This repository contains the side-channel setup and postprocessing code used for the article "How Strong is the FO-Calypse, Really? Instantiating Plaintext-Checking Oracles against Masked Software Implementations of ML-KEM" authored by Brieuc Balon, Gaëtan Cassiers, Thibaud Schoenauen and François-Xavier Standaert.
To build and run this project, you will need the following hardware and software.
- CW308 motherboard and an STM32F4 target board (tested with the STM32F415).
- ST-link programmer and a UART cable.
- A CT1 probe (or SMA cable, depending on your measurement setup).
- A PicoScope oscilloscope (tested with the
PS5000D, it should also work withPS5000Bseries).
-
A Linux-based operating system with at least 32 GB of RAM and 40 GB of available storage.
-
Python 3.12.3 or later (installation link).
-
uv 0.9.17 or later (installation link)
-
PicoScope 7:
Add the Pico Technology repository and its signing key:
sudo bash -c 'wget -O- https://labs.picotech.com/Release.gpg.key | gpg --dearmor > /usr/share/keyrings/picotech-archive-keyring.gpg' sudo bash -c 'echo "deb [signed-by=/usr/share/keyrings/picotech-archive-keyring.gpg] https://labs.picotech.com/picoscope7/debian/ picoscope main" >/etc/apt/sources.list.d/picoscope7.list'
Update the package lists and install PicoScope:
sudo apt-get update sudo apt-get install picoscope
-
OpenOCD 0.12.0 or later :
Install the latest version directly from the official Git repository. Create a directory for source code:
sudo mkdir -p /opt/src sudo chown "$USER:$USER" /opt/srcClone and build OpenOCD:
cd /opt/src git clone https://github.com/openocd-org/openocd.git cd openocd ./bootstrap ./configure make -j4 sudo make install
-
Meson 1.3.2 or later (
sudo apt install meson) -
Ninja 1.11.1 or later (
sudo apt install ninja-build)
Additional dependencies :
- gcc-arm-none-eabi :
sudo apt install gcc-arm-none-eabi - gcc-arm-linux-gnueabi :
sudo apt instal gcc-arm-linux-gnueabi - qemu-user-static :
sudo apt install qemu-system-arm
Clone the repository and submodules
git clone https://github.com/uclcrypto/FO_Calypse_software.git --recursive
This repository is organized into three main directories:
measurement_setupcontains the code used to acquire the datasets.post_processingcontains the scripts used to post-process the datasets and reproduce the results presented in Section 3 of the article.modelingcontains the code used to build the theoritical models described in Section 4 of the article.
Each directory is self-contained and includes its own README and Makefile, allowing it to be used independently. However, the workflow is sequential:
post_processingrequires the datasets generated bymeasurement_setupmodelingrequires the datasets generated bymeasurement_setup
This work evaluates four different masked Keccak software implementations, referred to by the IMPLEM_CHOICE parameter :
- The PINI implementation by Bronchain et al. (ePrint, GitHub) implemented in
C. - The PINI implementation by Bronchain et al. (ePrint, GitHub) implemented in
Cwith gadgets written inASM - The Domain-Oriented Masking (DOM) implementation by Kundu et al. (ePrint, GitHub) written in
C. - The Threshold Implementation (TI) by Gaspoz et al. (ePrint, GitHub) coded in
ASM.
and that can be masked to certain number of shares NSHARES.
As described in the article:
IMPLEM_CHOICE=1or2supportsNSHARESvalues from 1 to 6.IMPLEM_CHOICE=3supportsNSHARESvalues from 1 to 7.IMPLEM_CHOICE=4supports onlyNSHARES=2.
The different README files illustratre the workflow using IMPLEM_CHOICE=3 and NSHARES=2and a reduced number of traces for demonstration purposes. You are free to modify these parameters as needed. Common configuration parameters can be adjusted in the common.mk file.
This project has been developped by the UCLouvain Crypto Group.
This project is released under the MIT license.