9 Side Channel Assessment Platforms and Tools for Ubiquitous Systems
151
the C computation. Each operation O i is linked to an information leakage variable
L i . A side channel attack is possible if there is some secret information s that is
shared between O i and its leakage L i . The ultimate goal of a side channel analysis
is, by using some strategy, to deduce s from a series of information leakage L i
values [220]. To achieve that we collect leakage traces L which are sequences (in
time) L = {L 0 , L 1 , . . . L n−1 } and try to associate them with the computation C as
a sequence of operations C = {O 0 , O 1 , . . . O n−1 }.
SCAs follow either the vertical or horizontal leakage collection and analysis
strategy, as originally described in [60]. In the vertical approach, the implementation
is used N times using either the same or different inputs each time in order to
collect leakage traces. Each trace is associated with the j -th execution of the
computation. In the horizontal approach, leakage traces and related analysis is
collected/performed from a single execution of the computation and each trace
corresponds to a different time period within the time frame of this execution. As
expected, in horizontal attacks the implementation input is always the same.
By associating and distinguishing specific patterns of O i operations (consisting
of a single or multiple operations) in a leakage trace L, an attacker can recover the
secret s. Such an attack approach is typically followed in simple SCAs (SSCAs) that
are mostly horizontal attacks meaning that they are mounted using a single leakage
trace that is processed in time. Vertical SSCAs that need more than one leakage
trace rely on comparative analysis for pattern matching between computations with
different inputs. Vertical SSCAs require a few hundred leakage traces to be collected
considering that averaging technique for noise reduction is applied between leakage
traces of the same computation.
There exist several countermeasures that can thwart SSCAs, thus, more advanced
attacks have been devised (i.e., Advanced SCAs (ASCAs)). ASCAs do not focus
only on single operations or series of operations (e.g., O i ) but also on the
computation operands (i.e., the operation inputs X i ) [61, 220]. ASCAs are focused
on a specific subset of the calculation C (e.g., some O i operations that are strongly
associated with s) and examine how this subset behaves over a large collection of
(e.g., N) leakage traces L j associated with computations C j with different inputs
(where j ∈ {1, . . . , N}). ASCAs on this subset of operations and associated leakage
traces, exploit the statistical dependency between the calculation C for all X j and
the secret s. ASCAs follow the hypothesis test principle [60, 335] where a series of
hypothesis ´
s on s (usually on some bit j of s i.e., ´
s j =0 or 1) are made and a series
of leakage prediction values are found based on each of these hypotheses using an
appropriate prediction model. The values of each hypothesis are evaluated against
all actual leakage traces using an appropriate distinguisher δ for all inputs X i so as
to decide which hypothesis is correct.
Most ASCAs are of vertical nature and their success is highly related to the
number of processed leakage traces. The most widely used ASCA vertical attack is
Differential Attack (DSCA) originally proposed by Kocher in [336], which was later
expanded into the more sophisticated Correlation SCA (requiring fewer traces to
reveal the secret than DSCA) [21] and the collision correlation attack [99, 210, 425],
which can be mounted even if the attacker does not have full control of the
Précédent

- 160/268

Suivant