DevToSCA

DevToSCA

a research project funded by the BMBF

Developer-Centric Tools for Side-Channel Analysis

Motivation

Companies face enormous challenges both in protecting cryptographic implementations against side-channel attacks and in maintaining security features on different hardware platforms. Side-channel attacks do not target the cryptographic algorithms themselves, but target the compromise of the implementation. These types of attacks take place, for example, via a characteristic runtime behavior of measured computations, differences in power consumption, or electromagnetic radiation.

Approach and goals

The objective of the DevToSCA project is to enable developers to automatically test and optimize their software and hardware products for side-channel resistance, based on crypto and security functions that are already available but also those they have developed themselves. For this purpose, the DevToSCA project develops innovative verification tools for side channel analysis. These tools are intended to enable software developers to check the resistance of their own implementations – even without in-depth expertise in side channels. In order to achieve a high level of user acceptance, usability is also specifically taken into account in the design. Thus, we can increase developer awareness and sensitivity to cryptographic side-channel attacks and reduce the occurrence of such vulnerabilities.

Rohde & Schwarz Cybersecurity is particularly involved in the project with the integration of side-channel analysis tools into productive development and test environments – especially for use in crypto libraries and IT security products. To create appealing and efficient environments for professional developers and testers, several work steps are usually interconnected in an automated and configurable way for the purpose of Continuous Integration (CI). An important quality criterion is the reliability and comprehensibility of the tools, e.g. the comprehensibility of test results in order to be able to recognize, comprehend and eliminate side channels. The appropriate integrability and configurability of the tools in integrated development environments (IDEs) and automation scripts is also essential for acceptance by the addressed target group.

Project organization

DevToSCA is a joint research project funded by the German Federal Ministry of Education and Research (BMBF). Various specialist partners from both research and industry are involved in the project. The Hochschule Bonn-Rhein-Sieg, University of Applied Sciences, is responsible for the project lead.

  • Project management: VDI/VDE-IT Berlin
  • Consortium: Hochschule Bonn-Rhein-Sieg University of Applied Sciences, Ruhr University Bochum, Kasper & Oswald GmbH, Rohde & Schwarz Cybersecurity GmbH
  • Project duration: 07/2022 – 06/2025

문의하기

추가 문의 사항이나 추가 정보가 필요하십니까? 이 양식에 맞춰 내용을 입력해 주시면 회신 드리겠습니다.

마케팅 동의

로데슈바르즈에서 다음과 같은 방법으로 정보를 수신하겠습니다

Rohde & Schwarz GmbH & Co. KG 및 본 웹사이트의 기업 정보에 명시된 Rohde & Schwarz 각 법인 또는 각 지사가 마케팅 및 광고 목적(예: 특별 행사 및 할인 프로모션에 대한 정보)으로 이메일 또는 우편을 통해 연락하는 것에 동의합니다. 개인 데이터 사용 및 해지 절차에 대한 자세한 내용은 개인정보 보호정책마케팅 동의 단락에 명시되어 있습니다.

신청하신 내용이 제출되었습니다. 빠른 시일 내 회신 받으실 것입니다.
An error has occurred, please try again later.