Non-Profiled Semi-Supervised Horizontal Attack Against Elliptic Curve Scalar Multiplication Using Support Vector Machines
There are different ways to leverage Side Channel information into a successful attack against cryptographic hardware. The most constraint attack scenario assumes no knowledge about the internal states of the hardware during secret key processing and therefore provides no labels for power hungry deep learning algorithms, which are the state of the art in profiling attacks. In our non-profiled single-trace attack we used a statistical method the comparison to the mean to retrieve the initial key candidates and trained a highly regularized Support Vector Machine (SVM) using those candidates. We achieved an improvement in attack correctness of about 10% between the initial and final key candidates. We attacked two implementations of Elliptic Curve Scalar Multiplication. One is an ASIC produced in the IHP 250nm technology, where the hardware description was compiled using the compile_ultra option, which has been proven to increase the resistance against SCA attacks. Another one is an FPGA implementation, using the sequential addressing countermeasure, which minimizes the number of clock cycles with bus addressing leakage.
Paper
Full text
Non-Profiled Semi-Supervised Horizontal Attack Against Elliptic Curve Scalar Multiplication Using Support Vector Machines
Semantic Scholar · Computer Science · 2023
Abstract
There are different ways to leverage Side Channel information into a successful attack against cryptographic hardware. The most constraint attack scenario assumes no knowledge about the internal states of the hardware during secret key processing and therefore provides no labels for power hungry deep learning algorithms, which are the state of the art in profiling attacks. In our non-profiled single-trace attack we used a statistical method the comparison to the mean to retrieve the initial key candidates and trained a highly regularized Support Vector Machine (SVM) using those candidates. We achieved an improvement in attack correctness of about 10% between the initial and final key candidates. We attacked two implementations of Elliptic Curve Scalar Multiplication. One is an ASIC produced in the IHP 250nm technology, where the hardware description was compiled using the compile_ultra option, which has been proven to increase the resistance against SCA attacks. Another one is an FPGA implementation, using the sequential addressing countermeasure, which minimizes the number of clock cycles with bus addressing leakage.