On the Easiness of Turning Higher-Order Leakages into First-Order

On the Easiness of Turning Higher-Order Leakages into First-Order
复制标题

DOI:
10.1007/978-3-319-64647-3_10
复制
发表时间:
2017-04
期刊:
--
影响因子:
--
通讯作者:
Thorben Moos;A. Moradi
Thorben Moos;A. Moradi
中科院分区:
其他
文献类型:
--
作者:
Thorben Moos;A. Moradi

文献摘要

相似文献

对加密算法的处理中间值应用随机和统一的掩码可以说是阻止侧信道分析攻击的最常见对策。所谓的掩蔽方案存在多种形式,但主要用于防止侧信道泄漏达到一定的统计顺序。因此,为了了解有关涉及密钥的计算的任何信息,侧信道对手必须估计泄漏分布的高阶统计矩。然而,这种方法的复杂性随着要估计的统计阶数呈指数增加,并且估计的精度受到对噪声水平的巨大敏感性的影响。在这项工作中,我们提出了一种利用高阶泄漏的替代程序,其简单性和有效性令人着迷。我们的方法专注于(但不限于)硬件屏蔽方案的单变量泄漏,基于根据泄漏点的分布对功率迹线进行分类。特别是,在每个样本点,单独的踪迹子集被认为发起普通的一阶攻击。我们基于模拟轨迹提出了我们方法的理论概念,并检查了其在嘈杂的现实世界测量中的效率,该测量取自分组密码 PRESENT-80 的一阶安全阈值实现,在 150 nm CMOS ASIC 原型芯片上实现。我们的分析验证了所提出的技术确实是传统高阶攻击的有价值的替代方案,并表明它可能能够放松高阶评估对噪声水平的敏感性。
Applying random and uniform masks to the processed intermediate values of cryptographic algorithms is arguably the most common countermeasure to thwart side-channel analysis attacks. So-called masking schemes exist in various shapes but are mostly used to prevent side-channel leakages up to a certain statistical order. Thus, to learn any information about the key-involving computations a side-channel adversary has to estimate the higher-order statistical moments of the leakage distributions. However, the complexity of this approach increases exponentially with the statistical order to be estimated and the precision of the estimation suffers from an enormous sensitivity to the noise level. In this work we present an alternative procedure to exploit higher-order leakages which captivates by its simplicity and effectiveness. Our approach, which focuses on (but is not limited to) univariate leakages of hardware masking schemes, is based on categorizing the power traces according to the distribution of leakage points. In particular, at each sample point an individual subset of traces is considered to mount ordinary first-order attacks. We present the theoretical concept of our approach based on simulation traces and examine its efficiency on noisy real-world measurements taken from a first-order secure threshold implementation of the block cipher PRESENT-80, implemented on a 150 nm CMOS ASIC prototype chip. Our analyses verify that the proposed technique is indeed a worthy alternative to conventional higher-order attacks and suggest that it might be able to relax the sensitivity of higher-order evaluations to the noise level.