Attacking on-chip oscillators in cryptographic applications
Résumé
In this chapter, we describe a methodology of combined passive-active attacks on ring-oscillator based TRNG (RO-TRNG) using EM channel. The proposed coupled attack first uses a spectral differential analysis of the TRNG electromagnetic radiation to obtain valuable information on the position of ring oscillators and their frequency range (passive attack). This information is then used to tune the electromagnetic harmonic signal to temporarily synchronize the ring oscillators (active attack)