SPA Analysis
Simple Power Analysis (SPA)¶
Simple Power Analysis (SPA) is a foundational side-channel attack technique that leverages variations in a device’s power consumption during cryptographic operations to infer sensitive information, such as cryptographic keys. Unlike more complex methods like Differential Power Analysis (DPA), SPA requires no statistical processing of multiple traces. Instead, it relies on direct observation of power consumption patterns during deterministic operations, making it a practical entry point for understanding side-channel vulnerabilities.
Principles of Simple Power Analysis¶
In cryptographic operations (e.g., AES, RSA), power consumption varies based on the operations performed. For example, each round of AES involves specific computations (e.g., SubBytes, ShiftRows) that draw distinct power signatures. An attacker captures these power traces and correlates them with the algorithm’s execution steps. By analyzing the timing and magnitude of power spikes, the attacker can deduce key-dependent operations, such as the value of individual key bits.
For instance, during AES decryption, the SubBytes step involves non-linear S-box lookups. If the attacker observes a consistent power spike during this step, they can infer the input byte and, through iterative analysis, reconstruct the key.
Tools and Setup¶
To perform SPA, you need:
- Power measurement equipment: A high-resolution oscilloscope or power meter (e.g., Siglent SDS1202X-E, Keysight 33500A).
- Target device: A device executing cryptographic operations (e.g., a microcontroller running AES).
- Software: Tools for capturing and analyzing traces (e.g., Python with matplotlib, ScopeFlash, or GNU Radio).
Example setup command (hypothetical tool):
Execution Workflow¶
- Capture power traces: Monitor the device’s power consumption during cryptographic operations (e.g., encrypting a known plaintext).
- Align traces with algorithm steps: Synchronize the power traces with the cryptographic algorithm’s execution (e.g., AES rounds).
- Identify key-dependent patterns: Look for unique power signatures correlated with specific operations (e.g., key scheduling, data-dependent computations).
Example Python script for trace analysis:
import matplotlib.pyplot as plt
import numpy as np
# Load captured trace data
trace_data = np.fromfile('trace_1.bin', dtype=np.int16)
# Plot the trace
plt.figure(figsize=(12, 4))
plt.plot(trace_data)
plt.title("Power Trace During AES Encryption")
plt.xlabel("Sample Index")
plt.ylabel("Power Consumption (mV)")
plt.grid(True)
plt.show()
Analysis and Key Extraction¶
Once traces are captured, the attacker identifies correlations between power spikes and key-dependent operations. For example: - A power spike at a specific time may indicate a particular S-box lookup. - The amplitude of the spike may reflect the value of a key bit (e.g., higher consumption for a 1 bit).
By isolating these patterns, the attacker can deduce the key. This process often requires multiple traces and manual inspection, but it can yield results with sufficient signal-to-noise ratio.
Mitigations and Countermeasures¶
To defend against SPA: - Masking: Use secret-sharing techniques to obscure key-dependent operations. - Shuffling: Randomize the order of cryptographic operations to disrupt pattern correlation. - Constant-time algorithms: Ensure power consumption is independent of secret data. - Physical protections: Shield the device’s power supply and use noise injection to obscure traces.
Modern cryptographic libraries (e.g., OpenSSL, BearSSL) often include built-in countermeasures against SPA and other side-channel attacks.
Key takeaways¶
- SPA is a basic yet effective method for extracting cryptographic keys by analyzing power consumption patterns.
- It requires capturing and analyzing power traces during deterministic operations, often using tools like oscilloscopes and Python scripts.
- Mitigations include masking, shuffling, and constant-time algorithms, alongside physical protections for the power supply.