A Side-Channel-Aware Cryptographic Framework for Secure Interactive, Embedded, IoT, and Edge Communication Systems

Authors

  • Walid W. Souror Zagazig University
  • Mohamed Fouad Higher Institute of Technology in Beheira
  • Fahmi Khalif Mansoura University
  • Ali E. Takieldeen Delta University for Science and Technology

DOI:

https://doi.org/10.62411/jcta.16745

Keywords:

AES, Blowfish, CPA, Hybrid cryptography, IoT cryptography, Side-channel security, TVLA, Simulation-based leakage assessment

Abstract

Secure interactive, embedded, and edge communication systems are often deployed in physically exposed environments where algorithmically secure ciphers may exhibit implementation-specific leakage. This paper presents a simulation-based evaluation of a configurable hybrid AES-Blowfish framework comprising AES-Hybridization, Combined Blowfish Trilogy, and cascaded Blowfish-to-AES modes. The AES-Hybridization path combines AES-256-CBC, Argon2id-derived whitening material, HMAC-based integrity binding, plaintext masking, and modeled randomized hiding activity. The hiding activity is represented solely within the leakage simulation and does not modify the plaintext or ciphertext. The Blowfish path employs session-dependent P-array randomization, dynamic S-box initialization, and a three-stage Feistel-like structure. The framework is evaluated using representative IoT/edge workload proxies, component-level ablation studies, modeled leakage assessment, non-ideal leakage scenarios, parameter-sensitivity analysis, and a software-level performance model. Compared with the simulated baseline configurations, the proposed modes reduce modeled TVLA, CPA, and DPA distinguishability, with AES-Hybridization providing the most balanced security-performance trade-off and the cascaded mode achieving the lowest modeled distinguishability at the highest computational cost. All findings are derived exclusively from simulation; no validation using physical power traces, electromagnetic traces, FPGA implementations, or microcontroller platforms is claimed.

Author Biographies

Walid W. Souror, Zagazig University

Department of Electronics and Communications Engineering, Faculty of Engineering, Zagazig University, Zagazig 44519, Sharkia, Egypt

Mohamed Fouad, Higher Institute of Technology in Beheira

Higher Institute of Technology in Beheira, Abu El Matamir, Beheira Governorate, Egypt; Department of Electronics and Communications Engineering, Faculty of Engineering, Mansoura University, Mansoura 35516, Dakahlia, Egypt

Fahmi Khalif, Mansoura University

Department of Electronics and Communications Engineering, Faculty of Engineering, Mansoura University, Mansoura 35516, Dakahlia, Egypt; Department of Electrical and Computer Engineering, Morgan State University, Baltimore, MD 21251, United States

Ali E. Takieldeen, Delta University for Science and Technology

Department of Cyber Security, Faculty of Artificial Intelligence, Delta University for Science and Technology, Gamasa 35712, Dakahlia, Egypt

References

W. Liu et al., “Full-Element Analysis of Side-Channel Leakage Dataset on Symmetric Cryptographic Advanced Encryption Standard,” Symmetry (Basel)., vol. 17, no. 5, p. 769, May 2025, doi: 10.3390/sym17050769.

J. Mishra and S. K. Sahay, “Modern Hardware Security: A Review of Attacks and Countermeasures,” ArXiv. Jan. 08, 2025. [Online]. Available: http://arxiv.org/abs/2501.04394

S. Belaïd et al., “SoK: A Methodology to Achieve Provable Side-Channel Security in Real-World Implementations,” IACR Commun. Cryptol., vol. 2, no. 1, 2025, doi: 10.62056/aebngy4e-.

D. Ramakrishna and M. A. Shaik, “PSESV: A hybrid post-quantum encryption Framework with real-time thermal and EM side-channel attack detection,” Ain Shams Eng. J., vol. 16, no. 12, p. 103776, Dec. 2025, doi: 10.1016/j.asej.2025.103776.

N. S. Dokku, R. David Amar Raj, S. K. Bodapati, A. Pallakonda, Y. R. M. Reddy, and K. Krishna Prakasha, “Resilient cybersecurity in smart grid ICS communication using BLAKE3-driven dynamic key rotation and intrusion detection,” Sci. Rep., vol. 15, no. 1, p. 32754, Sep. 2025, doi: 10.1038/s41598-025-17530-z.

R. K. Muhammed et al., “Comparative Analysis of AES, Blowfish, Twofish, Salsa20, and ChaCha20 for Image Encryption,” Kurdistan J. Appl. Res., vol. 9, no. 1, pp. 52–65, May 2024, doi: 10.24017/science.2024.1.5.

V. T. Hoang and P. Rogaway, “On Generalized Feistel Networks,” in Lecture Notes in Computer Science, 2010, pp. 613–630. doi: 10.1007/978-3-642-14623-7_33.

R. C and K. G. N., “An optimized encryption algorithm and F function with dynamic substitution for creating S-box and P-box entries for blowfish algorithm,” Comput. Sci. Inf. Technol., vol. 2, no. 1, pp. 16–25, Mar. 2021, doi: 10.11591/csit.v2i1.p16-25.

S. S. Abdul-Jabbar, A. E. Abed, S. G. Mohammed, and F. G. Mohammed, “Fast 128-bit Multi-Pass Stream Ciphering Method,” Iraqi J. Sci., pp. 2589–2600, May 2023, doi: 10.24996/ijs.2023.64.5.40.

P. Kietzmann, T. C. Schmidt, and M. Wählisch, “A Guideline on Pseudorandom Number Generation (PRNG) in the IoT,” ACM Comput. Surv., vol. 54, no. 6, pp. 1–38, Jul. 2022, doi: 10.1145/3453159.

Y. Chinnam and B. Sambana, “Artificial Intelligence enhanced Security Problems in Real-Time Scenario using Blowfish Algorithm,” arXiv. Apr. 14, 2024. [Online]. Available: http://arxiv.org/abs/2404.09286

P. Tippe and M. P. Berner, “Evaluating Argon2 Adoption and Effectiveness in Real-World Software,” in Lecture Notes in Computer Science, 2025, pp. 25–46. doi: 10.1007/978-3-032-00627-1_2.

A. S. Tushar, “Enhancement of AES Security On FPGA: Mitigating Side Channel Attacks,” Int. J. Res. Appl. Sci. Eng. Technol., vol. 13, no. 6, pp. 2605–2611, Jun. 2025, doi: 10.22214/ijraset.2025.72696.

A. Ghosh, D.-H. Seo, D. Das, S. Ghosh, and S. Sen, “R-STELLAR: A Resilient Synthesizable Signature Attenuation SCA Protection on AES-256 With Built-In Attack-on-Countermeasure Detection,” IEEE Open J. Solid-State Circuits Soc., vol. 5, pp. 167–179, 2025, doi: 10.1109/OJSSCS.2025.3571334.

H. Li and G. Perin, “A systematic study of data augmentation for protected AES implementations,” J. Cryptogr. Eng., vol. 14, no. 4, pp. 649–666, Nov. 2024, doi: 10.1007/s13389-024-00363-3.

G. Barthe, G. Betarte, J. Campo, C. Luna, and D. Pichardie, “System-level Non-interference for Constant-time Cryptography,” in Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, Nov. 2014, pp. 1267–1279. doi: 10.1145/2660267.2660283.

E. Almaraz Luengo and J. Román Villaizán, “Cryptographically Secured Pseudo-Random Number Generators: Analysis and Testing with NIST Statistical Test Suite,” Mathematics, vol. 11, no. 23, p. 4812, Nov. 2023, doi: 10.3390/math11234812.

C. Chevalier, G. Lebrun, and A. Martinelli, “Spilling-Cascade: An Optimal PKE Combiner for KEM Hybridization,” in Lecture Notes in Computer Science, 2025, pp. 455–485. doi: 10.1007/978-3-031-95761-1_16.

Et. al., Pravin Soni, “Performance Analysis of Cascaded Hybrid Symmetric Encryption Models,” Turkish J. Comput. Math. Educ., vol. 12, no. 2, pp. 1699–1708, Apr. 2021, doi: 10.17762/turcomat.v12i2.1506.

M. Rivain and E. Prouff, “Provably Secure Higher-Order Masking of AES,” in Lecture Notes in Computer Science, 2010, pp. 413–427. doi: 10.1007/978-3-642-15031-9_28.

S. Nikova, C. Rechberger, and V. Rijmen, “Threshold Implementations Against Side-Channel Attacks and Glitches,” in Lecture Notes in Computer Science, 2006, pp. 529–545. doi: 10.1007/11935308_38.

L. E. Bassham et al., “A statistical test suite for random and pseudorandom number generators for cryptographic applications,” Gaithersburg, MD, 2010. doi: 10.6028/NIST.SP.800-22r1a.

M.-J. O. Saarinen, “SP 800–22 and GM/T 0005–2012 Tests: Clearly Obsolete, Possibly Harmful,” in 2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Jun. 2022, pp. 31–37. doi: 10.1109/EuroSPW55150.2022.00011.

G. Goodwill, B. Jun, J. Jaffe, and P. Rohatgi, “A Testing Methodology for Side-Channel Resistance Validation,” 2011. [Online]. Available: https://csrc.nist.gov/csrc/media/events/non-invasive-attack-testing-workshop/documents/08_goodwill.pdf

International Organization for Standardization, “ISO/IEC 17825:2024 Information Technology -- Security Techniques -- Testing Methods for the Mitigation of Non-Invasive Attack Classes Against Cryptographic Modules,” 2024.

E. Brier, C. Clavier, and F. Olivier, “Correlation Power Analysis with a Leakage Model,” in Lecture Notes in Computer Science, 2004, pp. 16–29. doi: 10.1007/978-3-540-28632-5_2.

S. Mangard, E. Oswald, and T. Popp, Power Analysis Attacks: Revealing the Secrets of Smart Cards. Boston, MA: Springer US, 2007. doi: 10.1007/978-0-387-38162-6.

P. Kocher, J. Jaffe, and B. Jun, “Differential Power Analysis,” in Lecture Notes in Computer Science, 1999, pp. 388–397. doi: 10.1007/3-540-48405-1_25.

Y. Bai, R. Y. Acharya, and D. Forte, “SPERO: Simultaneous Power/EM Side-channel Dataset Using Real-time and Oscilloscope Setups,” ArXiv. May 10, 2024. [Online]. Available: http://arxiv.org/abs/2405.06571

J. Ming, Y. Zhou, H. Li, and Q. Zhang, “A secure and highly efficient first-order masking scheme for AES linear operations,” Cybersecurity, vol. 4, no. 1, p. 14, Dec. 2021, doi: 10.1186/s42400-021-00082-w.

A. R. Shahmirzadi, D. Božilov, and A. Moradi, “New First-Order Secure AES Performance Records,” IACR Trans. Cryptogr. Hardw. Embed. Syst., vol. 2021, no. 2, pp. 304–327, Feb. 2021, doi: 10.46586/tches.v2021.i2.304-327.

S. Lee and J.-N. Kim, “Balanced Encoding of Near-Zero Correlation for an AES Implementation,” IEEE Trans. Inf. Forensics Secur., vol. 19, pp. 6589–6603, 2024, doi: 10.1109/TIFS.2024.3420101.

R. Benadjila, E. Prouff, R. Strullu, E. Cagli, and C. Dumas, “Deep learning for side-channel analysis and introduction to ASCAD database,” J. Cryptogr. Eng., vol. 10, no. 2, pp. 163–188, Jun. 2020, doi: 10.1007/s13389-019-00220-8.

L. Masure and R. Strullu, “Side-channel analysis against ANSSI’s protected AES implementation on ARM: end-to-end attacks with multi-task learning,” J. Cryptogr. Eng., vol. 13, no. 2, pp. 129–147, Jun. 2023, doi: 10.1007/s13389-023-00311-7.

S. Picek, G. Perin, L. Mariot, L. Wu, and L. Batina, “SoK: Deep Learning-based Physical Side-channel Analysis,” ACM Comput. Surv., vol. 55, no. 11, pp. 1–35, Nov. 2023, doi: 10.1145/3569577.

M. Panoff, H. Yu, H. Shan, and Y. Jin, “A Review and Comparison of AI-enhanced Side Channel Analysis,” ACM J. Emerg. Technol. Comput. Syst., vol. 18, no. 3, pp. 1–20, Jul. 2022, doi: 10.1145/3517810.

H. Wang, “Amplitude-modulated EM side-channel attack on provably secure masked AES,” J. Cryptogr. Eng., vol. 14, no. 3, pp. 537–549, Sep. 2024, doi: 10.1007/s13389-024-00347-3.

M. S. Turan, K. A. McKay, D. Chang, J. Kang, and J. Kelsey, “Ascon-based lightweight cryptography standards for constrained devices :,” Aug. 2025. doi: 10.6028/NIST.SP.800-232.

C. Silva, N. Tenório, and J. Bernardino, “Lightweight Encryption Algorithms for IoT,” Computers, vol. 14, no. 12, p. 505, Nov. 2025, doi: 10.3390/computers14120505.

J. Kaur, A. Cintas Canto, M. Mozaffari Kermani, and R. Azarderakhsh, “A Survey on the Implementations, Attacks, and Countermeasures of the Current NIST Lightweight Cryptography Standard,” TechRxiv. May 22, 2023. doi: 10.36227/techrxiv.22970855.

S. Deb, A. A.-A. Gutub, and A. K. Sahu, Eds., Fortressing Pixels: Information security for images, videos, audio and beyond. United Kingdom: The Institution of Engineering and Technology, 2025. doi: 10.1049/PBSE030E.

A. K. Chandanan, V. K. Sarathe, A. Dwivedi, R. Chandrasekaran, V. Roy, and A. K. Sahu, “Cloud-based analysis with quantum cryptography-based cloud security model (QC-CSM) for enhanced data security in storage and access,” in Fortressing Pixels, United Kingdom: The Institution of Engineering and Technology, 2025, pp. 93–115. doi: 10.1049/PBSE030E_ch6.

B. V. S. S. Praneeth, R. Ch, C. N. Manikanta, D. Pavan Kumar, M. Sahu, and A. K. Sahu, “Privacy protection of medical data using NTRU-based post-quantum cryptography,” in Fortressing Pixels, United Kingdom: The Institution of Engineering and Technology, 2025, pp. 197–211. doi: 10.1049/PBSE030E_ch10.

Downloads

Published

2026-07-26

How to Cite

Souror, W. W., Fouad, M., Khalif, F., & Takieldeen, A. E. (2026). A Side-Channel-Aware Cryptographic Framework for Secure Interactive, Embedded, IoT, and Edge Communication Systems. Journal of Computing Theories and Applications, 4(1), 164–184. https://doi.org/10.62411/jcta.16745