Attestation Waves: Platform Trust via Remote Power Analysis
Ignacio M. Delgado-Lozano, Macarena C. Mart\'inez-Rodr\'iguez,, Alexandros Bakas, Billy Bob Brumley, Antonis Michalas

TL;DR
This paper proposes a novel attestation method using power side-channel information captured internally within a System-on-Chip, eliminating the need for physical proximity and external measurement setups.
Contribution
It introduces a new approach to system attestation leveraging internal power fluctuations via ADCs, enhancing security against remote attacks.
Findings
Power traces can distinguish specific operations reliably.
Internal power-based attestation does not require physical proximity.
Method effectively detects malicious modifications.
Abstract
Attestation is a strong tool to verify the integrity of an untrusted system. However, in recent years, different attacks have appeared that are able to mislead the attestation process with treacherous practices as memory copy, proxy, and rootkit attacks, just to name a few. A successful attack leads to systems that are considered trusted by a verifier system, while the prover has bypassed the challenge. To mitigate these attacks against attestation methods and protocols, some proposals have considered the use of side-channel information that can be measured externally, as it is the case of electromagnetic (EM) emanation. Nonetheless, these methods require the physical proximity of an external setup to capture the EM radiation. In this paper, we present the possibility of performing attestation by using the side-channel information captured by a sensor or peripheral that lives in the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPhysical Unclonable Functions (PUFs) and Hardware Security · Cryptographic Implementations and Security · Security and Verification in Computing
