Cryptographic Hardware and Embedded Systems - CHES 2009

Volume 5747 of the series Lecture Notes in Computer Science pp 112-127

Differential Cluster Analysis

  • Lejla BatinaAffiliated withESAT/SCD-COSIC and IBBT, K.U. Leuven
  • , Benedikt GierlichsAffiliated withESAT/SCD-COSIC and IBBT, K.U. Leuven
  • , Kerstin Lemke-RustAffiliated withUniversity of Applied Sciences Bonn-Rhein-Sieg


We propose a new technique called Differential Cluster Analysis for side-channel key recovery attacks. This technique uses cluster analysis to detect internal collisions and it combines features from previously known collision attacks and Differential Power Analysis. It captures more general leakage features and can be applied to algorithmic collisions as well as implementation specific collisions. In addition, the concept is inherently multivariate. Various applications of the approach are possible: with and without power consumption model and single as well as multi-bit leakage can be exploited. Our findings are confirmed by practical results on two platforms: an AVR microcontroller with implemented DES algorithm and an AES hardware module. To our best knowledge, this is the first work demonstrating the feasibility of internal collision attacks on highly parallel hardware platforms. Furthermore, we present a new attack strategy for the targeted AES hardware module.


Differential Cluster Analysis Side-channel Cryptanalysis Collision Attacks Differential Power Analysis AES Hardware