Side-channel Leakage Evaluator Using Device Simulator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for evaluating side-channel attacks (SCA) on cryptographic systems are cumbersome, requiring physical hardware, side-channel collection equipment, and expertise, and are prone to inconsistent results due to environmental and analytical variations, making it difficult to detect vulnerabilities in software-based countermeasures effectively.

Innovation Solution

A method and system that analyze SCA vulnerabilities by executing software applications on a device simulator, determining dependencies of simulated device components on secret inputs without requiring physical hardware or side-channel equipment, using a full system simulator to evaluate platform-specific interactions and compute vulnerability metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If penetration testing is used to evaluate SCA countermeasures, then the evaluation can be performed on actual systems, but the process requires expensive side-channel collection equipment, specialized tools, and expert knowledge

Engineering Contradiction:
Improveevaluation accuracyVSAvoidequipment and tool complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the target system using a device simulator that replicates the hardware architecture, instruction set, and execution behavior. This virtual model allows SCA evaluation to be performed on actual system behavior without requiring physical access to the target device or expensive side-channel collection equipment. The simulator produces virtual side-channel traces that mirror real hardware behavior, enabling reliable evaluation while eliminating the need for complex physical testing setups.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary layer consisting of the device simulator and analysis kit that mediates between the evaluator and the target system. This intermediary performs the side-channel analysis in software, translating the need for physical side-channel measurements into a virtualized process. The intermediary handles all complex operations including trace generation, preprocessing, and vulnerability detection, making the evaluation process accessible without expert knowledge while maintaining reliability through accurate simulation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If penetration testing is used to evaluate SCA countermeasures, then real vulnerabilities can be detected, but the results are inconsistent due to environmental conditions, tester skill, and equipment variations

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidresult consistency
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The device simulator creates a controlled virtual environment that copies the essential behavior of the target system without being affected by external environmental factors. By replicating the system's execution and side-channel behavior in software, the simulator eliminates variations caused by temperature, electromagnetic noise, and hardware aging that affect physical testing. This ensures that vulnerability detection results are consistent and reproducible across different evaluation sessions and environments.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The analysis kit performs automated vulnerability detection without requiring human expertise. The system automatically executes the evaluation algorithm, processes virtual traces, and generates vulnerability reports. This self-service capability eliminates the impact of tester skill and experience variations, ensuring that the same input always produces the same output, thereby improving result consistency while maintaining detection accuracy.

Inventive Principle:
Principle #25Self-service

3Reliability

If penetration testing is used to evaluate SCA countermeasures, then comprehensive system security can be assessed, but the process is time-consuming and cannot evaluate individual countermeasures in isolation

Engineering Contradiction:
Improvesecurity assessment completenessVSAvoidevaluation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables segmentation of the evaluation process by allowing assessors to target specific countermeasures, code regions, or security features independently. The device simulator can be configured to execute only relevant portions of the application, and the analysis kit can focus on specific vulnerability types or countermeasure effectiveness. This segmentation maintains comprehensive security assessment capability while dramatically reducing evaluation time by eliminating the need to test the entire system when only specific components need verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device simulator performs preliminary setup and configuration before the actual vulnerability assessment begins. The system pre-loads the target application, configures the virtual hardware environment, and prepares the analysis parameters in advance. This preliminary action allows the actual evaluation to proceed quickly once initiated, reducing the time loss associated with system setup and configuration during the assessment process.

Inventive Principle:
Principle #10Preliminary action

4Extent of automation

If software-based tools are used to evaluate SCA countermeasures, then the process can be automated, but existing tools require real side-channel traces and source code access

Engineering Contradiction:
Improveevaluation automationVSAvoidaccess requirements
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The device simulator generates virtual side-channel traces by copying the behavior of real hardware during application execution. These synthetic traces contain the same types of information as real traces (power consumption patterns, timing information, electromagnetic radiation characteristics) but are produced entirely in software. This copying approach eliminates the need for physical trace collection equipment and expert knowledge for trace generation, while maintaining the authenticity and utility of the traces for vulnerability detection.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10025926B2Side-channel leakage evaluator and analysis kit
Publication Date: 2018.07.17 THE MITRE CORPORATION
  • US10025926B2 patent drawing
  • US10025926B2 patent drawing
  • US10025926B2 patent drawing

AI summary

A method for analyzing side-channel leakage of an application running on a device including loading the application on a system comprising a device simulator, wherein the application is configured to accept public inputs and secret inputs and selecting a set of public inputs. The method includes, for each public input in the set of public inputs, executing the application on the system comprising the device simulator based on a respective public input and a first value for a secret input and extracting first intermediate values for the simulated device, and executing the application on the system based on the respective public input and a second value for the secret input and extracting second intermediate values for the simulated device. The method includes determining an amount of dependency of a location of the simulated device on the secret input based on a plurality of the first and second intermediate values.