8 It Started with Templates: The Future of Profiling in Side-Channel Analysis
141
variable, i.e., let [·] b define the function selecting the bth bit and using the same
intermediate variable as in Sect. 8.2.1 then
([Sbox[T ⊕ k]] 1 [Sbox[T ⊕ k]] 2 . . . [Sbox[T ⊕ k]] n )
(8.9)
is an n-dimensional vector used as regressors. One benefit of SA is the constructive
feedback of side-channel leakage detection it might bring to the evaluator (see,
e.g., [278]).
8.4 Machine Learning-Based Attacks
Machine learning encompasses a number of methods used for classification,
clustering, regression, feature selection, and other knowledge discovering methods [423]. A typical division of machine learning algorithms is into supervised,
semi-supervised, and unsupervised approaches. Each of those paradigms can also be
used in SCAs—supervised (profiling) attacks, semi-supervised attacks (profiling),
unsupervised (non-profiling) attacks.
In Fig. 8.2, we depict differences in the supervised and semi-supervised cases.
Supervised Techniques
The supervised approach assumes that the attacker first possesses a device similar to
the one under attack. Having this additional device, he is then able to build a precise
profiling model using a set of measurements while knowing the plaintext/ciphertext
and the secret key of this device. In the second step, the attacker uses the earlier
profiling model to reveal the secret key of the device under attack. For this, he
additionally measures a new set of traces, but as the key is secret he has no further
information about the intermediate processed data and thus builds hypotheses. The
only information that the attacker transfers between the profiling phase and the
attacking phase is the profiling model he builds.
When considering supervised machine learning and SCA, in recent years there
have been numerous papers considering various targets, machine learning algorithms, and scenarios. Actually, the most common denominator for most of the work
traces
labels
algorithm
model
traces
hypothetical
labels
algorithm
secret
Attacking phase
traces
labels
algorithm
model
traces
hypothetical
labels
algorithm
secret
traces
Attacking phase
Fig. 8.2 Profiling side-channel scenario: supervised (left), semi-supervised (right)
141
variable, i.e., let [·] b define the function selecting the bth bit and using the same
intermediate variable as in Sect. 8.2.1 then
([Sbox[T ⊕ k]] 1 [Sbox[T ⊕ k]] 2 . . . [Sbox[T ⊕ k]] n )
(8.9)
is an n-dimensional vector used as regressors. One benefit of SA is the constructive
feedback of side-channel leakage detection it might bring to the evaluator (see,
e.g., [278]).
8.4 Machine Learning-Based Attacks
Machine learning encompasses a number of methods used for classification,
clustering, regression, feature selection, and other knowledge discovering methods [423]. A typical division of machine learning algorithms is into supervised,
semi-supervised, and unsupervised approaches. Each of those paradigms can also be
used in SCAs—supervised (profiling) attacks, semi-supervised attacks (profiling),
unsupervised (non-profiling) attacks.
In Fig. 8.2, we depict differences in the supervised and semi-supervised cases.
Supervised Techniques
The supervised approach assumes that the attacker first possesses a device similar to
the one under attack. Having this additional device, he is then able to build a precise
profiling model using a set of measurements while knowing the plaintext/ciphertext
and the secret key of this device. In the second step, the attacker uses the earlier
profiling model to reveal the secret key of the device under attack. For this, he
additionally measures a new set of traces, but as the key is secret he has no further
information about the intermediate processed data and thus builds hypotheses. The
only information that the attacker transfers between the profiling phase and the
attacking phase is the profiling model he builds.
When considering supervised machine learning and SCA, in recent years there
have been numerous papers considering various targets, machine learning algorithms, and scenarios. Actually, the most common denominator for most of the work
traces
labels
algorithm
model
traces
hypothetical
labels
algorithm
secret
Attacking phase
traces
labels
algorithm
model
traces
hypothetical
labels
algorithm
secret
traces
Attacking phase
Fig. 8.2 Profiling side-channel scenario: supervised (left), semi-supervised (right)
