162
A. P. Fournaris et al.
Table 9.1 Leakage trace collection architectures qualitative features comparisons
Collection setup Flexibility Single encr. Multi-encr. Averaging Ease-of use Clock control
FlexLeco three
step approach
High
Yes
Yes
Yes
High
5–230 MHz
Sakura/Sasebo
[353]
No
Yes
No
No
None
No
ChipWhisperer
[451]
Moderate b Yes
Partial c
Yes
Moderate b 5–160 MHz
FOBOS [565]
No
Yes
No
No
Minimum a Max.
50 MHz
a Hardware interfaces are unique for each cryptography DUT
b Hard to implement software control loop and tedious, time-consuming interfacing of different
cryptographic DUTs
c Multi-encryption only with constant or random plaintexts
projects or from personal communication with the projects’ developers. The table
indicates that the three-step approach is flexible enough to rival existing and wellestablished solutions offered to the SCA community by Sakura and ChipWhisperer.
9.5 Conclusions
In this book chapter we focused on an important aspect of SCA analysis, evaluation
and leakage assessment, which is the efficient and easy collection of needed SCA
traces. We presented the traditional mechanism for collecting traces from DUT
ubiquitous devices and commented on the drawbacks of this approach. After briefly
describing dominant SCA attack categories and leakage assessment methodologies
in view of their needed number of traces, considering also the high level of trace
noise and possible misalignments that are ever present in ubiquitous devices, we
concluded that the traditional model is not practically useful for ubiquitous systems
SCA evaluation. To further explore the recent SCA trace collection and analysis
landscape, we described the most prominent open source and commercial toolsets,
both research and commercial. Most have shortcomings in terms of controlling
in a flexible and easy manner the DUT to be SCA evaluated, thus giving us the
motivation to propose a three-step trace collection methodology using a design, an
execution, and a trace processing phase. To validate the applicability, efficiency, and
ease-of-use of this proposed approach, we applied it to the FlexLeco project open
source solution, which is highly compatible with our proposal. Using this use case
we managed to easily design experiments and collect results even when we applied
complex design scenarios, like the multi-encryption mode where multiple inputs
are provided on the DUT, multiple traces are collected as one, and the actual single
traces (that are usable for SCA evaluation or leakage assessment) are extracted after
Précédent

- 171/268

Suivant