Logo image
SNOW-SCA: ML-assisted Side-Channel Attack on SNOW-V
Conference proceeding   Open access   Peer reviewed

SNOW-SCA: ML-assisted Side-Channel Attack on SNOW-V

Harshit Saurabh, Anupam Golder, Samarth Shivakumar Titti, Suparna Kundu, Chaoyun Li, Angshuman Karmakar and Debayan Das
2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), pp.139-149
IEEE International Workshop on Hardware Oriented Security and Trust
2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) (Tysons Corner, VA, USA, 06/05/2024–09/05/2024)
06/06/2024

Abstract

Index Terms—SNOW-V, Side-Channel Analysis (SCA), Cor- relation Power Attack (CPA), Linear Feedback Shift Registers (LFSR), Linear Discriminant Analysis (LDA), Countermeasures
—This paper presents SNOW-SCA, the first power side-channel analysis (SCA) attack of a 5G mobile communication security standard candidate, SNOW-V, running on a 32-bit ARM Cortex-M4 microcontroller. First, we perform a generic known-key correlation (KKC) analysis to identify the leakage points. Next, a correlation power analysis (CPA) attack is performed, which reduces the attack complexity to two key guesses for each key byte. The correct secret key is then uniquely identified utilizing linear discriminant analysis (LDA). The profiled SCA attack with LDA achieves 100% accuracy after training with < 200 traces, which means the attack succeeds with just a single trace. Overall, using the combined CPA and LDA attack model, the correct secret key byte is recovered with < 50 traces collected using the ChipWhisperer platform. The entire 256-bit secret key of SNOW-V can be recovered incrementally using the proposed SCA attack. Finally, we suggest low-overhead countermeasures that can be used to prevent these SCA attacks.
pdf
2024-4281.64 MBDownloadView
Author's Accepted Manuscript Open Access CC BY V4.0

Metrics

842 File views/ downloads
41 Record Views

Details

Logo image

Usage Policy