2 Secure Implementation of Lattice-Based Encryption Schemes
27
target device during each run. DPA requires a leakage model that is a prediction of
the power consumption. Some leakage models are rather simple. For example, the
Hamming weight model is based on the observation that the Hamming weight of a
value that is stored in a register influences the power consumption. During the offline
phase, the attacker guesses the key byte and computes the intermediate value that he
considers suitable to apply the power model to. Depending on the power model and
the intermediate value, she assigns the corresponding power trace to one of the two
sets where one contains power traces with high predicted power consumption and
one set contains traces with low prediction power consumption. For all power traces,
the attacker stores the difference of the means of the sets. If the attack worked, the
correct key guess has a much higher difference of means than the other guesses.
Hiding Hiding countermeasures are applied to raise the difficulty for an attacker
to detect sensitive information in a set of power traces. This can be achieved
by introducing additional noise or by trying to equalize the power consumption
of all operations. The first approach can be achieved by other computations that
are executed in parallel or by shuffling the order of operations. For hardware
implementations one can even instantiate dedicated noise generators to randomize
the power consumption. If shuffling is applied an attacker needs to perform an
extra alignment step before analyzing the power traces. Otherwise the number of
required power traces drastically increases. The second approach is more suitable
for hardware implementations as in microcontrollers the developer has only limited
influence on the power consumption of an instruction and only one instruction can
be executed in parallel (except the microcontroller features SIMD instructions).
Masking The idea behind masking is to split a secret value into several shares.
The secret value can only be reconstructed with the knowledge of all shares. The
splitting of the secret value can be performed in a Boolean way or in an arithmetic
way. Boolean masking means that the XOR-sum of all shares results in the secret
value and arithmetic masking means that the arithmetic sum or difference of the
shares results in the secret value. There are conversion approaches to switch between
arithmetic and Boolean masking [18]. The major advantage of masking schemes is
that they allow to prove the side-channel security of an algorithm. Nevertheless,
there are still implementation challenges that have to be taken care of. Otherwise,
a provably secure algorithm might still have a side-channel leakage. To achieve
higher-order security, it is necessary to split the secret value into more shares.
2.3 CCA2 Conversion and Masking
In this section we describe how ring-LWE can be made resilient to CCA and sidechannel attacks using the Targhi–Unruh variant of the Fujisaki–Okamoto [22, 54]
(FO) transformation and our masking scheme.
Précédent

- 35/268

Suivant