144
L. Batina et al.
8.5 Performance Metrics
When considering profiling SCA, there are three performance metrics we mention:
accuracy, guessing entropy, and success rate. The accuracy is the proportion between
the correctly classified measurements and all measurements:
ACC =
T P + T N
T P + T N + F P + F N
.
(8.10)
TP refers to true positive (correctly classified positive), TN to true negative
(correctly classified negative), FP to false positive (falsely classified positive), and
FN to false negative (falsely classified negative) instances. TP, TN, FP, and FN are
well-defined for hypothesis testing and binary classification problems. In the multiclass classification, they are defined in a one class vs. all other classes manner, and
are calculated from the confusion matrix.
A side-channel adversary A E K ,L conducts an experiment Exp A E K ,L , with timecomplexity τ , memory complexity m, and making Q queries to the target implementation of the cryptographic algorithm. The attack outputs a guessing vector g of
length o, and is considered a success if g contains correct key k ∗ . o is also known
as the order of the success rate. The oth order success rate of the side channel attack
A E K ,L is defined as:
SR
o
A E K ,L
(τ, m, k
∗ ) = Pr[Exp A E K ,L = 1]
(8.11)
The Guessing entropy measures the average number of key candidates to test
after the attack. The Guessing entropy of the adversary A E k ,L against a key class
variable S is defined as:
GE A E K ,L (τ, m, k
∗ ) = E[Exp A E K ,L ]
(8.12)
8.6 Countermeasures Against SCA
There are various countermeasures against SCAs that have been proposed over the
years. A general approach focuses on decreasing the information gathered from the
measurements:
• Noise Addition. Introducing external noise in the side-channel, shuffling the
operations or inserting dummy operations in cryptographic implementations is
often used as a countermeasure against SCAs. The basic objective is to reduce
the signal-to-noise ratio (SNR) and thereby decrease the information gathered
from measurements. Still, as shown already by Durvaux et al. [194], these
countermeasures become insecure with increasing attack time.
Précédent

- 154/268

Suivant