SCNIFFER: Low-Cost, Automated, Efficient Electromagnetic Side-Channel Sniffing

被引:17
|
作者
Danial, Josef [1 ]
Das, Debayan [1 ]
Ghosh, Santosh [2 ]
Raychowdhury, Arijit [3 ]
Sen, Shreyas [1 ]
机构
[1] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47906 USA
[2] Intel Corp, Hillsboro, OR 97124 USA
[3] Georgia Inst Technol, Sch Elect & Comp Engn, Atlanta, GA 30332 USA
基金
美国国家科学基金会;
关键词
End-to-end EM SCA attack; low-cost EM scanning; automated framework; SCNIFFER; POWER ANALYSIS;
D O I
10.1109/ACCESS.2020.3025022
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Electromagnetic (EM) side-channel analysis (SCA) is a prominent tool to break mathematically-secure cryptographic engines, especially on resource-constrained devices. Presently, to perform EM SCA on an embedded device, the entire chip is manually scanned and the MTD (Minimum Traces to Disclosure) analysis is performed at each point on the chip to reveal the secret key of the encryption algorithm. However, an automated end-to-end framework for EM leakage localization, trace acquisition, and attack has been missing. This work proposes SCNIFFER: a low-cost, automated EM Side Channel leakage SNIFFing platform to perform efficient end-to-end Side-Channel attacks. Using a leakage measure such as Test Vector Leakage Assessment (TVLA), or the signal to noise ratio (SNR), we propose a greedy gradient-search heuristic that converges to one of the points of highest EM leakage on the chip (dimension: N x N) within O(N) iterations, and then perform Correlational EM Analysis (CEMA) at that point. This reduces the CEMA attack time by similar to N times compared to an exhaustive MTD analysis, and by >20 x compared to choosing an attack location at random. We demonstrate SCNIFFER using a low-cost custombuilt 3-D scanner with an H-field probe (<$500) compared to >$50; 000 commercial EM scanners, and a variety of microcontrollers as the devices under attack. The SCNIFFER framework is evaluated for several cryptographic algorithms (AES-128, DES, RSA) running on both an 8-bit Atmega microcontroller and a 32-bit ARM microcontroller to find a point of high leakage and then perform a CEMA at that point.
引用
收藏
页码:173414 / 173427
页数:14
相关论文
共 50 条
  • [31] Automated Formal Analysis of Side-Channel Attacks on Probabilistic Systems
    Novakovic, Chris
    Parker, David
    COMPUTER SECURITY - ESORICS 2019, PT I, 2019, 11735 : 319 - 337
  • [32] Efficient Simulation of EM Side-Channel Attack Resilience
    Kumar, Amit
    Scarborough, Cody
    Yilmaz, Ali
    Orshansky, Michael
    2017 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD), 2017, : 123 - 130
  • [33] Automated Software Protection for the Masses Against Side-Channel Attacks
    Belleville, Nicolas
    Courousse, Damien
    Heydemann, Karine
    Charles, Henri-Pierre
    ACM TRANSACTIONS ON ARCHITECTURE AND CODE OPTIMIZATION, 2019, 15 (04)
  • [34] Defeating Low-Cost Countermeasures against Side-Channel Attacks in Lattice-based Encryption A Case Study on Crystals-Kyber
    Ravi P.
    Paiva T.
    Jap D.
    D’anvers J.-P.
    Bhasin S.
    IACR Transactions on Cryptographic Hardware and Embedded Systems, 2024, 2024 (02): : 795 - 818
  • [35] Poster: Symbolic Path Cost Analysis for Side-Channel Detection
    Brennan, Tegan
    Saha, Seemanta
    Bultan, Tevfik
    PROCEEDINGS 2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING - COMPANION (ICSE-COMPANION, 2018, : 424 - 425
  • [36] Electromagnetic Side-Channel Analysis Against TERO-Based TRNG
    Osuka, Saki
    Fujimoto, Daisuke
    Kawamura, Shinichi
    Hayashi, Yuichi
    IEEE TRANSACTIONS ON ELECTROMAGNETIC COMPATIBILITY, 2022, 64 (05) : 1288 - 1295
  • [37] Electromagnetic Side-Channel Hardware Trojan Detection Based on Transfer Learning
    Sun, Shaofei
    Zhang, Hongxin
    Cui, Xiaotong
    Dong, Liang
    Fang, Xing
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-EXPRESS BRIEFS, 2022, 69 (03) : 1742 - 1746
  • [38] Electromagnetic Equalizer: An Active Countermeasure Against EM Side-channel Attack
    Wang, Chenguang
    Cai, Yici
    Wang, Haoyi
    Zhou, Qiang
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD) DIGEST OF TECHNICAL PAPERS, 2018,
  • [39] RF Analog Hardware Trojan Detection Through Electromagnetic Side-Channel
    Kan, John
    Shen, Yuyi
    Xu, Jiachen
    Chen, Ethan
    Zhu, Jimmy
    Chen, Vanessa
    IEEE OPEN JOURNAL OF CIRCUITS AND SYSTEMS, 2022, 3 : 237 - 251
  • [40] Efficient Solution to Secure ECC Against Side-channel Attacks
    Wu Keke
    Li Huiyun
    Zhu Dingju
    Yu Fengqi
    CHINESE JOURNAL OF ELECTRONICS, 2011, 20 (03): : 471 - 475