Unifying Leakage Models: From Probing Attacks to Noisy Leakage

Unifying Leakage Models: From Probing Attacks to Noisy Leakage
复制标题

DOI:
10.1007/s00145-018-9284-1
复制
发表时间:
2014-05
影响因子:
3
通讯作者:
Alexandre Duc;Stefan Dziembowski;Sebastian Faust
Alexandre Duc;Stefan Dziembowski;Sebastian Faust
中科院分区:
计算机科学4区
文献类型:
--
作者:
Alexandre Duc;Stefan Dziembowski;Sebastian Faust

文献摘要

被引文献

相似文献

密码学的一个最新趋势是在给定的泄漏模型下形式化地显示密码实现的泄漏弹性。最著名的泄漏模型之一--所谓的有界泄漏模型--假定对手收到的泄漏量是先验有界的。遗憾的是,一些工作已经指出,有界渗漏的假设在实践中很难验证。一个更现实的假设是,根据工程观察,真实世界的物理泄漏天生就会受到物理噪声的干扰,因此认为泄漏是足够噪声的。虽然这已经是Chari等人的开创性工作。Prouff和Rivain(见:Johansson T,Nguyen PQ(Eds)Eurocrypt,931 Computer Science中7881卷的课堂讲稿,第142-159页,Springer,2013)对物理激励噪声模型中的掩蔽对策进行了全面的正式分析。特别地,作者证明了使用布尔掩码方案的分组密码实现对于一类非常一般的噪声泄漏函数是安全的。虽然这是朝着更好地理解掩蔽计划的安全性迈出的重要一步,但对Prouff和Rivain的分析有几个缺点,特别是需要无泄漏门。在这项工作中,我们在相同的噪声模型中提供了一种替代的安全证明来克服这些挑战。我们通过从噪声泄漏到探测对手的重要模型的新的减少来实现这一目标(Ishai等人。见:Crypto,第463-481页,2003年)。这一减少是我们工作的主要技术贡献,它显著简化了针对现实侧通道泄漏的掩蔽方案的形式化安全分析。
A recent trend in cryptography is to formally show the leakage resilience of cryptographic implementations in a given leakage model. One of the most prominent leakage model—the so-called bounded leakage model—assumes that the amount of leakage that an adversary receives is a-priori bounded. Unfortunately, it has been pointed out by several works that the assumption of bounded leakages is hard to verify in practice. A more realistic assumption is to consider that leakages are sufficiently noisy, following the engineering observation that real-world physical leakages are inherently perturbed by physical noise. While already the seminal work of Chari et al. (in: CRYPTO, pp 398–412, 1999) study security of side-channel countermeasures in the noisy model, only recently Prouff and Rivain (in: Johansson T, Nguyen PQ (eds) EUROCRYPT, volume 7881 of lecture notes in 931 computer science, pp 142–159, Springer, 2013) offer a full formal analysis of the masking countermeasure in a physically motivated noise model. In particular, the authors show that a block-cipher implementation that uses the Boolean masking scheme is secure against a very general class of noisy leakage functions. While this is an important step toward better understanding the security of masking schemes, the analysis of Prouff and Rivain has several shortcomings including in particular requiring leak-free gates. In this work, we provide an alternative security proof in the same noise model that overcomes these challenges. We achieve this goal by a new reduction from noisy leakage to the important model of probing adversaries (Ishai et al. in: CRYPTO, pp 463–481, 2003). This reduction is the main technical contribution of our work that significantly simplifies the formal security analysis of masking schemes against realistic side-channel leakages.