【24h】

Simulatable Leakage: Analysis, Pitfalls, and New Constructions

机译:可模拟泄漏:分析,陷阱和新建筑

获取原文

摘要

In 2013, Standaert et al. proposed the notion of simulatable leakage to connect theoretical leakage resilience with the practice of side channel attacks. Their use of simulators, based on physical devices, to support proofs of leakage resilience allows verification of underlying assumptions: the indistinguishability game, involving real vs. simulated leakage, can be 'played' by an evaluator. Using a concrete, block cipher based leakage resilient PRG and high-level simulator definition (based on concatenating two partial leakage traces), they included detailed reasoning why said simulator (for AES-128) resists state-of-the-art side channel attacks. In this paper, we demonstrate a distinguisher against their simulator and thereby falsify their hypothesis. Our distinguishing technique, which is evaluated using concrete implementations of the Standaert et al. simulator on several platforms, is based on 'tracking' consistency (resp. identifying simulator inconsistencies) in leakage traces by means of cross-correlation. In attempt to rescue the approach, we propose several alternative simulator definitions based on splitting traces at points of low intrinsic cross-correlation. Unfortunately, these come with significant caveats, and we conclude that the most natural way of producing simulated leakage is by using the underlying construction 'as is' (but with a random key).
机译:在2013年,钟鸣等。提出模拟的泄漏的概念来理论泄漏弹性带的边信道攻击的做法连接。他们使用模拟器,基于物理设备,泄漏的弹性支持证明允许基本假设的验证:不可区分的游戏,涉及到真正的与模拟泄漏,通过评估可以“玩”。使用混凝土,块密码基于泄漏弹性PRG和高级别模拟器定义(基于串联两个部分泄漏的痕迹),它们包括详细的理由为什么所述模拟器(对于AES-128)抵抗状态的最先进的侧信道攻击。在本文中,我们表现出对他们的模拟器了一个标识符,从而伪造他们的假设。我们的区别技术,其通过使用所述钟鸣等人的具体实现进行评价。模拟器在多种平台上,基于由交叉相关的装置中泄漏的痕迹“跟踪”一致性(分别识别模拟器不一致)。在试图营救的办法,提出了一种基于分割的痕迹在较低的固有的交叉相关的几个点模拟器替代的定义。不幸的是,这些配有显著的警告,我们得出结论,生产模拟泄漏的最自然的方式是通过使用基础建设“是”(但随机密钥)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号