160
A. P. Fournaris et al.
input values. 1 By doing so, the attacker/evaluator can use the API functions to
create any SCA or leakage assessment scenario to be executed inside the softcore
microprocessor, omitting the slow, PC-based software control loops. In that sense,
the FlexLeco solution fully supports and favors the design phase of the proposed
trace collection approach of this chapter and provides to an SCA evaluator all the
tools required to design diverse and complex SCA evaluation experiments.
The cryptographic interface on the cryptography FPGA side is primarily
designed for testing specific security/cryptography hardware implementations.
It is an open source HDL (Hardware Design Language) design that can be adapted
to the DUT’s cryptographic algorithm specifications during design time. By simply
assigning appropriate values for five HDL generic parameters, the number of inputs,
outputs and their bit length is adjusted to that of the DUT’s algorithm. The generic
interface is synthesized and downloaded whenever a new hardware implemented
cryptography algorithm is tested.
Inside the cryptographic interface, a Digital Clock Manager has been included
that provides different clock frequencies to the DUT and the interface. The
frequency of the interface is the same as that of the other one inside the control
FPGA, while the frequency of the DUT can be clocked as high as the component’s
critical path and the FPGA chip’s functional specifications allow (or as low as the
attacker/evaluator desires). By raising the frequency of the DUT, the evaluator is
now able to use DSOs with low memory size buffers, thus fitting more traces on
the time interval the DSO offers (as long as the DSO’s sampling frequency allows
it). The DCM’s output frequencies update is a straightforward process done by
changing a single parameter during the cryptographic FPGA’s synthesis phase.
Presenting such flexibility and scalability, the FlexLeCo mechanism allows the
evaluator to perform various trace collection scenarios like a Single-Encryption, a
Single-Encryption with Rapid Block Mode (if an oscilloscope with such a feature
is available) and a Multi-encryption mode [427], for different DUTs and with
minimum overhead between the mode updates.
During any trace-collection scenario (Fig. 9.1), at design phase, the softcore
microprocessor is set up so as to initiate communication transactions with the
cryptographic FPGA, in which it either reads and sends the contents of the
corresponding test vector records (i.e., plaintexts) or signals a random value
generation (using an API function or the hardware PRNG) and transmits it to the
DUT. We can design an experiment where this procedure continues until all of the
test vectors on the microprocessor’s memory have been sent to the cryptographic
device (DUT) or until the needed number of random inputs is reached. After the
design phase, the actual experiment is executed in the softcore microprocessor and
post-collection operations may be performed. As an example of such postcollection
operations, we showcase the Multi-encryption scenario, detailed in [427], which
is enabled in the FlexLeco project in case an RBM (Rapid Block Mode) Digital
1 Both software- and hardware-based randomization is supported through the PRNG module.
Précédent

- 169/268

Suivant