Quantities to Judge Side Channel Resilience
Elisabeth Oswald · 2025
Evaluations in the context of side-channel attacks can take different forms, depending on the intended outcomes. This chapter reviews the most widely used metrics which are used within informal and formal evaluation schemes. It starts by utilizing intuitive ways to judge the quality of concrete attack vectors, which will bring us naturally to the concept of the key rank (and thereby judging the remaining effort of an adversary). Thereafter, the chapter reviews how to compute (independently of an attack vector) how much an implementation leaks, and contrast this with the concept of leakage detection, which is to decide whether there is leakage (or not) without performing attacks. During the evaluation process, sponsors must state the envisioned security level (EAL). The EAL indicates a minimal level for requirements for each subclass (development process, guidance, conformity of security target, vulnerability assessment, etc.) that will be taken into account during the evaluation.