On the Cost of Lazy Engineering for Masked Software implementations

Balasch, Josep;Gierlichs, Benedikt;Grosso, Vincent;Reparaz, Oscar;Standaert, François-Xavier
(2014) 13th Smart Card Research and Advanced Application Conference (CARDIS 2014) — Location: Paris (France) (5.November.2014)

Files

OntheCostofLazyEngineeringforMaskedSoftwareImplementations.pdf
  • Open Access
  • Adobe PDF
  • 1.49 MB

Details

Authors
  • Balasch, JosepKU Leuven, Dept. Electrical Engineering-ESAT/COSIC and iMinds
    Author
  • Gierlichs, BenediktKU Leuven, Dept. Electrical Engineering-ESAT/COSIC and iMinds
    Author
  • Grosso, VincentUCLouvain
    Author
  • Reparaz, OscarKU Leuven, Dept. Electrical Engineering-ESAT/COSIC and iMinds
    Author
Abstract
Masking is one of the most popular countermeasures to mitigate side-channel analysis. Yet, its deployment in actual cryptographic devices is well known to be challenging, since designers have to ensure that the leakage corresponding to different shares is independent. Several works have shown that such an independent leakage assumption may be contradicted in practice, because of physical effects such as glitches" or ransition-based" leakages. As a result, implementing masking securely can be a time-consuming engineering problem. This is in strong contrast with recent and promising approaches for the automatic insertion of countermeasures exploiting compilers, that aim to limit the development time of side-channel resistant software. Motivated by this contrast, we question what can be hoped for these approaches - or more generally for masked software implementations based on careless assembly generation. For this purpose, our first contribution is a simple reduction from security proofs obtained in a (usual but not always realistic) model where leakages depend on the intermediate variables manipulated by the target device, to security proofs in a (more realistic) model where the transitions between these intermediate variables are leaked. We show that the cost of moving from one context to the other implies a division of the security order by two for masking schemes. Next, our second and main contribution is to provide a comprehensive empirical validation of this reduction, based on two microcontrollers, several (handwritten and compiler-based) ways of generating assembly codes, with and without "recycling" the randomness used for sharing. These experiments confirm the relevance of our analysis, and therefore quantify the cost of lazy engineering for masking.
Affiliations

Citations

Balasch, J., Gierlichs, B., Grosso, V., Reparaz, O., & Standaert, F.-X. (2014). On the Cost of Lazy Engineering for Masked Software implementations. In Marc Joye, Amir Moradi (ed.), Proceedings of the 13th Smart Card Research and Advanced Application Conference - Revised Selected Papers (p. p. 64-81). Springer. https://doi.org/10.1007/978-3-319-16763-3_5