By Eric Peeters

Advanced DPA idea and perform presents an intensive survey of recent actual leakages of embedded structures, particularly the facility and the electromagnetic emanations. The e-book provides a radical research approximately leakage beginning of embedded process. This ebook examines the systematic strategy of the various points and complicated information about experimental setup for electromagnetic assault. the writer discusses complex statistical how you can effectively assault embedded units akin to high-order assault, template assault in crucial subspaces, laptop studying tools. The booklet comprises theoretical framework to outline side-channel in response to metrics: mutual info and luck rate.

Extra resources for Advanced DPA Theory and Practice: Towards the Security Limits of Secure Embedded Circuits

It is illustrated in Fig. 3, where the charges/discharges of the load capacitance are clearly observable. 2 EM Emanations in CMOS Devices Current ICs are constituted of millions of transistors and interconnections in which data-dependent current flows. 5 8 time(s) 8 Fig. 2 PSPICE simulation. a Current in the NMOS and C L . 04 0 1 2 3 4 t 5 6 7 8 −7 Fig. 3 Experimental results on 74HC04 inverter. a CMOS inverter without C L . b CMOS inverter with C L = 10 p F ing charges are assumed to produce a variable magnetic field, which itself produces a variable electric field.

In parallel, [AARR02, GMO01, QS01] suggested using the electromagnetic emanations of microelectronic circuits as an alternative, and potentially more powerful, source of side-channel leakage. The approach was shown to provide significant advantages, both from the theoretical and practical points of view. For example, Agrawal et al. [AARR02] explained that electromagnetic emanations may be modulated by an inner loop structure and detailed that an adequate AM demodulator can be used to perform efficient attacks even a few meters away from the chip.

35 µm technology (see [62001]). As we will underline below the features of this PDN can be characterized and by inverting and applying its transfer function to the externally measured current, we succeed to observe the actual inner current. The whole measurement chain between the IC’s die and the oscilloscope can be modeled with the following elements: 1. Noise from the environment on the IC. 2. The PDN which can be much more complex than the simple one depicted below on the Fig. 5. 3. Noise from the environment on the probe.

