},{"key":"9342_CR27","doi-asserted-by":"crossref","unstructured":"T. G\u00fcneysu, H. Handschuh, editors, Cryptographic Hardware and Embedded Systems - CHES 2015\u201317th International Workshop, Saint-Malo, France, September 13-16, 2015, Proceedings, Lecture Notes in Computer Science. vol. 9293 (Springer) (2015)","DOI":"10.1007\/978-3-662-48324-4"},{"key":"9342_CR28","unstructured":"G. Goodwill, B. Jun, J. Jaffe, P. Rohatgi, A testing methodology for Side channel resistance validation. in NIST Non-invasive Attack Testing Workshop (2011)"},{"issue":"11","key":"9342_CR29","doi-asserted-by":"publisher","first-page":"1498","DOI":"10.1109\/TC.2008.80","volume":"57","author":"Tim G\u00fcneysu","year":"2008","unstructured":"T. G\u00fcneysu, T. Kasper, M. Novotn\u00fd, C. Paar, A. Rupp, Cryptanalysis with COPACOBANA. IEEE Trans. Computers, 57(11), 1498\u20131513 (2008)","journal-title":"IEEE Trans. Computers"},{"key":"9342_CR30","first-page":"486","volume":"2016","author":"Hannes Gro\u00df","year":"2016","unstructured":"H. Gro\u00df, S. Mangard, T. Korak, Domain-oriented masking: Compact masked hardware implementations with arbitrary protection order. IACR Cryptology ePrint Archive, 2016, 486 (2016)","journal-title":"IACR Cryptology ePrint Archive"},{"key":"9342_CR31","doi-asserted-by":"crossref","unstructured":"H. Gro\u00df, S. Mangard, T. Korak, An efficient side-channel protected AES implementation with arbitrary protection order. in H. Handschuh, editor, Topics in Cryptology\u2013CT-RSA 2017\u2013The Cryptographers\u2019 Track at the RSA Conference 2017, San Francisco, CA, USA, February 14\u201317, 2017, Proceedings, Lecture Notes in Computer Science, vol. 10159 (Springer, 2017), pp. 95\u2013112","DOI":"10.1007\/978-3-319-52153-4_6"},{"key":"9342_CR32","doi-asserted-by":"crossref","unstructured":"Y. Ishai, A. Sahai, D.A. Wagner, Private circuits: Securing hardware against probing attacks. in D. Boneh, editor, Advances in Cryptology\u2013CRYPTO 2003, 23rd Annual International Cryptology Conference, Santa Barbara, California, USA, August 17\u201321, 2003, Proceedings, Lecture Notes in Computer Science, vol. 2729 (Springer, 2003), pp. 463\u2013481","DOI":"10.1007\/978-3-540-45146-4_27"},{"key":"9342_CR33","doi-asserted-by":"crossref","unstructured":"J. Jean, A. Moradi, T. Peyrin, P. Sasdrich, Bit-sliding: A generic technique for bit-serial implementations of SPN-based primitives\u2013applications to AES, PRESENT and SKINNY. in W. Fischer and N. Homma, editors, Cryptographic Hardware and Embedded Systems\u2013CHES 2017\u201319th International Conference, Taipei, Taiwan, September 25\u201328, 2017, Proceedings, Lecture Notes in Computer Science, vol. 10529 (Springer, 2017), pp. 687\u2013707","DOI":"10.1007\/978-3-319-66787-4_33"},{"key":"9342_CR34","doi-asserted-by":"crossref","unstructured":"P.C. Kocher, J. Jaffe, B. Jun, Differential power analysis. in Wiener [Wie99], pp. 388\u2013397","DOI":"10.1007\/3-540-48405-1_25"},{"key":"9342_CR35","doi-asserted-by":"crossref","unstructured":"N. Mentens, L. Batina, B. Preneel, I. Verbauwhede, A systematic evaluation of compact hardware implementations for the Rijndael S-Box. in A. Menezes, editor, Topics in Cryptology\u2013CT-RSA 2005, The Cryptographers\u2019 Track at the RSA Conference 2005, San Francisco, CA, USA, February 14\u201318, 2005, Proceedings, Lecture Notes in Computer Science, vol. 3376 (Springer, 2005), pp. 323\u2013333","DOI":"10.1007\/978-3-540-30574-3_22"},{"key":"9342_CR36","doi-asserted-by":"crossref","unstructured":"A. Moradi, O. Mischke, Glitch-free implementation of masking in modern fpgas. in 2012 IEEE International Symposium on Hardware-Oriented Security and Trust, HOST 2012, San Francisco, CA, USA, June 3\u20134, 2012 (IEEE, 2012), pp. 89\u201395","DOI":"10.1109\/HST.2012.6224326"},{"key":"9342_CR37","doi-asserted-by":"crossref","unstructured":"A. Moradi, O. Mischke, T. Eisenbarth, Correlation-enhanced power analysis collision attack. in S. Mangard and F.-X. Standaert, editors, Cryptographic Hardware and Embedded Systems, CHES 2010, 12th International Workshop, Santa Barbara, CA, USA, August 17\u201320, 2010. Proceedings, Lecture Notes in Computer Science, vol. 6225 (Springer, 2010), pp. 125\u2013139","DOI":"10.1007\/978-3-642-15031-9_9"},{"key":"9342_CR38","unstructured":"S. Mangard, E. Oswald, T. Popp, Power analysis attacks\u2013revealing the secrets of smart cards (Springer, 2007)"},{"key":"9342_CR39","unstructured":"A. Moradi, Advances in Side-channel Security (2016)"},{"key":"9342_CR40","doi-asserted-by":"crossref","unstructured":"A. Moradi, A. Poschmann, S. Ling, C. Paar, H. Wang, Pushing the limits: A very compact and a threshold implementation of AES. in K.G. Paterson, editor, Advances in Cryptology\u2013EUROCRYPT 2011\u201330th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tallinn, Estonia, May 15\u201319, 2011. Proceedings, Lecture Notes in Computer Science, vol. 6632 (Springer, 2011), pp. 69\u201388","DOI":"10.1007\/978-3-642-20465-4_6"},{"key":"9342_CR41","doi-asserted-by":"crossref","unstructured":"S. Mangard, N. Pramstaller, E. Oswald, Successfully attacking masked AES hardware implementations. in Rao and Sunar [RS05], pp. 157\u2013171","DOI":"10.1007\/11545262_12"},{"key":"9342_CR42","doi-asserted-by":"crossref","unstructured":"A. Moradi, F.-X. Standaert, Moments-correlating DPA. in B. Bilgin, S. Nikova, and V. Rijmen, editors, Proceedings of the ACM Workshop on Theory of Implementation Security, TIS@CCS 2016 Vienna, Austria, October, 2016 (ACM, 2016), pp. 5\u201315","DOI":"10.1145\/2996366.2996369"},{"key":"9342_CR43","doi-asserted-by":"crossref","unstructured":"A. Moradi, A. Wild, Assessment of Hiding the Higher-Order Leakages in Hardware\u2013What Are the Achievements Versus Overheads? in G\u00fcneysu and Handschuh [GH15], pp. 453\u2013474","DOI":"10.1007\/978-3-662-48324-4_23"},{"key":"9342_CR44","doi-asserted-by":"crossref","unstructured":"M. Nassar, S. Bhasin, J.-L. Danger, G. Duc, S. Guilley, BCDL: A high speed balanced DPL for FPGA with global precharge and no early evaluation. in G.\u00a0De Micheli, B.M. Al-Hashimi, W. M\u00fcller, E. Macii, editors, Design, Automation and Test in Europe, DATE 2010, Dresden, Germany, March 8\u201312, 2010 (IEEE Computer Society, 2010), pp. 849\u2013854","DOI":"10.1109\/DATE.2010.5456932"},{"key":"9342_CR45","first-page":"103","volume":"2018","author":"Svetla Nikova","year":"2018","unstructured":"S. Nikova, V. Nikov, V. Rijmen, Decomposition of permutations in a finite field. IACR Cryptology ePrint Archive, 2018, 103 (2018)","journal-title":"IACR Cryptology ePrint Archive"},{"key":"9342_CR46","doi-asserted-by":"crossref","unstructured":"S. Nikova, C. Rechberger, V. Rijmen, Threshold implementations against side-channel attacks and glitches. in P. Ning, S. Qing, and N. Li, editors, Information and Communications Security, 8th International Conference, ICICS 2006, Raleigh, NC, USA, December 4\u20137, 2006, Proceedings, Lecture Notes in Computer Science, vol. 4307 (Springer, 2006), pp. 529\u2013545","DOI":"10.1007\/11935308_38"},{"issue":"2","key":"9342_CR47","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1007\/s00145-010-9085-7","volume":"24","author":"Svetla Nikova","year":"2011","unstructured":"S. Nikova, V. Rijmen, M. Schl\u00e4ffer, Secure hardware implementation of nonlinear functions in the presence of glitches. J. Cryptology, 24(2), 292\u2013321 (2011)","journal-title":"J. Cryptology"},{"issue":"6","key":"9342_CR48","doi-asserted-by":"publisher","first-page":"799","DOI":"10.1109\/TC.2009.15","volume":"58","author":"Emmanuel Prouff","year":"2009","unstructured":"E. Prouff, M. Rivain, R. Bevan, Statistical analysis of second order differential power analysis. IEEE Trans. Computers, 58(6), 799\u2013811 (2009)","journal-title":"IEEE Trans. Computers"},{"key":"9342_CR49","doi-asserted-by":"crossref","unstructured":"V. Rijmen, P.S.L.M. Barreto, D.L. Gazzoni Filho, Rotation symmetry in algebraically generated cryptographic substitution tables. Inf. Process. Lett., 106(6), 246\u2013250 (2008)","DOI":"10.1016\/j.ipl.2007.09.012"},{"key":"9342_CR50","doi-asserted-by":"crossref","unstructured":"D.B. Roy, S. Bhasin, S. Guilley, J.-L. Danger, D. Mukhopadhyay, From theory to practice of private circuit: A cautionary note. in 33rd IEEE International Conference on Computer Design, ICCD 2015, New York City, NY, USA, October 18\u201321, 2015 (IEEE Computer Society, 2015), pp. 296\u2013303","DOI":"10.1109\/ICCD.2015.7357117"},{"key":"9342_CR51","doi-asserted-by":"crossref","unstructured":"O. Reparaz, B. Bilgin, S. Nikova, B. Gierlichs, I. Verbauwhede, Consolidating masking schemes. in R. Gennaro and M. Robshaw, editors, Advances in Cryptology\u2013CRYPTO 2015\u201335th Annual Cryptology Conference, Santa Barbara, CA, USA, August 16\u201320, 2015, Proceedings, Part I, Lecture Notes in Computer Science, vol. 9215 (Springer, 2015), pp. 764\u2013783","DOI":"10.1007\/978-3-662-47989-6_37"},{"key":"9342_CR52","doi-asserted-by":"crossref","unstructured":"J. R. Rao, B. Sunar, editors. Cryptographic Hardware and Embedded Systems\u2013CHES 2005, 7th International Workshop, Edinburgh, UK, August 29\u2013September 1, 2005, Proceedings, Lecture Notes in Computer Science, vol. 3659 (Springer, 2005)","DOI":"10.1007\/11545262"},{"key":"9342_CR53","unstructured":"F. Regazzoni, Y. Wang, F.-X. Standaert, Fpga implementations of the aes masked against power analysis attacks. In Constructive Side-Channel Analysis and Secure Design\u20132nd International Workshop, COSADE 2011, Darmstadt, Germany, February 24\u201325, 2011. Revised Selected Papers, pp. 56\u201366 (2011)"},{"key":"9342_CR54","unstructured":"Side-channel AttacK User Reference Architecture. http:\/\/satoh.cs.uec.ac.jp\/SAKURA\/index.html"},{"key":"9342_CR55","doi-asserted-by":"crossref","unstructured":"P. Sasdrich, T. G\u00fcneysu, A grain in the silicon: SCA-protected AES in less than 30 slices. in 27th IEEE International Conference on Application-specific Systems, Architectures and Processors, ASAP 2016, London, United Kingdom, July 6\u20138, 2016 (IEEE Computer Society, 2016), pp. 25\u201332","DOI":"10.1109\/ASAP.2016.7760769"},{"key":"9342_CR56","doi-asserted-by":"crossref","unstructured":"T. Schneider, A. Moradi, Leakage assessment methodology\u2013A clear roadmap for side-channel evaluations. in G\u00fcneysu and Handschuh [GH15], pp. 495\u2013513","DOI":"10.1007\/978-3-662-48324-4_25"},{"key":"9342_CR57","doi-asserted-by":"crossref","unstructured":"P. Sasdrich, O. Mischke, A. Moradi, T. G\u00fcneysu, Side-channel protection by randomizing look-up tables on reconfigurable hardware\u2013pitfalls of memory primitives. in S. Mangard and A.Y. Poschmann, editors, Constructive Side-Channel Analysis and Secure Design\u20136th International Workshop, COSADE 2015, Berlin, Germany, April 13\u201314, 2015. Revised Selected Papers, Lecture Notes in Computer Science, vol. 9064 (Springer, 2015), pp. 95\u2013107","DOI":"10.1007\/978-3-319-21476-4_7"},{"key":"9342_CR58","doi-asserted-by":"crossref","unstructured":"A. Satoh, S. Morioka, K. Takano, S. Munetoh, A compact rijndael hardware architecture with s-box optimization. In C. Boyd, editor, Advances in Cryptology\u2013ASIACRYPT 2001, 7th International Conference on the Theory and Application of Cryptology and Information Security, Gold Coast, Australia, December 9\u201313, 2001, Proceedings, Lecture Notes in Computer Science, vol. 2248 (Springer, 2001), pp. 239\u2013254","DOI":"10.1007\/3-540-45682-1_15"},{"key":"9342_CR59","first-page":"236","volume":"2003","author":"Elena Trichina","year":"2003","unstructured":"E. Trichina, Combinational logic design for AES subbyte transformation on masked data. IACR Cryptology ePrint Archive, 2003, 236 (2003)","journal-title":"IACR Cryptology ePrint Archive"},{"key":"9342_CR60","doi-asserted-by":"crossref","unstructured":"R. Ueno, N. Homma, T. Aoki, A systematic design of tamper-resistant galois-field arithmetic circuits based on threshold implementation with (d + 1) input shares. in 47th IEEE International Symposium on Multiple-Valued Logic, ISMVL 2017, Novi Sad, Serbia, May 22\u201324, 2017 (IEEE Computer Society, 2017), pp. 136\u2013141","DOI":"10.1109\/ISMVL.2017.35"},{"key":"9342_CR61","doi-asserted-by":"crossref","unstructured":"R. Ueno, N. Homma, T. Aoki, Toward more efficient dpa-resistant AES hardware architecture based on threshold implementation. In S. Guilley, editor, Constructive Side-Channel Analysis and Secure Design\u20138th International Workshop, COSADE 2017, Paris, France, April 13\u201314, 2017, Revised Selected Papers, Lecture Notes in Computer Science, vol. 10348 (Springer, 2017), pp. 50\u201364","DOI":"10.1007\/978-3-319-64647-3_4"},{"key":"9342_CR62","doi-asserted-by":"crossref","unstructured":"J. Vliegen, O. Reparaz, N. Mentens, Maximizing the throughput of threshold-protected AES-GCM implementations on FPGA. in IEEE 2nd International Verification and Security Workshop, IVSW 2017, Thessaloniki, Greece, July 3\u20135, 2017 (IEEE, 2017), pp. 140\u2013145","DOI":"10.1109\/IVSW.2017.8031559"},{"key":"9342_CR63","doi-asserted-by":"crossref","unstructured":"M.S. Wamser, Ultra-small designs for inversion-based S-Boxes. in 17th Euromicro Conference on Digital System Design, DSD 2014, Verona, Italy, August 27\u201329, 2014 (IEEE Computer Society, 2014), pp. 512\u2013519","DOI":"10.1109\/DSD.2014.37"},{"key":"9342_CR64","doi-asserted-by":"crossref","unstructured":"M.S. Wamser, L. Holzbaur, G. Sigl, A petite and power saving design for the AES S-Box. in 2015 Euromicro Conference on Digital System Design, DSD 2015, Madeira, Portugal, August 26\u201328, 2015 (IEEE Computer Society, 2015), pp. 661\u2013667","DOI":"10.1109\/DSD.2015.29"},{"key":"9342_CR65","doi-asserted-by":"crossref","unstructured":"M.J. Wiener, editor, Advances in Cryptology\u2013CRYPTO \u201999, 19th Annual International Cryptology Conference, Santa Barbara, California, USA, August 15\u201319, 1999, Proceedings, Lecture Notes in Computer Science, vol. 1666 (Springer, 1999)","DOI":"10.1007\/3-540-48405-1"},{"key":"9342_CR66","unstructured":"R. Ward, T.C.A. Molteno, Table of linear feedback shift registers. Technical Report 2012-1 (University of Otago, 2012) http:\/\/www.physics.otago.ac.nz\/reports\/electronics\/ETR2012-1.pdf."},{"key":"9342_CR67","doi-asserted-by":"crossref","unstructured":"F. Wegener, A. Moradi, A first-order SCA resistant AES without fresh randomness. in Constructive Side-Channel Analysis and Secure Design\u20139th International Workshop, COSADE 2018, Singapore, April 23\u201325, 2018 (2018)","DOI":"10.1007\/978-3-319-89641-0_14"},{"issue":"3","key":"9342_CR68","doi-asserted-by":"crossref","first-page":"66","DOI":"10.46586\/tches.v2019.i3.66-85","volume":"2019","author":"Lennert Wouters","year":"2019","unstructured":"L. Wouters, E. Marin, T. Ashur, B. Gierlichs, B. Preneel, Fast, furious and insecure: Passive keyless entry and start systems in modern supercars. IACR Trans. Cryptogr. Hardw. Embed. Syst., 2019(3), 66\u201385 (2019)","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"9342_CR69","doi-asserted-by":"crossref","unstructured":"M.S. Wamser, G. Sigl, Pushing the limits further: Sub-atomic AES. in 2017 IFIP\/IEEE International Conference on Very Large Scale Integration, VLSI-SoC 2017, Abu Dhabi, United Arab Emirates, October 23\u201325, 2017 (IEEE, 2017), pp. 1\u20136","DOI":"10.1109\/VLSI-SoC.2017.8203470"},{"key":"9342_CR70","unstructured":"X., Spartan-6 FPGA configurable logic block user guide. https:\/\/www.xilinx.com\/support\/documentation\/user_guides\/ug384.pdf (2010)"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-019-09342-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00145-019-09342-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-019-09342-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,12]],"date-time":"2022-10-12T12:08:44Z","timestamp":1665576524000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00145-019-09342-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,1,22]]},"references-count":70,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2020,7]]}},"alternative-id":["9342"],"URL":"https:\/\/doi.org\/10.1007\/s00145-019-09342-y","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,1,22]]},"assertion":[{"value":"29 March 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 December 2019","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 January 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}