ERI: Foundations of Machine Learning for Side-channel Analysis
ERI: Foundations of Machine Learning for Side-channel Analysis
批准号:
2138420
负责人:
Fatemeh Ganji
金额:
$19.47万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-03-01 至 2025-02-28
中文摘要
针对现实硬件平台的攻击,研究其脆弱性和相应的对策具有重要意义。作为此类攻击的主要示例,可以提及针对在硬件设备中用于认证的用户私钥的攻击,其中分析电磁辐射、功耗和定时(通常称为侧信道泄漏)导致危及设备的安全性。由于这种利用侧通道的攻击的有效性,人们对AI辅助的安全验证给予了极大的关注。标准化的参与(例如,美国国家标准与技术研究所(National Institute of Standards and Technology)和认证机构在开发侧信道分析工具的活动中的合作进一步突出了这一问题的重要性。尽管在这方面做出了努力,但由于关于已知的侧信道攻击的数量不断增长的困难,侧信道弹性的评估可能不太实际。为了解决这个问题,并与标准化活动保持一致,该项目旨在解决依赖于机器学习的现有方法的一些基本缺点,特别是深度学习,作为评估设备安全性的强大工具。因此,通过该项目获得的结果预计将提高在敏感应用中使用的数百万设备的安全性,包括医疗保健,情报,金融,运输和国防。此外,在这个项目中进行的研究活动与教育和推广工作紧密结合,因为研究生和本科生都将参与该项目,从而获得硬件安全方面的尖端技能和专业知识。从技术上讲,该项目将回答以下关键问题:1)哪种深度学习模型可以以较低的复杂性和较高的可解释性来近似加密实现的泄漏特性?2)如何解释将一个实施实例所取得的结果推广到另一个实例?3)除了深度学习之外,还有哪些机器学习框架,最好是可证明的框架,可以用来保证密码系统对机器学习增强的侧信道分析具有鲁棒性?在此过程中,该项目创建了一套依赖于深度学习理论基础的新技术,以评估密码系统及其相应嵌入式设备的安全性。此外,还将对真实世界的加密实现进行实验,即不受保护和针对侧信道分析的对策。这些系统的侧信道测量结果将公开提供。这一奖项是为了满足标准化和认证机构、行业以及专注于密码系统安全评估的研究人员的需求。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
In light of the attacks against real-world hardware platforms, the research on their vulnerabilities and corresponding countermeasures has gained further importance. As a prime example of such attacks, one targeting the users’ private keys used in hardware devices for authentication can be mentioned, where analyzing electromagnetic emanation, power consumption, and timing (often referred to as side-channel leakages) results in compromising the security of the device. Due to the effectiveness of such attacks leveraging side-channels, a great deal of attention has been paid to, particularly AI-assisted security verification. The involvement of standardization (e.g., National Institute of Standards and Technology) and certification bodies in the activities related to the development of tools for side-channel analysis further highlights the importance of this matter. In spite of the effort made in this respect, due to difficulties with regard to the constantly growing number of known side-channel attacks, evaluation of side-channel resiliency could be less practical. To tackle this and in line with the standardization activities, this project aims to address some of the fundamental shortcomings of the existing approaches relying on machine learning, specifically, deep learning, as a powerful tool to assess the security of devices against side-channel attacks. Hence, the results obtained through this project are expected to improve the security of millions of devices used across sensitive applications, including healthcare, intelligence, finance, transportation, and defense. Moreover, the research activities performed in this project are closely integrated with education and outreach efforts as both graduate, and undergraduate students will work on the project, thus gaining cutting-edge skills and expertise in hardware security. More technically, this project will answer these vital questions: 1) Which deep learning model can approximate the leakage properties of a cryptographic implementation with less complexity and high interpretability? 2) How can the generalization of the results achieved for one instance of the implementation to another be explained? 3) Besides deep learning, which other machine learning frameworks, preferably provable ones, can be applied to offer a guarantee that a cryptosystem is robust against machine learning-enhanced side-channel analysis? In doing so, the project creates a novel set of techniques relying on the theoretical foundations of deep learning to assess the security of cryptosystems and their respective embedded devices in practice. Furthermore, experimentation on real-world cryptographic implementations, namely unprotected and with countermeasures against side-channel analysis, will be conducted. Side-channel measurements from these systems will be made publicly available. This is indeed geared to the needs of the standardization and certification bodies, industry, and researchers focusing on security evaluation for cryptosystems.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DOI:
--
发表时间:
2023
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
作者:
[Devyani M. Mehta;M. Hashemi;D. Koblah;Domenic Forte;F. Ganji]
通讯作者:
Devyani M. Mehta;M. Hashemi;D. Koblah;Domenic Forte;F. Ganji
DOI:
10.46586/tches.v2023.i1.401-437
发表时间:
2021-04
期刊:
IACR Trans. Cryptogr. Hardw. Embed. Syst.
影响因子:
--
作者:
[R. Acharya;F. Ganji;Domenic Forte]
通讯作者:
R. Acharya;F. Ganji;Domenic Forte
DOI:
10.1007/978-3-031-54776-8_13
发表时间:
2023
期刊:
影响因子:
--
作者:
[M. Hashemi;Domenic Forte;F. Ganji]
通讯作者:
M. Hashemi;Domenic Forte;F. Ganji
MRI: Acquisition of High-Resolution Photon Emission/Laser Fault Injection Microscope with High-Performance Computers for Failure Analysis and Security Assessment of Electronic Syst
-
批准号:2117349
-
项目类别:Standard Grant
-
资助金额:$36.06万
-
财政年份:2021
-
负责人:Fatemeh Ganji
-
依托单位:
海外基金