| Energy evaluation of software implementations of block ciphers under memory constraints |
| Full text |
Pdf
(262 KB)
|
| Source
|
Design, Automation, and Test in Europe
archive
Proceedings of the conference on Design, automation and test in Europe
table of contents
Nice, France
SESSION: Secure systems
table of contents
Pages: 1110 - 1115
Year of Publication: 2007
ISBN:978-3-9810801-2-4
|
|
Authors
|
|
Johann Großschädl
|
Graz University of Technology, Graz, Austria
|
|
Stefan Tillich
|
Graz University of Technology, Graz, Austria
|
|
Christian Rechberger
|
Graz University of Technology, Graz, Austria
|
|
Michael Hofmann
|
Graz University of Technology, Graz, Austria
|
|
Marcel Medwed
|
Graz University of Technology, Graz, Austria
|
|
| Sponsors |
|
| Publisher |
EDA Consortium
San Jose, CA, USA
|
| Bibliometrics |
Downloads (6 Weeks): 17, Downloads (12 Months): 79, Citation Count: 1
|
|
|
ABSTRACT
Software implementations of modern block ciphers often require large lookup tables along with code size increasing optimizations like loop unrolling to reach peak performance on general-purpose processors. Therefore, block ciphers are difficult to implement efficiently on embedded devices like cell phones or sensor nodes where run-time memory and program ROM are scarce resources. In this paper we analyze and compare the performance, energy consumption, run-time memory requirements, and code size of the five block ciphers RC6, Rijndael, Serpent, Twofish, and XTEA on the StrongARM SA-1100 processor. Most previous evaluations of block ciphers considered performance as the sole metric of interest and did not care about memory requirements or code size. In contrast to previous work, our study of the performance and energy characteristics of block ciphers has been conducted with "lightweight" implementations which restrict the size of lookup tables to 1 kB and also impose constraints on the code size. We found that Rijndael and RC6 can be well optimized for high performance and energy efficiency, while at the same time meeting the demand for low memory (RAM and ROM) footprint. In addition, we discuss the impact of key expansion and modes of operation on the overall performance and energy consumption of each block cipher. Our simulation results show that RC6 is the most energy-efficient block cipher under memory constraints and thus the best choice for resource-restricted devices.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
R. J. Anderson, E. Biham, and L. R. Knudsen. Serpent: A proposal for the Advanced Encryption Standard. Technical report, University of Cambridge, 1998.
|
| |
2
|
ARM Limited. ARM Architecture Reference Manual. ARM Doc No. DDI-0100, Issue H, 2003.
|
| |
3
|
|
| |
4
|
|
| |
5
|
|
| |
6
|
B. R. Gladman. AES second round implementation experience. Available online at http://fp.gladman.plus.com/cryptography_technology/aesr2/index.htm, 2000.
|
| |
7
|
|
| |
8
|
|
 |
9
|
|
| |
10
|
R. M. Needham and D. J. Wheeler. Tea extensions. Technical report, University of Cambridge, 1997.
|
 |
11
|
|
| |
12
|
D. Remondoa and I. G. Niemegeers. Ad-hoc networking in future wireless communications. Computer Communications, 26(1):36--40, 2003.
|
| |
13
|
R. L. Rivest et al. The RC6#8482; block cipher. Technical report, RSA Laboratories, 1998.
|
| |
14
|
B. Schneier et al. Twofish: A 128-bit block cipher. Technical report, Counterpane Systems, 1998.
|
 |
15
|
|
| |
16
|
|
| |
17
|
S. Tillich, J. Großschädl, and A. Szekely. An instruction set extension for fast and memory-efficient AES implementation. In Communications and Multimedia Security --- CMS 2005, LNCS 3677 pp. 11--21. Springer Verlag, 2005.
|
| |
18
|
University of Michigan. Sim-Panalyzer 2.0. Available for download at http://www.eecs.umich.edu/~panalyzer.
|
| |
19
|
M. Weiser. The computer for the 21st century. Scientific American, 265(3):94--104, 1991.
|
|