{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T07:22:33Z","timestamp":1768461753262,"version":"3.49.0"},"reference-count":50,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2016,11,11]],"date-time":"2016-11-11T00:00:00Z","timestamp":1478822400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Des. Autom. Electron. Syst."],"published-print":{"date-parts":[[2017,1,31]]},"abstract":"<jats:p>\n            In this article, we present a compact implementation of the Salsa20 stream cipher that is targeted towards lightweight cryptographic devices such as radio-frequency identification (RFID) tags. The Salsa20 stream cipher, ann addition-rotation-XOR (ARX) cipher, is used for high-security cryptography in NEON instruction sets embedded in ARM Cortex A8 CPU core-based tablets and smartphones. The existing literature shows that although classical cryptanalysis has been effective on reduced rounds of Salsa20, the stream cipher is immune to software side-channel attacks such as branch timing and cache timing attacks. To the best of our knowledge, this work is the first to perform hardware power analysis attacks, where we evaluate the resistance of all eight keywords in the proposed compact implementation of Salsa20. Our technique targets the three subrounds of the first round of the implemented Salsa20. The correlation power analysis (CPA) attack has an attack complexity of 2\n            <jats:sup>19<\/jats:sup>\n            . Based on extensive experiments on a compact implementation of Salsa20, we demonstrate that all these keywords can be recovered within 20,000 queries on Salsa20. The attacks show a varying resilience of the key words against CPA that has not yet been observed in any stream or block cipher in the present literature. This makes the architecture of this stream cipher interesting from the side-channel analysis perspective. Also, we propose a lightweight countermeasure that mitigates the leakage in the power traces as shown in the results of Welch\u2019s\n            <jats:italic>t<\/jats:italic>\n            -test statistics. The hardware area overhead of the proposed countermeasure is only 14% and is designed with compact implementation in mind.\n          <\/jats:p>","DOI":"10.1145\/2934677","type":"journal-article","created":{"date-parts":[[2016,11,11]],"date-time":"2016-11-11T17:02:54Z","timestamp":1478883774000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["A Compact Implementation of Salsa20 and Its Power Analysis Vulnerabilities"],"prefix":"10.1145","volume":"22","author":[{"given":"Bodhisatwa","family":"Mazumdar","sequence":"first","affiliation":[{"name":"New York University Abu Dhabi, Abu Dhabi"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sk. Subidh","family":"Ali","sequence":"additional","affiliation":[{"name":"New York University Abu Dhabi, Abu Dhabi"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ozgur","family":"Sinanoglu","sequence":"additional","affiliation":[{"name":"New York University Abu Dhabi, Abu Dhabi"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2016,11,11]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Security in Silicon by Helion. http:\/\/www.heliontech.com\/. Accessed: 2015-012-17.  Security in Silicon by Helion. http:\/\/www.heliontech.com\/. Accessed: 2015-012-17."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-014-0236-y"},{"key":"e_1_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Frederik Armknecht Matthias Hamann and Vasily Mikhalev. 2014. Lightweight authentication protocols on ultra-constrained RFIDs - Myths and facts. In RFIDSec. 1--18.  Frederik Armknecht Matthias Hamann and Vasily Mikhalev. 2014. Lightweight authentication protocols on ultra-constrained RFIDs - Myths and facts. In RFIDSec. 1--18.","DOI":"10.1007\/978-3-319-13066-8_1"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-71039-4_30"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-68351-3_8"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33027-8_19"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2003.1190590"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2629552"},{"key":"e_1_2_1_9_1","volume-title":"Proceedings. 16--29","author":"Brier Eric","year":"2004","unstructured":"Eric Brier , Christophe Clavier , and Francis Olivier . 2004 . Correlation power analysis with a leakage model. In Cryptographic Hardware and Embedded Systems\u2014CHES 2004: 6th International Workshop Cambridge, MA, USA, August 11--13, 2004 . Proceedings. 16--29 . Eric Brier, Christophe Clavier, and Francis Olivier. 2004. Correlation power analysis with a leakage model. In Cryptographic Hardware and Embedded Systems\u2014CHES 2004: 6th International Workshop Cambridge, MA, USA, August 11--13, 2004. Proceedings. 16--29."},{"key":"e_1_2_1_10_1","volume-title":"SASC 2006--Stream Ciphers Revisited","author":"Crowley Paul","year":"2006","unstructured":"Paul Crowley . 2006 . Truncated differential cryptanalysis of five rounds of Salsa20 . SASC 2006--Stream Ciphers Revisited (2006). Paul Crowley. 2006. Truncated differential cryptanalysis of five rounds of Salsa20. SASC 2006--Stream Ciphers Revisited (2006)."},{"key":"e_1_2_1_11_1","volume-title":"Third International Conference on Cryptology in India","author":"Daemen Joan","year":"2002","unstructured":"Joan Daemen and Vincent Rijmen . 2002 . Security of a wide trail design. In Progress in Cryptology - INDOCRYPT 2002 , Third International Conference on Cryptology in India , Hyderabad, India, December 16--18 , 2002. 1--11. Joan Daemen and Vincent Rijmen. 2002. Security of a wide trail design. In Progress in Cryptology - INDOCRYPT 2002, Third International Conference on Cryptology in India, Hyderabad, India, December 16--18, 2002. 1--11."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-31410-0_11"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MDT.2007.178"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-25286-0_2"},{"key":"e_1_2_1_15_1","volume-title":"Workshop on The State of the Art of Stream Ciphers (SASC2007)","author":"Feldhofer Martin","year":"2007","unstructured":"Martin Feldhofer . 2007 . Comparison of low-power implementations of Trivium and Grain . In Workshop on The State of the Art of Stream Ciphers (SASC2007) . 236--246. Martin Feldhofer. 2007. Comparison of low-power implementations of Trivium and Grain. In Workshop on The State of the Art of Stream Ciphers (SASC2007). 236--246."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-28632-5_26"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1049\/ip-ifs:20055006"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/11941378_2"},{"key":"e_1_2_1_19_1","volume-title":"NIST Non-Invasive Attack Testing Workshop.","author":"Gilbert Goodwill Benjamin Jun","year":"2011","unstructured":"Benjamin Jun Gilbert Goodwill , Josh Jaffe , Pankaj Rohatgi , and others. 2011 . A testing methodology for side-channel resistance validation . In NIST Non-Invasive Attack Testing Workshop. Benjamin Jun Gilbert Goodwill, Josh Jaffe, Pankaj Rohatgi, and others. 2011. A testing methodology for side-channel resistance validation. In NIST Non-Invasive Attack Testing Workshop."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1980.1056265"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/11545262_31"},{"key":"e_1_2_1_22_1","volume-title":"NIST Non-Invasive Attack Testing Workshop. http:\/\/csrc.nist.gov\/newsevents\/non-invasive-attack-testing-workshop\/papers\/08_Goodwill.pdf.","author":"Goodwill G.","unstructured":"G. Goodwill , B. Jun , J. Jaffe , and P. Rohatgi . 2011. A testing methodology for side channel resistance validation . In NIST Non-Invasive Attack Testing Workshop. http:\/\/csrc.nist.gov\/newsevents\/non-invasive-attack-testing-workshop\/papers\/08_Goodwill.pdf. G. Goodwill, B. Jun, J. Jaffe, and P. Rohatgi. 2011. A testing methodology for side channel resistance validation. In NIST Non-Invasive Attack Testing Workshop. http:\/\/csrc.nist.gov\/newsevents\/non-invasive-attack-testing-workshop\/papers\/08_Goodwill.pdf."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-014-0092-8"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSCS.2008.4746906"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2005.861395"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.5555\/647834.738167"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICECS.2010.5724742"},{"key":"e_1_2_1_28_1","volume-title":"17th International Workshop, FSE 2010","author":"Khovratovich Dmitry","year":"2010","unstructured":"Dmitry Khovratovich and Ivica Nikolic . 2010 . Rotational cryptanalysis of ARX. In Fast Software Encryption , 17th International Workshop, FSE 2010 , Seoul, Korea, February 7--10 , 2010, Revised Selected Papers. 333--346. Dmitry Khovratovich and Ivica Nikolic. 2010. Rotational cryptanalysis of ARX. In Fast Software Encryption, 17th International Workshop, FSE 2010, Seoul, Korea, February 7--10, 2010, Revised Selected Papers. 333--346."},{"key":"e_1_2_1_29_1","volume-title":"RFID Security: Techniques, Protocols and System-On-Chip Design","author":"Kitsos Paris","unstructured":"Paris Kitsos and Yan Zhang . 2008. RFID Security: Techniques, Protocols and System-On-Chip Design . Springer . Paris Kitsos and Yan Zhang. 2008. RFID Security: Techniques, Protocols and System-On-Chip Design. Springer."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-011-0006-y"},{"key":"e_1_2_1_31_1","volume-title":"Quantifying and Exploring the Gap Between FPGAs and ASICs","author":"Kuon Ian","unstructured":"Ian Kuon and Jonathan Rose . 2009. Quantifying and Exploring the Gap Between FPGAs and ASICs ( 1 st ed.). Springer Publishing Company, Inc orporated. Ian Kuon and Jonathan Rose. 2009. Quantifying and Exploring the Gap Between FPGAs and ASICs (1st ed.). Springer Publishing Company, Incorporated.","edition":"1"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2008.148"},{"key":"e_1_2_1_33_1","volume-title":"Power Analysis Attacks: Revealing the Secrets of Smart Cards (Advances in Information Security)","author":"Mangard Stefan","unstructured":"Stefan Mangard , Elisabeth Oswald , and Thomas Popp . 2007. Power Analysis Attacks: Revealing the Secrets of Smart Cards (Advances in Information Security) . Springer-Verlag New York , NY. Stefan Mangard, Elisabeth Oswald, and Thomas Popp. 2007. Power Analysis Attacks: Revealing the Secrets of Smart Cards (Advances in Information Security). Springer-Verlag New York, NY."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-42033-7_25"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12678-9_17"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/DFT.2015.7315144"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCAS.2007.378273"},{"key":"e_1_2_1_38_1","volume-title":"Robshaw and Olivier Billet (Eds.)","author":"Matthew J.","year":"2008","unstructured":"Matthew J. B. Robshaw and Olivier Billet (Eds.) . 2008 . New Stream Cipher Designs - The eSTREAM Finalists. Lecture Notes in Computer Science, Vol. 4986 . Springer . Matthew J. B. Robshaw and Olivier Billet (Eds.). 2008. New Stream Cipher Designs - The eSTREAM Finalists. Lecture Notes in Computer Science, Vol. 4986. Springer."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-85893-5_7"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2012.11"},{"key":"e_1_2_1_41_1","volume-title":"CHES 2015, 17th International Workshop, Saint-Malo, France, September 13--16, 2015, Proceedings. 495--513","author":"Schneider Tobias","year":"2015","unstructured":"Tobias Schneider and Amir Moradi . 2015 . Leakage assessment methodology\u2014A clear roadmap for side-channel evaluations. In Cryptographic Hardware and Embedded Systems , CHES 2015, 17th International Workshop, Saint-Malo, France, September 13--16, 2015, Proceedings. 495--513 . Tobias Schneider and Amir Moradi. 2015. Leakage assessment methodology\u2014A clear roadmap for side-channel evaluations. In Cryptographic Hardware and Embedded Systems, CHES 2015, 17th International Workshop, Saint-Malo, France, September 13--16, 2015, Proceedings. 495--513."},{"key":"e_1_2_1_42_1","first-page":"66","article-title":"Arithmetic addition over boolean masking - Towards first- and second-order resistance in hardware","volume":"2015","author":"Schneider Tobias","year":"2015","unstructured":"Tobias Schneider , Amir Moradi , and Tim G\u00fcneysu . 2015 . Arithmetic addition over boolean masking - Towards first- and second-order resistance in hardware . IACR Cryptology ePrint Archive 2015 (2015), 66 . Tobias Schneider, Amir Moradi, and Tim G\u00fcneysu. 2015. Arithmetic addition over boolean masking - Towards first- and second-order resistance in hardware. IACR Cryptology ePrint Archive 2015 (2015), 66.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2463209.2488898"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-01001-9_26"},{"key":"e_1_2_1_45_1","volume-title":"New Results in Dependability and Computer Systems","author":"Sugier Jaros\u0142aw","unstructured":"Jaros\u0142aw Sugier . 2013. Implementing Salsa20 vs. AES and serpent ciphers in popular-grade FPGA devices . In New Results in Dependability and Computer Systems . Springer , 431--438. Jaros\u0142aw Sugier. 2013. Implementing Salsa20 vs. AES and serpent ciphers in popular-grade FPGA devices. In New Results in Dependability and Computer Systems. Springer, 431--438."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/11796435_46"},{"key":"e_1_2_1_47_1","volume-title":"Workshop Record of SASC.","author":"Tsunoo Yukiyasu","year":"2007","unstructured":"Yukiyasu Tsunoo , Teruo Saito , Hiroyasu Kubo , Tomoyasu Suzaki , and Hiroki Nakashima . 2007 . Differential cryptanalysis of Salsa20\/8 . In Workshop Record of SASC. Yukiyasu Tsunoo, Teruo Saito, Hiroyasu Kubo, Tomoyasu Suzaki, and Hiroki Nakashima. 2007. Differential cryptanalysis of Salsa20\/8. In Workshop Record of SASC."},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/FPL.2009.5272260"},{"key":"e_1_2_1_49_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11432-015-5459-7","article-title":"RECTANGLE: A bit-slice lightweight block cipher suitable for multiple platforms","volume":"58","author":"Zhang Wentao","year":"2015","unstructured":"Wentao Zhang , Zhenzhen Bao , Dongdai Lin , Vincent Rijmen , Bohan Yang , and Ingrid Verbauwhede . 2015 . RECTANGLE: A bit-slice lightweight block cipher suitable for multiple platforms . SCIENCE CHINA Information Sciences 58 , 12 (2015), 1 -- 15 . Wentao Zhang, Zhenzhen Bao, Dongdai Lin, Vincent Rijmen, Bohan Yang, and Ingrid Verbauwhede. 2015. RECTANGLE: A bit-slice lightweight block cipher suitable for multiple platforms. SCIENCE CHINA Information Sciences 58, 12 (2015), 1--15.","journal-title":"SCIENCE CHINA Information Sciences"},{"key":"e_1_2_1_50_1","unstructured":"Y. Zhang and P. Kitsos. 2009. Security in RFID and Sensor Networks. CRC Press.   Y. Zhang and P. Kitsos. 2009. Security in RFID and Sensor Networks. CRC Press."}],"container-title":["ACM Transactions on Design Automation of Electronic Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2934677","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2934677","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:39:47Z","timestamp":1750217987000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2934677"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,11,11]]},"references-count":50,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2017,1,31]]}},"alternative-id":["10.1145\/2934677"],"URL":"https:\/\/doi.org\/10.1145\/2934677","relation":{},"ISSN":["1084-4309","1557-7309"],"issn-type":[{"value":"1084-4309","type":"print"},{"value":"1557-7309","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,11,11]]},"assertion":[{"value":"2015-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2016-04-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2016-11-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}