Cryptographic hardware and embedded systems-- CHES 2005: 7th by Josyula R. Rao, Berk Sunar

This publication constitutes the refereed court cases of the seventh foreign Workshop on Cryptographic and Embedded structures, CHES 2005, held in Edinburgh, united kingdom in August/September 2005.

The 32 revised complete papers awarded have been rigorously reviewed and chosen from 108 submissions. The papers are geared up in topical sections on aspect channels, mathematics for cryptanalysis, low assets, distinctive goal undefined, assaults and countermeasures, mathematics for cryptography, depended on computing, and effective hardware.

The letter x ∈ {0, 1}p denotes a known part of the plaintext or the ciphertext, respectively. We view a measurement at time t as a realization of the random variable It (x, k) = ht (x, k) + Rt . (1) The first summand ht (x, k) quantifies the deterministic part of the measurement as far it depends on x and k. The term Rt denotes a random variable that does not depend on x and k. Without loss of generality we may assume that E(Rt ) = 0 since otherwise we could replace ht (x, k) and Rt by ht (x, k) + E(Rt ) and Rt − E(Rt ), respectively.

Choice of Vector Subspaces. Different vector spaces are evaluated regarding their efficiency. g, by including all terms of gi (φ(x, k))gi (φ(x, k)) (i = i ) (see (9) and (23)) did not lead to great improvements. We observed only weak contributions of second-order coefficients that even vanish at many combinations. We present results for F2 = F2;t for all t: the Hamming weight model (u = 2), F5 = F5;t for all t: a set of four bit-wise coefficients (u = 5) (these are the most significant bit-wise coefficients of F9 ), 1 2 Note, that we do not consider the covariance of the noise at the chosen points in this approach for key extraction.

The adversary just adds these squared norms for each admissible subkey over several instants t, and decides for that subkey for which this sum is minimal (see Sect. 1 for an experimental verification). In fact, the determination of k is a by-product of the profiling phase which costs no additional measurements. At least principally, this observation could also be used for a direct attack without profiling, which yet requires a sufficient number of measurements. Definition 3. Rt denotes the random vector (Rt1 , .

