Wei Cheng 0003

dblp:89/2506-3 · DBLP profile ↗
← Back
40ranked-venue papers
5as first author
33since 2021 · last 2026
0000-0001-9433-7576ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 18 · 1 first-author · 14 since 2021Security and privacy · 15 · 3 first-author · 12 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021Theory of computation · 3 · 3 since 2021
YearPublicationVenuePosition
2026 Rejection Matters: Efficient Non-Profiling Side-Channel Attack on ML-DSA via Exploiting Public Templates
abstract
ML-DSA (formerly CRYSTALS-Dilithium), NIST’s primary post-quantum signature standard, is increasingly deployed along with the post-quantum transitions. Yet when the implementations of ML-DSA are deployed in practice, their physical security remains underexplored. In this work, we reveal a new attack surface against ML-DSA by exploiting the leakages from both rejected signing trials and the final accepted signing trial. We present, to the best of our knowledge, the first side-channel attack that simultaneously leverages leakage from both trials without relying on clone devices. Unlike traditional Secret-based Template Attacks, which require profiling the leakage of the sensitive intermediates on a clone device, our PTA (Public-based Template Attack) builds leakage templates solely from publicly available data on the target device itself. With challenge c known, we then perform CPA on the sensitive intermediates using traces from both rejected and accepted signing trials, quadrupling (on average) exploitable leakage per signing request for ML-DSA-44. The experimental results on power traces from an ARM Cortex-M4 board show that challenges c are fully recovered with only 96 traces, and then the key recovery succeeds in around 300 traces — a fact of 10x fewer than prior art. We highlight that our attack can be applied across all three ML-DSA variants with different security levels. Moreover, our attack works straightforwardly in the hedged (non-deterministic) mode of ML-DSA, demonstrating that the hedging offers no SCA protection in this scenario.
Wei Cheng 0003, Zehua Qiao, Yuejun Liu, Yongbin Zhou
DATE2
2026 Memory-Optimized Masked CRYSTALS-Kyber Implementation on ARM Cortex-M4
Ruiqi Hou, Yiwen Gao 0001, Wei Cheng 0003, Yuejun Liu, Jingdian Ming, Yongbin Zhou
ICDCS3
2026 Deep Learning-based Public Template Attack against ML-DSA on ARM Microcontrollers
Zehua Qiao, Wei Cheng 0003, Yuejun Liu, Yongbin Zhou
ISCAS3
2026 Constructing optimal linear codes for code-based masking schemes of higher-orders
Jihao Fan, Wei Cheng 0003, Yongbin Zhou, Sylvain Guilley
Des. Codes Cryptogr.2
2026 VCAlign: An Effective Method for the Removal of Random Delays by Vertical Clustering
abstract
Random Delay Insertion (RDI) is one of the most investigated types ofhidingcountermeasure. Multifarious approaches to compromise RDI have emerged over the past two decades, with a horizontal perspective considering waveform segment as a unit. Interestingly in this paper, we transform such traditional perspective to a novel vertical one and find that the distribution feature of samples extracted vertically exposures the existence of delays directly, which can be exploited for both RDI detection and measurements alignment. On this basis, we conceive a generic approach calledVCAlign, leveraging binary classification to align the measurements sample by sample vertically. This approach favors adversaries significantly since it requires no reference trace, no prior knowledge, no profiling stage. As a case study, we further propose a practical paradigm and evaluate it on several RDI-protected implementations on an ARM Cortex-M4 micro-controller. The experimental results demonstrate that VCAlign has a powerful capability to eliminate the delays completely while remaining the encryption-related segments, which can be regarded as an enhanced alignment solution to conquer RDI. We firmly believe that VCAlign is a valid application of instruction effects on physical leakage from the novel vertical perspective that could bring new vitality to the alignment solutions.
Qianmei Wu, Chengdong Xie, Wei Cheng 0003, Fan Zhang 0010
IEEE Trans. Computers3
2025 CBM-TI: Code-Based Masking against Glitches by Hybridization with Threshold Implementation
abstract
Code-Based Masking (CBM) has been introduced to enhance high-order Boolean masking by increasing its resistance order via further decorrelating the coordinates of each symbol involved in the computation. Additionally, CBM enables cost amortization and fault detection. Notably, as demonstrated at CHES 2024, CBM facilitates the computation of provably masked operations under the Strong Non-Interference (SNI) security assumption with quasi-linear complexity. On the other hand, Threshold Implementation (TI) serves as an extension of Boolean masking, armoring it against combinational hazards. In this article, we show that merits of CBM and TI can be combined, paving the way to more secure hardware (high-order) masked implementations. We demonstrate CBM-TI, which is proven secure as well under SNI assumption and security when glitches worsen the leakage model.The security of CBM-TI is studied in a n-share setting, where n = 3 (minimal random splitting order required for TI). We analyzed CBM-TI in simulation and in real hardware (FPGA) to validate its security property. Leveraging high-order T-test leakage detection tool, we show that CBM-TI is endowed with higher-order security. Namely, TI leaks at order d = 3, whereas CBM-TI does not. We study several CBM-TI variants and show that the smallest leaking order of CBM-TI can be tuned to be as high as 7. This represents a significant progress over TI as each marginally improved order translates into exponentially more traces to attack the implementation.
Hasin Ishraq Reefat, Hossein Pourmehrani, Wei Cheng 0003, Claude Carlet, Abderrahman Daif, Cédric Tavernier, Sylvain Guilley, Naghmeh Karimi
VTS3
2025 Uncover Secrets Through the Cover: A Deep Learning-Based Side-Channel Attack Against Kyber Implementations With Anti-Tampering Covers
abstract
The probe can directly contact the microcontroller in a typical EM side-channel attack (SCA) targeting cryptographic implementations. However, in a more practical setting such as security level 2 of FIPS 140-3 or ISO/IEC 19790 standards, the microcontroller is required to be safeguarded by an opaque anti-tampering cover. This raises an interesting problem: Can we still launch EM attacks against microcontrollers running cryptographic implementations even when equipped with the cover? This paper proposes an improved deep-learning-based profiled attack against NIST KEM standard Kyber. Our key observation is that the distance between the probe and the microcontroller results in attenuation of signal strength. Moreover, the cover restricts the proximity of the probe, thereby limiting the signal-to-noise ratio. We propose an Adaptive Slimmed Pyramid Network (ASPN) model to instantiate a distinguisher in a plaintext-checking oracle-based SCA, which is generic and easy to implement. The proposed ASPN approach significantly enhances the feature extraction process by employing a pyramid network structure, while simultaneously avoiding the inclusion of excessive parameters. Real-world experiments demonstrate that our proposed distinguishers achieve an accuracy above$99\%$with an$18$mm cover and higher than$89\%$accuracy even with a$24$mm cover.
Jinnuo Li, Wei Cheng 0003, Chi Cheng 0003
IEEE Trans. Computers3
2025 Statistical Analysis of Non-Profiling Higher-Order Distinguishers Against Inner Product Masking
abstract
Inner Product Masking (IPM) is one representative masking scheme, which captivates by so-called Security Order Amplification (SOA) property. It is commonly recognized that SOA holds under linear leakages. In this paper, we revisit SOA from a non-profiling attack perspective. Specifically, we conduct statistical analyses on three non-profiling distinguishers, including Pearson Coefficient Distinguisher (PCD), Spearman Coefficient Distinguisher (SCD) and Kruskal-Wallis Distinguisher (KWD). We find a fundamental connection between SCD and KWD such that SCD is a more generic distinguisher which encompasses KWD. Theoretical explanations for why KWD outperforms SCD under non-linear leakages are provided. We also propose a new adjusted SCD and present its optimal form, which bridges the efficiency gap with KWD. Grounded on this, SOA is extensively assessed and the observations are two-fold. On the one hand, we confirm again the effectiveness of SOA under Hamming weight leakage through the statistical analysis of PCD. On the other hand, we show that SOA can not resist rank-based distinguishers even under linear leakages, which has never been revealed before (to the best of our knowledge). At last, we verify the theoretical findings through both simulated and real-world measurements. Our results demonstrate the advantage of rank-based distinguishers in uncovering non-linear relationships hidden in leakage, enriching the tool-set for non-profiling class of side-channel attacks. Remarkably, we provide an adversary perspective to investigate SOA, highlighting that the side-channel resistance promised by SOA is vulnerable even considering the ideal linear leakage models.
Qianmei Wu, Wei Cheng 0003, Fan Zhang 0010, Sylvain Guilley
IEEE Trans. Inf. Forensics Secur.2
2025 LD-PA: Distilling Univariate Leakage for Deep Learning-Based Profiling Attacks
abstract
The deep learning-based profiling attacks have received significant attention for their potential against masking-protected devices. Currently, additional capabilities like exploiting only a segment of the side-channel traces or having knowledge of the specific countermeasure scheme have been granted to attackers during the profiling phase. In case either capability is removed, a practical profiling attack faces great difficulty and complexity. To address this challenge, we propose an efficient and scheme-agnostic Leakage Distillation-based Profiling Attack (LD-PA). By distilling univariate leakage from a reference, we can train an encoder that extracts multivariate leakage from raw traces and transforms it into an effective representation (transitional leakage). An indirect connection between multivariate leakage and the target variable is established by bridging through the transitional leakage, thereby facilitating the inference of leaked values. Remarkably, LD-PA achieves successful attacks on multiple public datasets using a simple multilayer perceptron (MLP) without necessitating an exhaustive hyperparameter search, while its performance is competitive with state-of-the-art methods. Simultaneously, we delve into the nature of transitional leakage, confirming the existence of combined leakage. This, in turn, validates that the guidance from univariate leakage references aids in the combination of multivariate leakage. Besides that, each component of the multivariate leakage is extracted and stacked in a highly aligned manner. Moreover, we explored several factors impacting LD-PA performance, covering scenarios with limited profiling traces, noisy references, alternative references, and hyperparameter tuning.
Chong Xiao, Ming Tang 0002, Sengim Karayalcin, Wei Cheng 0003
IEEE Trans. Inf. Forensics Secur.4
2024 Formal Security Proofs via Doeblin Coefficients: - Optimal Side-Channel Factorization from Noisy Leakage to Random Probing
Julien Béguinot, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul
CRYPTO (6)2
2024 Improving Interpretability: Visual Analysis of Deep Learning-Based Multi-channel Attacks
Ziyue Shen, Yiwen Gao 0001, Wei Cheng 0003, Jiabei Wang, Yongbin Zhou
SecureComm (1)3
2024 Towards High-Quality Electromagnetic Leakage Acquisition in Side-Channel Analysis
abstract
Side-channel leakage acquisition plays a crucial role in side-channel analysis against cryptographic implementations, since it usually has a decisional impact on the security claims of the target devices. While most existing research has concentrated on power consumption acquisition settings, the exploration of electromagnetic (EM) radiation leakage acquisition remains limited and surprisingly under-discussed. In this study, we systematically investigate the parameter setting for EM leakage acquisition across two devices of different architectures. We specifically examine the effects of the amplifier, coupling mode, sampling rate, and EM probe on the quality of collected EM traces. For the first device STM32F405, our proposed optimal acquisition settings enhance the signal-to-noise ratio by a factor of 16 compared to the reference settings and reduce the number of EM traces required to achieve a success rate of 90% by a factor of 38. For the second device ATmega2560, the optimal settings improve the signal-to-noise ratio by a factor of 400 compared to the reference settings and reduce the number of EM traces required to achieve a success rate of 90% by a factor of 320. In summary, this work offers a comprehensive investigation into high-quality EM leakage acquisition. While some conclusions may be specific to certain devices, we believe that the proposed guidelines can be applied to EM trace acquisition in other devices as well.
Xiaoran Huang, Yiwen Gao 0001, Wei Cheng 0003, Yuejun Liu, Jingdian Ming, Yongbin Zhou, Jian Weng 0001
TrustCom3
2024 Towards Securing ASCON Implementation by Inner Product Masking
abstract
Ascon algorithm has been selected by NIST for standardization of the lightweight cryptography, that will be used in embedded systems, IoT devices, and other resource-constrained devices. As a lightweight cryptographic algorithm, Ascon implementation requires less computation and memory. However, the current implementations of Ascon algorithms and existing protection schemes are vulnerable to side-channel attacks. In this paper, we propose an IPM (inner product masking) based protection for Ascon implementations. Our new masking scheme can prevent side-channel attacks from successfully retrieving the key, even when the leakage levels are nearly identical. Alternatively, the cost of obtaining the key can increase by several orders of magnitude, making the attack significantly more challenging. The proposed scheme is experimentally validated by porting it into a STM32F407 microcontroller and conducting correlation power analysis (CPA) and template attack (TA) on the collected power traces. The experimental results show that while CPA can successfully retrieve the keys from both the unprotected Ascon implementation and the Boolean-masked Ascon implementation, they fail against the new masking scheme. Although TA attacks can break the new scheme, they require approximately 50 times more data compared to attacking the Boolean mask. This demonstrates that the new masking scheme offers significantly greater security than both the Boolean mask and the unprotected implementations.
Wei Cheng 0003, Jihao Fan, Yongbin Zhou
TrustCom2
2024 Attacking High-order Masked Cryptosystem via Deep Learning-based Side-Channel Analysis
abstract
Masking is widely considered as an effective countermeasure against side-channel analysis (SCA) due to its provable security and efficiency. However, recent works have demonstrated that the deep learning-based SCA (DL-SCA) can effectively break the cryptographic implementations protected by the first-order Boolean maskings. Still, it is open whether higher-order masking can resist DL-SCA. In this work, we demonstrate that deep learning methods can also effectively exploit the inherent leakage of higher-order Boolean masking to compromise its security. Furthermore, we employed neural weight visualization techniques to demonstrate the neural network’s capability to extract high-level features. We assess the efficiency of this novel profiling attack in both simulated and real-world scenarios. In particular, our results show that DL-SCA can effectively break the higher-order Boolean masking schemes up to the sixth and the third order in simulated and real-world cases, respectively. Furthermore, we find that using plaintext-related leakage can significantly improve the effectiveness of side-channel attacks.
Zelong Zhang, Wei Cheng 0003, Yongbin Zhou, Zehua Qiao, Jian Weng 0001
TrustCom2
2024 Multi-modal Pre-silicon Evaluation of Hardware Masking Styles
abstract
Abstract Protecting sensitive logic functions in ASICs requires side-channel countermeasures. Many gate-level masking styles have been published, each with pros and cons. Some styles such as RSM, GLUT, and ISW are compact but can feature 1st-order leakage. Some other styles, such as TI, DOM, and HPC are secure at the 1st-order but incur significant overheads in terms of performance. Another requirement is that security shall be ensured even when the device is aged. Pre-silicon security evaluation is now a normatively approved method to characterize the expected resiliency against attacks ahead of time. However, in this regard, there is still a fragmentation in terms of leakage models, Points of Interest (PoI) selection, attack order, and distinguishers. Accordingly, in this paper we focus on such factors as they affect the success of side-channel analysis attacks and assess the resiliency of the state-of-the-art masking styles in various corners. Moreover, we investigate the impact of device aging as another factor and analyze its influence on the success of side-channel attacks targeting the state-of-the-art masking schemes. This pragmatic evaluation enables risk estimation in a complex PPA (Power, Performance, and Area) and security plane while also considering aging impacts into account. For instance, we explore the trade-off between low-cost secure styles attackable at 1st-order vs high-cost protection attackable only at 2nd-order.
Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Wei Cheng 0003, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
J. Electron. Test.3
2024 Statistical Higher-Order Correlation Attacks Against Code-Based Masking
abstract
Masking is one of the most well-established methods to thwart side-channel attacks. Many masking schemes have been proposed in the literature, and code-based masking emerges and unifies several masking schemes in a coding-theoretic framework. In this work, we investigate the side-channel resistance of code-based masking from a non-profiling perspective by utilizing correlation-based side-channel attacks. We present a systematic evaluation of correlation attacks with various higher-order (centered) moments and then present the form of optimal correlation attacks. Interestingly, the Pearson correlation coefficient between the hypothetical leakage and the measured traces is connected to the signal-to-noise ratio in higher-order moments, and it turns out to be easy to evaluate rather than launch repeated attacks. We also identify some ineffective higher-order correlation attacks at certain orders when the device leaks under the Hamming weight leakage model. Our theoretical findings are verified through both simulated and real-world measurements.
Wei Cheng 0003, Jingdian Ming, Sylvain Guilley, Jean-Luc Danger
IEEE Trans. Computers1
2023 Table Re-Computation Based Low Entropy Inner Product Masking Scheme
abstract
is a popular countermeasure due to its provable security. Table re-computation based Boolean masking (BM) is efficient at small masking share number, and addition chain based inner product masking (IPM) provides higher security order than BM. As a result, the natural question is: can we design a masking scheme that costs close to that of re-computation based BM while providing security comparable to that of addition chain based IPM? In this paper, we propose a table re-computation based IPM scheme that provides 3rd-order security while being slightly more expensive than table re-computation based BM. Furthermore, we improve the side-channel security of IPM by randomly selecting the parameter$L$from an elaborated low entropy set, which we call low entropy inner product masking (LE-IPM). In an Intel Core i7-4790 CPU and ARM Cortex M4 based MCU for AES, we implemented four masking schemes, namely the addition chain based IPM and table re-computation based BM, IPM, and LE-IPM. Our proposals perform slightly slower (by about 0.8 times) than table re-computation based BM but significantly faster (at least 30 times) than addition chain based IPM. Furthermore, we assess the security of our proposals using a standard method named test vector leakage assessment methodology (TVLA). Our proposals provide the expected security against side-channel attacks according to the evaluation.
Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li
DATE3
2023 Maximal Leakage of Masked Implementations Using Mrs. Gerber's Lemma for Min-Entropy
abstract
A common countermeasure against side-channel attacks on secret key cryptographic implementations is $d$ thorder masking, which splits each sensitive variable into $d + 1$ random shares. In this paper, maximal leakage bounds on the probability of success of any side-channel attack are derived for any masking order. Maximal leakage (Sibson's information of order infinity) is evaluated between the sensitive variable and the noisy leakage, and is related to the conditional "min-entropy" (Arimoto's entropy of order infinity) of the sensitive variable given the leakage. The latter conditional entropy is then lower-bounded in terms of the conditional entropies for each share using majorization inequalities. This yields a generalization of Mrs. Gerber's lemma for min-entropy in finite Abelian groups.
Julien Béguinot, Yi Liu 0066, Olivier Rioul, Wei Cheng 0003, Sylvain Guilley
ISIT4
2023 Improved Alpha-Information Bounds for Higher-Order Masked Cryptographic Implementations
abstract
Embedded cryptographic devices are usually protected against side-channel attacks by masking strategies. In this paper, the security of protected cryptographic implementations is evaluated for any masking order, using alpha-information measures. Universal upper bounds on the probability of success of any type of side-channel attack are derived. These also provide lower bounds on the minimum number of queries required to achieve a given success rate. An important issue, solved in this paper, is to remove the loss factor due to the masking field size.
Yi Liu 0066, Julien Béguinot, Wei Cheng 0003, Sylvain Guilley, Loïc Masure, Olivier Rioul, François-Xavier Standaert
ITW3
2023 Self-dual bent sequences for complex Hadamard matrices
Minjia Shi, Yaya Li, Wei Cheng 0003, Dean Crnkovic, Denis S. Krotov, Patrick Solé
Des. Codes Cryptogr.3
2022 Be My Guess: Guessing Entropy vs. Success Rate for Evaluating Side-Channel Attacks of Secure Chips
abstract
In a theoretical context of side-channel attacks, optimal bounds between success rate and guessing entropy are derived with a simple majorization (Schur-concavity) argument. They are further theoretically refined for different versions of the classical Hamming weight leakage model, in particular assuming a priori equiprobable secret keys and additive white Gaussian measurement noise. Closed-form expressions and numerical computation are given. A study of the impact of the choice of the substitution box with respect to side-channel resistance reveals that its nonlinearity tends to homogenize the expressivity of success rate and guessing entropy. The intriguing approximate relation$GE=1/SR$is observed in the case of 8-bit bytes and low noise.
Julien Béguinot, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul
DSD2
2022 Attacking Masked Cryptographic Implementations: Information-Theoretic Bounds
abstract
Measuring the information leakage is critical for evaluating the practical security of cryptographic devices against side-channel analysis. Information-theoretic measures can be used (along with Fano’s inequality) to derive upper bounds on the success rate of any possible attack in terms of the number of side-channel measurements. Equivalently, this gives lower bounds on the number of queries for a given success probability of attack. In this paper, we consider cryptographic implementations protected by (first-order) masking schemes, and derive several information-theoretic bounds on the efficiency of any (second-order) attack. The obtained bounds are generic in that they do not depend on a specific attack but only on the leakage and masking models, through the mutual information between side-channel measurements and the secret key. Numerical evaluations confirm that our bounds reflect the practical performance of optimal maximum likelihood attacks.
Wei Cheng 0003, Yi Liu 0066, Sylvain Guilley, Olivier Rioul
ISIT1
2022 Cross-PUF Attacks: Targeting FPGA Implementation of Arbiter-PUFs
Trevor Kroeger, Wei Cheng 0003, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
J. Electron. Test.2
2022 Information Leakage in Code-Based Masking: A Systematic Evaluation by Higher-Order Attacks
abstract
Code-based masking is a recent line of research on masking schemes aiming at provably counteracting side-channel attacks. It generalizes and unifies many masking schemes within a coding-theoretic formalization. In code-based masking schemes, the tuning parameters are the underlying linear codes, whose choice significantly affects the side-channel resilience. In this paper, we investigate the exploitability of the information leakage in code-based masking and present attack-based evaluation results of higher-order optimal distinguisher (HOOD). Particularly, we consider two representative instances of code-based masking, namely inner product masking (IPM) and Shamir’s secret sharing (SSS) based masking. Our results do confirm the state-of-the-art theoretical derivatives in an empirical manner with numerically simulated measurements. Specifically, theoretical results are based on quantifying information leakage; we further complete the panorama with attack-based evaluations by investigating the exploitability of the leakage. Moreover, we classify all possible candidates of linear codes in IPM with 2 and 3 shares and (3, 1)-SSS based masking, and highlight both optimal and worst codes for them. Relying on our empirical evaluations, we therefore recommend investigating the coding-theoretic properties to find the best linear codes in strengthening instances of code-based masking. As for applications, our attack-based evaluation directly empowers designers, by employing optimal linear codes, to enhance the protection of code-based masking. Our framework leverages simulated leakage traces, hence allowing for source code validation or patching in case it is found to be attackable.
Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger
IEEE Trans. Inf. Forensics Secur.1
2022 Optimizing Higher-Order Correlation Analysis Against Inner Product Masking Scheme
abstract
In recent years, inner product masking (IPM) has been proposed as a promising code based masking scheme against side-channel attacks. However, most studies mainly focus on leakages in terms of information-theoretic metrics, and simulated experiments utilizing profiled attacks (with known templates). In this paper, we investigate the security of IPM scheme against one typical non-profiled side-channel attack, namely higher-order correlation analysis. We demonstrate that three factors mainly influence the efficiency of higher-order correlation analysis against IPM, and they are the attack order vector, output size of the target function and attack model. In particular, we propose a new method to measure the efficiency of higher-order correlation analyses. Generally speaking, this method is based on the correlation coefficient between leakage expectations with certain shares and sensitive values under the attack model. We validate our method by both simulation-based experiments and practical one with different attack factors. All experiments are running on the IPM in the different noise scenarios. The results demonstrate that our method works well as an indicator for higher-order correlation analyses against IPM.
Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li
IEEE Trans. Inf. Forensics Secur.3
2022 Assessment and Mitigation of Power Side-Channel-Based Cross-PUF Attacks on Arbiter-PUFs and Their Derivatives
abstract
Unintentional uncontrollable variations in the manufacturing process of integrated circuits are used to realize silicon primitives known as physical unclonable functions (PUFs). These primitives are used to create unique signatures for security purposes. Investigating the vulnerabilities of PUFs is of utmost importance to uphold their usefulness in secure applications. One such investigation includes exploring the susceptibility of PUFs to modeling attacks that aim at extracting the PUFs’ behavior. To date, these attacks have mainly focused on a single PUF instance where the targeted PUF is attacked using the model built based on the very same PUF’s challenge–response pairs or power side channel. In this article, we move one step forward and introduceCross-PUFattacks where a model is created using the power consumption of one PUF instance to attack another PUF created from the same GDSII file. Through SPICE simulations, we show that these attacks are highly effective in modeling PUF behaviors even in the presence of noise and mismatches in temperature and aging of the PUF used for modeling versus the targeted PUF. To mitigate theCross-PUFattacks, we then propose a lightweight countermeasure based on dual-rail and random initialization logic approaches called DRILL. We show that DRILL is highly effective in thwartingCross-PUFattacks.
Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi
IEEE Trans. Very Large Scale Integr. Syst.2
2021 Making Obfuscated PUFs Secure Against Power Side-Channel Based Modeling Attacks
abstract
To enhance the security of digital circuits, there is often a desire to dynamically generate, rather than statically store, random values used for identification and authentication purposes. Physically Unclonable Functions (PUFs) provide the means to realize this feature in an efficient and reliable way by utilizing commonly overlooked process variations that unintentionally occur during the manufacturing of integrated circuits (ICs) due to the imperfection of fabrication process. When given a challenge, PUFs produce a unique response. However, PUFs have been found to be vulnerable to modeling attacks where by using a set of collected challenge response pairs (CRPs) and training a machine learning model, the response can be predicted for unseen challenges. To combat this vulnerability, researchers have proposed techniques such as Challenge Obfuscation. However, as shown in this paper, this technique can be compromised via modeling the PUF's power side-channel. We first show the vulnerability of a state-of-the-art Challenge Obfuscated PUF (CO-PUF) against power analysis attacks by presenting our attack results on the targeted CO-PUF. Then we propose two countermeasures, as well as their hybrid version, that when applied to the CO-PUFs make them resilient against power side-channel based modeling attacks. We also provide some insights on the proper design metrics required to be taken when implementing these mitigations. Our simulation results show the high success of our attack in compromising the original Challenge Obfuscated PUFs (success rate > 98%) as well as the significant improvement on resilience of the obfuscated PUFs against power side-channel based modeling when equipped with our countermeasures.
Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi
DATE2
2021 APT: Efficient Side-Channel Analysis Framework against Inner Product Masking Scheme
abstract
Due to its provable security and remarkable device-independence, masking has been widely accepted as a good algorithmic-level countermeasure against side-channel attacks. Subsequently, several code-based masking schemes are proposed to strengthen the original Boolean masking (BM) scheme, and Inner Product Masking (IPM) scheme is typically one of those. In this paper, we provide a framework, named analysis with predicted template (APT), for side-channel analysis against the IPM scheme. Following this framework, we propose two attacks based on maximum likelihood and Euclidean distance, respectively. To evaluate their efficiency, we perform simulated experiments on first-order BM and an optimal IPM scheme. The results show that our proposals are equivalent to a second-order CPA against BM scheme, but they are significantly efficient against an optimal IPM. In practical experiments based on an ARM Cortex-M4 architecture, the results of our proposals do not turn out well because of a few outliers in collected leakages. After filtering out these outliers, our proposals perform efficiently as expected. Finally, we argue that the side-channel security of IPM can be improved by keeping the vector L to be randomly selected from an elaborated small set.
Jingdian Ming, Wei Cheng 0003, Yongbin Zhou, Huizhong Li
ICCD2
2021 Cumulant Expansion of Mutual Information for Quantifying Leakage of a Protected Secret
abstract
The information leakage of a cryptographic implementation with a given degree of protection is evaluated in a typical situation when the signal-to-noise ratio is small. This is solved by expanding Kullback-Leibler divergence, entropy, and mutual information in terms of moments/cumulants.
Olivier Rioul, Wei Cheng 0003, Sylvain Guilley
ISIT2
2021 Bent Sequences over Hadamard Codes for Physically Unclonable Functions
abstract
We study challenge codes for physically unclonable functions (PUFs). Starting from the classical Hadamard challenge code, we augment it by one vector. Numerical values suggest that the optimal choice of this vector for maximizing the entropy is to pick a vector the farthest away from the code formed by the challenges and their binary complements. This leads us to study the covering radius of Hadamard codes. A notion of bent sequence that generalizes the classical notion from Hadamard matrices of Sylvester type to general Hadamard matrices is given. Lower bounds for Paley-type Hadamard matrices are given.
Patrick Solé, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul
ISIT2
2021 On Conditional Alpha-Information and its Application to Side-Channel Analysis
abstract
A conditional version of Sibson’s $\alpha$-information is defined using a simple closed-form “log-expectation” expression, which satisfies important properties such as consistency, uniform expansion, and data processing inequalities. This definition is compared to previous ones, which in contrast do not satisfy all of these properties. Based on our proposal and on a generalized Fano inequality, we extend the case $\alpha=1$ of previous works to obtain sharp universal upper bounds for the probability of success of any type side-channel attack, particularly when $\alpha=2$.
Yi Liu 0066, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul
ITW2
2021 Linear Programming Bounds on the Kissing Number of q-ary Codes
abstract
We use linear programming (LP) to derive upper and lower bounds on the “kissing number” $A_{d}$ of any q-ary linear code C with distance distribution frequencies $A_{i}$, in terms of the given parameters $[n,\ k,\ d]$. In particular, a polynomial method gives explicit analytic bounds in a certain range of parameters, which are sharp for some low-rate codes like the first-order Reed-Muller codes. The general LP bounds are more suited to numerical estimates. Besides the classical estimation of the probability of decoding error and of undetected error, we outline recent applications in hardware protection against side-channel attacks using code-based masking countermeasures, where the protection is all the more efficient a s the kissing number is low.
Patrick Solé, Yi Liu 0066, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul
ITW3
2021 Optimizing Inner Product Masking Scheme by a Coding Theory Approach
abstract
Masking is one of the most popular countermeasures to protect cryptographic implementations against side-channel analysis since it is provably secure and can be deployed at the algorithm level. To strengthen the original Boolean masking scheme, several works have suggested using schemes with high algebraic complexity. The Inner Product Masking (IPM) is one of those. In this paper, we propose a unified framework to quantitatively assess the side-channel security of the IPM in a coding-theoretic approach. Specifically, starting from the expression of IPM in a coded form, we use two defining parameters of the code to characterize its side-channel resistance. In order to validate the framework, we then connect it to two leakage metrics (namely signal-to-noise ratio and mutual information, from an information-theoretic aspect) and one typical attack metric (success rate, from a practical aspect) to build a firm foundation for our framework. As an application, our results provide ultimate explanations on the observations made by Balasch et al. at EUROCRYPT'15 and at ASIACRYPT'17, Wang et al. at CARDIS'16 and Poussier et al. at CARDIS'17 regarding the parameter effects in IPM, like higher security order in bounded moment model. Furthermore, we show how to systematically choose optimal codes (in the sense of a concrete security level) to optimize IPM by using this framework. Eventually, we present a simple but effective algorithm for choosing optimal codes for IPM, which is of special interest for designers when selecting optimal parameters for IPM.
Wei Cheng 0003, Sylvain Guilley, Claude Carlet, Sihem Mesnager, Jean-Luc Danger
IEEE Trans. Inf. Forensics Secur.1
2020 Effect of Aging on PUF Modeling Attacks based on Power Side-Channel Observations
abstract
Thanks to the imperfections in manufacturing process, Physically Unclonable Functions (PUFs) produce their unique outputs for given input signals (challenges) fed to identical circuitry designs. PUFs are often used as hardware primitives to provide security, e.g., for key generation or authentication purposes. However, they can be vulnerable to modeling attacks that predict the output for an unknown challenge, based on a set of known challenge/response pairs (CRPs). In addition, an attacker may benefit from power side-channels to break a PUFs' security. Although such attacks have been extensively discussed in literature, the effect of device aging on the efficacy of these attacks is still an open question. Accordingly, in this paper, we focus on the impact of aging on Arbiter-PUFs and one of its modeling-resistant counterparts, the Voltage Transfer Characteristic (VTC) PUF. We present the results of our SPICE simulations used to perform modeling attack via Machine Learning (ML) schemes on the devices aged from 0 to 20 weeks. We show that aging has a significant impact on modeling attacks. Indeed, when the training dataset for ML attack is extracted at a different age than the evaluation dataset, the attack is greatly hindered despite being performed on the same device. We show that the ML attack via power traces is particularly efficient to recover the responses of the anti-modeling VTC PUF, yet aging still contributes to enhance its security.
Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi
DATE2
2020 Cross-PUF Attacks on Arbiter-PUFs through their Power Side-Channel
abstract
The silicon primitives known as Physically Unclonable Functions (PUFs) are used for various security purposes including key generation, device authentication, etc. Due to the imperfections in manufacturing process, PUFs produce their unique outputs (responses) for given input signals (challenges) fed to identical circuitry designs. Although PUFs are deployed to preserve security and are assumed to be unclonable, their functionality may still be compromised by modeling attacks. However, such attacks only target one single PUF aiming at reversing its behavior (based on a subset of its challenge-response pairs), and are not useful for attacking other PUFs. Moreover a subset of the target PUF's response has to be known by the attacker. This paper moves one step forward and investigates the possibility of Cross-PUF attacks in which a particular PUF's power fingerprints can be used to break another PUF's security. In these Cross-PUF attacks, the attacker has at his disposal a reference PUF, and uses its power side-channel to train a machine learning model which can be deployed to attack other identical PUFs. The experimental results show the high success of the proposed attacks even in presence of noise and temperature differences between the target PUF and the one used to train the model. We target arbiter-PUFs but we deduce that the findings extend to all its derivatives, e.g., XOR-PUFs and Feed-Forward-PUFs.
Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi
ITC2
2020 Efficient electro-magnetic analysis of a GPU bitsliced AES implementation
abstract
Abstract The advent of CUDA-enabled GPU makes it possible to provide cloud applications with high-performance data security services. Unfortunately, recent studies have shown that GPU-based applications are also susceptible to side-channel attacks. These published work studied the side-channel vulnerabilities of GPU-based AES implementations by taking the advantage of the cache sharing among multiple threads or high parallelism of GPUs. Therefore, for GPU-based bitsliced cryptographic implementations, which are immune to the cache-based attacks referred to above, only a power analysis method based on the high-parallelism of GPUs may be effective. However, the leakage model used in the power analysis is not efficient at all in practice. In light of this, we investigate electro-magnetic (EM) side-channel vulnerabilities of a GPU-based bitsliced AES implementation from the perspective of bit-level parallelism and thread-level parallelism in order to make the best of the localization effect of EM leakage with parallelism. Specifically, we propose efficient multi-bit and multi-thread combinational analysis techniques based on the intrinsic properties of bitsliced ciphers and the effect of multi-thread parallelism of GPUs, respectively. The experimental result shows that the proposed combinational analysis methods perform better than non-combinational and intuitive ones. Our research suggests that multi-thread leakages can be used to improve attacks if the multi-thread leakages are not synchronous in the time domain.
Yiwen Gao 0001, Yongbin Zhou, Wei Cheng 0003
Cybersecur.3
2020 Mind the Balance: Revealing the Vulnerabilities in Low Entropy Masking Schemes
abstract
Low Entropy Masking Schemes (LEMS) have attracted wide attention due to their implementations simplicity and relatively good performance in protecting cryptographic implementations against Side-Channel-Attacks (SCAs). To achieve desired security, it is necessary (but not sufficient) to find proper low entropy mask sets to protect all sensitive secret-dependant intermediate variables. However, one crucial problem concerning this intuitive idea is that what `proper' mask sets should be. To formally capture such crucial qualification, we introduce the notion of balancedness to characterize this natural attribute of mask sets themselves. Considering that this notion is limited to characterize first-order security, we generalize it to d-dimension balancedness to accommodate dth-order security, then we exhibit lower and upper bounds on d-dimension balancedness for any d. With the help of these essential definitions, we prove that no balanced low entropy mask set really exists, which implies that LEMS implementations always have vulnerabilities in theory due to the unbalancedness of underlying mask sets. In order to further demonstrate the practical implications of balancedness, we show 4 different kinds of attacks on three state-of-the-art LEMS implementations. Specifically, the distribution attack proposed in this paper is a general first-order attack on LEMS. The results demonstrate that unbalanced mask sets actually do lead to serious vulnerabilities.
Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li, Guang Yang 0042, Qian Zhang 0042
IEEE Trans. Inf. Forensics Secur.3
2018 Electro-magnetic analysis of GPU-based AES implementation
abstract
In this work, for the first time, we investigate Electro-Magnetic (EM) attacks on GPU-based AES implementation. In detail, we first sample EM traces using a delicate trigger; then, we build a heuristic leakage model and a novel leakage model to exploit the simultaneous EM leakages in parallel scenarios. After that, we evaluate the effectiveness of EM attacks on GPU-based AES implementation. Our evaluation results show that GPU-based AES implementation is vulnerable to EM attacks. This work also suggests that GPU-based AES implementation needs to be protected against EM attacks in real scenarios.
Yiwen Gao 0001, Hailong Zhang 0001, Wei Cheng 0003, Yongbin Zhou, Yuchen Cao 0002
DAC3
2018 A Compact AES Hardware Implementation Secure Against 1st-Order Side-Channel Attacks
abstract
Efficient cryptographic implementations with desired side-channel attacks (SCA) resistance are highly required, especially for those resources-constrained devices. In this paper, we propose a very compact AES hardware implementation scheme provably secure against 1st-order SCAs. Basically, our scheme is inspired by ideas of Redundant Tower Field (RTF for short) circuit due to Ueno et al. and of private circuits due to Ishai, Sahai and Wagner (ISW for short), and is therefore named ISW-RTF. In terms of security, practical attacks on real leakages from prototype implementation show that ISW-RTF scheme is secure against 1st-order attacks and 2nd-order zero-offset attacks as well. Results of t-test leakage detection of these leakages also verify this observation. In terms of efficiency, compared with the state-of-the-art 1st-order masking scheme, our scheme outperforms at least 55.08% decreases in area, and 34.87% decreases in area-time product on three popular FPGA/ASIC devices. To the best of our knowledge, the proposed ISW-RTF scheme is the most compact one provably secure against SCA.
Qian Zhang 0042, Yongbin Zhou, Shuang Qiu 0004, Wei Cheng 0003, Jingdian Ming, Rui Zhang 0002
ICCD4
2016 Differential Fault Analysis on Midori
Wei Cheng 0003, Yongbin Zhou, Laurent Sauvage
ICICS1