Improved DPA attack on rotating S-boxes masking scheme
Shourong Hou, Yujie Zhou, Hongming Liu, Nianhao Zhu · 2017
Power Analysis (PA) is a powerful method to extract leakage information from theoretically secure cryptographic devices. In general, Differential Power Analysis (DPA) correlates the processed data with power consumption of devices through statistical analysis to reveal systems' secret key. A common approach to counteract DPA is a low-entropy lightweight masking strategy. This masking scheme, known as Rotating S-Boxes Masking (RSM), has inherent flaws in masks' hamming weights for software implementation. In this paper, an improved DPA (IDPA) for the RSM countermeasure is proposed in terms of smaller computational complexity and better success rate of recovering the secret key. Using the public power traces provided by the latest DPA Contest, we come to the conclusion that the IDPA method takes as low as 20 traces to retrieve the first 128-bits secret key when analyzing the first-order leakage information. Furthermore, our approach reduces significantly the number of traces, but still gets better attack effects compared with other DPA methods.