Pragmatism vs. Elegance: comparing two approaches to Simple Power Attacks on AES.
Valentina Banciu, Elisabeth Oswald · 2014
Abstract. Simple side-channel attacks trade off data complexity (i.e. the number of side-channel observations needed for a successful attack) with computational complexity (i.e. the number of operations applied to the side-channel traces). In the specific example of Simple Power Anal-ysis (SPA) attacks on the Advanced Encryption Standard (AES), two approaches can be found in the literature, one which is a pragmatic ap-proach that involves basic techniques such as efficient enumeration of key candidates, and one that is seemingly more elegant and uses alge-braic techniques. Both of these different techniques have been used in complementary settings: the pragmatic attacks were solely applied to the key schedule whereas the more elegant methods were only applied to the encryption rounds. In this article, we investigate how these methods compare in what we consider to be a more practical setting in which adversaries gain access to erroneous information about both key sched-ule and encryption rounds. We conclude that the pragmatic enumeration technique better copes with erroneous information which makes it more interesting in practice. 1