Modeling Soft Analytical Side-Channel Attacks from a Coding Theory Viewpoint

Modeling Soft Analytical Side-Channel Attacks from a Coding Theory Viewpoint
复制标题

DOI:
10.13154/tches.v2020.i4.209-238
复制
发表时间:
2020-08
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Qian Guo;Vincent Grosso;François-Xavier Standaert
Qian Guo;Vincent Grosso;François-Xavier Standaert
中科院分区:
其他
文献类型:
--
作者:
Qian Guo;Vincent Grosso;François-Xavier Standaert

文献摘要

被引文献

相似文献

侧信道分析中的一个重要的开放问题是找出实现中的所有泄漏样本是否都可以被对手利用,正如掩蔽安全证明所建议的那样。对于利用分而治之策略的攻击,答案是否定的:只有与分组密码的第一轮/最后一轮相对应的泄漏可以被利用。软分析侧信道攻击(SASCA)已被引入作为一个强大的解决方案,以减轻这一限制。它们将目标实现及其泄漏表示为一个代码(类似于低密度奇偶校验码),该代码通过置信传播进行解码。以前的工作已经表明SASCA在实践中可以达到的低数据复杂度。在本文中,我们重新审视这些攻击,他们与随机探测模型用于掩蔽安全证明,我们表示为本地随机探测模型(LRPM)的变化建模。我们的研究在这个模型和编码理论中使用的擦除通道之间建立了有趣的联系,带来了以下好处。首先,LRPM允许以快速和直观的方式限制具体实现的安全性。我们使用它,以确认在块密码中的任何操作的泄漏可以被利用,虽然外部操作的泄漏在已知的明文/密文攻击方案中占主导地位。其次,我们表明,LRPM是一个工具的选择(几乎最坏的情况下)分析的掩蔽实现在嘈杂的泄漏模型,利用所有的操作进行,并导致新的权衡其数量的随机性和物理噪声水平。第三,我们表明,它可以大大加快其他对策,如洗牌的评估。
One important open question in side-channel analysis is to find out whether all the leakage samples in an implementation can be exploited by an adversary, as suggested by masking security proofs. For attacks exploiting a divide-and-conquer strategy, the answer is negative: only the leakages corresponding to the first/last rounds of a block cipher can be exploited. Soft Analytical Side-Channel Attacks (SASCA) have been introduced as a powerful solution to mitigate this limitation. They represent the target implementation and its leakages as a code (similar to a Low Density Parity Check code) that is decoded thanks to belief propagation. Previous works have shown the low data complexities that SASCA can reach in practice. In this paper, we revisit these attacks by modeling them with a variation of the Random Probing Model used in masking security proofs, that we denote as the Local Random Probing Model (LRPM). Our study establishes interesting connections between this model and the erasure channel used in coding theory, leading to the following benefits. First, the LRPM allows bounding the security of concrete implementations against SASCA in a fast and intuitive manner. We use it in order to confirm that the leakage of any operation in a block cipher can be exploited, although the leakages of external operations dominate in known-plaintext/ciphertext attack scenarios. Second, we show that the LRPM is a tool of choice for the (nearly worst-case) analysis of masked implementations in the noisy leakage model, taking advantage of all the operations performed, and leading to new tradeoffs between their amount of randomness and physical noise level. Third, we show that it can considerably speed up the evaluation of other countermeasures such as shuffling.