Stammdaten

Titel: A Critical Analysis of {ISO} 17825
Untertitel: Testing Methods for the Mitigation of Non-invasive Attack Classes Against Cryptographic Modules
Kurzfassung:

The ISO standardisation of ‘Testing methods for the mitigation of non-invasive attack classes against cryptographic modules’ (ISO/IEC 17825:2016) specifies the use of the Test Vector Leakage Assessment (TVLA) framework as the sole measure to assess whether or not an implementation of (symmetric) cryptography is vulnerable to differential side-channel attacks. It is the only publicly available standard of this kind, and the first side-channel assessment regime to exclusively rely on a TVLA instantiation.

TVLA essentially specifies statistical leakage detection tests with the aim of removing the burden of having to test against an ever increasing number of attack vectors. It offers the tantalising prospect of ‘conformance testing’: if a device passes TVLA, then, one is led to hope, the device would be secure against all (first-order) differential side-channel attacks.

In this paper we provide a statistical assessment of the specific instantiation of TVLA in this standard. This task leads us to inquire whether (or not) it is possible to assess the side-channel security of a device via leakage detection (TVLA) only. We find a number of grave issues in the standard and its adaptation of the original TVLA guidelines. We propose some innovations on existing methodologies and finish by giving recommendations for best practice and the responsible reporting of outcomes.

Schlagworte: Side-channel analysis; Leakage detection; Security certification; Statistical power analysis
Publikationstyp: Beitrag in Proceedings (Autorenschaft)
Erscheinungsdatum: 22.11.2019 (Online)
Erschienen in: ASIACRYPT 2019: Advances in Cryptology – ASIACRYPT 2019
ASIACRYPT 2019: Advances in Cryptology – ASIACRYPT 2019
zur Publikation
 ( )
Titel der Serie: Advances in Cryptology - {ASIACRYPT} 2019 - 25th International Conference on the Theory and Application of Cryptology and Information Security
Bandnummer: 11923
Erstveröffentlichung: Ja
Version: -
Seite: S. 256 - 284
Bild der Titelseite: Cover

Versionen

Keine Version vorhanden
Erscheinungsdatum: 22.11.2019
ISBN (e-book):
  • 978-3-030-34617-1
eISSN: -
DOI: http://dx.doi.org/10.1007/978-3-030-34618-8
Homepage: https://link.springer.com/book/10.1007%2F978-3-030-34618-8
Open Access
  • Online verfügbar (Open Access)

Zuordnung

Organisation Adresse
Fakultät für Technische Wissenschaften
 
Institut für Artificial Intelligence und Cybersecurity
Universitätsstr. 65-67
A-9020 Klagenfurt
Österreich
  -993705
   aics-office@aau.at
https://www.aau.at/en/aics/
zur Organisation
Universitätsstr. 65-67
AT - A-9020  Klagenfurt

Kategorisierung

Sachgebiete
  • 102016 - IT-Sicherheit
  • 102017 - Kryptologie
Forschungscluster
  • Humans in the Digital Age
Peer Reviewed
  • Ja
Publikationsfokus
  • Science to Science (Qualitätsindikator: I)
Klassifikationsraster der zugeordneten Organisationseinheiten:
Arbeitsgruppen
  • Cybersecurity

Kooperationen

Organisation Adresse
Bristol University
Tyndall Ave
BS Bristol
Großbrit. u. Nordirland
Tyndall Ave
GB - BS  Bristol

Beiträge der Publikation

Keine verknüpften Publikationen vorhanden