
Proof-of-concept demonstrating a power analysis side-channel attack against a vulnerable RSA implementation on Arduino (Atmega328P), with detailed hardware setup and measurement methodology.
Recently, I observed people implementing cryptography for Arduino by themselves like state in this topic in stackoverflow:
https://stackoverflow.com/questions/39189065/rsa-encryption-decryption-functions-for-arduino
Several of them can be found over the internet, some by the way are in well-knowm libraries.
I decide to do this small PoC ( Proof of concept )to show why is important not invented your own cryptography algorithm, but also use a robust implementation of such a algorithms.
This PoC performs an side channel attack ( power analysis attack ) against a bad implementation of an auxiliary routine used in the RSA implementation ( fast exponentiation).
A side-channel attack is a method of compromising a cryptographic system by exploiting indirect information leakage rather than directly attacking the cryptographic algorithm or protocol itself.
This type of leakage can originate from various sources such as timing information, power consumption, electromagnetic emissions, or even sound.
Such attacks can be highly effective in compromising cryptographic systems like RSA without requiring the attacker to solve the underlying mathematical problems that ensure the security of the cryptographic scheme (Kocher, Jaffe, & Jun, 1999).
This paper will perform a power analysis attack on a well-known vulnerability in an implementation of the RSA algorithm in a firmware for Arduino ( Atmega328P).
Note I did it on the rush, please forgive me for the spells / grammar errors that eventually you will find.
Power analysis attacks involve measuring the power consumption of a device during cryptographic operations.
Differential Power Analysis (DPA) involves statistical analysis of power consumption patterns across multiple cryptographic operations to extract secrets, making it more sophisticated than Simple Power Analysis (SPA), which directly correlates power fluctuations with specific cryptographic operations to deduce secrets.
Differential Power Analysis (DPA) and Simple Power Analysis (SPA) can be used to extract private keys by analyzing patterns in power consumption during RSA computations.
These attacks can reveal the private key by identifying distinct power usage patterns associated with different key bits (Kocher, Jaffe, & Jun, 1999).
RSA (Rivest-Shamir-Adleman) is a widely used public-key encryption algorithm named after its inventors: Ron Rivest, Adi Shamir, and Leonard Adleman, who introduced it in 1977 (Paar & Pelzl, 2010).
It remains one of the most secure methods for transmitting data securely over the internet.
One of the foundations of RSA's security lies in the difficulty of factoring large composite numbers into their prime factors (Menezes, van Oorschot, & Vanstone, 1996).
This problem, known as the factoring problem, involves finding the prime numbers that multiply together to form a given large number.
RSA encryption relies on the assumption that this factoring problem is computationally difficult enough to make it impractical to break the encryption by factoring the modulus into its prime factors (Menezes, van Oorschot, & Vanstone, 1996).
The Figure 1 illustrates the RSA encryption and decryption process using a simple example.

Figure 1 - RSA example.
Please note that in this case, 3 and 33 are public. The number 7 in the example is the private key.
The Phi (N) function, Euler's totient function, computes all coprime numbers in the interval from 1 to 33.
The value 33 is obtained from the multiplication of P and Q; in this case, 11 multiplied by 3.
The result of the Phi function is obtained by multiplying (P - 1) by (Q - 1); in this case, 10 multiplied by 2.
The operation e<sup>-1</sup> mod 20 denotes the modular inverse operation (Menezes, van Oorschot, & Vanstone, 1996).
Note: If you wish to delve deeper into RSA, which is not necessary to understand this paper. There is a quick introduction to these basic number theory operations within this repository the file number_theory.md. The explanation can enhance your understanding of RSA operations.
The experiment used an osciloscope DS1102 (presented in the Figure 2) manufactured by Rigol.
The osciloscope's manual can be found in the references (RIGOL Technologies, Inc., 2017).
A generic power supply was used either ( presented in Figure 3).

Figure 2 - Oscilloscope used in the experiment.

Figure 3 - Power supply used in the experiment.
Ohm's Law is a fundamental principle in the field of electrical engineering and physics.
It states that the current flowing through a conductor between two points is directly proportional to the voltage across the two points and inversely proportional to the resistance between them (Boylestad, 2015).
The Figure 4 shows an circuit and the Ohm's law.

Figure 4 - Ohm law illustration.
The Ohm law implies that if you increase the voltage across a conductor, the current will also increase, provided the resistance remains constant(Johnson & Hilburn, 2013). Figure 5 present an example of Ohm's law application which the goal is to find the current in the circuit.

Figure 5 - Ohm law example.
Kirchhoff's Voltage Law (KVL) is a fundamental principle in electrical engineering and physics (Boylestad, 2015).
It states that the sum of all electrical potential differences (voltages) around any closed network or loop is zero (Boylestad, 2015).
The Figure 6 ilustrates the Kirchhoff's voltage law.

Figure 6 - Kirchhoff law illustration.
There is an example of the Kirchhoff's law's application in the Figure 7 in order to find the current over the
resistors R1 and R2.

Figure 7 - Kirchhoff law example.
The voltage divider is a consequence of Kirchhoff's Voltage Law (KVL) and states a way to calculates the Vout that is the voltage between
the resistor R1and R2.
The formula of the voltage divider is presented in the Figure 8.
An example of voltage divider application is presented in the Figure 9.