Abstract:
In this paper, it is shown that the electromagnetic (EM) emanation of cryptographic chips could be captured easily with a handmade loop probe, and its amplitude is related to the hamming weight of the related operands.Based on the description of the principle and steps of template analysis, EM template analysis attack against cryptographic chips was introduced.Additionally, an experiment of EM template analysis attack against a singlechip (AT89C52) implemented DES was given, and the 48-bit subkey used in the 16th round of DES was recovered.