150
A. P. Fournaris et al.
electromagnetic emanation signals, and some kind of tool that will speed up leakage
trace capturing.
There are a large variety of DUTs that can be assessed for their SCA resistance
using the above setup. Under the ubiquitous computing framework, small embedded
system devices (e.g., RFID tags, wireless sensor network nodes, smart card devices),
having lightweight versions of cryptographic algorithms, are the most prominent
candidates to have SCA vulnerabilities. Assessing the SCA resistance of such
devices can be achieved by evaluating the device when it is deployed and is fully
operational (in that case the DUT is the whole device) or can be achieved by
evaluating individually, in a controlled environment, a specific cryptography or
security implementation that is meant to be deployed on the ubiquitous device. In
the first case, SCA assessment is very hard to perform since, apart from security
functions, on the DUT there are many operations, unrelated to security, that are
being executed in parallel [219]. Such operations can be considered as hard-toremove noise inside the collected traces [219]. In the second case, the DUT is not the
full ubiquitous device but a specific security hardware or software implementation
deployed on this device. No other operations are executed in the second case control
environment, thus noise is minimized, enabling the evaluator to test many SCA
resistance scenarios in depth.
When trace collection is needed for SCA analysis or assessment, the
attacker/evaluator needs to pass the cryptography/security algorithm’s expected
input data each time from his control point (usually a personal computer) to the
control component, which is responsible for sending the data to the DUT for one
security/cryptography process to begin. After having set the right settings in the
oscilloscope (e.g., sampling rate, time window capture, resolution capture) the
attacker arms it. The attacker then sends a command to the DUT, for it to start
performing the evaluated security process. Before the start of the process the DUT
sends a triggering signal to the oscilloscope, warning it that the process is about
to start and a trace capture must be performed. As soon as the trigger signal
reaches the oscilloscope, it captures a leakage trace measurement (e.g., power
consumption or the electromagnetic emanation, depending on the used probes) of
the DUT. The attacker/evaluator then requests from the oscilloscope the captured
trace for analysis at his PC. When the captured trace reaches the PC, various signal
processing techniques are applied on it and it is used for side-channel analysis
of the DUT. The above procedure (called loop round) is repeated for each new
security/cryptography process we want the DUT to perform.
9.2.1 Side Channel Attack Categories
Adopting the formulation approach described in [60, 61, 220] we can model each
security/cryptography computation C as a series of n different O i operations (for
i ∈ {0, 1, . . . n − 1}) that each require inputs X i (thus O i (X i )). We can also assume
that each operation output can be considered as input to another operation during
A. P. Fournaris et al.
electromagnetic emanation signals, and some kind of tool that will speed up leakage
trace capturing.
There are a large variety of DUTs that can be assessed for their SCA resistance
using the above setup. Under the ubiquitous computing framework, small embedded
system devices (e.g., RFID tags, wireless sensor network nodes, smart card devices),
having lightweight versions of cryptographic algorithms, are the most prominent
candidates to have SCA vulnerabilities. Assessing the SCA resistance of such
devices can be achieved by evaluating the device when it is deployed and is fully
operational (in that case the DUT is the whole device) or can be achieved by
evaluating individually, in a controlled environment, a specific cryptography or
security implementation that is meant to be deployed on the ubiquitous device. In
the first case, SCA assessment is very hard to perform since, apart from security
functions, on the DUT there are many operations, unrelated to security, that are
being executed in parallel [219]. Such operations can be considered as hard-toremove noise inside the collected traces [219]. In the second case, the DUT is not the
full ubiquitous device but a specific security hardware or software implementation
deployed on this device. No other operations are executed in the second case control
environment, thus noise is minimized, enabling the evaluator to test many SCA
resistance scenarios in depth.
When trace collection is needed for SCA analysis or assessment, the
attacker/evaluator needs to pass the cryptography/security algorithm’s expected
input data each time from his control point (usually a personal computer) to the
control component, which is responsible for sending the data to the DUT for one
security/cryptography process to begin. After having set the right settings in the
oscilloscope (e.g., sampling rate, time window capture, resolution capture) the
attacker arms it. The attacker then sends a command to the DUT, for it to start
performing the evaluated security process. Before the start of the process the DUT
sends a triggering signal to the oscilloscope, warning it that the process is about
to start and a trace capture must be performed. As soon as the trigger signal
reaches the oscilloscope, it captures a leakage trace measurement (e.g., power
consumption or the electromagnetic emanation, depending on the used probes) of
the DUT. The attacker/evaluator then requests from the oscilloscope the captured
trace for analysis at his PC. When the captured trace reaches the PC, various signal
processing techniques are applied on it and it is used for side-channel analysis
of the DUT. The above procedure (called loop round) is repeated for each new
security/cryptography process we want the DUT to perform.
9.2.1 Side Channel Attack Categories
Adopting the formulation approach described in [60, 61, 220] we can model each
security/cryptography computation C as a series of n different O i operations (for
i ∈ {0, 1, . . . n − 1}) that each require inputs X i (thus O i (X i )). We can also assume
that each operation output can be considered as input to another operation during
