INSTITUT MINES-TÉLÉCOM
Revealing the secrets of success
Theoretical efficiency of side-channel distinguishers
Annelie Heuser, Sylvain Guilley, Olivier Rioul
Revealing the secrets of success Theoretical efficiency of - - PowerPoint PPT Presentation
Revealing the secrets of success Theoretical efficiency of side-channel distinguishers Annelie Heuser, Sylvain Guilley, Olivier Rioul INSTITUT MINES-TLCOM Outline Motivation State of the art New metric: success metric (SM)
INSTITUT MINES-TÉLÉCOM
Annelie Heuser, Sylvain Guilley, Olivier Rioul
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
2
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
Problem Statement
3 Interclass Information Analysis Kolmogorov-Smirnov Analysis Linear Regression Linear Correlation Analysis Difference of Means Mutual Information Analysis Empirically
How to compare side-channel distinguishers? Theoretically
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
State of the Art [Standaert+09] Unified framework for the analysis
4 E m p i r i c a l C r i t e r i a
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
[WhitnallOswald11] A fair evaluation framework for comparing side-channel distinguisher
(e.g., nearest distinguishing margin)
leakage
5 T h e
e t i c a l C r i t e r i a
State of the Art
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
6
[Fei+12] Algorithmic confusion analysis for DPA
success rate using a multivariate normal CDF
Algorithmic confusion coefficient Signal-to-noise ratio Number of traces
State of the Art
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
7 Theoretical Criteria Empirical Criteria
displays the practical
ad-hoc computation displays the theoretical distinguishability equivalent to the practical outcome?
State of the Art
coincides with the empirical success rate
New metric
more insights on parameters Closed-form expression
reflects relevant parameters
multivariate CDF estimation
“simple“ closed-form expression for any additive distinguisher
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
8 measured leakage with RV modeling the key secret key on the device sensitive variable depending on the key sensitive variable - correct key guess
Notation
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
9 distinguisher difference estimated difference
Notation
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
10 Estimation Bias Estimation Variance such that the mean-squared error of the estimation is given by
Notation
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
11 Failure rate To derive our new metric we start with the theoretical success rate:
Success Metric
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
12
Normal approximation Chebyshev/ Chernov bound Approximate the failure rate: Failure rate
Success Metric
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
13
exponentially for large m
Success Metric
Assumption
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
14
Since we achieved exponentially convergence
Success Metric
Relation to failure rate Normal approximation
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
15 Derived from the theoretical success rate through approximations, we define the success metric as
Success Metric
Roughly speaking
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
16 is the first DES Sbox in each setting we conducted 300 experiments
Empirical Evaluation
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
17 Noise level = 4
Empirical Evaluation
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
18 Relative Distinguishing Margin
Empirical Evaluation
[WhitnallOswald11]
T h e
e t i c a l C r i t e r i a does not depends on
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
19 Using 50 traces
Empirical Evaluation
Using 500 traces
SM depends on the number of traces
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
20 Using 500 traces
Empirical Evaluation
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
21
Success Metric
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
22
[Fei+12]
models
Generalized Confusion Coefficient
We assume that that the sensitive variable is normalized
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
23
Closed-form Expression
derived from the theoretical success rate
empirical success rate
crossings that are not visible in the SR
success metric that is easier to compute
distinguishers
leakage model
between X and Y*
estimation
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
24
Conclusion & Future Work
Future Work Conclusion
INSTITUT MINES-TÉLÉCOM
REVEALING THE SECRETS OF SUCCESS, A. HEUSER, S. GUILLEY, O. RIOUL
25