Mode‐Level Side‐Channel Countermeasures
Olivier Pereira, Thomas PETERS, François‐Xavier Standaert · 2025
Differential power analysis (DPA) attacks are powerful side-channel attacks that continuously leak information about the secret key. This chapter discusses some basic building blocks that offer improved security against leakage. It shows that it is possible to design leakage-resilient pseudo-random generators and pseudo-random functions based on block ciphers that only require security against a weaker form of side-channel attacks, namely, simple power analysis (SPA). The chapter discusses the models that are needed to analyze authentication and encryption in the presence of leakage, and their connection with concrete attacks such as SPA and DPA. It analyzes how these security definitions can be matched by actual authentication, encryption and authenticated encryption schemes. Mode-level countermeasures provide an interesting path toward leveled implementations, where different parts of a cryptographic construction require different levels of security against leakage and therefore different hardware-level or algorithmic countermeasures.