DevToSCA

DevToSCA

a research project funded by the BMBF

Developer-Centric Tools for Side-Channel Analysis

Motivation

Companies face enormous challenges both in protecting cryptographic implementations against side-channel attacks and in maintaining security features on different hardware platforms. Side-channel attacks do not target the cryptographic algorithms themselves, but target the compromise of the implementation. These types of attacks take place, for example, via a characteristic runtime behavior of measured computations, differences in power consumption, or electromagnetic radiation.

Approach and goals

The objective of the DevToSCA project is to enable developers to automatically test and optimize their software and hardware products for side-channel resistance, based on crypto and security functions that are already available but also those they have developed themselves. For this purpose, the DevToSCA project develops innovative verification tools for side channel analysis. These tools are intended to enable software developers to check the resistance of their own implementations – even without in-depth expertise in side channels. In order to achieve a high level of user acceptance, usability is also specifically taken into account in the design. Thus, we can increase developer awareness and sensitivity to cryptographic side-channel attacks and reduce the occurrence of such vulnerabilities.

Rohde & Schwarz Cybersecurity is particularly involved in the project with the integration of side-channel analysis tools into productive development and test environments – especially for use in crypto libraries and IT security products. To create appealing and efficient environments for professional developers and testers, several work steps are usually interconnected in an automated and configurable way for the purpose of Continuous Integration (CI). An important quality criterion is the reliability and comprehensibility of the tools, e.g. the comprehensibility of test results in order to be able to recognize, comprehend and eliminate side channels. The appropriate integrability and configurability of the tools in integrated development environments (IDEs) and automation scripts is also essential for acceptance by the addressed target group.

Project organization

DevToSCA is a joint research project funded by the German Federal Ministry of Education and Research (BMBF). Various specialist partners from both research and industry are involved in the project. The Hochschule Bonn-Rhein-Sieg, University of Applied Sciences, is responsible for the project lead.

  • Project management: VDI/VDE-IT Berlin
  • Consortium: Hochschule Bonn-Rhein-Sieg University of Applied Sciences, Ruhr University Bochum, Kasper & Oswald GmbH, Rohde & Schwarz Cybersecurity GmbH
  • Project duration: 07/2022 – 06/2025

Contáctenos

¿Tiene preguntas o necesita información adicional? Simplemente complete este formulario y nos pondremos en contacto con usted.

Permiso de marketing

Deseo recibir información de Rohde & Schwarz por

Quiero recibir información de marketing y publicidad (p. ej. sobre ofertas especiales o descuentos) de Rohde & Schwarz GmbH & Co. KG, o de la empresa o subsidiaria de Rohde & Schwarz mencionadas en la Información legal de este sitio web por correo electrónico o postal. En la Declaración de privacidad y en el Permiso de marketing encontrará información adicional sobre el uso de datos personales y el retiro del consentimiento.

Se ha enviado su solicitud. Nos pondremos en contacto con usted en breve.
An error has occurred, please try again later.