SLIDE 17 ‘A FAIR EVALUATION FRAMEWORK’
10 20 30 40 50 60 −0.4 −0.2 0.2 0.4 0.6 Key hypothesis Distinguisher value 10 20 30 40 50 60 −2 −1 1 2 3 # standard deviations
Correct key ranking in the theoretic vector ◮ Distinguisher must isolate key in theory to stand a
chance in practice
10 20 30 40 50 60 −0.4 −0.2 0.2 0.4 0.6 Key hypothesis Distinguisher value 10 20 30 40 50 60 −2 −1 1 2 3 # standard deviations
Nearest-rival distinguishing score – # s.d. between correct key value and highest ranked alternative ◮ The smaller the margin, the fewer the traces needed
for estimation!
10 20 30 40 0.2 0.4 0.6 0.8 1 Support size Theoretic success rate
Average minimum support – how large an input support does the distinguisher need? ◮ An attack which needs to ‘see more inputs’ will
inevitably need more traces
- C. WHITNALL (UNIVERSITY OF BRISTOL)
EVALUATING MIA CRYPTO 2011 6 / 1