On Second-Order Difierential Power Analysis ?

Difierential Power Analysis (DPA) is a powerful cryptana- lytic technique aiming at extracting secret data from a cryptographic device by collecting power consumption traces and averaging over a se- ries of acquisitions. In order to prevent the leakage, hardware designers and software programmers make use of masking techniques (a.k.a. data whitening methods). However, the resulting implementations may still succumb to second-order DPA. Several recent papers studied second- order DPA but, although the conclusions that are drawn are correct, the analysis is not. This paper fllls the gap by providing an exact analysis of second-order DPA as introduced by Messerges. It also considers several generaliza- tions, including an extended analysis in the more general Hamming- distance model.