Glossary

Power Analysis Attack

A power analysis attack extracts secret keys by measuring the electrical power consumption of a device during cryptographic operations.

Key Takeaways

  • A power analysis attack is a side-channel attack that recovers secret keys by measuring the electrical power a device consumes during cryptographic operations, rather than breaking the underlying mathematics.
  • Simple power analysis (SPA) reads key bits from a single power trace, while differential power analysis (DPA) uses statistical methods across many traces to extract keys even from noisy measurements.
  • Defenses include constant-power circuit design, data masking, random delays, and certified secure elements: this is why hardware wallet manufacturers invest in chips with Common Criteria EAL5+ or higher certification.

What Is a Power Analysis Attack?

A power analysis attack is a technique for extracting cryptographic secrets from a physical device by monitoring its electrical power consumption while it performs operations like signing transactions or decrypting data. Every transistor in a processor draws a slightly different amount of current depending on the data it processes and the operation it performs. By recording these power fluctuations with a high-resolution oscilloscope and a small resistor on the device's power line, an attacker can work backward from the measurements to reconstruct the private key stored inside.

First demonstrated by Paul Kocher, Joshua Jaffe, and Benjamin Jun in 1998, power analysis proved devastatingly effective against smart cards, embedded processors, and cryptographic coprocessors. Kocher reported that at the time of publication, no commercially available cryptographic smart card was immune to the technique. The attack class has since expanded and refined, driving significant changes in how secure hardware is designed and certified.

Unlike a brute-force attack that tries every possible key, power analysis exploits physical leakage. A 256-bit key that would take billions of years to guess can sometimes be recovered in minutes from a vulnerable device.

How It Works

The core insight behind power analysis is that a chip's power consumption is data-dependent. When a transistor switches from 0 to 1 (or 1 to 0), it draws a brief pulse of current. When it stays the same, it draws less. The aggregate switching activity across millions of transistors produces a measurable signal that correlates with the data being processed.

The attacker's setup is straightforward: insert a small resistor (typically 1 to 50 ohms) in series with the target device's power supply, then measure the voltage drop across it with an oscilloscope while the device executes a cryptographic operation. The resulting waveform is called a power trace.

Simple Power Analysis (SPA)

SPA works by visually or computationally inspecting a single power trace. It succeeds when different operations produce visibly distinct power signatures. The classic example is RSA signing using the square-and-multiply algorithm:

  • When the current key bit is 0, the algorithm performs only a squaring operation
  • When the current key bit is 1, it performs both a squaring and a multiplication

Because multiplication consumes more power and takes longer than squaring alone, each key bit produces a recognizably different pattern in the trace. An attacker can read the key bits directly from the shape of the waveform, much like reading Morse code.

SPA typically requires prior knowledge of the algorithm running on the device, since the attacker needs to know which operations to look for. It works best against implementations that use conditional branches (if/else logic) based on key bits.

# Pseudocode: vulnerable square-and-multiply
def modular_exponentiation(base, key, modulus):
    result = 1
    for bit in key_bits(key):
        result = (result * result) % modulus    # square (always)
        if bit == 1:
            result = (result * base) % modulus  # multiply (only for 1-bits)
    return result
# The conditional multiply leaks each key bit through power consumption

Differential Power Analysis (DPA)

DPA is far more powerful than SPA. Instead of reading a single trace, DPA collects thousands of traces from operations performed with the same key but different inputs. It then uses statistical analysis to extract the key, even when noise dominates the signal.

The attack proceeds in steps:

  1. Collect many power traces: the attacker records the device's power consumption across thousands of encryption or signing operations with known inputs (plaintexts)
  2. Hypothesize key bits: for a small portion of the key (typically one byte), the attacker generates all possible guesses (256 for an 8-bit subkey)
  3. Predict intermediate values: for each key guess and each known input, the attacker calculates what the intermediate value inside the cipher would be
  4. Correlate with measurements: using a power model (such as Hamming weight or Hamming distance), the attacker predicts the power consumption for each guess and compares it statistically against the real traces
  5. Identify the correct key: the key guess with the highest statistical correlation to the actual measurements is overwhelmingly likely to be correct

Kocher described the principle simply: everything that is not the key falls away with averaging, so even incredibly noisy measurements eventually reveal the key. This makes DPA effective against complex, noisy systems where cryptographic computations account for only a small fraction of the overall power consumption.

Correlation Power Analysis (CPA)

CPA is a refinement of DPA that uses Pearson correlation coefficients instead of difference-of-means. For each key hypothesis, CPA calculates the linear correlation between the predicted power model and the actual power measurements across all traces. This approach is more statistically efficient, typically requiring fewer traces to recover the key.

What Can Be Attacked

Power analysis has been successfully demonstrated against a wide range of cryptographic algorithms and hardware:

AlgorithmAttack TypeVulnerability
RSASPAConditional multiply in square-and-multiply reveals key bits
AESDPA / CPAS-box lookups leak Hamming weight of intermediate values
DESDPAFeistel round functions leak subkey information
ECCSPA / DPAPoint doubling vs. point addition reveals scalar bits
SHA-256 (in HMAC)DPAIntermediate hash state leaks key material during seed derivation

A 2024 study published in IEEE Access demonstrated a non-invasive attack that extracted master seeds from hardware wallets by capturing power traces during SHA-256 operations inside HMAC processing. The attack required no profiling phase and would be difficult for the wallet owner to detect.

Relevance to Bitcoin and Hardware Wallets

For Bitcoin users, power analysis is primarily a concern for hardware wallets and signing devices. These devices store private keys and perform digital signatures using elliptic curve cryptography on the secp256k1 curve. Each time the device signs a transaction, it executes scalar multiplication: the exact type of operation vulnerable to both SPA and DPA.

The threat model assumes an attacker with temporary physical access to the device. This could be a supply-chain compromise (the device is intercepted and modified before delivery), an "evil maid" scenario (someone accesses the device while the owner is away), or a border crossing where equipment is inspected. For a deeper look at hardware wallet threats, see the research article on Bitcoin hardware wallet attack vectors.

A poorly designed signing device running unprotected Schnorr or ECDSA signing could leak the private key in as few as a handful of signing operations. This is why the choice of hardware matters: a general-purpose microcontroller without side-channel protections is fundamentally less secure than a dedicated secure element built to resist these attacks.

Defenses and Countermeasures

Defending against power analysis requires a layered approach spanning hardware design, algorithm implementation, and certification.

Constant-Power Execution

The most direct defense is ensuring that power consumption does not vary with the data being processed. Techniques include:

  • Constant-time algorithms: rewrite cryptographic routines so they always execute the same sequence of operations regardless of the key value (for example, always performing both squaring and multiplication in RSA, discarding the unused result)
  • Balanced logic gates: use complementary circuit designs where every 0-to-1 transition is paired with a 1-to-0 transition, keeping total switching activity constant
  • Power-flattening circuits: add on-chip voltage regulators or current-smoothing circuits that mask the internal activity from external measurement

Masking (Randomization)

Masking splits sensitive intermediate values into random shares. Instead of computing directly on the key, the device works on randomized representations. Even if the attacker measures power from one share, they learn nothing without all shares.

However, masking has known limitations. First-order masking (using a single mask) is vulnerable to second-order DPA attacks, which combine measurements from two points in the computation to cancel the mask. Higher-order masking provides stronger protection but significantly increases execution time: implementations can be hundreds of times slower.

Random Delays and Noise Injection

Inserting random timing delays between operations desynchronizes the power traces, making statistical alignment difficult. Some secure chips also inject deliberate noise into their power consumption. These techniques do not eliminate leakage but can increase the number of traces required for a successful attack from thousands to millions.

Detect-and-Respond Mechanisms

Advanced secure elements include circuits that monitor for abnormal conditions: voltage glitches, unusual clock frequencies, or probing attempts. When triggered, the chip can erase all stored keys or permanently disable itself. This defeats both passive power measurement and active fault-injection attacks.

Common Criteria Certification

The Common Criteria (CC) framework provides standardized security evaluation for hardware. The evaluation assurance levels (EAL) most relevant to power analysis resistance are:

LevelDescriptionRelevance
EAL5+Semiformally designed and testedIncludes AVA_VAN.5 vulnerability analysis with side-channel testing
EAL6+Semiformally verified design and testedRequires demonstration of resistance to attackers with high attack potential

Chips used in modern hardware wallets typically carry EAL5+ or EAL6+ certification. The AVA_VAN.5 component of these evaluations specifically covers resistance to side-channel attacks including power analysis, electromagnetic emanation analysis, and timing analysis. Independent labs perform the evaluation, not the chip vendor, providing a level of assurance that vendor claims alone cannot.

Power Analysis vs. Other Side-Channel Attacks

Power analysis is one member of a broader family of side-channel attacks. Each exploits a different physical leakage channel:

Attack TypeLeakage ChannelEquipment Needed
Power analysis (SPA/DPA)Electrical current drawResistor + oscilloscope
Electromagnetic analysisEM radiation from chipNear-field EM probe
Timing attackExecution time variationPrecise timer (can be remote)
Cold boot attackDRAM data remanencePhysical access + cooling
Acoustic analysisSound from componentsSensitive microphone

Power analysis and electromagnetic analysis are closely related: both measure the physical effects of transistor switching. Electromagnetic attacks can sometimes be performed without direct contact with the device, making them a concern even for devices with hardened power pins. Defenses against power analysis (masking, constant-time code) generally also mitigate electromagnetic leakage.

Practical Considerations for Bitcoin Users

While power analysis requires physical access and specialized equipment, the threat is real for high-value targets. Users protecting significant Bitcoin holdings should consider:

  • Use hardware wallets with certified secure elements (EAL5+ or higher) rather than general-purpose microcontrollers
  • Verify the device's supply chain integrity: purchase directly from manufacturers and inspect for tampering upon delivery
  • Combine hardware wallets with multisig setups: even if one device is compromised, the attacker still lacks enough keys to spend funds
  • Consider air-gapped signing devices that never connect to networks, limiting the attacker's ability to exfiltrate captured data
  • Keep firmware updated: manufacturers regularly patch side-channel vulnerabilities as new attack techniques are published

Layer-2 solutions like Spark can reduce the frequency of on-chain signing operations, which in turn reduces the number of power traces an attacker could collect from a signing device. Fewer signing events means fewer opportunities for power analysis.

Risks and Considerations

Power analysis remains an active area of research with an ongoing arms race between attackers and defenders:

  • New attack refinements continue to emerge: higher-order DPA, template attacks, and machine learning-based trace classification can defeat individual countermeasures
  • No single countermeasure is sufficient on its own: effective defense requires combining constant-time code, masking, hardware protections, and detect-and-respond mechanisms
  • Open-source hardware wallets face a particular challenge: their designs are public, potentially making it easier for attackers to identify vulnerable code paths and build targeted attacks
  • Certification is not a guarantee: EAL5+ testing evaluates resistance at a defined attack potential, but state-level attackers may exceed that threshold
  • Remote power analysis is generally impractical today, but research into using built-in power sensors (for battery management or thermal throttling) as side channels is ongoing

For further reading on protecting Bitcoin keys from physical and cryptographic threats, see the research articles on seed phrase entropy and security and post-quantum cryptography threats to Bitcoin.

This glossary entry is for informational purposes only and does not constitute financial or investment advice. Always do your own research before using any protocol or technology.