Attacks on Protected Devices
摘要
In the previous chapter, we studied various attacks with different side-channel distinguishers. The attacks are essential pertaining to the category of “first order,” in which the leakage of the secret-dependent sensitive variables is used to launch the attacks. However, this strategy generally does not work in the presence of side-channel countermeasures such as masking (provided masking is properly implemented). Indeed, the aim of using masking schemes is to force the potential adversary to carry out “higher-order” attacks that are less efficient and effective than first-order attacks. In this chapter, we consider higher-order attacks against masked implementations and present the optimal form of higher-order attacks in the sense that they maximize the success rate. We begin by studying the application of an expectation-maximization (EM) algorithm to a non-profiling attack and show that this EM-based attack can outperform conventional higher-order correlation attacks. Next, we present optimal higher-order distinguishers (HOOD) that essentially follow the maximum likelihood principle. We then present a Taylor expansion of HOOD that can be applied in the presence of masking at very high orders.