WEBVTT

1
00:00:00.000 --> 00:00:03.252
A control path that rejects bad output does
not prove a

2
00:00:03.252 --> 00:00:05.964
cryptographic implementation leaks nothing.

3
00:00:05.964 --> 00:00:09.129
DFA exploits differences in faulty outputs;

4
00:00:09.129 --> 00:00:14.367
SIFA conditions on ineffective faulted
computations—the fault was induced, but the

5
00:00:14.367 --> 00:00:19.314
output stayed correct—and analyzes
statistical bias in an intermediate value.

6
00:00:19.314 --> 00:00:23.507
Both require an explicit observation and
attacker model.

7
00:00:23.507 --> 00:00:29.080
A food factory’s metal detector may stop a
contaminant, yet production logs can still

8
00:00:29.080 --> 00:00:31.479
reveal which recipe line was active.

9
00:00:31.479 --> 00:00:33.337
The first is control safety;

10
00:00:33.337 --> 00:00:35.659
the second is information leakage.

11
00:00:35.659 --> 00:00:41.859
A crypto block may suppress faulty output
and still leak through an error/valid flag,

12
00:00:41.859 --> 00:00:45.242
completion time, retries, or power
differences.

13
00:00:45.242 --> 00:00:47.820
The analogy separates the questions;

14
00:00:47.820 --> 00:00:51.231
it does not model cryptanalytic statistics.

15
00:00:51.500 --> 00:00:56.391
DFA often compares correct and faulty
ciphertexts to derive key candidates from

16
00:00:56.391 --> 00:00:58.805
differences in selected rounds or bytes.

17
00:00:58.805 --> 00:01:03.427
Fault location, timing, round, and
observable output determine feasibility.

18
00:01:03.427 --> 00:01:08.928
SIFA keeps samples from ineffective faulted
computations: the fault was induced, but the

19
00:01:08.928 --> 00:01:10.270
output stayed correct.

20
00:01:10.270 --> 00:01:15.231
It then uses statistical bias in an
intermediate value conditioned on those

21
00:01:15.231 --> 00:01:17.655
samples to distinguish key candidates;

22
00:01:17.655 --> 00:01:19.864
a faulty ciphertext is not required.

23
00:01:19.864 --> 00:01:26.610
Under this scenario’s oracle, effective and
ineffective describe whether the computation

24
00:01:26.610 --> 00:01:29.808
changed, not the DUT’s output-valid pin.

25
00:01:30.083 --> 00:01:35.032
At RTL, assert that error state cannot
create an unauthorized branch in

26
00:01:35.032 --> 00:01:38.118
valid/ready, retry, or key-release control.

27
00:01:38.118 --> 00:01:41.442
SVA cannot establish secret-independent
power.

28
00:01:41.442 --> 00:01:45.633
Use gate-level/netlist and
physical measurements for side-channel

29
00:01:45.633 --> 00:01:49.681
evaluation, and keep control properties
separate from leakage evidence.

30
00:01:49.681 --> 00:01:54.869
For every sample, record the fault class,
whether the computation changed, the error

31
00:01:54.869 --> 00:01:59.191
flag, latency, and whether the observation
distinguishes outcome classes.

32
00:01:59.191 --> 00:02:03.994
A classifier that only performs well on its
training samples has not shown

33
00:02:03.994 --> 00:02:07.473
generalization; hold out samples and report
confidence.

34
00:02:07.473 --> 00:02:13.006
Failure to observe a distinction only means
none was detected under these conditions.

35
00:02:13.292 --> 00:02:19.152
These are property sketches: define the
harness transaction, reset and oracle, then

36
00:02:19.152 --> 00:02:23.084
confirm sampling boundaries before binding
to the design.

37
00:02:23.084 --> 00:02:25.600
They have not been compiled or proven.

38
00:02:25.600 --> 00:02:30.081
The sketch has one assertion: error_seen
implies out_valid is low.

39
00:02:30.081 --> 00:02:33.878
It says nothing about ready, retry, or key
release;

40
00:02:33.878 --> 00:02:35.774
each needs its own property.

41
00:02:35.774 --> 00:02:39.883
If error_seen never occurs, the assertion
passes vacuously.

42
00:02:39.883 --> 00:02:45.808
The harness flag fault_class_applied records
that the selected model fault was applied

43
00:02:45.808 --> 00:02:46.993
for this attempt.

44
00:02:46.993 --> 00:02:50.388
The cover pairs that record with error_seen;

45
00:02:50.388 --> 00:02:54.013
it does not prove physical injection reached
silicon.

46
00:02:54.013 --> 00:02:59.546
The property in the article does not prove
CDC, timing, side-channel, or physical

47
00:02:59.546 --> 00:03:04.157
injection behavior; each requires its own
tool evidence or measurement.

48
00:03:04.157 --> 00:03:08.099
Keep two questions separate: was faulty data
released, and did

49
00:03:08.099 --> 00:03:10.108
any output reveal information?

50
00:03:10.108 --> 00:03:13.253
DFA compares correct and faulty outputs.

51
00:03:13.253 --> 00:03:18.899
SIFA conditions on ineffective faulted
computations and analyzes statistical bias

52
00:03:18.899 --> 00:03:22.037
in an intermediate value under that
condition.

53
00:03:22.037 --> 00:03:26.382
Masking ciphertext does not hide every
possible signal;

54
00:03:26.382 --> 00:03:31.067
validity, latency, retries, or power may
still classify outcomes.

55
00:03:31.067 --> 00:03:36.738
First state which inputs an attacker can
choose, how often faults can be repeated,

56
00:03:36.738 --> 00:03:38.875
and which signals are visible.

57
00:03:38.875 --> 00:03:43.082
Then evaluate on held-out samples and report
uncertainty.

58
00:03:43.082 --> 00:03:46.814
A test that finds no distinction only
reports that none was

59
00:03:46.814 --> 00:03:49.220
detected under its conditions.

60
00:03:49.500 --> 00:03:56.062
An attacker may repeat faults and observe
ciphertext, result class, latency, or power

61
00:03:56.062 --> 00:03:59.374
while targeting a key or intermediate state.

62
00:03:59.374 --> 00:04:03.645
DFA uses differences between correct and
faulty outputs.

63
00:04:03.645 --> 00:04:09.444
SIFA keeps samples from ineffective faulted
computations and analyzes the conditional

64
00:04:09.444 --> 00:04:11.315
bias in an intermediate value.

65
00:04:11.315 --> 00:04:16.066
The review must state which faults and
observations the attacker can control.

66
00:04:16.066 --> 00:04:22.250
It must check output suppression and error
handling, then assess physical side channels

67
00:04:22.250 --> 00:04:26.569
with separate evidence. Control assertions
do not measure attack

68
00:04:26.569 --> 00:04:28.728
success or information leakage.

69
00:04:28.728 --> 00:04:34.061
These synthetic samples are not a
cryptographic implementation test.

70
00:04:34.061 --> 00:04:39.899
If an experiment has no leakage model, a
lack of detected differences only describes

71
00:04:39.899 --> 00:04:45.079
that test; it does not prove zero leakage or
cover every power and EM attack.

72
00:04:45.079 --> 00:04:47.517
Now take the attacker’s view.

73
00:04:47.517 --> 00:04:52.490
If faulty data is withheld, could the result
class, latency, retries, or

74
00:04:52.490 --> 00:04:54.936
power still distinguish outcomes?

75
00:04:54.936 --> 00:05:00.909
If latency is randomized or a new sample set
is collected, which part of the oracle

76
00:05:00.909 --> 00:05:03.941
changes, and which signals remain visible?

77
00:05:03.941 --> 00:05:10.192
Report those observation conditions and the
limits of what the experiment detected.
