SCNIFFER: Low-Cost, Automated, Efficient Electromagnetic Side-Channel Sniffing

08/25/2019
by   Josef Danial, et al.
0

Electromagnetic (EM) side-channel analysis (SCA) is a prominent tool to break mathematically-secure cryptographic engines, especially on resource-constrained IoT devices. Presently, to perform EM SCA on an embedded IoT device, the entire chip is manually scanned and the MTD (Minimum Traces to Disclosure) analysis is performed at each point on the chip to reveal the secret key of the encryption algorithm. However, an automated end-to-end framework for EM trace collection and attack has been missing. This work proposes SCNIFFER: a lowcost, automated EM leakage SNIFFing platform to perform efficient end-to-end Side-Channel attacks. Using a leakage measure such as the signal amplitude or TVLA, we propose a greedy gradient-search heuristic that converges to one of the points of highest EM leakage on the chip (dimension: N x N) within O(N) iterations, and then perform Correlational EM Analysis (CEMA) at that point. This reduces the CEMA attack time by N times compared to an exhaustive MTD analysis, and > 20x compared to choosing an attack location at random. We demonstrate SCNIFFER using a low-cost custom-built 3-D scanner (< 300) compared to > 50, 000 commercial EM scanners, an H-field probe, and a variety of microcontrollers as the devices under attack. The SCNIFFER framework is evaluated for several cryptographic algorithms (AES-128, DES, RSA) running on both an 8-bit Atmega microcontroller and a 32-bit ARM microcontroller to find the best point of leakage and then perform a CEMA at that point.

READ FULL TEXT

page 1

page 3

page 4

page 5

page 6

page 8

research
02/25/2018

Blindsight: Blinding EM Side-Channel Leakage using Built-In Fully Integrated Inductive Voltage Regulator

Modern high-performance as well as power-constrained System-on-Chips (So...
research
11/12/2020

EM-X-DL: Efficient Cross-Device Deep Learning Side-Channel Attack with Noisy EM Signatures

This work presents a Cross-device Deep-Learning based Electromagnetic (E...
research
03/18/2019

A Survey of Electromagnetic Side-Channel Attacks and Discussion on their Case-Progressing Potential for Digital Forensics

The increasing prevalence of Internet of Things (IoT) devices has made i...
research
12/22/2021

Electromagnetic Side-Channel Attack Resilience against PRESENT Lightweight Block Cipher

Lightweight cryptography is a novel diversion from conventional cryptogr...
research
01/03/2018

Power Analysis Based Side Channel Attack

Power analysis is a branch of side channel attacks where power consumpti...
research
06/21/2022

A Practical Methodology for ML-Based EM Side Channel Disassemblers

Providing security guarantees for embedded devices with limited interfac...
research
10/21/2022

Virtual Triggering: a Technique to Segment Cryptographic Processes in Side Channel Traces

Side-Channel Attacks (SCAs) exploit data correla-tion in signals leaked ...

Please sign up or login with your details

Forgot password? Click here to reset