The security assessment of cryptographic devices cannot be limited to the mathematical analysis of the implemented algorithms. Physical implementations may reveal information through observable effects such as timing variations, electromagnetic emissions, or power consumption. For this reason, side channel analysis plays a central role in the evaluation of device security. In experimental settings, this evaluation involves multiple stages, including dataset handling, preprocessing, leakage detection, feature reduction and attack execution. These tasks are often managed through separate tools and heterogeneous data sources, making the overall workflow less uniform, less reusable and more difficult to reproduce. This thesis addresses this problem through the design and implementation of FreeSCA, a modular Python library for side channel analysis. The framework integrates the main stages of the analysis workflow within a common structure and introduces the FSCA trace format for the uniform management of traces and associated metadata, conversion tools for heterogeneous data sources, and an incremental processing approach suited to realistic experimental conditions. Within this framework, a representative set of methods for practical side channel evaluation is implemented, including different variants of Welch's t-test for statistical leakage detection, Correlation Power Analysis, Template Attack and feature reduction procedures for high dimensional trace data. The framework is validated experimentally on masked and unmasked datasets associated with AES-128 implementations running on an ARM Cortex-M4 microcontroller. The results show that the proposed library supports the main stages of a practical side channel workflow in a consistent manner. The implemented statistical methods highlight meaningful differences between protected and unprotected settings, while the attack techniques support the practical evaluation of leakage exploitability under different analysis conditions. Overall, the thesis contributes a modular and extensible framework for side channel analysis, combining methodological coherence, practical usability and experimental validation.
La valutazione della sicurezza dei dispositivi crittografici non può limitarsi all’analisi matematica degli algoritmi implementati. Le implementazioni fisiche possono infatti rivelare informazioni attraverso effetti osservabili, quali variazioni temporali, emissioni elettromagnetiche o consumo di potenza. Per questo motivo, la side channel analysis svolge un ruolo centrale nella valutazione della sicurezza del dispositivo. In contesti sperimentali, tale valutazione coinvolge più fasi, tra cui gestione dei dataset, preprocessing, leakage detection, riduzione delle feature ed esecuzione degli attacchi. Queste attività sono spesso gestite tramite strumenti separati e sorgenti di dati eterogenee, rendendo il workflow meno uniforme, meno riusabile e più difficile da riprodurre. Questa tesi affronta tale problema attraverso la progettazione e l'implementazione di FreeSCA, una libreria Python modulare per la side channel analysis. Il framework integra le principali fasi del workflow di analisi all'interno di una struttura comune e introduce il formato FSCA per la gestione uniforme di tracce e metadati associati, strumenti di conversione per sorgenti di dati eterogenee e un approccio di elaborazione incrementale adatto a condizioni sperimentali realistiche. All'interno di questo framework è implementato un insieme rappresentativo di metodi per la valutazione pratica side channel, comprendente diverse varianti del Welch t-test per la rilevazione statistica del leakage, Correlation Power Analysis, Template Attack e procedure di riduzione delle feature per tracce ad alta dimensionalità. Il framework è validato sperimentalmente su dataset masked e unmasked associati a implementazioni AES-128 eseguite su un microcontrollore ARM Cortex-M4. I risultati mostrano che la libreria proposta supporta in modo coerente le principali fasi di un workflow pratico di side channel analysis. I metodi statistici implementati evidenziano differenze significative tra scenari protetti e non protetti, mentre le tecniche di attacco supportano la valutazione pratica della sfruttabilità del leakage in diverse condizioni di analisi. Nel complesso, la tesi contribuisce con un framework modulare ed estendibile per la side channel analysis, combinando coerenza metodologica, usabilità pratica e validazione sperimentale.
Design, implementation and experimental validation of FreeSCA, a Python Library for side channel analysis
BORGHI, VALENTINA
2025/2026
Abstract
The security assessment of cryptographic devices cannot be limited to the mathematical analysis of the implemented algorithms. Physical implementations may reveal information through observable effects such as timing variations, electromagnetic emissions, or power consumption. For this reason, side channel analysis plays a central role in the evaluation of device security. In experimental settings, this evaluation involves multiple stages, including dataset handling, preprocessing, leakage detection, feature reduction and attack execution. These tasks are often managed through separate tools and heterogeneous data sources, making the overall workflow less uniform, less reusable and more difficult to reproduce. This thesis addresses this problem through the design and implementation of FreeSCA, a modular Python library for side channel analysis. The framework integrates the main stages of the analysis workflow within a common structure and introduces the FSCA trace format for the uniform management of traces and associated metadata, conversion tools for heterogeneous data sources, and an incremental processing approach suited to realistic experimental conditions. Within this framework, a representative set of methods for practical side channel evaluation is implemented, including different variants of Welch's t-test for statistical leakage detection, Correlation Power Analysis, Template Attack and feature reduction procedures for high dimensional trace data. The framework is validated experimentally on masked and unmasked datasets associated with AES-128 implementations running on an ARM Cortex-M4 microcontroller. The results show that the proposed library supports the main stages of a practical side channel workflow in a consistent manner. The implemented statistical methods highlight meaningful differences between protected and unprotected settings, while the attack techniques support the practical evaluation of leakage exploitability under different analysis conditions. Overall, the thesis contributes a modular and extensible framework for side channel analysis, combining methodological coherence, practical usability and experimental validation.| File | Dimensione | Formato | |
|---|---|---|---|
|
2026_07_Borghi_Executive_Summary.pdf
accessibile in internet per tutti
Descrizione: Executive Summary
Dimensione
20.88 MB
Formato
Adobe PDF
|
20.88 MB | Adobe PDF | Visualizza/Apri |
|
2026_07_Borghi_Master_Thesis.pdf
accessibile in internet per tutti
Descrizione: Master Thesis
Dimensione
24.68 MB
Formato
Adobe PDF
|
24.68 MB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/259557