Practical aspects on non-profiled deep-learning side-channel attacks against AES software implementation with two types of masking countermeasures including RSM

Practical aspects on non-profiled deep-learning side-channel attacks against AES software implementation with two types of masking countermeasures including RSM
复制标题

针对 AES 软件实施的非剖析深度学习侧信道攻击的实际问题,采用包括 RSM 在内的两种类型的屏蔽对策

DOI:
10.1007/s13389-023-00312-6
复制
发表时间:
2023
影响因子:
1.9
通讯作者:
Takeshi Fujino
Takeshi Fujino
中科院分区:
计算机科学4区
文献类型:
--
作者:
Kunihiro Kuroda;Yuta Fukuda;Kota Yoshida;Takeshi Fujino

文献摘要

相似文献

众所周知,深度学习侧信道攻击 (DL-SCA) 将深度神经网络 (DNN) 应用于 SCA,可以轻松攻击一些现有的 SCA 对策,例如掩蔽和随机抖动。虽然关于分析 DL-SCA 的研究很多,但 2018 年提出了一种将深度学习应用于非分析攻击的新方法。在我们的研究中,我们使用 ANSSI SCA 数据库和屏蔽对策,研究非分析 DL-SCA 的 DNN 模型和攻击点(PoI:兴趣点)的结构。调查结果表明,最好使用简单的网络模型,应用正则化来防止过度拟合,并选择包含侧信道信息的大范围功率迹线作为 PoI。我们还在 Xmega128 微控制器上实现了受 RSM(旋转 Sboxes Masking)对策保护的 AES-128 软件实现,该软件从未受到非配置文件 DL-SCA 的攻击,并对其进行了非配置文件 DL-SCA。非分析 DL-SCA 成功恢复了所有部分密钥,而传统功率分析则无法恢复。我们进行了两种类型的实验分析,以阐明 DL-SCA 学习掩蔽对策中使用的掩码值。一种是之前研究中使用的梯度可视化,另一种是使用部分去除功率痕迹的新分析方法。
Deep-learning side-channel attacks (DL-SCAs), applying deep neural networks (DNNs) to SCAs, are known that can easily attack some existing SCA countermeasures such as masking and random jitter. While there have been many studies on profiled DL-SCAs, a new approach that involves applying deep learning to non-profiled attacks was proposed in 2018. In our study, we investigate the structure of DNN models and attack points (PoI: Points of Interests) for non-profiled DL-SCAs using the ANSSI SCA database with a masking countermeasure. The results of investigations indicate that it is better to use a simple network model, apply regularization to prevent over-fitting, and select a wide range of power traces that contain side-channel information as the PoI. We also implemented AES-128 software implementation protected with the RSM (Rotating Sboxes Masking) countermeasure, which has never been attacked by non-profiled DL-SCAs, on the Xmega128 microcontroller and carried out non-profiled DL-SCAs against it. Non-profiled DL-SCAs successfully recovered all partial keys while the conventional power analysis could not. We conducted two types of experimental analyses to clarify that DL-SCAs learn mask-values used in the masking countermeasure. One is the-gradient visualization used in previous studies, and the other is a new analysis method using partial removal of power traces.