LeakyOhm: Secret Bits Extraction using Impedance Analysis
Saleh Khalaj Monfared, Tahoura Mosavirik, Shahin Tajik
摘要
The threats of physical side-channel attacks and their countermeasures have been widely researched. Most physical side-channel attacks rely on the unavoidable influence of computation or storage on current consumption or voltage drop on a chip. Such datadependent influence can be exploited by, for instance, power or electromagnetic analysis. In this work, we introduce a novel noninvasive physical side-channel attack, which exploits the datadependent changes in the impedance of the chip. Our attack relies on the fact that the temporarily stored contents in registers alter the physical characteristics of the circuit, which results in changes in the die's impedance. To sense such impedance variations, we deploy a well-known RF/microwave method called scattering parameter analysis, in which we inject sine wave signals with high frequencies into the system's power distribution network (PDN) and measure the echo of the signals. We demonstrate that according to the content bits and physical location of a register, the reflected signal is modulated differently at various frequency points enabling the simultaneous and independent probing of individual registers. Such side-channel leakage challenges the 𝑡-probing security model assumption used in masking, which is a prominent side-channel countermeasure. To validate our claims, we mount non-profiled and profiled impedance analysis attacks on hardware implementations of unprotected and high-order masked AES. We show that in the case of the profiled attack, only a single trace is required to recover the secret key. Finally, we discuss how a specific class of hiding countermeasures might be effective against impedance leakage. CCS CONCEPTS • Security and privacy → Embedded systems security; Side-channel analysis and countermeasures; Hardware reverse engineering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Chypnosis: Undervolting-based Static Side-channel AttacksKyle Mitard, Saleh Khalaj Monfared, Fatemeh Khojasteh Dana, Robert Dumitru 等S&P 2026 · 被引用 1 次
- On Borrowed Time - Preventing Static Side-Channel AnalysisRobert Dumitru, Thorben Moos, Andrew Wabnitz, Yuval YaromNDSS 2025
- Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware NonlinearityHaoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang 等USENIX Security 2026
它引用的顶会 Paper3
- Real-World Snapshots vs. Theory: Questioning the t-Probing Security ModelThilo Krachenfels, Fatemeh Ganji, Amir Moradi, Shahin Tajik 等S&P 2021 · 被引用 42 次
- Automatic Extraction of Secrets from the Transistor Jungle using Laser-Assisted Side-Channel AttacksThilo Krachenfels, Tuba Kiyan, Shahin Tajik, Jean-Pierre SeifertUSENIX Security 2021 · 被引用 40 次
- On the Success Rate of Side-Channel Attacks on Masked Implementations: Information-Theoretical Bounds and Their Practical UsageAkira Ito, Rei Ueno, Naofumi HommaCCS 2022 · 被引用 18 次
相关 Paper
- Glitch-Stopping Circuits: Hardware Secure Masking without RegistersZhenda Zhang, Svetla Petkova-Nikova, Ventzislav NikovCCS 2024 · 被引用 2 次
- DExiM: Exposing Impedance-Based Data Leakage in Emerging MemoriesMd. Sadik Awal, Md Tauhidur RahmanMICRO 2025 · 被引用 1 次
- PERSEUS - Probabilistic Evaluation of Random Probing SEcurity Using Efficient SamplingSonia Belaïd, Gaëtan CassiersEUROCRYPT 2026
- Cross-Device Profiled Side-Channel Attacks using Meta-Transfer LearningHonggang Yu, Haoqi Shan, Maximillian Panoff, Yier JinDAC 2021 · 被引用 38 次
- Secure Wire Shuffling in the Probing ModelJean-Sébastien Coron, Lorenzo SpignoliCRYPTO 2021 · 被引用 13 次
