Skip to Main content Skip to Navigation
New interface
Journal articles

Side-Channel Expectation-Maximization Attacks

Julien Béguinot 1, 2, 3 Wei Cheng 1, 2, 3 Sylvain Guilley 1, 4, 3, 5 Olivier Rioul 1, 2, 3 
2 COMNUM - Communications Numériques
LTCI - Laboratoire Traitement et Communication de l'Information
4 SSH - Secure and Safe Hardware
LTCI - Laboratoire Traitement et Communication de l'Information
Abstract : Block ciphers are protected against side-channel attacks by masking. On one hand, when the leakage model is unknown, second-order correlation attacks are typically used. On the other hand, when the leakage model can be profiled, template attacks are prescribed. But what if the profiled model does not exactly match that of the attacked device? One solution consists in regressing on-the-fly the scaling parameters from the model. In this paper, we leverage an Expectation-Maximization (EM) algorithm to implement such an attack. The resulting unprofiled EM attack, termed U-EM, is shown to be both efficient (in terms of number of traces) and effective (computationally speaking). Based on synthetic and real traces, we introduce variants of our U-EM attack to optimize its performance, depending on trade-offs between model complexity and epistemic noise. We show that the approach is flexible, in that it can easily be adapted to refinements such as different points of interest and number of parameters in the leakage model.
Document type :
Journal articles
Complete list of metadata
Contributor : Olivier Rioul Connect in order to contact the contributor
Submitted on : Friday, August 12, 2022 - 12:59:20 PM
Last modification on : Thursday, August 18, 2022 - 10:46:15 AM
Long-term archiving on: : Sunday, November 13, 2022 - 6:32:24 PM


Files produced by the author(s)


  • HAL Id : hal-03718805, version 1


Julien Béguinot, Wei Cheng, Sylvain Guilley, Olivier Rioul. Side-Channel Expectation-Maximization Attacks. IACR Transactions on Cryptographic Hardware and Embedded Systems, inPress, 2022 (4). ⟨hal-03718805⟩



Record views


Files downloads