CORSICA: A Framework for Conducting Real-World Side-Channel Analysis

Jens Trautmann, Stefan Wildermann, Jürgen Teich · 2021

With the abundance of computing devices in our everyday life, such as IoT devices, improving their security has become a number one priority. While the major focus lies on software security, hardware vulnerabilities are often not considered. Here, particularly side-channel attacks pose a realistic threat to such systems. However, conducting Side-Channel Analysis (SCA) to evaluate those threats currently requires deep expert knowledge, a lab environment, and numerous manual steps. Therefore, it is often ignored in security considerations.In this paper, we analyze the challenges when conducting SCA on consumer-grade devices using template-matching based triggering techniques. By introducing a three-staged framework called CORSICA, we elaborate the obstacles and deficiencies of current state-of-the-art techniques and provide potential solutions for them. Moreover, we validate our claims by introducing a method for semi-automatic extraction of a waveform template of an AES-128 encryption that can be used in combination with a template-matching triggering system. This extraction is based on generic meta information and is demonstrated on a consumer-grade ARM processor board.

Read the paper · More papers on PaperTik