9 Side Channel Assessment Platforms and Tools for Ubiquitous Systems
153
N traces of n s samples each, let L = {L 1 , . . . , L n s } be the leakage traces of a
security/cryptography implementation, having mean values ¯
L i . For the traces null
hypothesis to be true the expected leakage value ¯
L exp should be the same as the
measured value, if there is no leakage, i.e., ¯
L exp = ¯
L i ∀i ∈ {1, . . . , n s }. In
practice, to perform the TVLA we conduct two experiments. In both experiments,
we collect N/2 traces where the variable to be leakage assessed has a known, fixed,
value and N/2 traces where this variable has a random value. This trace collection
is done in an interleaved way by randomly choosing to acquire either a fixed trace
or a random trace each time. After collecting the necessary traces, we perform a
Welch’s t-test as described in [516] and check the outcome against a threshold.
TVLA and all similar leakage assessment tests can provide an initial indication
regarding SCA leakage but require huge amounts of collected traces in order to
provide an accurate assessment result. In the case of symmetric key cryptography
algorithms (e.g., in AES implementations) this number is in the order of millions
(in [516] N =100M traces for an AES evaluation). This number is reduced in Public
Key algorithms (in the order of thousands of traces) yet still is hard to collect since
each public key algorithm implementation trace consists of a very large number of
samples n s . From a trace collection perspective, TVLA is a very slow assessment
method due to this high N number, and can become very frustrating for an SCA
evaluator.
9.2.3 Practical Considerations in SCA Trace Collection
When, in practice, the above described SCA attacks are applied to actual, raw
collected traces using real hardware or software implementations, their success rate
is very low. This happens since in a trace, leakage information is mingled with a
considerable amount of SCA-useless signals that we can consider here as “noise”.
Noise, as very accurately described in [411], can be external, intrinsic, quantization
or algorithmic. External noise that is picked up from external to the DUT sources
as well as intrinsic noise, due to the DUT’s physical characteristics (capacitance,
conduction, transistor, non-linear behavior, etc.), are not under the control of the
attacker and the DUT SCA resistance designer, and must be removed or reduced
by some appropriate trace preprocessing technique. On the other hand, quantization
noise can be considerably reduced by using better trace collection equipment (with
small A/D quantization for example). Algorithmic noise is usually designer infused
on a DUT in an effort to increase randomness in data processing but also infused by
computation functionalities unrelated to security, such as interrupts, pipelining, OS
system calls, etc., these can very often appear in ubiquitous devices.
In order to practically make a successful SCA, noise cancellation techniques
must be applied during or after trace collection in order to have clear and useful
leakage traces. Traditional noise reduction techniques can be applied on traces
after collection based on low-, band- or high-pass filtering after finding dominant
frequencies using, for example, Fast Fourier Transform analysis or based on trace
Précédent

- 162/268

Suivant