Meaning
The capability of a cryptographic hardware system to prevent the leakage of secret information through physical channels during computation is an essential defense metric. Designing for side-channel resistance involves implementing defenses against the analysis of execution time, power consumption, and electromagnetic emissions. This ensures that an attacker cannot extract cryptographic keys even with physical access to the device.
Defense Method
Implementing these defenses often requires both hardware and software countermeasures. To achieve side-channel resistance, engineers use techniques like clock jittering, random noise generation, and masked software algorithms. These methods obscure the correlation between the processed data and the physical signals emitted by the chip.
Validation Test
Security certification bodies perform extensive penetration testing to measure the leakage from the chip under various operating conditions. This includes collecting and analyzing thousands of power traces or electromagnetic profiles to see if any pattern relates to the secret key. If the analysis cannot extract the key after several million iterations, the device is certified as secure.
The resulting test certificate is a primary part of the compliance folder for high-security applications like payment cards or automotive controllers.
Integration Factor
Physical board layout must also be designed to minimize electromagnetic emissions and isolate power lines. This prevents the sensitive signals from leaking to other components or being easily measured by external probes.