Side-Channel Based Reverse Engineering of Secret Algorithms
Roman Novak, Jozef Stefan · 2003
Two techniques are introduced that enable sidechannel based reverse engineering of secret algorithms. The first is sign-extended differential power analysis (SDPA) while the second technique targets table lookups. The SDPA reveals values that collide with the DPA target value within the circuitry. The interpretation of those values can provide significant amounts of the information about the algorithm. The attack on substitution blocks may reveal contents of lookup tables. It is based on identifying equal intermediate results from power measurements. The techniques have been successfully tested in a demonstration attack on a secret authentication and session key generation algorithm implemented on SIM cards in GSM networks.