Revealing the secrets of success Theoretical efficiency of side-channel distinguishers Annelie Heuser, Sylvain Guilley, Olivier Rioul INSTITUT MINES-TÉLÉCOM
Outline ‣ Motivation ‣ State of the art ‣ New metric: success metric (SM) ‣ Empirical evaluation ‣ Closed-form expression of SM ‣ Outlook 2 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Problem Statement Interclass Information Analysis Difference of Means Mutual Information Analysis Linear Correlation Analysis Kolmogorov-Smirnov Analysis Linear Regression How to compare side-channel distinguishers? Empirically Theoretically ‣ Real measurements (portable?) ‣ Is this realistic? ‣ Simulations (model suitable?) 3 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
State of the Art E m p i r i c a C l r i t e r i a [Standaert+09] Unified framework for the analysis of side-channel key recovery attacks ‣ Estimated success rate ( o -th order) ‣ Estimated guessing entropy 4 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
State of the Art T h e o r e t i c C a l r i t e r i a [WhitnallOswald11] A fair evaluation framework for comparing side-channel distinguisher ‣ Theoretical evaluation criteria (e.g., nearest distinguishing margin) ‣ Distinguisher is provided with full information about the leakage ‣ New insights in the theoretical behavior 5 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
State of the Art [Fei+12] Algorithmic confusion analysis for DPA ‣ Closed-form expression of one-bit DPA for the success rate using a multivariate normal CDF Algorithmic confusion coefficient Signal-to-noise ratio Number of traces 6 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
State of the Art Closed-form Empirical Theoretical expression Criteria Criteria displays the practical displays the theoretical reflects relevant parameters outcome distinguishability equivalent to the only DPA; ad-hoc computation practical outcome? multivariate CDF estimation coincides with the empirical success rate more insights on parameters “simple“ closed-form expression for any New metric additive distinguisher 7 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Notation Side-channel Model RV modeling the key secret key on the device sensitive variable depending on the key sensitive variable - correct key guess measured leakage with 8 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Notation Distinguisher distinguisher difference estimated difference 9 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Notation Statistical parameter from Estimation Theory E stimation B ias E stimation V ariance such that the mean-squared error of the estimation is given by 10 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Success Metric To derive our new metric we start with the theoretical success rate : Failure rate 11 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Success Metric Approximate the failure rate: 1. Union bound Failure rate Normal approximation Chebyshev/ Chernov bound 12 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Success Metric 2. Normal Approximation Assumption exponentially for large m 13 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Success Metric 3. First order approximation Since we achieved exponentially convergence Normal approximation Relation to failure rate FR = 1 - SR 14 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Success Metric Derived from the theoretical success rate through approximations , we define the success metric as Roughly speaking 15 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Empirical Evaluation is the first DES Sbox p u t e S in each setting we conducted 300 experiments ‣ Correlation Power Analysis (CPA) ‣ Mutual Information Analysis (MIA) r e h s i u ‣ Histograms g n i t s i D ‣ Parzen window ‣ Kolmogorov-Smirnov Analysis (KSA) 16 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Empirical Evaluation Noise level = 4 S R a n d S M c o i n c i d e 17 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Empirical Evaluation Relative Distinguishing Margin [WhitnallOswald11] does not depends on a l T h e o r e t i c ‣ number of traces C r i t e r i a ‣ estimation method 18 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Empirical Evaluation Using 50 traces Using 500 traces SM depends on the number of traces 19 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Empirical Evaluation Using 500 traces 20 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Success Metric Closed-form expressions for additive distinguisher 21 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Generalized Confusion Coefficient only valid for one-bit [Fei+12] models = One-bit models = We assume that that the sensitive variable is normalized 22 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Closed-form Expression CPA one-bit DPA 23 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Conclusion & Future Work Conclusion ‣ Introduced the success metric that is derived from the theoretical success rate Future Work ‣ Success metric coincide with the ‣ Explain the ranking of various empirical success rate distinguishers ‣ We are able to make predictions about ‣ Determine the influence of the crossings that are not visible in the SR leakage model ‣ Extended the idea of confusion ‣ Sbox ‣ Derived a closed-form expression for the ‣ Mask success metric that is easier to compute ‣ nonlinear relationship between X and Y* ‣ Determine the influence of the estimation 24 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Questions? 25 INSTITUT MINES-TÉLÉCOM REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Recommend
More recommend