Near Collision Side Channel Attacks

Near Collision Side Channel Attacks
复制标题

DOI:
10.1007/978-3-319-31301-6_17
复制
发表时间:
2015-08
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Baris Ege;T. Eisenbarth;L. Batina
Baris Ege;T. Eisenbarth;L. Batina
中科院分区:
其他
文献类型:
--
作者:
Baris Ege;T. Eisenbarth;L. Batina

文献摘要

被引文献

相似文献

边信道碰撞攻击是利用边信道泄漏的一种有效方法。除了少数例外,碰撞攻击通常结合了来自不同时间点的联合收割机泄漏,使其本质上是双变量的。这项工作引入了近碰撞的概念,利用这一事实,即取决于相同的子密钥的值可以有类似的,而不是相同的泄漏。我们展示了如何利用这些知识来进行密钥恢复攻击。与其他最先进的碰撞攻击相比,所提出的方法具有几个理想的功能:近碰撞攻击是真正的单变量。它们对泄漏函数的要求较低,因为它们对于在目标中间状态的位中为线性的泄漏工作良好。如果存在明显的泄漏(如泄漏挤压),则可适用于掩蔽对策。结果得到了针对无保护和屏蔽实施的广泛模拟以及DPA Contest v4提供的测量集分析的支持。
Side channel collision attacks are a powerful method to exploit side channel leakage. Otherwise than a few exceptions, collision attacks usually combine leakage from distinct points in time, making them inherently bivariate. This work introduces the notion of near collisions to exploit the fact that values depending on the same sub-key can have similar while not identical leakage. We show how such knowledge can be exploited to mount a key recovery attack. The presented approach has several desirable features when compared to other state-of-the-art collision attacks: Near collision attacks are truly univariate. They have low requirements on the leakage functions, since they work well for leakages that are linear in the bits of the targeted intermediate state. They are applicable in the presence of masking countermeasures if there exist distinguishable leakages, as in the case of leakage squeezing. Results are backed up by a broad range of simulations for unprotected and masked implementations, as well as an analysis of the measurement set provided by DPA Contest v4.