134
L. Batina et al.
about the data processed through physical side-channels such as timing [338], power
consumption [339], EM emanation [493], and sound [225].
Side-channel attacks (SCAs) exploit weaknesses in the physical implementation
of cryptographic algorithms rather than the algorithms themselves [389]. Those
weaknesses stem from the physics of the underlying computing elements, i.e.,
CMOS cells, which makes it hard to eliminate such threats.
Numerous evaluation techniques, which generally involve some form of digital
signal processing and statistical computations, have been proposed in the literature.
Some of the most important methods include Simple Power Analysis (SPA) [339],
Differential Power Analysis (DPA), and Template Attacks (TA) [135].
The SPA technique implies that the attacker aims at reconstructing the secret
key using just a single trace of side-channel information, and it often exploits
the difference in basic public-key operations such as double-and-add, or add-andmultiply [339]. Still, SPA is not possible if the observed signal-to-noise ratio (SNR)
is not high enough. Consequently, most of the time developed countermeasures
make SPA futile.
DPA techniques are based on the evaluation of many traces with varying
input data for the targeted algorithm. After that step, a brute-force attack, testing
sub-key hypotheses, is performed on a part of the algorithm (so-called “divide
and conquer”). In the DPA approach, a large number of samples are used in
order to reduce noise by averaging, and a single-bit power model is commonly
adopted [339]. On the other hand, Correlation Power Analysis (CPA) represents a
multi-bit power model in order to reduce the influence of noise on the possibility to
execute a successful attack [115]. The main difference between these two techniques
is that DPA is based on computing the difference between two trace sets, while
CPA uses the correlation coefficient in order to calculate the dependency test. We
often also say that the two use different side-channel distinguishers. Side-channel
attacks using the above three techniques have been reported on a wide variety of
cryptographic implementations, see, e.g., [154, 402, 410, 412, 434, 500] including
some real-world applications [196].
In contrast to DPA, TA requires a profiling stage, i.e., a step during which
the cryptographic hardware is under full control of the adversary to estimate the
probability distribution of the leaked information and make better use of all the
information present in each sample [135]. In this way, TA can provide a promising
model of the real device, instead of using some a priori model.
TA is the best (optimal) technique from an information-theoretic point of view if
the attacker has an unbounded number of traces and the noise follows the Gaussian
distribution [277, 367]. After the template attack, the stochastic attack emerged
using linear regression in the profiling phase [515]. In the years that followed,
researchers recognized certain shortcomings of template attacks and tried to modify
them in order to deal better with the complexity and portability issues. An example
of such an approach is the pooled template attack where only one pooled covariance
matrix is used in order to cope with statistical difficulties [142]. Alongside such
techniques, the SCA community realized that a similar approach to profiling is
used in other domains in the form of supervised machine learning. Consequently,
L. Batina et al.
about the data processed through physical side-channels such as timing [338], power
consumption [339], EM emanation [493], and sound [225].
Side-channel attacks (SCAs) exploit weaknesses in the physical implementation
of cryptographic algorithms rather than the algorithms themselves [389]. Those
weaknesses stem from the physics of the underlying computing elements, i.e.,
CMOS cells, which makes it hard to eliminate such threats.
Numerous evaluation techniques, which generally involve some form of digital
signal processing and statistical computations, have been proposed in the literature.
Some of the most important methods include Simple Power Analysis (SPA) [339],
Differential Power Analysis (DPA), and Template Attacks (TA) [135].
The SPA technique implies that the attacker aims at reconstructing the secret
key using just a single trace of side-channel information, and it often exploits
the difference in basic public-key operations such as double-and-add, or add-andmultiply [339]. Still, SPA is not possible if the observed signal-to-noise ratio (SNR)
is not high enough. Consequently, most of the time developed countermeasures
make SPA futile.
DPA techniques are based on the evaluation of many traces with varying
input data for the targeted algorithm. After that step, a brute-force attack, testing
sub-key hypotheses, is performed on a part of the algorithm (so-called “divide
and conquer”). In the DPA approach, a large number of samples are used in
order to reduce noise by averaging, and a single-bit power model is commonly
adopted [339]. On the other hand, Correlation Power Analysis (CPA) represents a
multi-bit power model in order to reduce the influence of noise on the possibility to
execute a successful attack [115]. The main difference between these two techniques
is that DPA is based on computing the difference between two trace sets, while
CPA uses the correlation coefficient in order to calculate the dependency test. We
often also say that the two use different side-channel distinguishers. Side-channel
attacks using the above three techniques have been reported on a wide variety of
cryptographic implementations, see, e.g., [154, 402, 410, 412, 434, 500] including
some real-world applications [196].
In contrast to DPA, TA requires a profiling stage, i.e., a step during which
the cryptographic hardware is under full control of the adversary to estimate the
probability distribution of the leaked information and make better use of all the
information present in each sample [135]. In this way, TA can provide a promising
model of the real device, instead of using some a priori model.
TA is the best (optimal) technique from an information-theoretic point of view if
the attacker has an unbounded number of traces and the noise follows the Gaussian
distribution [277, 367]. After the template attack, the stochastic attack emerged
using linear regression in the profiling phase [515]. In the years that followed,
researchers recognized certain shortcomings of template attacks and tried to modify
them in order to deal better with the complexity and portability issues. An example
of such an approach is the pooled template attack where only one pooled covariance
matrix is used in order to cope with statistical difficulties [142]. Alongside such
techniques, the SCA community realized that a similar approach to profiling is
used in other domains in the form of supervised machine learning. Consequently,
