Capacity of Deliberate Side-Channels Created by Software Activities
Baki Berkay Yilmaz, Milos Prvulović, Alenka G. Zajic · 2018
It has been shown that electromagnetic (EM) emanations that are result of instruction executions in a computer system can create a wireless side-channel which attackers can use to extract sensitive information such as a cryptography key. When an attacker modifies the software application to exfiltrate sensitive information through a channel, this channel is called a deliberate side-channel or a covert channel. Because deliberate side-channels are not created for a conventional wireless communication to transmit information, these channels are exposed not only to the errors created by the wireless transmission (the transmitted signal propagates through a channel hindered by metal and plastic), but also by varying execution time of computer activities, and by insertions from other computer activities such as interrupts. Combining all of these effects, we propose to model deliberate side-channels as an insertion channel where the transmitted sequence is a pulse amplitude modulated signal with varying pulse width. Utilizing this model, we derive upper and lower bounds for the channel capacity of the deliberate side-channels. The bounds demonstrate the severity of data leakage through deliberate side channels by revealing the potential to transmit high data rates. Moreover, the proposed bounds for the channel capacity can be employed by any noisy insertion channel and provides more confidential results.