Multi-target DPA Attacks: Pushing DPA Beyond the Limits of a Desktop Computer

Multi-target DPA Attacks: Pushing DPA Beyond the Limits of a Desktop Computer
复制标题

DOI:
10.1007/978-3-662-45611-8_13
复制
发表时间:
2014-12
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Luke Mather;E. Oswald;C. Whitnall
Luke Mather;E. Oswald;C. Whitnall
中科院分区:
其他
文献类型:
--
作者:
Luke Mather;E. Oswald;C. Whitnall

文献摘要

被引文献

相似文献

继Kocher等人的开创性的“99年专利商标局”论文之后,差分功率分析(DPA)最初是围绕使用标准桌面设备执行的低成本计算进行的,对设备特定假设的依赖最小。在随后的几年里,范围扩大了,例如,明确使用(近似)功率模型。这样做的一个重要的实际动机是降低攻击的数据复杂性,通常以增加计算复杂性为代价。这是我们在本文中试图探索的权衡。我们从几个方面的文献,高性能计算,后侧通道的全球关键枚举,并有效地结合不同的信息源,通过推进(非配置文件)的“标准DPA”走向一个更现实的威胁模型,其中跟踪收购稀缺,但对手的资源充足。使用我们专门设计的计算平台(包括我们的并行和可扩展的DPA实现,这使我们能够有效地工作与多达232个关键假设),我们展示了一些显着的改进,是可能的“标准DPA”时,结合DPA的结果几个中间目标。与大多数以前的“信息组合”尝试不同,我们能够证明这样一个事实,即即使相关信息(即“有趣的点”)的确切跟踪位置不知道优先级,但必须同时搜索正确的子键,改进也适用。
Following the pioneering CRYPTO ’99 paper by Kocher et al., differential power analysis (DPA) was initially geared around low-cost computations performed using standard desktop equipment with minimal reliance on device-specific assumptions. In subsequent years, the scope was broadened by, e.g., making explicit use of (approximate) power models. An important practical incentive of so-doing is to reduce the data complexity of attacks, usually at the cost of increased computational complexity. It is this trade-off which we seek to explore in this paper. We draw together emerging ideas from several strands of the literature—high performance computing, post-side-channel global key enumeration, and effective combination of separate information sources—by way of advancing (non-profiled) ‘standard DPA’ towards a more realistic threat model in which trace acquisitions are scarce but adversaries are well resourced. Using our specially designed computing platform (including our parallel and scalable DPA implementation, which allows us to work efficiently with as many as 232key hypotheses), we demonstrate some dramatic improvements that are possible for ‘standard DPA’ when combining DPA outcomes for several intermediate targets. Unlike most previous ‘information combining’ attempts, we are able to evidence the fact that the improvements apply even when the exact trace locations of the relevant information (i.e. the ‘interesting points’) are not knowna prioribut must be searched simultaneously with the correct subkey.