xiv
Contents
7.2 Relay Attacks in Practice . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 115
7.2.1 Basic Relay Strategies . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 116
7.2.2 Advanced Relay Strategies . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 117
7.3 Canonical Distance-Bounding Protocols .. . . . . . .. . . . . . . . . . . . . . . . . . . . 119
7.3.1 General Structure . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 119
7.3.2 The Hancke-Kuhn Protocol . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 120
7.3.3 The Brands-Chaum Protocol .. . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 121
7.4 Distance-Bounding Threat Model and Its Formal Treatments . . . . . 122
7.4.1 Main Threat-Model .. . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 122
7.4.2 Provable Security and Formal Verification . . . . . . . . . . . . . . . . 123
7.5 Distance-Bounding Protocols in Practice . . . . . . .. . . . . . . . . . . . . . . . . . . . 125
7.5.1 NXP’s Mifare Technology . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 125
7.5.2 3DB Technology .. . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 127
7.5.3 Relay-Resistance in EMV . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 127
7.6 Current Challenges in Distance Bounding . . . . . .. . . . . . . . . . . . . . . . . . . . 128
7.6.1 Theory vs. Practice . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 128
7.6.2 Application-Aware DB . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 129
7.6.3 Specialist Implementations and Slow Adoption . . . . . . . . . . 130
Part IV Hardware Implementation and Systems
8 It Started with Templates: The Future of Profiling in
Side-Channel Analysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 133
Lejla Batina, Milena Djukanovic, Annelie Heuser, and Stjepan Picek
8.1 Introduction .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 133
8.2 Profiled Side-Channel Attacks .. . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 135
8.2.1 Definition of Profiling Attacks . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 135
8.2.2 Data Preprocessing . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 136
8.2.3 Feature Engineering . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 137
8.3 Template Attacks .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 138
8.3.1 Context of Template Attack .. . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 139
8.3.2 Standard Template Attack . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 140
8.3.3 Pooled Template Attack .. . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 140
8.3.4 Stochastic Attack . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 140
8.4 Machine Learning-Based Attacks . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 141
8.4.1 Conducting Sound Machine Learning Analysis.. . . . . . . . . . 142
8.5 Performance Metrics . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 144
8.6 Countermeasures Against SCA . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 144
8.7 Conclusions .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 145
9 Side Channel Assessment Platforms and Tools for Ubiquitous
Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 147
Apostolos P. Fournaris, Athanassios Moschos, and Nicolas Sklavos
9.1 Introduction .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 147
9.2 Side Channel Attacks, Leakage Assessment Methods
and Problems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 149
Contents
7.2 Relay Attacks in Practice . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 115
7.2.1 Basic Relay Strategies . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 116
7.2.2 Advanced Relay Strategies . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 117
7.3 Canonical Distance-Bounding Protocols .. . . . . . .. . . . . . . . . . . . . . . . . . . . 119
7.3.1 General Structure . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 119
7.3.2 The Hancke-Kuhn Protocol . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 120
7.3.3 The Brands-Chaum Protocol .. . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 121
7.4 Distance-Bounding Threat Model and Its Formal Treatments . . . . . 122
7.4.1 Main Threat-Model .. . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 122
7.4.2 Provable Security and Formal Verification . . . . . . . . . . . . . . . . 123
7.5 Distance-Bounding Protocols in Practice . . . . . . .. . . . . . . . . . . . . . . . . . . . 125
7.5.1 NXP’s Mifare Technology . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 125
7.5.2 3DB Technology .. . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 127
7.5.3 Relay-Resistance in EMV . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 127
7.6 Current Challenges in Distance Bounding . . . . . .. . . . . . . . . . . . . . . . . . . . 128
7.6.1 Theory vs. Practice . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 128
7.6.2 Application-Aware DB . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 129
7.6.3 Specialist Implementations and Slow Adoption . . . . . . . . . . 130
Part IV Hardware Implementation and Systems
8 It Started with Templates: The Future of Profiling in
Side-Channel Analysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 133
Lejla Batina, Milena Djukanovic, Annelie Heuser, and Stjepan Picek
8.1 Introduction .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 133
8.2 Profiled Side-Channel Attacks .. . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 135
8.2.1 Definition of Profiling Attacks . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 135
8.2.2 Data Preprocessing . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 136
8.2.3 Feature Engineering . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 137
8.3 Template Attacks .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 138
8.3.1 Context of Template Attack .. . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 139
8.3.2 Standard Template Attack . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 140
8.3.3 Pooled Template Attack .. . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 140
8.3.4 Stochastic Attack . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 140
8.4 Machine Learning-Based Attacks . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 141
8.4.1 Conducting Sound Machine Learning Analysis.. . . . . . . . . . 142
8.5 Performance Metrics . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 144
8.6 Countermeasures Against SCA . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 144
8.7 Conclusions .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 145
9 Side Channel Assessment Platforms and Tools for Ubiquitous
Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 147
Apostolos P. Fournaris, Athanassios Moschos, and Nicolas Sklavos
9.1 Introduction .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 147
9.2 Side Channel Attacks, Leakage Assessment Methods
and Problems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 149
