Harishma Boyapally and Dirmanto Jap, Temasek Laboratories, Nanyang Technological University, Singapore; and National integrated Centre For Evaluation, Nanyang Technological University, Singapore; Qianmei Wu, School of Physical and Mathematical Sciences, Nanyang Technological University, Singapore; and School of Cyber Science and Technology, College of Computer Science and Technology, Zhejiang University, China; Fan Zhang, School of Cyber Science and Technology, College of Computer Science and Technology, Zhejiang University, China; Shivam Bhasin, Temasek Laboratories, Nanyang Technological University, Singapore; and National integrated Centre For Evaluation, Nanyang Technological University, Singapore
Side-channel analysis (SCA) has posed a significant threat to systems for nearly three decades. Numerous practical demonstrations have targeted everyday devices, such as smart cards, cryptocurrency wallets, and smartphones. However, much of the research in the public domain has focused on low-end microcontrollers, limiting our understanding of the challenges involved in attacking more complex systems. In this work, we conduct a reality check on SCA by targeting a high-performance ARM Cortex-A72 out-of-order processor, commonly found in smartphones. We evaluate the practical effort required for key recovery attacks, considering various threat models, from basic to advanced. Our results show that while basic approaches fail, advanced approaches like deep learning-based SCA can successfully recover the secret key. This multi-tier evaluation approach is crucial for comprehensive risk assessment and informed decision-making regarding mitigation strategies, balancing security, performance, and area constraints.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

author = {Harishma Boyapally and Dirmanto Jap and Qianmei Wu and Fan Zhang and Shivam Bhasin},
title = {Reality Check on {Side-Channels}: Lessons learnt from breaking {AES} on {ARM} {Cortex-A72} processor with {Out-of-Order} Execution},
booktitle = {19th USENIX WOOT Conference on Offensive Technologies (WOOT 25)},
year = {2025},
isbn = {978-1-939133-50-2},
address = {Seattle, WA},
pages = {179--189},
url = {https://www.usenix.org/conference/woot25/presentation/boyapally},
publisher = {USENIX Association},
month = aug
}
