Abstract
We investigate the use of bit-level Soft Analytical Side-Channel Attacks (SASCA) to recover secret inputs of the SHA-256 hash function, and secret keys of HMAC-SHA-256, using Sentential Decision Diagrams to overcome the computational challenge posed to classical Belief Propagation by multiple-word modular addition. Our attack on HMAC requires no control nor knowledge of the input, and exploits its double manipulation of the key to improve key-recovery performance. We make comprehensive simulations to evaluate the attacker’s recovery capacity for both SHA-256 and HMAC-SHA-256. Finally, we study the profiling capabilities of load instructions in a multiposition EM probe setup on a STM32F303RET6 microcontroller, and use these results to evaluate the capability of our attack against software implementations of HMAC-SHA-256 in a realistic scenario.
| Original language | English |
|---|---|
| Pages (from-to) | 1205-1227 |
| Number of pages | 23 |
| Journal | IACR Transactions on Cryptographic Hardware and Embedded Systems |
| Volume | 2026 |
| Issue number | 3 |
| DOIs | |
| Publication status | Published - 17 Jul 2026 |
Keywords
- HMAC
- SASCA
- Sentential Decision Diagrams
- SHA-256
- Side-Channel Attack
Fingerprint
Dive into the research topics of 'Soft Analytical Side-Channel Attacks on SHA-2 and HMAC'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver