LeakyOhm: Secret Bits Extraction using Impedance Analysis
Saleh Khalaj Monfared, Tahoura Mosavirik, Shahin Tajik
Abstract
The threats of physical side-channel attacks and their countermeasures have been widely researched. Most physical side-channel attacks rely on the unavoidable influence of computation or storage on current consumption or voltage drop on a chip. Such datadependent influence can be exploited by, for instance, power or electromagnetic analysis. In this work, we introduce a novel noninvasive physical side-channel attack, which exploits the datadependent changes in the impedance of the chip. Our attack relies on the fact that the temporarily stored contents in registers alter the physical characteristics of the circuit, which results in changes in the die's impedance. To sense such impedance variations, we deploy a well-known RF/microwave method called scattering parameter analysis, in which we inject sine wave signals with high frequencies into the system's power distribution network (PDN) and measure the echo of the signals. We demonstrate that according to the content bits and physical location of a register, the reflected signal is modulated differently at various frequency points enabling the simultaneous and independent probing of individual registers. Such side-channel leakage challenges the 𝑡-probing security model assumption used in masking, which is a prominent side-channel countermeasure. To validate our claims, we mount non-profiled and profiled impedance analysis attacks on hardware implementations of unprotected and high-order masked AES. We show that in the case of the profiled attack, only a single trace is required to recover the secret key. Finally, we discuss how a specific class of hiding countermeasures might be effective against impedance leakage. CCS CONCEPTS • Security and privacy → Embedded systems security; Side-channel analysis and countermeasures; Hardware reverse engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Chypnosis: Undervolting-based Static Side-channel AttacksKyle Mitard, Saleh Khalaj Monfared, Fatemeh Khojasteh Dana, Robert Dumitru et al.S&P 2026 · 1 citation
- On Borrowed Time - Preventing Static Side-Channel AnalysisRobert Dumitru, Thorben Moos, Andrew Wabnitz, Yuval YaromNDSS 2025
- Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware NonlinearityHaoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang et al.USENIX Security 2026
Builds on3
- Real-World Snapshots vs. Theory: Questioning the t-Probing Security ModelThilo Krachenfels, Fatemeh Ganji, Amir Moradi, Shahin Tajik et al.S&P 2021 · 42 citations
- Automatic Extraction of Secrets from the Transistor Jungle using Laser-Assisted Side-Channel AttacksThilo Krachenfels, Tuba Kiyan, Shahin Tajik, Jean-Pierre SeifertUSENIX Security 2021 · 40 citations
- On the Success Rate of Side-Channel Attacks on Masked Implementations: Information-Theoretical Bounds and Their Practical UsageAkira Ito, Rei Ueno, Naofumi HommaCCS 2022 · 18 citations
Related papers
- Glitch-Stopping Circuits: Hardware Secure Masking without RegistersZhenda Zhang, Svetla Petkova-Nikova, Ventzislav NikovCCS 2024 · 2 citations
- DExiM: Exposing Impedance-Based Data Leakage in Emerging MemoriesMd. Sadik Awal, Md Tauhidur RahmanMICRO 2025 · 1 citation
- PERSEUS - Probabilistic Evaluation of Random Probing SEcurity Using Efficient SamplingSonia Belaïd, Gaëtan CassiersEUROCRYPT 2026
- Cross-Device Profiled Side-Channel Attacks using Meta-Transfer LearningHonggang Yu, Haoqi Shan, Maximillian Panoff, Yier JinDAC 2021 · 38 citations
- Secure Wire Shuffling in the Probing ModelJean-Sébastien Coron, Lorenzo SpignoliCRYPTO 2021 · 13 citations
