Skip to main content

Table 2 Comparison of the costs on linear operations of one round

From: A secure and highly efficient first-order masking scheme for AES linear operations

Cost Number of XOR Number of GF256MUL2 Number of Shift
Operation AddRoundKey MixColumns Remask MixColumns ShiftRows
Original Implementation 16 64 × 2 0/32/64/96 32 × 2 12 × 2
Improved Implementation 16 60 × 2 0/32/64/96 16 × 2 12 × 2
Our Proposal 16 120 0/32/64/96 20 12 × 2