148
A. P. Fournaris et al.
devices of urban and industrial systems, critical infrastructures and individual
households [540]. This highlights the need for strong security features that must
be installed on embedded systems. However, ubiquitous devices have several nonfunctional constraints like small processing power, low power consumption or
small memory footprint, that prohibit the use of several traditional security and
cryptography schemes (e.g., asymmetric cryptography). This has led to the redesign
and simplification of existing security solutions (like TLS schemes and their cipher
modes) or the development of cryptography algorithms especially designed for low
performance devices (lightweight cryptography schemes [197]).
The design and evaluation of security schemes and cryptographic algorithms
must take into account several parameters that are related to a scheme’s cryptographic strength (addressed by cryptanalysis, formal security verification methods
etc.), to its algorithmic performance (addressed by collecting and comparing performance and resource measurements) and to its resistance against implementation
attacks like side channel and fault injection attacks [337]. Side channel attacks
(SCAs) have a leading role in the design of modern cryptosystems, since they are
the weakest point and they have been exploited by many well-known attacks in
order to break otherwise unbreakable security/cryptography algorithms. SCAs can
be easily applicable to ubiquitous, cyberphysical systems, where devices are left
unattended in potentially security “hostile” environments (in remote, secluded areas,
inside malicious user premises, etc.)
There is a broad research field related to various SCAs, aiming to exploit
various physical characteristics of a device including timing, power consumption,
electromagnetic emission, etc. The flagship SCA analysis methods are of statistical
nature and can be categorized into horizontal attacks (using one or a few collected
inputs) or vertical attacks (using many collected inputs). Among the most potent
and successful such attacks are Differential Power Analysis (DPA) or Correlation
DPA [390] as well as template, online template [58] and Mutual Information Attack
(MIA) [229]. A simple review of the above advanced SCAs reveals that all of them
require a considerable amount of collected leaked physical characteristic inputs in
order to be effective.
Assessing if a security/cryptography scheme on a ubiquitous device is SCA
resistant, is not a straightforward process. It usually follows two directions. In the
first direction, a security scheme is evaluated against specific SCAs while the second
direction is based on performing a generic information leakage assessment based on
some statistical test. Student’s or Welch t-test are two such tests that use statistical
hypothesis testing in order to detect if one of a series of sensitive intermediate
processes during a security procedure significantly influences the measurement data
or (more often in a non-specific test) detect how different is a collected trace from
random noise (indicating a bias addressed to exploitable information leakage).
Collecting inputs for SCA analysis is done using specialized equipment in a fairly
cheap and easy way. However, when a huge number of inputs need to be acquired
then the processing of an input (or trace, as they are usually denoted in the literature)
becomes a very slow and cumbersome process. A restricted number of tools that
help the acquisition of the needed traces for advanced SCA attacks exist. Most of
Précédent

- 157/268

Suivant