2 Secure Implementation of Lattice-Based Encryption Schemes
41
performed on both shares independently (e.g., point-wise multiplication), this
is easily achieved by executing the operations on all coefficients of one share
first and only then do the operations for the coefficients of the other share. For
operations that require both shares (i.e., Decode) hand-crafted assembly code is
necessary.
2.5 Side-Channel Evaluation
Even though we provide proofs for most of our modules against one probe,
practical first-order side-channel security is not automatically implied by that.
Implementation errors can still negatively affect the resistance due to effects that are
not included in the model [5]. Therefore, to extensively evaluate the security of our
masked implementation, we performed basic side-channel experiments. Since our
aim is to show first-order resistance, we rely on the commonly used t-test leakage
detection methodology initially proposed in [16, 23]. We performed the test at first
and second order. For bivariate second-order evaluation, we relied on the optimal
centered product [41, 53] as the combination function.
We use a PicoScope 5203 with a sample rate of 125 MS/s to measure the
power consumption at our STM32F4 Discovery board. To increase the measurement
quality, we reduce the internal clock to 12 MHz and remove some capacitors from
the PCB. The communication with the board is done over USART as the onboard USB interface causes additional noise in the power traces. Since the entirely
masked decryption requires an extremely high number of clock cycles, we cannot
easily perform a bivariate evaluation with our proposed method. Instead, we split
the practical evaluation into the modules similar to the theoretical evaluation of
Sect. 2.3.2. For first-order evaluation this is appropriate as noted in Sect. 2.3.2.
However, for the bivariate second-order test we do not cover the scenario of
two probes in different modules. Nevertheless, our goal is to show the existence
of second-order leakage to verify our measurement setup and we found this
for every module separately. For each module we took 100,000 measurements
and performed the aforementioned tests. To further speed up the second-order
evaluation, we adjusted the module to only process a small number of coefficients.
In our experiments, we perform the non-specific fixed vs. random t-test. To this
end, we take two types of measurements. One with fixed input and one with random
input. The t-statistic t is computed as
t =
μ F − μ R
σ 2
F
n F
+
σ 2
R
n R
,
41
performed on both shares independently (e.g., point-wise multiplication), this
is easily achieved by executing the operations on all coefficients of one share
first and only then do the operations for the coefficients of the other share. For
operations that require both shares (i.e., Decode) hand-crafted assembly code is
necessary.
2.5 Side-Channel Evaluation
Even though we provide proofs for most of our modules against one probe,
practical first-order side-channel security is not automatically implied by that.
Implementation errors can still negatively affect the resistance due to effects that are
not included in the model [5]. Therefore, to extensively evaluate the security of our
masked implementation, we performed basic side-channel experiments. Since our
aim is to show first-order resistance, we rely on the commonly used t-test leakage
detection methodology initially proposed in [16, 23]. We performed the test at first
and second order. For bivariate second-order evaluation, we relied on the optimal
centered product [41, 53] as the combination function.
We use a PicoScope 5203 with a sample rate of 125 MS/s to measure the
power consumption at our STM32F4 Discovery board. To increase the measurement
quality, we reduce the internal clock to 12 MHz and remove some capacitors from
the PCB. The communication with the board is done over USART as the onboard USB interface causes additional noise in the power traces. Since the entirely
masked decryption requires an extremely high number of clock cycles, we cannot
easily perform a bivariate evaluation with our proposed method. Instead, we split
the practical evaluation into the modules similar to the theoretical evaluation of
Sect. 2.3.2. For first-order evaluation this is appropriate as noted in Sect. 2.3.2.
However, for the bivariate second-order test we do not cover the scenario of
two probes in different modules. Nevertheless, our goal is to show the existence
of second-order leakage to verify our measurement setup and we found this
for every module separately. For each module we took 100,000 measurements
and performed the aforementioned tests. To further speed up the second-order
evaluation, we adjusted the module to only process a small number of coefficients.
In our experiments, we perform the non-specific fixed vs. random t-test. To this
end, we take two types of measurements. One with fixed input and one with random
input. The t-statistic t is computed as
t =
μ F − μ R
σ 2
F
n F
+
σ 2
R
n R
,
