Improving cross-device attacks using zero-mean unit-variance normalization

Improving cross-device attacks using zero-mean unit-variance normalization
复制标题

DOI:
10.1007/s13389-012-0038-y
复制
发表时间:
2013-06
影响因子:
1.9
通讯作者:
David P. Montminy;R. Baldwin;M. Temple;Eric D. Laspe
David P. Montminy;R. Baldwin;M. Temple;Eric D. Laspe
中科院分区:
计算机科学4区
文献类型:
--
作者:
David P. Montminy;R. Baldwin;M. Temple;Eric D. Laspe

文献摘要

被引文献

相似文献

模板攻击是一种非常强大的侧信道分析形式。假设对手可以访问与受攻击设备相同的训练设备,以建立侧信道发射的精确多变量表征。假设培训和测试设备具有相同或至少非常相似的电磁发射。通常,在评估模板攻击的有效性时,训练和测试数据来自同一设备。使用40个PIC微控制器设备评估从不同设备或跨设备攻击收集训练和测试数据的有效性。当标准模板攻击方法无法产生足够的结果时,对每个步骤进行评估以识别设备相关的变化。一个简单的预处理技术,规范化的跟踪手段和方差的训练和测试设备,评估各种测试数据集的大小。此步骤将相同部件号跨设备模板攻击的成功密钥字节提取率从65.1%提高到100%,并改善了对同一设备系列中类似设备的攻击。此外,它表明,由于设备泄漏的差异,最大限度地减少区分功能的数量降低了跨设备攻击的有效性。
Template attacks are a very powerful form of side-channel analysis. It is assumed an adversary has access to a training device, identical to the device under attack, to build a precise multivariate characterization of the side-channel emissions. The training and test devices are assumed to have identical, or at least very similar, electromagnetic emissions. Often, when evaluating the effectiveness of a template attack, training and test data are from the same-device. The effectiveness of collecting training and test data from different devices, or cross-device attacks, are evaluated here using 40 PIC microcontroller devices. When the standard template attack methodology fails to produce adequate results, each step is evaluated to identify device-dependent variations. A simple pre-processing technique, normalizing the trace means and variances from the training and test devices, is evaluated for various test data set sizes. This step improves the success key-byte extraction rate for same part number cross-device template attacks from 65.1 to 100 % and improves attacks against similar devices in the same-device family. Additionally, it is demonstrated that due to differences in device leakage, minimizing the number of distinguishing features reduces the effectiveness of cross-device attacks.