Overview
ISO/IEC 20085-1:2019 specifies test tool requirements and techniques for measuring and analysing side-channel leakage when assessing non-invasive attack mitigations in cryptographic modules. The standard focuses on the measurement and automated analysis of physical signals (side-channels) emitted by an Implementation Under Test (IUT) - e.g., power consumption, electromagnetic emissions and computation timing - to support non-invasive attack testing and evaluation.
Key topics and technical requirements
- Scope and purpose: Defines specifications for non-invasive attack test tools and how to operate them to collect side-channel leakage and perform analysis as part of an attack simulation on cryptographic modules.
- Types of side-channels: Power consumption, electromagnetic (EM) emissions, and computation time are addressed as primary measurements for side-channel analysis.
- Test tool categorization:
- Laboratory-assembled tools: Built from commercial off‑the‑shelf (COTS) equipment.
- Application-specific tools: Dedicated instruments tailored to ISO/IEC 20085 measurement and analysis requirements.
- Test tool components:
- Measurement tool: Digitizers, timers or sensors that capture time-synchronised traces (voltage, EM field, timing) in digital format for later analysis.
- Analysis tool: Controls measurement, post-processes traces, and identifies successful attacks (including simple and advanced side-channel analysis).
- Test techniques & interactions: Operational modes and interfaces between measurement tool, analysis tool and the IUT; supports batch measurements, cartography and trace types (univariate/multivariate).
- Metrics & calibration: Measurement quality is characterized by metrics such as signal-to-noise ratio (S/N); calibration methods are covered in ISO/IEC 20085-2 to ensure reproducible, comparable results.
- Terminology and conformance: Aligns with ISO/IEC 17825 and ISO/IEC 19790 for terms, testing scope and security level conformance (notably Security Levels 3 and 4).
Applications and who uses it
- Security test laboratories and evaluators performing conformance and penetration testing of cryptographic modules.
- Module manufacturers and designers validating mitigation strategies against non-invasive attacks (side-channel resistance).
- Certification bodies and auditors assessing compliance with ISO/IEC 19790 security levels.
- Academic and industry researchers working on side-channel analysis, countermeasures and tool development.
Practical uses include vulnerability assessment, tool selection and calibration, reproducible attack emulation, and supporting certification for high-assurance cryptographic products.
Related standards
Keywords: ISO/IEC 20085-1:2019, non-invasive attack, side-channel, cryptographic modules, test tool, measurement tool, analysis tool, signal-to-noise ratio, calibration, ISO/IEC 17825, ISO/IEC 19790.