EMV Power Side-Channel Analysis
Budget: $15 – $25 USD
We are looking for a Machine Learning expert with proven experience in Side-Channel Analysis (SCA) to help build a full ML pipeline capable of extracting sensitive cryptographic information from 4-channel smart-card traces (Power, Clock, I/O, Trigger).
The objective is to train and deploy ML models that can perform single-trace or reduced-trace key recovery, including 3DES, RSA private key extraction, PIN recovery, and Track 2 reconstruction, based on the data and workflow outlined in our technical documents.
Core Requirements (Machine Learning & SCA)
The freelancer must be capable of delivering the following:
1. Trace Pre-Processing & Alignment
Filtering, normalization, denoising, jitter correction
Automatic alignment of thousands of EM traces
Region-of-Interest (ROI) detection for DES / 3DES / RSA operations
ML expert
2. Dataset Preparation
Build labeled datasets from multi-trace captures
Implement augmentation strategies for noise robustness
Prepare training sets for CPA-assisted or standalone ML attacks
ML expert
3. Model Design, Training & Validation
Develop CNN, LSTM, or Transformer-based SCA models
Train ML models to recover:
3DES subkeys via first-round S-Box leakage
RSA private exponent (d) from square-and-multiply leakage
Single-trace key inference models
Hyperparameter tuning and performance reporting
ML expert
4. Inference Pipeline (Single-Trace or Reduced-Trace)
Create a Python-based inference tool that takes one power trace and outputs:
Key hypotheses
Confidence scoring
ROI visualization
Must integrate with our hardware capture pipeline (Husky / oscilloscope workflow)
ML expert
5. EMV-Specific Leakage Expertise
The ML expert must understand or be willing to learn:
Track-2 / EMV data extraction from I/O lines (C7)
3DES cryptogram generation (GENERATE AC)
RSA VERIFY command and modulus extraction (Tag 9F46)
Leakage patterns for DES rounds, RSA S&M operations, and PIN block structures
Track2-3DES-From-4Channel Data
RSA-Pin-4Chaneel Data
6. Deliverables
The final delivery must include:
Fully documented preprocessing pipeline
Trained ML models
Python scripts for inference, training, and visualization
ROI definitions & performance benchmarks
Instructions for integrating the inference engine with Husky/PC capture scripts
ML expert
Ideal Freelancer
Strong background in Machine Learning + Signal Processing
Prior experience with Side-Channel Analysis (CPA, DPA, Template Attacks)
Experience with cryptography (DES/3DES, RSA) is a major advantage
Ability to convert raw oscilloscope/Husky traces into ML-ready datasets
To Apply
Please share:
Relevant ML/SCA experience
Examples of similar projects
Proposed approach and timeline
The objective is to train and deploy ML models that can perform single-trace or reduced-trace key recovery, including 3DES, RSA private key extraction, PIN recovery, and Track 2 reconstruction, based on the data and workflow outlined in our technical documents.
Core Requirements (Machine Learning & SCA)
The freelancer must be capable of delivering the following:
1. Trace Pre-Processing & Alignment
Filtering, normalization, denoising, jitter correction
Automatic alignment of thousands of EM traces
Region-of-Interest (ROI) detection for DES / 3DES / RSA operations
ML expert
2. Dataset Preparation
Build labeled datasets from multi-trace captures
Implement augmentation strategies for noise robustness
Prepare training sets for CPA-assisted or standalone ML attacks
ML expert
3. Model Design, Training & Validation
Develop CNN, LSTM, or Transformer-based SCA models
Train ML models to recover:
3DES subkeys via first-round S-Box leakage
RSA private exponent (d) from square-and-multiply leakage
Single-trace key inference models
Hyperparameter tuning and performance reporting
ML expert
4. Inference Pipeline (Single-Trace or Reduced-Trace)
Create a Python-based inference tool that takes one power trace and outputs:
Key hypotheses
Confidence scoring
ROI visualization
Must integrate with our hardware capture pipeline (Husky / oscilloscope workflow)
ML expert
5. EMV-Specific Leakage Expertise
The ML expert must understand or be willing to learn:
Track-2 / EMV data extraction from I/O lines (C7)
3DES cryptogram generation (GENERATE AC)
RSA VERIFY command and modulus extraction (Tag 9F46)
Leakage patterns for DES rounds, RSA S&M operations, and PIN block structures
Track2-3DES-From-4Channel Data
RSA-Pin-4Chaneel Data
6. Deliverables
The final delivery must include:
Fully documented preprocessing pipeline
Trained ML models
Python scripts for inference, training, and visualization
ROI definitions & performance benchmarks
Instructions for integrating the inference engine with Husky/PC capture scripts
ML expert
Ideal Freelancer
Strong background in Machine Learning + Signal Processing
Prior experience with Side-Channel Analysis (CPA, DPA, Template Attacks)
Experience with cryptography (DES/3DES, RSA) is a major advantage
Ability to convert raw oscilloscope/Husky traces into ML-ready datasets
To Apply
Please share:
Relevant ML/SCA experience
Examples of similar projects
Proposed approach and timeline