Skip to main content
QUICK REVIEW

[论文解读] Blindsight: Blinding EM Side-Channel Leakage using Built-In Fully Integrated Inductive Voltage Regulator

Monodeep Kar, Arvind Singh|arXiv (Cornell University)|Feb 25, 2018
Cryptographic Implementations and Security参考文献 28被引用 11
一句话总结

本文提出了一种名为 Blindsight 的新型侧信道防御机制,利用内置的高频感应电压调节器(IVR)并配合随机化控制,以阻断针对 AES 硬件的电磁(EM)侧信道攻击。通过将 125MHz 的 IVR 与随机切换频率相结合,该技术可扰乱 AES 引擎的电磁泄漏,使针对熟练攻击者的平均破解时间(MTD)提升最多 500 倍。

ABSTRACT

Modern high-performance as well as power-constrained System-on-Chips (SoC) are increasingly using hardware accelerated encryption engines to secure computation, memory access, and communication operations. The electromagnetic (EM) emission from a chip leaks information of the underlying logical operations and can be collected using low-cost non-invasive measurements. EM based side-channel attacks (EMSCA) have emerged as a major threat to security of encryption engines in a SoC. This paper presents the concept of Blindsight where a high-frequency inductive voltage regulator (IVR) integrated on the same chip with an encryption engine is used to increase resistance against EMSCA. High-frequency (~100MHz) IVRs are present in modern microprocessors to improve energy-efficiency. We show that an IVR with a randomized control loop (R-IVR) can reduce EMSCA as the integrated inductance acts as a strong EM emitter and blinds an adversary from EM emission of the encryption engine. The EM measurements are performed on a test-chip containing two architectures of a 128-bit Advanced Encryption Standard (AES) engine powered by a high-frequency R-IVR and under two attack scenarios, one, where an adversary gains complete physical access of the target device and the other, where the adversary is only in proximity of the device. In both attack modes, an adversary can observe information leakage in Test Vector Leakage Assessment (TVLA) test in a baseline IVR (B-IVR, without control loop randomization). However, we show that EM emission from the R-IVR blinds the attacker and significantly reduces SCA vulnerability of the AES engine. A range of practical side-channel analysis including TVLA, Correlation Electromagnetic Analysis (CEMA), and a template based CEMA shows that R-IVR can reduce information leakage and prevent key extraction even against a skilled adversary.

研究动机与目标

  • 应对现代 SoC 中硬件保护的 AES 引擎面临的日益增长的低成本、非侵入式电磁侧信道攻击(EMSCA)威胁。
  • 克服传统 EM 抗干扰措施的局限性,这些措施通常带来高功耗、性能损失或面积开销,或需要昂贵的屏蔽措施。
  • 利用现有片上组件——特别是高频感应电压调节器(IVR)——提供一种低开销、集成化的 EMSCA 防御方案。
  • 证明随机化 IVR 控制环路可有效掩盖 AES 引擎的电磁特征,即使在复杂攻击模型下也具备防护能力。

提出的方法

  • 将高频(125MHz)感应电压调节器(IVR)直接集成在与 AES 引擎同一芯片上,以利用其固有的电磁辐射特性。
  • 实现一种随机化控制环路(R-IVR),通过改变 IVR 的开关频率来扩散并模糊 AES 操作产生的电磁泄漏。
  • 在原型测试芯片中使用键合线电感来模拟真实的片上集成,并在受控条件下测量电磁辐射。
  • 在两种攻击场景下进行电磁测量:物理访问(完整设备访问)和近距离探测(非侵入式探测),以评估防护强度。
  • 对记录的信号轨迹应用多种电磁侧信道分析(EMSCA)技术——TVLA、CEMA 和基于模板的 CEMA——以评估密钥恢复的成功率。
  • 使用基于模板的差分分析方法,分离并减去稳态电磁分量,测试 R-IVR 对高级后处理攻击的抗性。

实验结果

研究问题

  • RQ1片上高频感应电压调节器(IVR)是否能通过干扰有效掩盖 AES 引擎的电磁泄漏?
  • RQ2随机化 IVR 的开关频率在多大程度上可减少电磁侧信道攻击中的信息泄露?
  • RQ3R-IVR 防御对使用先进 EM 分析(如 CEMA、模板攻击)的初级和熟练攻击者分别有多有效?
  • RQ4当攻击者拥有物理访问权限或仅能近距离探测时,该方法是否仍保持有效性?
  • RQ5该技术是否可适配用于低频运行的公钥密码算法?

主要发现

  • 未采用随机化的基线 IVR(B-IVR)由于 IVR 本身产生的电磁干扰,已使 MTD 至少提升 13 倍,相比独立的 AES 引擎。
  • 采用随机化控制环路(R-IVR)后,高性能 AES 的 MTD 至少提升 13 倍,而低功耗紧凑型 AES 设计的 MTD 最多可提升 500 倍。
  • 在物理访问和近距离探测两种场景下,TVLA 和 CEMA 攻击均对 R-IVR 失效,即使使用 500,000 条轨迹也未能成功。
  • 尽管基于模板的 CEMA 试图抵消随机化影响,但仍无法提取密钥,证明其对智能后处理攻击具备强抗性。
  • 该防御有效,是因为 R-IVR 的高频(100MHz)电磁辐射掩盖了与 AES 相关的电磁特征,二者处于同一频段。
  • 该技术实用且开销极低,因为它利用了现有的片上 IVR 基础设施,无需额外功耗、面积或性能损失。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。