Phillip Hallam-Baker phill at hallambaker.com
Mon Jun 22 17:52:16 EDT 2020

I am looking into making some videos on side channel attacks. There are two
separate types of attack I am looking at.

The first, I am calling 'leakage' where an unintended side channel leaks
information to an attacker. Timing attacks, power etc come under this

The second I am calling 'exfiltration' in which the system designer
intentionally leaks information. For example, Dual EX RNG, or Moti
Yung's smuggling the RSA seed in the top bits of an RSA modulus.

In between there are induced side channel attacks such as hitting a chip
with radiation while it is operating, smartcard in microwave, etc.

Does this leakage/induced/exfiltration nomenclature make sense or should I
use something else?
