Paper 2026/2071

Soft Analytical Side-Channel Attacks on SHA-2 and HMAC

Maxime Lecomte, Univ. Grenoble Alpes, CEA, Leti, F-38000 Grenoble, France.
Julien Maillard, Univ. Grenoble Alpes, CEA, Leti, F-38000 Grenoble, France.
Antoine Moran, Univ. Grenoble Alpes, CEA, Leti, F-38000 Grenoble, France., LIX, CNRS, École polytechnique, Institut Polytechnique de Paris, Palaiseau, France.
Guénaël Renault, ANSSI
Benjamin Smith, LIX, CNRS, École polytechnique, Institut Polytechnique de Paris, Palaiseau, France.
Abstract

We investigate the use of bit-level Soft Analytical Side-Channel Attacks (SASCA) to recover secret inputs of the SHA-256 hash function, and secret keys of HMAC-SHA-256, using Sentential Decision Diagrams to overcome the computational challenge posed to classical Belief Propagation by multiple-word modular addition. Our attack on HMAC requires no control nor knowledge of the input, and exploits its double manipulation of the key to improve key-recovery performance. We make comprehensive simulations to evaluate the attacker’s recovery capacity for both SHA-256 and HMAC-SHA-256. Finally, we study the profiling capabilities of load instructions in a multiposition EM probe setup on a STM32F303RET6 microcontroller, and use these results to evaluate the capability of our attack against software implementations of HMAC-SHA-256 in a realistic scenario.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published by the IACR in TCHES 2026
DOI
10.46586/tches.v2026.i3.1205-1227
Keywords
Side-Channel AttackSASCASHA-256HMACSentential Decision Diagrams
Contact author(s)
antoine moran @ cea fr
History
2026-09-19: approved
2026-09-17: received
See all versions
Short URL
https://ia.cr/2026/2071
License
Creative Commons Attribution-ShareAlike
CC BY-SA

BibTeX

@misc{cryptoeprint:2026/2071,
      author = {Maxime Lecomte and Julien Maillard and Antoine Moran and Guénaël Renault and Benjamin Smith},
      title = {Soft Analytical Side-Channel Attacks on {SHA}-2 and {HMAC}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2071},
      year = {2026},
      doi = {10.46586/tches.v2026.i3.1205-1227},
      url = {https://eprint.iacr.org/2026/2071}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.