Chicken or the Egg - Computational Data Attacks or Physical Attacks.
Julien Allibert, Benoît Feix, Georges Gagnerot, Ismael Kane, Hugues Thiebeauld, Tiana Razafindralambo · 2015
Abstract. Side-channel and fault injection analyses are well-known domains that have been used for years to evaluate the resistance of hardware based prod-ucts. These techniques remain a threat for the secret assets embedded in prod-ucts like smart cards or System On Chip. But most of these products contain nowadays several strong protections rendering side-channel and fault attacks difficult or inefficient. For two decades embedded cryptography for payment, pay tv, identity areas have relied a lot on secure elements. Nowadays more al-ternative solutions on mobile phones appear with the aim to offer software-based security services including payment and security solutions as the HCE and DRM products. Cryptographic operations running in such applications are then exe-cuted most often on unprotected hardware devices. Therefore the binary code is often accessible to attackers who can use static and dynamic reverse engineer-ing techniques to extract and analyse operations including data modification as faults. Hence, hiding or obfuscating secrets and/or whitebox cryptography becomes a strong alternatives to secure element storage for assets. We explain