On the Security of Partially Masked Software Implementations
Alessandro Barenghi, Gerardo Pelosi · 2014
Providing sound countermeasures against passive side channel attacks has received large interest in open literature. The scheme proposed in (Ishai et al., 2003) secures a computation against a d-probing adversary splitting it into d+1 shares, albeit with a significant performance overhead (5× to 20×). We maintain that it is possible to apply such countermeasures only to a portion of the cipher implementation, retaining the same computational security, backing a widespread intuition present among practitioners. We provide the sketch of a computationally bound attacker model, adapted as an extension of the one in (Ishai et al., 2003), and detail the resistance metric employed to estimate the computational effort of such an attacker, under sensible assumptions on the characteristic of the device leakage (which is, to the current state of the art, still lacking a complete formalization).