8 It Started with Templates: The Future of Profiling in Side-Channel Analysis
139
8.3.1 Context of Template Attack
In the pioneering template attacks article of Chari, Rao, and Rohatgi, it is shown that
template attacks apply advanced statistical methods and can break implementations
secure against other forms of side-channel attacks [135].
In some works template attacks are built to classify the state of a byte, e.g., a
key byte in RC4 [135, 498]. The weakness of these papers is the need to create
256 templates for each byte. Additionally, the template building process can only be
guided by partial attack results. In [498], the authors reduce the number of points of
a trace by using an efficient algorithm instead of the standard principal component
analysis method, which increases the speed of selecting points of interest. Also, by
introducing a preprocessing phase with the use of discrete Fourier transformation
on traces, the authors improve the template attack results in practice.
Agrawal et al. develop two new attack techniques that extend the work of the
previously mentioned research results [11]. The first is a single-bit template attack
technique that creates templates from peaks observed in a DPA attack resulting
with a high probability value of a single DPA-targeted bit. Their second, templateenhanced DPA attack technique can be used to attack DPA protected cards and
consists of two steps: a profiling phase and a hypothesis testing phase. In the first,
profiling phase, the attacker, who is in possession of a smart card with a biased RNG,
builds templates, and in the hypothesis testing phase the attacker uses previously
built templates to mount a DPA-like attack on a target card which is identical to
the test smart card, but has a perfect RNG. The authors illustrate these two attack
techniques considering unprotected implementations of DES and AES on smart
cards.
Archambeau et al. take template attacks techniques a step further by transforming
leakage traces in order to identify important features (i.e., transformed time instants)
and their number automatically. Actually, they use the optimal linear combination
of the relevant time samples and execute template attacks in the principal subspace
of the mean traces creating a new approach, the principal subspace-based template
attack (PSTA) [25]. The authors validate this approach by attacking the RC4 stream
cipher implementation and an FPGA implementation of AES.
In the literature, the main focus is on template attacks aiming at recovering
the secret key of a cryptographic core from measurements of its dynamic power
consumption. But with scaling of technology, static power consumption grows faster
and creates new issues in the security of smart card hardware. Therefore, Bellizia et
al. proposed Template Attack Exploiting Static Power (TAESP) in order to extract
information from a hardware implementation of a cryptographic algorithm using
temperature-dependence of static currents as a source of information leakage [70].
139
8.3.1 Context of Template Attack
In the pioneering template attacks article of Chari, Rao, and Rohatgi, it is shown that
template attacks apply advanced statistical methods and can break implementations
secure against other forms of side-channel attacks [135].
In some works template attacks are built to classify the state of a byte, e.g., a
key byte in RC4 [135, 498]. The weakness of these papers is the need to create
256 templates for each byte. Additionally, the template building process can only be
guided by partial attack results. In [498], the authors reduce the number of points of
a trace by using an efficient algorithm instead of the standard principal component
analysis method, which increases the speed of selecting points of interest. Also, by
introducing a preprocessing phase with the use of discrete Fourier transformation
on traces, the authors improve the template attack results in practice.
Agrawal et al. develop two new attack techniques that extend the work of the
previously mentioned research results [11]. The first is a single-bit template attack
technique that creates templates from peaks observed in a DPA attack resulting
with a high probability value of a single DPA-targeted bit. Their second, templateenhanced DPA attack technique can be used to attack DPA protected cards and
consists of two steps: a profiling phase and a hypothesis testing phase. In the first,
profiling phase, the attacker, who is in possession of a smart card with a biased RNG,
builds templates, and in the hypothesis testing phase the attacker uses previously
built templates to mount a DPA-like attack on a target card which is identical to
the test smart card, but has a perfect RNG. The authors illustrate these two attack
techniques considering unprotected implementations of DES and AES on smart
cards.
Archambeau et al. take template attacks techniques a step further by transforming
leakage traces in order to identify important features (i.e., transformed time instants)
and their number automatically. Actually, they use the optimal linear combination
of the relevant time samples and execute template attacks in the principal subspace
of the mean traces creating a new approach, the principal subspace-based template
attack (PSTA) [25]. The authors validate this approach by attacking the RC4 stream
cipher implementation and an FPGA implementation of AES.
In the literature, the main focus is on template attacks aiming at recovering
the secret key of a cryptographic core from measurements of its dynamic power
consumption. But with scaling of technology, static power consumption grows faster
and creates new issues in the security of smart card hardware. Therefore, Bellizia et
al. proposed Template Attack Exploiting Static Power (TAESP) in order to extract
information from a hardware implementation of a cryptographic algorithm using
temperature-dependence of static currents as a source of information leakage [70].
