International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

New Circuit Minimization Techniques for Smaller and Faster AES SBoxes

Authors:
Alexander Maximov , Ericsson Research, Lund
Patrik Ekdahl , Ericsson Research, Lund
Download:
DOI: 10.13154/tches.v2019.i4.91-125
URL: https://tches.iacr.org/index.php/TCHES/article/view/8346
Search ePrint
Search Google
Presentation: Slides
Abstract: In this paper we consider various methods and techniques to find the smallest circuit realizing a given linear transformation on n input signals and m output signals, with a constraint of a maximum depth, maxD, of the circuit. Additional requirements may include that input signals can arrive to the circuit with different delays, and output signals may be requested to be ready at a different depth. We apply these methods and also improve previous results in order to find hardware circuits for forward, inverse, and combined AES SBoxes, and for each of them we provide the fastest and smallest combinatorial circuits. Additionally, we propose a novel technique with “floating multiplexers” to minimize the circuit for the combined SBox, where we have two different linear matrices (forward and inverse) combined with multiplexers. The resulting AES SBox solutions are the fastest and smallest to our knowledge.
Video from TCHES 2019
BibTeX
@article{tches-2019-29847,
  title={New Circuit Minimization Techniques for Smaller and Faster AES SBoxes},
  journal={IACR Transactions on Cryptographic Hardware and Embedded Systems},
  publisher={Ruhr-Universität Bochum},
  volume={2019, Issue 4},
  pages={91-125},
  url={https://tches.iacr.org/index.php/TCHES/article/view/8346},
  doi={10.13154/tches.v2019.i4.91-125},
  author={Alexander Maximov and Patrik Ekdahl},
  year=2019
}