152
A. P. Fournaris et al.
implementation inputs. There are, however, also horizontal ASCAs that apply
differential or correlation statistics on a single leakage trace assuming that a subset
of operations associated with the secret s appear many times in this trace. Finally,
ASCAs can bypass strong SCA countermeasures (e.g., randomization/blinding) by
combining horizontal and vertical approaches [59, 210, 220].
Following the above categorization (Vertical vs. Horizontal, SSCA vs. ASCA),
we can include profiling SCAs like Template Attacks or Machine Learning
Attacks [367] among the vertical ASCAs. Profiling attacks operate in two phases:
Initially, they need to collect a series of leakage traces from a device under the full
control of the attacker (with known inputs and secrets) so as to create a leakage
model. In the second phase, the leakage model is used as a template or as the
training set of a machine learning algorithm in order to recover a secret from a
series of traces collected from a device (similar to the one used for profiling) not
under attacker control.
9.2.2 Leakage Assessment Using t-Test
In addition to SCA resistance assessment based on the success of various SCAs, a
generic methodology for finding information leakage from a DUT has been gaining
ground. The dominant, generic, leakage assessment methodologies are based on
Student’s t-distribution following specific and non-specific t-tests [67, 516]. The
goal is to detect any type of information leakage that occurs during the computation
of security/cryptography functions in the DUT, at a certain n-th SCA order.
[An SCA attack of order n appears when there exists an n set of intermediate
variables that appear during the computation of the algorithm, such that knowing
a few key bits (in practice fewer than 32 bits) allows us to decide whether two
inputs (respectively two outputs) give the same value for a known function of
these n variables.] Any sensitive computational intermediate operation O i series
that appears on the side channel as significantly different from random noise
can potentially be detected using the above leakage assessment approach without
conducting any specific SCA. This significant difference is enough to mark a DUT
implementation as leaky and SCA insecure.
Test Vector Leakage Assessment (TVLA) is one of the most promising, generic,
non-specific leakage detection techniques, initially proposed by Cryptography
Research (CRI) [67]. The method is practically used as the first action towards
assessing a system’s SCA leakage. It consists of a univariate test that is performed
on a series of traces obtained from a DUT. The DUT implementation is evaluated
as non-leaky if the test throughout the duration of the DUT trace remains below
a certain threshold, independently of the leakage model that might be used. More
precisely, we test the case where there is no leakage (null hypothesis) versus the
case where there is some leakage at a certain intermediate point L(t) at time t.
Let n tr be the number of traces that the evaluator collects and n s the number of
samples in each trace. Following the notation of [597], and assuming that we have
A. P. Fournaris et al.
implementation inputs. There are, however, also horizontal ASCAs that apply
differential or correlation statistics on a single leakage trace assuming that a subset
of operations associated with the secret s appear many times in this trace. Finally,
ASCAs can bypass strong SCA countermeasures (e.g., randomization/blinding) by
combining horizontal and vertical approaches [59, 210, 220].
Following the above categorization (Vertical vs. Horizontal, SSCA vs. ASCA),
we can include profiling SCAs like Template Attacks or Machine Learning
Attacks [367] among the vertical ASCAs. Profiling attacks operate in two phases:
Initially, they need to collect a series of leakage traces from a device under the full
control of the attacker (with known inputs and secrets) so as to create a leakage
model. In the second phase, the leakage model is used as a template or as the
training set of a machine learning algorithm in order to recover a secret from a
series of traces collected from a device (similar to the one used for profiling) not
under attacker control.
9.2.2 Leakage Assessment Using t-Test
In addition to SCA resistance assessment based on the success of various SCAs, a
generic methodology for finding information leakage from a DUT has been gaining
ground. The dominant, generic, leakage assessment methodologies are based on
Student’s t-distribution following specific and non-specific t-tests [67, 516]. The
goal is to detect any type of information leakage that occurs during the computation
of security/cryptography functions in the DUT, at a certain n-th SCA order.
[An SCA attack of order n appears when there exists an n set of intermediate
variables that appear during the computation of the algorithm, such that knowing
a few key bits (in practice fewer than 32 bits) allows us to decide whether two
inputs (respectively two outputs) give the same value for a known function of
these n variables.] Any sensitive computational intermediate operation O i series
that appears on the side channel as significantly different from random noise
can potentially be detected using the above leakage assessment approach without
conducting any specific SCA. This significant difference is enough to mark a DUT
implementation as leaky and SCA insecure.
Test Vector Leakage Assessment (TVLA) is one of the most promising, generic,
non-specific leakage detection techniques, initially proposed by Cryptography
Research (CRI) [67]. The method is practically used as the first action towards
assessing a system’s SCA leakage. It consists of a univariate test that is performed
on a series of traces obtained from a DUT. The DUT implementation is evaluated
as non-leaky if the test throughout the duration of the DUT trace remains below
a certain threshold, independently of the leakage model that might be used. More
precisely, we test the case where there is no leakage (null hypothesis) versus the
case where there is some leakage at a certain intermediate point L(t) at time t.
Let n tr be the number of traces that the evaluator collects and n s the number of
samples in each trace. Following the notation of [597], and assuming that we have
