Title
Simulatable Leakage: Analysis, Pitfalls, and New Constructions.
Abstract
In 2013, Standaert et al. proposed the notion of simulatable leakage to connect theoretical leakage resilience with the practice of side channel attacks. Their use of simulators, based on physical devices, to support proofs of leakage resilience allows verification of underlying assumptions: the indistinguishability game, involving real vs. simulated leakage, can be 'played' by an evaluator. Using a concrete, block cipher based leakage resilient PRG and high-level simulator definition (based on concatenating two partial leakage traces), they included detailed reasoning why said simulator (for AES-128) resists state-of-the-art side channel attacks. In this paper, we demonstrate a distinguisher against their simulator and thereby falsify their hypothesis. Our distinguishing technique, which is evaluated using concrete implementations of the Standaert et al. simulator on several platforms, is based on 'tracking' consistency (resp. identifying simulator inconsistencies) in leakage traces by means of cross-correlation. In attempt to rescue the approach, we propose several alternative simulator definitions based on splitting traces at points of low intrinsic cross-correlation. Unfortunately, these come with significant caveats, and we conclude that the most natural way of producing simulated leakage is by using the underlying construction 'as is' (but with a random key).
Year
DOI
Venue
2014
10.1007/978-3-662-45611-8_12
ADVANCES IN CRYPTOLOGY - ASIACRYPT 2014, PT I
Keywords
Field
DocType
leakage resilience,side channel attack,simulatable leakage,cross-correlation
Block cipher,Leakage (electronics),Computer science,Theoretical computer science,Leakage resilience,Mathematical proof,Side channel attack,Concatenation,Distributed computing
Conference
Volume
ISSN
Citations 
8873
0302-9743
8
PageRank 
References 
Authors
0.42
13
6
Name
Order
Citations
PageRank
Jake Longo Galea180.42
Daniel P. Martin2434.20
Elisabeth Oswald319717.67
Dan Page430120.67
Martijn Stam5165967.36
Michael Tunstall61388.59