154
A. P. Fournaris et al.
resampling where sample windows are specified and they are replaced by their
average value [501]. However, many researchers apply the averaging technique to
increase the signal-to-noise ratio and mount a successful attack. Using averaging,
we collect T leakage traces with the same inputs and secret, then average them
sample-per-sample to come up with a single, averaged leakage trace that contains a
lot less noise than each individual trace itself. The technique is very popular (almost
mandatory) in embedded system SCAs to remove noise, but it increases the needed
number of collected traces by a factor of T since we need T trace collections for
each SCA useful, averaged, leakage trace.
Another practical factor to be considered during trace collection, which also
has an impact on the number of collected traces, is trace misalignment. This phenomenon happens when, after triggering a security/cryptography computation, the
various O i operations do not always appear at the same point in time in all leakage
traces of this computation, even if the same inputs and secret are used. Misalignment
can appear frequently in software based security computations (a common case
in ubiquitous devices) since such computations run in parallel to other securityunrelated processes, or random events may happen that influence the computation execution sequence. Misalignment can also appear in hardware-implemented
security computations when related SCA countermeasures are introduced in the
computation flow. To solve the problem, SCA theory states that traces should
be realigned using postcollection trace processing techniques [390]. However, in
practice, for several cases of ubiquitous devices, traces are so misaligned that they
become SCA useless and cannot be effectively realigned. Thus, there is a percentage
of collected traces that due to misalignment should be discarded. This makes it
imperative to collect more traces than those needed, having in mind that some of
them will be useless due to misalignment. A rule of thumb in such cases is to
collect 20% more traces than needed. This percentage can increase to 50% in highly
misaligned traces (usually on ubiquitous software implementations).
9.3 Side Channel Attack Trace Collection Platforms
There exist several Security Test Labs and individual researchers who have proposed
and manufactured their own ad hoc hardware boards [399, 532, 565] for trace collection. In the years following the discovery of SCAs, several Side-Channel Analysis
measurement boards and evaluation setups emerged in the security community. The
purpose of such boards is to provide a common platform for the aspiring attackers
to mount their attacks and help them get low noise measurements in an easy way.
Typically, they accommodate a general purpose device (a microprocessor, an ASIC,
or an FPGA) serving as the DUT, connected with a controlling device (control
component) on the same board (mainly some sort of microcontroller). There were
also boards that accommodated signal-enhancing mechanisms on the same board to
ease the oscilloscope’s work [117]. Gradually the quality of the boards improved
to such a degree that several of them found their way to the market for commercial
use, with significant success.
Précédent

- 163/268

Suivant