Co-relation Scan Attack Analysis (COSAA) on AES: A Comprehensive Approach

Dipojjwal Ray, Siddharth Singh, Sk Subidh Ali, Santosh Biswas · 2019

Scan based DFT in IC testing is invariably taken into account in the semiconductor chip industry to ensure structurally and functionally correct chips. The fact that scan chain hugely benefits manufacturing test due to high fault coverage, cryptographic ICs employ it as a standard technique. The increased observability and controllability of sequential elements to facilitate testing yet comes at a compromise in security as cryptochips consisting of a secret user key can be retrieved by skillfully designed differential attacks. Existing differential scan attacks target unique hamming weight pairs. In this paper we propose a comprehensive attack on a crypto-chip using an AES implementation, namely Co-relation scan attack (COSA). The motivation behind this attack is that the existing attacks can be easily defended by carefully crafting additional bits in order to convert a unique hamming weight to non unique one. The proposed comprehensive attack can work using any possible hamming weight model. Now the designer has to protect the circuit under tests from relatively large attack surface. Our experimental results show that the attack can recover the secret key of AES in 22 micro-seconds on an average desktop machine.

Read the paper · More papers on PaperTik