Composable and efficient masking schemes for side-channel secure implementations

(2022)

Files

thesis_elec.pdf
  • Open Access
  • Adobe PDF
  • 1.49 MB

Details

Authors
Supervisors
Standaert, FranƧois-Xavier
Abstract
Modern cryptography has been widely deployed in the last decades, allowing any computing device to secure its communications. Facing the strength of the cryptographic algorithms, attackers turned to their implementations. In particular, side-channel attacks have been shown to threaten the security of cryptographic embedded devices by exploiting information leaked through physical characteristics such as power consumption or electromagnetic radiation. In order to mitigate side-channel attacks, implementations use countermeasures, among which masking is the most investigated choice. In this thesis, we design and analyze masking schemes with the goal of having efficient masking schemes with strong and well-understood security. Efficiency is an important criterion for masking schemes, since they sometimes have orders of magnitude performance overheads over an implementation without countermeasures. Regarding security, our approach is to prove the security of the masking scheme as comprehensively as possible by analyzing complete masked algorithms in leakage models which are well-aligned with the characteristics of real-world leakage. We first work in the threshold probing model, which is the simplest and most widely used side-channel leakage model. Our focus is the problem of composability, that is, the possibility to build complex algorithms from small building blocks while preserving the security. Concretely, we introduce a new composable security definition, design efficient constructions that satisfy it, and use them to build more complex circuits. Next, we adapt our results from the threshold probing model to the robust probing model. This model extends the threshold probing model by taking into account physical phenomena named glitches and transitions. These phenomena that appear in concrete hardware implementations violate the independence assumption of the threshold probing model. Finally, the threshold and robust probing models fix a bound on the amount of leakage available to the adversary, while in practice, the amount of leakage depends on the amount of computation performed by the implementation. This issue is taken into account by the random probing model, for which we introduce a new composable analysis technique that gives a better security bound for simple and efficient masking schemes, compared to state-of-the-art techniques.
Affiliations

Citations

Cassiers, G. (2022). Composable and efficient masking schemes for side-channel secure implementations. https://hdl.handle.net/2078.5/103367