SCNIFFER: Low-Cost, Automated, Efficient Electromagnetic Side-Channel Sniffing

被引:17
|
作者
Danial, Josef [1 ]
Das, Debayan [1 ]
Ghosh, Santosh [2 ]
Raychowdhury, Arijit [3 ]
Sen, Shreyas [1 ]
机构
[1] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47906 USA
[2] Intel Corp, Hillsboro, OR 97124 USA
[3] Georgia Inst Technol, Sch Elect & Comp Engn, Atlanta, GA 30332 USA
基金
美国国家科学基金会;
关键词
End-to-end EM SCA attack; low-cost EM scanning; automated framework; SCNIFFER; POWER ANALYSIS;
D O I
10.1109/ACCESS.2020.3025022
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Electromagnetic (EM) side-channel analysis (SCA) is a prominent tool to break mathematically-secure cryptographic engines, especially on resource-constrained devices. Presently, to perform EM SCA on an embedded device, the entire chip is manually scanned and the MTD (Minimum Traces to Disclosure) analysis is performed at each point on the chip to reveal the secret key of the encryption algorithm. However, an automated end-to-end framework for EM leakage localization, trace acquisition, and attack has been missing. This work proposes SCNIFFER: a low-cost, automated EM Side Channel leakage SNIFFing platform to perform efficient end-to-end Side-Channel attacks. Using a leakage measure such as Test Vector Leakage Assessment (TVLA), or the signal to noise ratio (SNR), we propose a greedy gradient-search heuristic that converges to one of the points of highest EM leakage on the chip (dimension: N x N) within O(N) iterations, and then perform Correlational EM Analysis (CEMA) at that point. This reduces the CEMA attack time by similar to N times compared to an exhaustive MTD analysis, and by >20 x compared to choosing an attack location at random. We demonstrate SCNIFFER using a low-cost custombuilt 3-D scanner with an H-field probe (<$500) compared to >$50; 000 commercial EM scanners, and a variety of microcontrollers as the devices under attack. The SCNIFFER framework is evaluated for several cryptographic algorithms (AES-128, DES, RSA) running on both an 8-bit Atmega microcontroller and a 32-bit ARM microcontroller to find a point of high leakage and then perform a CEMA at that point.
引用
收藏
页码:173414 / 173427
页数:14
相关论文
共 50 条
  • [1] Low-cost solutions for preventing simple side-channel analysis: Side-channel atomicity
    Chevallier-Mames, B
    Ciet, M
    Joye, M
    IEEE TRANSACTIONS ON COMPUTERS, 2004, 53 (06) : 760 - 768
  • [2] Side-Channel Analysis of CRYSTALS-Kyber and A Novel Low-Cost Countermeasure
    Hamoudi, Meziane
    Korchi, Amina Bel
    Guilley, Sylvain
    Takarabt, Sofiane
    Karray, Khaled
    Souissi, Youssef
    SECURITY AND PRIVACY, ICSP 2021, 2021, 1497 : 30 - 46
  • [3] Towards efficient and automated side-channel evaluations at design time
    Danilo Šijačić
    Josep Balasch
    Bohan Yang
    Santosh Ghosh
    Ingrid Verbauwhede
    Journal of Cryptographic Engineering, 2020, 10 : 305 - 319
  • [4] Towards efficient and automated side-channel evaluations at design time
    Sijacic, Danilo
    Balasch, Josep
    Yang, Bohan
    Ghosh, Santosh
    Verbauwhede, Ingrid
    JOURNAL OF CRYPTOGRAPHIC ENGINEERING, 2020, 10 (04) : 305 - 319
  • [5] EM Side-Channel Attacks on Commercial Contact less Smartcards Using Low-Cost Equipment
    Kasper, Timo
    Oswald, David
    Paar, Christof
    INFORMATION SECURITY APPLICATIONS, 2009, 5932 : 79 - 93
  • [6] Energy Efficient Obfuscation of Side-Channel Leakage for Preventing Side-Channel Attacks
    Jin, Shan
    Xu, Minghua
    Cai, Yiwei
    39TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2024, 2024, : 1405 - 1414
  • [7] Signal-to-Noise Ratio Measurements of Side-Channel Traces for Establishing Low-Cost Countermeasure Design
    Yano, Yusuke
    Iokibe, Kengo
    Toyota, Yoshitaka
    Teshima, Toshiaki
    2017 ASIA-PACIFIC INTERNATIONAL SYMPOSIUM ON ELECTROMAGNETIC COMPATIBILITY (APEMC), 2017, : 93 - 95
  • [8] Fresh Re-keying: Security against Side-Channel and Fault Attacks for Low-Cost Devices
    Medwed, Marcel
    Standaert, Francois-Xavier
    Grossschaedl, Johann
    Regazzoni, Francesco
    PROGRESS IN CRYPTOLOGY - AFRICACRYPT 2010, 2010, 6055 : 279 - +
  • [9] DESIGN OF EFFICIENT SIDE-CHANNEL SPILLWAY
    KNIGHT, ACE
    JOURNAL OF HYDRAULIC ENGINEERING-ASCE, 1989, 115 (09): : 1275 - 1289
  • [10] Efficient Electromagnetic Analysis Based on Side-channel Measurement Focusing on Physical Structures
    Wada, Shinpei
    Kim, Youngwoo
    Fujimoto, Daisuke
    Hayashi, Yuichi
    Homma, Naofumi
    2020 IEEE INTERNATIONAL SYMPOSIUM ON ELECTROMAGNETIC COMPATIBILITY AND SIGNAL & POWER INTEGRITY VIRTUAL SYMPOSIUM(IEEE EMC+SIPI), 2020, : 532 - 536