In this paper we report on the results of selected horizontal SCA attacks against two open-source designs that implement hardware accelerators for elliptic curve cryptography. Both designs use the complete addition formula to make the point addition and point doubling operations indistinguishable. One of the designs uses in addition means to randomize the operation sequence as a countermeasure. We used the comparison to the mean and an automated SPA to attack both designs. Despite all these countermeasures, we were able to extract the keys processed with a correctness of 100%.
Cite
@article{arxiv.2201.01158,
title = {Breaking a fully Balanced ASIC Coprocessor Implementing Complete Addition Formulas on Weierstrass Elliptic Curves},
author = {Ievgen Kabin and Zoya Dyka and Dan Klann and Nele Mentens and Lejla Batina and Peter Langendoerfer},
journal= {arXiv preprint arXiv:2201.01158},
year = {2022}
}
Comments
Author's version accepted for DSD-2020; the final publication is available at https://ieeexplore.ieee.org/document/9217817