Understanding side-channel attacks in the IIoT context
Side-Channel Attacks (SCA) are a distinct type of cyberattack, differing from traditional software or protocol vulnerabilities. Instead of directly breaking cryptographic algorithms, SCA leverage information unintentionally leaked from a physical system during cryptographic operations. This can include measurements of power consumption, electromagnetic radiation, execution time, or even acoustic noise. In the context of the Industrial Internet of Things (IIoT), where devices often operate in physically accessible environments, such attacks pose a critical threat, potentially leading to the leakage of sensitive data or the compromise of cryptographic keys.
Examples of successful side-channel attacks include attempts to decode RSA key bits by analyzing power consumption, as well as cache attacks that monitor cache access during AES operations to recover the secret key. In 2016, researchers demonstrated an attack that allowed them to extract a decryption key from a powered-off laptop in another room in a matter of seconds by intercepting electromagnetic emissions. These attacks do not cause cryptographic operation failures and can remain undetected.
The impact of SCA on IIoT systems can be catastrophic, as compromised cryptographic keys allow attackers to gain unauthorized access to sensitive data, manipulate it, or even take control of industrial processes. This can lead to production disruptions, financial losses, equipment damage, and threats to personnel safety.
Hardware architectural solutions for SCA protection
For effective protection of IIoT devices against side-channel attacks, hardware solutions that provide physical and logical isolation of cryptographic operations are critical.
- Secure Enclave / Trusted Execution Environment (TEE): This is a dedicated secure subsystem, isolated from the main processor, providing an additional layer of security. A Secure Enclave is designed to protect confidential user data, even if the application processor's kernel is compromised. It has its own CPU, memory, and a hardware Root of Trust established during boot. For example, Apple's Secure Enclave is integrated into the System-on-Chip (SoC) and uses a unique identifier (UID) to generate and store keys that never leave the enclave in plain text. NXP offers the EdgeLock Secure Enclave, which provides physical isolation of critical security functions, protecting the integrity of the SoC and sensitive data.
- Hardware Security Modules (HSM): HSMs are physical computing devices that protect digital keys and perform cryptographic operations. They provide protection against unauthorized access and physical tampering, creating trusted execution environments. HSMs are a robust solution for protecting IIoT ecosystems, ensuring secure cryptographic operations and resilience against unauthorized access.
- Physical shielding: Physical shielding methods, such as Faraday cages or specialized enclosures, can reduce the leakage of electromagnetic radiation used in electromagnetic (EM) attacks. While this can significantly reduce information leakage, some residual leakage always remains.
- Hardware True Random Number Generators (TRNG): Essential for generating robust cryptographic keys, TRNGs provide high entropy, which is the foundation for cryptographic strength. Apple's Secure Enclave, for example, uses a TRNG to generate a UID during manufacturing.
Software and firmware countermeasures against SCA
In addition to hardware solutions, software and firmware countermeasures are an integral part of the strategy for protecting IIoT devices from side-channel attacks.
- Masking: This technique is one of the most common countermeasures against SCA. It involves splitting sensitive variables of a cryptographic algorithm (e.g., AES, RSA) into several random parts (shares), so that no single part reveals secret information. This makes it difficult for attackers to extract useful information from physical measurements. Masking randomizes computations, weakening the link between physical emissions and secret information.
- Constant-Time Execution: Ensuring that cryptographic operations execute in a constant amount of time, regardless of the values of secret data, is key to preventing timing attacks. This requires careful programming and can impact performance.
- Lightweight Cryptography: Designed for resource-constrained devices, such as IIoT sensors, lightweight cryptography provides robust protection with minimal requirements for computational power, memory, and energy. The NIST standard for lightweight cryptography, based on the Ascon algorithm family, is designed to support SCA-resistant implementations more easily than many traditional algorithms.
- Secure firmware development: Includes isolation of cryptographic code, memory protection, and the use of secure architectural patterns. This helps minimize information leakage and makes it harder to exploit vulnerabilities.
Integrated architectures and implementation strategies
Effective protection of IIoT devices from side-channel attacks requires not isolated solutions, but integrated architectures that combine hardware and software countermeasures. The choice of the optimal strategy depends on a thorough risk analysis, performance requirements, and budget constraints.
Threat models and risk analysis are the first step in identifying the most vulnerable components and selecting appropriate countermeasures. For example, for devices storing highly sensitive keys, the use of an HSM or Secure Enclave in conjunction with masked cryptographic algorithms may be justified. For less critical devices, software countermeasures and lightweight cryptography may suffice.
NIST recommendations, particularly NIST SP 800-82, provide guidance on the security of operational technology (OT) systems, including IIoT, and emphasize the importance of a comprehensive approach to cybersecurity. They highlight the need for defense-in-depth, where no single failure should lead to unacceptable consequences.
The trade-off between the level of protection, implementation cost, and performance impact is a constant challenge. For example, implementing high-order masking can significantly increase computational overhead and power consumption, which is critical for resource-constrained IIoT devices. Therefore, it is important to evaluate each countermeasure in terms of its effectiveness against specific types of SCA and its impact on the overall system.
For example, NXP actively develops solutions for protection against physical and logical attacks, including SCA, at the chip level, offering various countermeasures adapted to specific applications. Their EdgeLock Secure Enclave platform provides a hardware root of trust and a robust security architecture to protect devices from physical and network attacks.
Mechanism for selecting architectural solutions
Selecting architectural solutions for protection against side-channel attacks requires a systematic approach. The matrix below helps evaluate different countermeasures against key criteria:
| Criterion | Secure Enclave / TEE | HSM | Physical Shielding | Masking | Constant-Time Execution | Lightweight Cryptography |
|---|---|---|---|---|---|---|
| Side-Channel Attack Type | Power, EM, Timing, Cache | Power, EM, Timing, Physical Tampering | EM | Power, EM, Timing, Cache | Timing | Power, EM, Timing, Cache |
| Protection Level | High | Very High | Medium | High | Medium | Medium |
| Implementation Cost (Hardware/Software) | High (Hardware) | Very High (Hardware) | Medium (Hardware) | Medium (Software) | Low (Software) | Low (Software/Hardware) |
| Performance/Resource Impact | Low/Medium | Low | Low | Medium/High | Medium | Low |
| Integration Complexity | High | High | Low | Medium | Medium | Low |
| Standard Compliance (e.g., NIST SP 800-193) | Yes | Yes | Partially | Yes | Yes | Yes (NIST LWC) |
Architects and engineers working with AZIOT can use these architectural solutions to design and develop industrial IoT systems, ensuring a high level of cryptographic resilience for devices and protection of confidential data in critical infrastructures. The AZIOT platform, by integrating protocols such as MQTT, Modbus, BACnet, and utilizing edge processing and access control mechanisms, can be strengthened by implementing these low-level countermeasures at the device level. This ensures the integrity and confidentiality of telemetry and facility automation data transmitted through gateways to dashboards and audit systems.
Protecting IIoT from side-channel attacks requires constant attention to implementation details and a willingness to adapt. By integrating hardware and software countermeasures early in the design phase, resilient and reliable systems capable of withstanding complex threats can be created. This will ensure the long-term security and functionality of critical infrastructure.
Learn more about Intecracy solutions at Intecracy solutions and inbase.com.ua solutions.
Frequently asked questions
- Why are side-channel attacks particularly dangerous for IIoT devices?
IIoT devices often operate in physically accessible environments where attackers can easily gain access to the device to measure physical parameters such as power consumption or electromagnetic radiation. These attacks exploit not algorithm vulnerabilities, but their physical implementation, making traditional protection methods ineffective and difficult to detect.
- What are the main differences between a Secure Enclave and a Hardware Security Module (HSM) in the context of IIoT?
A Secure Enclave is typically an integrated part of a microcontroller's SoC (System-on-Chip), providing an isolated environment for cryptographic operations and key storage at the device level. An HSM, on the other hand, is a separate, often external, device that offers a higher level of protection against physical tampering and certification, and is typically used for key management at the gateway or server level. HSMs provide a very high level of security, while Secure Enclaves offer a balance between security and integration in resource-constrained devices.
- Can lightweight cryptography provide sufficient protection against side-channel attacks?
Lightweight cryptography is designed for resource-constrained devices and can be resilient to SCA if its implementation considers these threats. The NIST standard for lightweight cryptography, based on the Ascon algorithms, is specifically designed to support SCA-resistant implementations. However, to achieve a high level of protection, it often needs to be combined with other countermeasures, such as masking or constant-time execution, depending on the device's risk profile and data sensitivity.
Source list
- en.wikipedia.orgSide-channel attack - Wikipedia
- rambus.comSide-channel attacks explained: All you need to know -Rambus
- x-phy.comSide Channel Attacks Explained: Types, Examples, DPA & Protection
- csrc.nist.govSide-Channel Attack - Glossary | CSRCLock
- enconnex.comWhat Is a Side-Channel Attack? | Vulnerabilities & Countermeasures
- pmc.ncbi.nlm.nih.govInternet of Things for System Integrity: A Comprehensive Survey on Security, Attacks and Countermeasures for Industrial Applications - PMC Lock
- support.apple.comThe Secure Enclave - Apple Support
- nxp.comEdgeLock Secure Enclave and Crypto Accelerators | NXP SemiconductorsNXPNXPFacebookYouTubeX (formerly Twitter)LinkedIn