📖 ABSTRACT/OVERVIEW
ARM Cortex-M based microcontrollers are widely used in Nigerian point-of-sale terminals, payment cards, and ATM peripherals, and their cryptographic implementations may be vulnerable to side-channel attacks that extract secret keys through power consumption or electromagnetic emissions, a security risk that has not been empirically assessed in the Nigerian FinTech device context. This study empirically evaluated the side-channel attack resistance of AES-128 software and hardware accelerator implementations on STM32F407 and STM32H743 (Cortex-M4 and M7) microcontrollers using correlation power analysis and simple power analysis. A custom power measurement setup using a 1-ohm shunt resistor and a Picoscope 6424E oscilloscope captured power traces during AES encryption operations. For the software AES implementation on Cortex-M4, a successful key recovery was demonstrated after 12,000 power traces using 256-byte trace windows, requiring approximately 22 minutes of measurement time. The hardware AES accelerator on the same Cortex-M4 required 45,000 traces, offering 3.75x improved resistance but not full immunity. Applying masking countermeasures to the software implementation increased traces required to 61,000, a 5.1x improvement. The Cortex-M7 hardware AES showed the strongest resistance, requiring more than 100,000 traces beyond the practical experimental budget. The study fills a gap in Nigerian FinTech device security assessment literature and recommends CBN mandate side-channel attack resistance testing as part of payment terminal type approval and require hardware AES accelerator usage in new POS terminal certification requirements.
Keywords: side-channel attack, ARM Cortex-M, AES, FinTech security, power analysis
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬