Exploring Leakage Characteristics and Attacks Through Profiles of Screaming Channels
摘要
Recent advancements have introduced screaming channels, a novel side channel where information leakages can propagate over extended distances. These developments have considerably threatened the design and security of particular mixed-signal chips. However, conventional research methods require extensive profiling prior to launching attacks, as the Hamming weight model is unsuitable for a screaming channel attack. Through the profiling conducted on BLE Nano V2, similar to previous studies, we observed that in tinyAES, the upper 4 bits of the S-box input exhibit leakage characteristics via the screaming channels. Based on these observations, we confirmed it is possible to recover keys for tinyAES by making assumptions that differ from simple Hamming weights, without relying entirely on comprehensive profiling. Using our leakage model, the executed attack demonstrated key recovery with fewer traces and less preparation than what is required for conventional profiled attacks. Additionally, we identified the specific conditions that allow the unique leakage characteristics of the screaming channels in tinyAES to emerge, based on our analysis of the assembly code.