A Tale of Resilience: On the Practical Security of Masked Software Implementations
Lorenzo Casalino, Nicolas Belleville, Damien Couroussé, Karine Heydemann · IEEE Access · 2023
Masking constitutes a provably-secure approach against side-channel attacks. However,recombination effects(e.g., transitions) severely reduce the proven security. Concerning the software domain, CPU microarchitectures encompass techniques improving the execution performances. Several studies show that such techniques induce recombination effects. Furthermore, these techniques implicitly induce some form of parallelism, and the potential associated threat has never been investigated. In addition, thepracticalsecurity of masking relies on the chosen masking scheme. Few works analysed the security of software protected by different masking schemes, and none considered the parallelism threat. Thus, literature lacks of a more comprehensive investigation on thepracticalsecurity of software implementations relying on various masking schemes in presence of micro-architecture-induced recombination effects and parallelism. This work performs a first step to fill this gap. Specifically, we evaluate the practical security offered by first-orderboolean,arithmetic-sumandinner-productmasking against transitions and parallelism in software. We firstly assess the presence of transition and parallel-induced leakages in software. Secondly, we evaluate the security of the encodings of the selected masking schemes with respect to each leakage source via micro-benchmarks. Thirdly, we assess the practical security of different AES-128 software implementations, one for each selected masking scheme. We lead the investigation on the STM32F215 and STM32F303 micro-controllers. We show that (1) CPU’s parallel features allow successful attacks against transition-resistant masked implementations; (2) implementation choices (e.g., finite field multiplication) impact on the practical security of masked software implementations in presence of recombination effects.