João Carlos Resende

dblp:160/7691 · DBLP profile ↗
← Back
7ranked-venue papers
5as first author
3since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 7 · 5 first-author · 3 since 2021
YearPublicationVenuePosition
2025 AEGIS+AES folded architecture for FPGA
abstract
Cryptography and data security are a main concern on the current digital communication world, but authenticated encryption (AE) protocols have been under performing. The CAESAR competition provided the opportunity for new proposals and discussions, that now reached the finalist stage with the AEGIS-128 and -256 authenticated ciphers. The work herein proposed takes into account the AEGIS implementation on FPGAs considering architectural trade-offs towards compact, efficient, and flexible implementations. A variation of the proposed solution also allows for the computation of both AEGIS and AES. This work considers a round-rolled 5/6-folded structure capable of processing both AEGIS-128 and -256 seamlessly, by carefully scheduling the 5 to 6 128-bit sub-states of the cipher. Experimental results suggest a maximum throughput of 5.9 and 4.9 Gbps for AEGIS-128 and AEGIS-256, respectively, on an AMD/Xilinx Zynq-7020. Furthermore, even though this design can process both AEGIS-128 and -256 variants (the first in the state-of-the-art) its occupation of only 496 Slices, makes it the most compact (and one of the most efficient) solutions on FPGAs, requiring $31.7 \%$ less resources than the smallest AEGIS-128 exclusive competitor. This is achieved with a cost of $16.6 \%$ less efficiency than the most efficient AEGIS-128 only design.
João Carlos Resende, Ricardo Chaves
DSD1
2024 External Memory Protection on FPGA-Based Embedded Systems
abstract
With the proliferation and increased capabilities of embedded systems, they become more exposed and easier targets to attacks. This includes the external components such as DRAM, particularly vulnerable to attacks, especially regarding unauthorized access to the stored data. With the goal of increasing storage security, this paper proposes a memory bridge evaluation platform and an improvement to the authenticated-encryption of off-chip memory, minimizing critical memory access latency. Most state-of-the-art works either use custom high-latency solutions, or frequently recur exclusively to AES-GCM standard for Authenticated Encryption with Associated Data. Besides AES-GCM, this work explores and implements different protection solutions, including NOEKEON-GCM and AEGIS-128L. This work also explores how much of the algorithms can be pre-computed between memory transmissions, by removing the address and data from critical path computations, placing it in the AAD field. The presented prototypes were evaluated on a Xilinx Zynq-7100, showing that the proposed platform allows to analyse and assess different approaches. The obtained experimental results suggest that with a careful selection of algorithms and implementations, memory access latency improvements up to 56% can be achieved in regard to equivalent AES-GCM designs.
João Carlos Resende, Aleksandar Ilic, Ricardo Chaves
DSD1
2022 SmartFusion2 SoC as a security module for the IoT world
abstract
Dedicated computational devices such as HSMs and FPGAs are frequently used to provide data security and privacy. However, these options have several drawbacks, particularly when considering IoT environments. HSMs offer high-grade services but are costly and lack application flexibility, while FPGAs, in general, are cheaper and adaptable, but lack security services and protection. Herein, the SmartFusion2 SoC FPGA, a security-oriented system, is evaluated as a possible low-cost and flexible platform for security modules for the IoT. This work analyzes the several security services of the SmartFusion2 SoC, their advantages, and possible trade-offs. To demonstrate the SoC viability as a security module and/or a more adaptable HSM alternative, several case study applications are considered and analyzed to elaborate on the potential, limitations, and mitigations of the latter.
Alexandre Rodrigues 0006, João Carlos Resende, Ricardo Chaves
CF2
2020 TBOX-Based Mask Scrambling Against SCA
abstract
In the last years Side-Channel Attacks have become a significant threat against security devices. Given this, several countermeasures have been proposed, ranging from reducing the leaked power consumption to masking schemes. However, these solutions imply a cost, typically in terms of resources, performance, and power consumption. This work re-adapts the masking scheme of Block Memory Content Scrambling (BMS) to the AES Look-up tables for System-on-Chip $(\mathrm {S}\mathrm {o}\mathrm {C})$ FPGAs, namely the SmartFusion 2 FPGA. The solution is further improved resource-wise by making use of the embedded ARM Cortex-M3 processor for updating the masks.
João Carlos Resende, Ricardo J. R. Maçãs, Ricardo Chaves
FCCM1
2020 Mask Scrambling Against SCA on Reconfigurable TBOX-Based AES
abstract
In the last years Side-Channel Attacks have become a significant threat against security devices. Given this, several countermeasures have been proposed, ranging from reducing the leaked power consumption to masking schemes. However, these solutions imply a cost, typically in terms of resources, performance, and power consumption. This paper focuses on the deployment of masking to the AES computation supported on re-configurable technologies, in this particular case on a SmartFusion 2 SoC and its FPGA fabric and embedded ARM Cortex-M3 processor. This work proposes a novel masking scheme using Auxiliary Random Tables (RBoxes) to further harden the protection against SCA by not only extending the set of used random masks, but also by improving the update frequency of the mask sets. The implementation results suggest that the existing related masking schemes can be deployed at a cost of 645 additional LUTs, 16 μSRAMs, and no additional Large SRAMs, whilst achieving the same operating frequency.
João Carlos Resende, Ricardo J. R. Maçãs, Ricardo Chaves
FPL1
2015 CLEFIA Implementation with Full Key Expansion
abstract
In this paper a compact and high throughput hardware structure is proposed allowing for the computation of the novel 128-bit CLEFIA encryption algorithm and its associated full key expansion. In the existing state of the art only the 128-bit key schedule is supported, given the needed modification to the CLEFIA Feistel network. This work shows that with a small area cost and with no performance impact, full key expansion can be supported. This is achieved by using addressable shift registers, available in modern FPGAs, and adaptable scheduling, allowing to compute the 4 and 8 branch CLEFIA Feistel network within the same structure. The obtained experimental results suggest that throughputs above 1 Gbps can be achieved with a low area cost, while achieving efficiency metrics above those of the restricted state of the art.
João Carlos Bittencourt, João Carlos Resende, Wagner Luiz Alves de Oliveira, Ricardo Chaves
DSD2
2015 Compact dual block AES core on FPGA for CCM Protocol
abstract
This paper presents a compact and FPGA based implementation of the AES encryption standard, specifically designed for processing two independent 128-bit input blocks in feedback modes. This configuration is particularly focused on the Counter with CBC-MAC Protocol, but can also be adapted to other AES based encryption-authentication protocols requiring the processing of two independent data streams. Most of the state of the art solutions implementing CCMP consider large datapaths, sometimes with separated encryption datapaths for the different data streams, leading to low resource efficiency. The work herein proposed suggests that with adequate FPGA component usage and with proper data scheduling a very compact and efficient dual AES core can be derived particularly on FPGAs. Overall, the proposed structure allows for a throughput of 1.7Gbps while achieving a Throughput/Slice efficiency of 24.22 Mbps/Slice, 47% higher than the existing related state of the art.
João Carlos Resende, Ricardo Chaves
FPL1