Skip to content
Open access

LISHARK: Lightweight Side Channel Protected Secure Hardware Extension with Re-keying

Jul 2026 · ACM Transactions on Embedded Computing Systems · 0 citations · 12 references

Abstract

The Secure Hardware Extension (SHE) provides crucial functionalities such as error-detection, authorization, and authentication of messages exchanged between Electronic Control Units (ECUs) over the Controller Area Network (CAN) bus with the help of Advanced Encryption Standard (AES) cryptographic cores. However, the security guarantees of SHE can be entirely compromised if an adversary with physical access to the vehicle extracts the secret key using power or electromagnetic side-channel measurements. While countermeasures like Threshold Implementation (TI) and Domain-Oriented Masking (DOM) offer robust protection, they are impractical for SHE due to the stringent resource constraints and real-time safety requirements of automotive systems. To address this critical vulnerability, this paper explores the concept of re-keying, utilizing two rounds of AES hardware as a lightweight key derivation function. This approach eliminates the need for additional key exchanges between the sender and receiver. Our experimental results, supported by theoretical analysis, indicate that re-keying every 10 encryptions provides a practical and secure solution that limits the effectiveness of side-channel attacks; leakage analysis performed on over 1,000,000 electromagnetic (EM) traces for this configuration revealed no detectable leakage. These findings are supported by real-world side-channel attack experiments conducted on a prototype implemented on the Cora-Z7 platform, built on Xilinx’s Zynq-7000 system featuring a single or dual-core 667 MHz ARM Cortex-A9 processor and Artix-7 FPGA. The proposed lightweight architecture, named LISHARK, maintains the same area footprint as a standalone AES core, making it significantly more efficient compared to TI and DOM. Measurements show that when integrated with the Secure Onboard Communication (SecOC) protocol, the design achieves end-to-end message authentication in approximately 90 microseconds, well within the industry-standard threshold of 10 milliseconds.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.