8 It Started with Templates: The Future of Profiling in Side-Channel Analysis
135
some researchers started experimenting with different machine learning (ML)
techniques and evaluating their effectiveness in the SCA context. Although mainly
considering distinct scenarios and various ML techniques, all those papers tend
to establish different use cases where ML techniques can outperform the template
attack and establish themselves as the best choice for profiled SCA. More recently,
we are witnessing the relevance of deep learning (DL) techniques in the SCA
community with strong results in side-channel analyses, even in the presence of
countermeasures.
8.2 Profiled Side-Channel Attacks
Profiled side-channel attacks estimate the worst-case security risk by considering
the most powerful side-channel attacker. In particular, one assumes that an attacker
can possess an additional device of which he or she has nearly full control. From this
device, he obtains leakage measurements and is able to control the used secret key
or at least knows which one is used. Knowing the secret key enables him to calculate
intermediate processed values that involve the secret key for which he is estimating
models. These models can then be used in the attacking phase to predict which
intermediate values are processed and therefore carry information about the secret
key. Commonly used models are the identity value or Hamming weight/distance.
Uniformly Distributed Classes Targeting intermediate variables, e.g., when
loaded or manipulated on the device and resulting mostly in 2 n uniformly distributed
classes where n is the number of bits of the intermediate variable.
Binomial Distributed Classes The Hamming Weight (HW) or the Hamming
Distance (HD) of a uniformly distributed intermediate variable results in n + 1
binomially distributed classes.
8.2.1 Definition of Profiling Attacks
In this section, we consider side-channel attacks on block ciphers for which a
divide and conquer approach can be utilized. Note that, as there exist operations
within the block cipher which manipulate each block/chunk (e.g., bytes in Advanced
Encryption Standard (AES)) independently and most importantly involving only
one block/chunk of the secret key, an attacker only needs to make hypotheses about
the secret key block/chunk instead of the complete secret key at once.
More formally, let k ∗ denote (a chunk of) the fixed secret cryptographic key that
is stored on the device and let t denote (a chunk of) the plaintext or ciphertext of
the cryptographic algorithm. The mapping y maps the plaintext or the ciphertext
Précédent

- 145/268

Suivant