Information-Theoretic Bounds on the Evaluation of Attacks
摘要
A fundamental question in side-channel analysis is how to characterize the concrete security level of the target cryptographic implementation in the presence of side-channel leakage. This is firstly the concern of security evaluators since they usually cannot enumerate side-channel attacks exhaustively within a given time period and costs. Secondly, the secure designers usually wonder how much security a given cryptographic implementation (or components) can ensure in practice. Thirdly, from the adversary’s perspective, they also wonder what are the potential outputs that the best attack may provide. In all those aspects, information-theoretic measures and coding-theoretic tools can be utilized effectively in establishing fundamental and generic bounds on side-channel attacks. This chapter builds a formal connection between attacks and information-theoretic metrics. The main goal is to provide some generic information-theoretic bounds that apply to any side-channel attack. In particular, we present generic bounds based on mutual information and \(\alpha \) -information for both unprotected and protected cryptographic devices. At last, we complete the information leakage quantification of CBM by providing attack-based evaluation results, which provide more explicit evidence that CBM is a promising approach in designing and constructing secure cryptographic implementations.