Exposing Data Value On a Risc-V Based SoC

Ezinam Bertrand Talaki, Mathieu Des Noes, Olivier Savry, David Hély, Simone Bacles-Min, Romain Lemaire · 2021

Performed usually with the aim of protecting cryptographic implementations, side-channel leakage assessment is progressively carried out on the micro-architecture elements of various circuits. Hamming Distance (HD) and Hamming Weight (HW) are widely used as leakage models for such analysis. In this paper, we present a study on how to retrieve the value of any data that is crossing the interconnect bus or stored in registers by using the power consumption of the circuit. We actually consider our recorded leakage to be the direct leakage of the value of the data as opposed to its Hamming weight or distance. We show that by using a divide and conquer approach including a template attack and an exhaustive search, a 32-bit data can be retrieved with a probability of 0.96 for 200 attack traces and a remaining research cost of 213.2. To achieve this goal, we first confirm and harness HW and HD leakage models on interconnect bus and registers of a RISC-V based ASIC SoC (28 nm bulk) through a template attack, and then we introduce a data value recovery attack on the interconnect bus.

Read the paper · More papers on PaperTik