Proceedings of the 2016 ACM Workshop on Theory of Implementation Security 2016
DOI: 10.1145/2996366.2996369
|View full text |Cite
|
Sign up to set email alerts
|

Moments-Correlating DPA

Abstract: We generalize correlation-enhanced power analysis collision attacks into moments-correlating DPA. The resulting distinguisher is applicable to the profiled and non-profiled (collision) settings and is able to exploit information lying in any statistical moment. It also benefits from a simple ruleof-thumb to estimate its data complexity. Experimental results show that such a tool allows answering with confidence to some important questions regarding the design of sidechannel countermeasures (e.g. what is the mo… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
40
0

Year Published

2019
2019
2021
2021

Publication Types

Select...
7
2

Relationship

3
6

Authors

Journals

citations
Cited by 52 publications
(40 citation statements)
references
References 40 publications
(54 reference statements)
0
40
0
Order By: Relevance
“…The Hamming weight and Hamming distance models are frequently used as a power model. For a leakage model, leakage characterization and average traces are occasionally used, because they are more similar to the actual leakage model than the Hamming weight or Hamming distance . In , an MLP was trained using the Sbox output value and real power trace as the data and label, respectively.…”
Section: Deep Learning‐based Side‐channel Analysismentioning
confidence: 99%
“…The Hamming weight and Hamming distance models are frequently used as a power model. For a leakage model, leakage characterization and average traces are occasionally used, because they are more similar to the actual leakage model than the Hamming weight or Hamming distance . In , an MLP was trained using the Sbox output value and real power trace as the data and label, respectively.…”
Section: Deep Learning‐based Side‐channel Analysismentioning
confidence: 99%
“…So we need another ingredient in order to reveal the informativeness of each moment of the leakage PDF, separately. The Moments-Correlating DPA (MC-DPA) recently introduced in [44] is a natural candidate for this purpose. We now describe how it can be used to (informally) analyze the security of a flawed masked implementation.…”
Section: Beyond Independent Leakagementioning
confidence: 99%
“…In order to relax this requirement moments-correlating DPA (MCDPA) [34] can be applied, that tries to make use of a perfect leakage model by profiling. Therefore, in each core and each chip we divided the collected measurements (n traces) into two halves, and used the first half (n/2 traces) as profiling traces t i∈{1...n/2} .…”
Section: ) Moments-correlating Dpamentioning
confidence: 99%