Test Vector Leakage Assessment ( TVLA ) methodology in practice

Many security standards require cryptographic devices and modules to resist side-channel attacks such as Timing Analysis as well as Simple and Differential Power/Electromagnetic Analysis. These requirements have also been included in the draft FIPS 140-3 standard [1]. However, existing security certification standards mandating side-channel resistance, such as Common Criterion, require an evaluation style testing approach to verify compliance. Such evaluation style testing approaches are not suitable for a conformance style testing program such as CMVP, and effective, yet cost-efficient, conformance style testing for side-channel resistance has been seen as a challenge.