LeakyOhm: Secret Bits Extraction using Impedance Analysis

LeakyOhm: Secret Bits Extraction using Impedance Analysis
复制标题

DOI:
10.1145/3576915.3623092
复制
发表时间:
2023-05
期刊:
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Saleh Khalaj Monfared;Tahoura Mosavirik;Shahin Tajik
Saleh Khalaj Monfared;Tahoura Mosavirik;Shahin Tajik
中科院分区:
其他
文献类型:
--
作者:
Saleh Khalaj Monfared;Tahoura Mosavirik;Shahin Tajik

文献摘要

被引文献

相似文献

物理侧信道攻击的威胁及其对策已经得到了广泛的研究。大多数物理侧信道攻击依赖于计算或存储对芯片上的电流消耗或电压降的不可避免的影响。这种依赖于数据的影响可以通过例如功率或电磁分析来利用。在这项工作中,我们介绍了一种新的非侵入性的物理侧信道攻击,它利用数据相关的芯片的阻抗变化。我们的攻击依赖于寄存器中临时存储的内容改变电路的物理特性,从而导致芯片阻抗的变化。为了检测这种阻抗变化,我们部署了一种称为散射参数分析的众所周知的RF/微波方法,在该方法中,我们将高频正弦波信号注入系统的配电网络(PDN)并测量信号的回波。我们证明,根据寄存器的内容位和物理位置,反射信号在各个频率点进行不同的调制,从而能够同时和独立地探测各个寄存器。这种侧信道泄漏挑战了掩蔽中使用的t探测安全模型假设,这是一种突出的侧信道对策。为了验证我们的说法,我们安装非轮廓和轮廓阻抗分析攻击的硬件实现的无保护和高阶屏蔽AES。我们表明,在剖析攻击的情况下,只需要一个单一的跟踪恢复的秘密密钥。最后,我们讨论了如何一个特定的类隐藏对策可能是有效的阻抗泄漏。
The threats of physical side-channel attacks and their countermeasures have been widely researched. Most physical side-channel attacks rely on the unavoidable influence of computation or storage on current consumption or voltage drop on a chip. Such data-dependent influence can be exploited by, for instance, power or electromagnetic analysis. In this work, we introduce a novel non-invasive physical side-channel attack, which exploits the data-dependent changes in the impedance of the chip. Our attack relies on the fact that the temporarily stored contents in registers alter the physical characteristics of the circuit, which results in changes in the die's impedance. To sense such impedance variations, we deploy a well-known RF/microwave method called scattering parameter analysis, in which we inject sine wave signals with high frequencies into the system's power distribution network (PDN) and measure the echo of the signals. We demonstrate that according to the content bits and physical location of a register, the reflected signal is modulated differently at various frequency points enabling the simultaneous and independent probing of individual registers. Such side-channel leakage challenges the t-probing security model assumption used in masking, which is a prominent side-channel countermeasure. To validate our claims, we mount non-profiled and profiled impedance analysis attacks on hardware implementations of unprotected and high-order masked AES. We show that in the case of the profiled attack, only a single trace is required to recover the secret key. Finally, we discuss how a specific class of hiding countermeasures might be effective against impedance leakage.