Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
power_analysis — Proof-of-concept demonstrating a power analysis side-channel attack against a vulnerable RSA implementation on Arduino (Atmega328P), with detailed hardware setup and measurement methodology. | Kitploit
Tools/GitHubGitHub/lord-feistel/power_analysis
Embedded Systems SecurityCryptographyHardware SecurityPapers & ResearchLearning & Education
GitHublord-feistel/power_analysis

power_analysis

Proof-of-concept demonstrating a power analysis side-channel attack against a vulnerable RSA implementation on Arduino (Atmega328P), with detailed hardware setup and measurement methodology.

View Repository
324672 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Power analysis attack over RSA

Index

Index

  • Introduction
  • Power Analysis Attacks
  • RSA: A Short Introduction
  • RSA Example
  • Equipment
  • Measuring Power: A Short Introduction
    • Ohm's Law
    • Kirchhoff's Voltage Law (KVL)
    • Voltage Divider
    • Shunt Resistor
  • Example Power Measurement
  • Fast Exponentiation
  • Fast Exponentiation in Arduino (Atmega328P)
  • Results
  • Conclusion
  • References

Introduction

Recently, I observed people implementing cryptography for Arduino by themselves like state in this topic in stackoverflow:

https://stackoverflow.com/questions/39189065/rsa-encryption-decryption-functions-for-arduino

Several of them can be found over the internet, some by the way are in well-knowm libraries.

I decide to do this small PoC ( Proof of concept )to show why is important not invented your own cryptography algorithm, but also use a robust implementation of such a algorithms.

This PoC performs an side channel attack ( power analysis attack ) against a bad implementation of an auxiliary routine used in the RSA implementation ( fast exponentiation).

A side-channel attack is a method of compromising a cryptographic system by exploiting indirect information leakage rather than directly attacking the cryptographic algorithm or protocol itself.

This type of leakage can originate from various sources such as timing information, power consumption, electromagnetic emissions, or even sound.

Such attacks can be highly effective in compromising cryptographic systems like RSA without requiring the attacker to solve the underlying mathematical problems that ensure the security of the cryptographic scheme (Kocher, Jaffe, & Jun, 1999).

This paper will perform a power analysis attack on a well-known vulnerability in an implementation of the RSA algorithm in a firmware for Arduino ( Atmega328P).

Note I did it on the rush, please forgive me for the spells / grammar errors that eventually you will find.

Power Analysis Attacks

Power analysis attacks involve measuring the power consumption of a device during cryptographic operations.

Differential Power Analysis (DPA) involves statistical analysis of power consumption patterns across multiple cryptographic operations to extract secrets, making it more sophisticated than Simple Power Analysis (SPA), which directly correlates power fluctuations with specific cryptographic operations to deduce secrets.

Differential Power Analysis (DPA) and Simple Power Analysis (SPA) can be used to extract private keys by analyzing patterns in power consumption during RSA computations.

These attacks can reveal the private key by identifying distinct power usage patterns associated with different key bits (Kocher, Jaffe, & Jun, 1999).

RSA: A Short Introduction

RSA (Rivest-Shamir-Adleman) is a widely used public-key encryption algorithm named after its inventors: Ron Rivest, Adi Shamir, and Leonard Adleman, who introduced it in 1977 (Paar & Pelzl, 2010).

It remains one of the most secure methods for transmitting data securely over the internet.

One of the foundations of RSA's security lies in the difficulty of factoring large composite numbers into their prime factors (Menezes, van Oorschot, & Vanstone, 1996).

This problem, known as the factoring problem, involves finding the prime numbers that multiply together to form a given large number.

RSA encryption relies on the assumption that this factoring problem is computationally difficult enough to make it impractical to break the encryption by factoring the modulus into its prime factors (Menezes, van Oorschot, & Vanstone, 1996).

RSA Example

The Figure 1 illustrates the RSA encryption and decryption process using a simple example.

RSA Example

Figure 1 - RSA example.

Please note that in this case, 3 and 33 are public. The number 7 in the example is the private key.

The Phi (N) function, Euler's totient function, computes all coprime numbers in the interval from 1 to 33.

The value 33 is obtained from the multiplication of P and Q; in this case, 11 multiplied by 3.

The result of the Phi function is obtained by multiplying (P - 1) by (Q - 1); in this case, 10 multiplied by 2.

The operation e<sup>-1</sup> mod 20 denotes the modular inverse operation (Menezes, van Oorschot, & Vanstone, 1996).

Note: If you wish to delve deeper into RSA, which is not necessary to understand this paper. There is a quick introduction to these basic number theory operations within this repository the file number_theory.md. The explanation can enhance your understanding of RSA operations.

Equipament

The experiment used an osciloscope DS1102 (presented in the Figure 2) manufactured by Rigol.

The osciloscope's manual can be found in the references (RIGOL Technologies, Inc., 2017).

A generic power supply was used either ( presented in Figure 3).

osciloscope

Figure 2 - Oscilloscope used in the experiment.

power_supply

Figure 3 - Power supply used in the experiment.

Meansuring power a short introduction

Ohm Law

Ohm's Law is a fundamental principle in the field of electrical engineering and physics.

It states that the current flowing through a conductor between two points is directly proportional to the voltage across the two points and inversely proportional to the resistance between them (Boylestad, 2015).

The Figure 4 shows an circuit and the Ohm's law.

ohm_law

Figure 4 - Ohm law illustration.

The Ohm law implies that if you increase the voltage across a conductor, the current will also increase, provided the resistance remains constant(Johnson & Hilburn, 2013). Figure 5 present an example of Ohm's law application which the goal is to find the current in the circuit.

ohm_example

Figure 5 - Ohm law example.

Kirchoff law and

Kirchhoff's Voltage Law (KVL) is a fundamental principle in electrical engineering and physics (Boylestad, 2015).

It states that the sum of all electrical potential differences (voltages) around any closed network or loop is zero (Boylestad, 2015).

The Figure 6 ilustrates the Kirchhoff's voltage law.

kirchoff_lay

Figure 6 - Kirchhoff law illustration.

There is an example of the Kirchhoff's law's application in the Figure 7 in order to find the current over the resistors R1 and R2.

kirchoff_example

Figure 7 - Kirchhoff law example.

Voltage divider

The voltage divider is a consequence of Kirchhoff's Voltage Law (KVL) and states a way to calculates the Vout that is the voltage between the resistor R1and R2.

The formula of the voltage divider is presented in the Figure 8.

An example of voltage divider application is presented in the Figure 9.

Download Tool