Power randomization is a hardware-level countermeasure against power analysis side-channel attacks, in which an adversary monitors a device's power consumption during cryptographic or other security-sensitive operations to extract secret information such as cryptographic keys by correlating power traces with internal computational states. The technique uses an on-chip hardware mechanism to add data-independent or randomized power activity intended to reduce the observable signal-to-noise ratio between measured power consumption and security-sensitive internal computations. Power randomization increases the number or sophistication of measurements required for power analysis but does not eliminate the underlying leakage or guarantee resistance against averaging, profiling, multi-trace, or higher-order analysis. Power randomization must be incorporated into the chip architecture or selected as an existing capability of the target device. Its implementation can increase dynamic power consumption, die area, thermal load, design and verification complexity, non-recurring engineering cost, and potentially unit fabrication cost. Resulting spacecraft-level mass or volume impacts depend on packaging, power-delivery, and thermal-management consequences. These tradeoffs must be evaluated during the system design phase against the mission's threat model and the availability of alternative or complementary side-channel countermeasures, with power randomization selected where the protection it provides justifies its SWaP and cost impact.
Sources
J. Daemen and V. Rijmen. Resistance against implementation attacks: A comparative study of the ales proposals. In The Second AES Candidate Conference, pages 122–132, Gaithersburg, MD, 1999. National Institute of Standards and Technology.
ID: CM0058
Tier: III
Onboard SV CM
Created: 2022/10/19
Last Modified: 2026/08/06
Pre-Operations Government
Acquisition requirements should address power analysis side-channel resistance as a security design requirement for chips performing cryptographic or other security-sensitive operations, with power randomization identified as one candidate implementation approach and the selection among available countermeasures governed by a documented trade analysis that accounts for the mission's SWaP constraints and threat environment. Requirements should specify the level of power analysis resistance required for each chip type, expressed in terms of resistance to simple power analysis (SPA) and differential power analysis (DPA) attacks, and should require that the selected countermeasure's effectiveness be validated through testing rather than accepted solely on design assertion. Contract language should require that any chip incorporating power randomization or equivalent side-channel countermeasures have the implementation documented as a controlled design attribute, with the SWaP and cost impact quantified and reflected in the system resource budget. Evaluation criteria should assess offerors' proposed approach to power analysis resistance for security-critical chip functions, the rigor of their side-channel evaluation methodology, and their demonstrated experience balancing side-channel protection requirements against SWaP constraints in space-grade hardware. Verification should include side-channel evaluation testing, such as power trace acquisition and statistical analysis, on production-representative hardware samples to confirm that the implemented countermeasure achieves the required level of power analysis resistance.
Pre-Operations Developer/Supplier
Power-randomization requirements must be addressed during component selection and hardware architecture design. For a custom ASIC or other custom-fabricated device, the mechanism must be incorporated and verified before tape-out. For an existing commercial or supplier-designed device, the program must select a component that already implements the required capability and obtain sufficient assurance evidence for the specific device, configuration, and manufacturing revision. The trade analysis for power randomization should quantify the specific SWaP impact on the target platform, comparing power overhead, die area increase, and fabrication cost increment against the side-channel protection benefit, and documenting this analysis as part of the hardware security design record. Where full power randomization across all chip functions is not feasible within SWaP margins, selective application to the most security-sensitive functions, particularly cryptographic execution paths, should be evaluated as a focused alternative that limits SWaP impact while protecting the highest-risk operations. Power randomization should be evaluated alongside complementary countermeasures such as masking or secret sharing, balanced or hiding logic, execution shuffling, observation limits, and physical shielding. Combined protections must be evaluated as an integrated implementation because countermeasure interactions, shared randomness, compiler behavior, glitches, synchronization, and implementation leakage may reduce the expected protection. Equivalent resistance and lower total SWaP impact must be demonstrated rather than assumed from the individual countermeasures. Side-channel evaluation must measure the residual relationship between security-sensitive computations and observable leakage, not merely the amount of noise produced by the randomization module. Testing must determine whether the remaining leakage can be exploited within the mission-defined adversary model and observation budget.
Sustainment & Maintenance Government
Software and firmware updates that change the protected computation, instruction sequence, memory behavior, countermeasure activation, randomization controls, or power and clock configuration must undergo regression analysis and side-channel retesting commensurate with the change. Where the hardware exposes countermeasure status, randomness-health, configuration, or fault indications, those indicators should be monitored and failures must invoke a defined response. On-orbit hardware generally cannot be redesigned, but configuration changes or software updates must not disable, bypass, or invalidate the assumptions under which the power-randomization mechanism was evaluated.
Sustainment & Maintenance Developer/Supplier
Software and firmware updates that change the protected computation, instruction sequence, memory behavior, countermeasure activation, randomization controls, or power and clock configuration must undergo regression analysis and side-channel retesting commensurate with the change. Where the hardware exposes countermeasure status, randomness-health, configuration, or fault indications, those indicators should be monitored and failures must invoke a defined response. On-orbit hardware generally cannot be redesigned, but configuration changes or software updates must not disable, bypass, or invalidate the assumptions under which the power-randomization mechanism was evaluated.
Information is extracted not by reading files or decrypting frames but by observing physical or protocol byproducts of computation, power draw, electromagnetic emissions, timing, thermal signatures, or traffic patterns. Repeated measurements create distinctive fingerprints correlated with internal states (key use, table loads, parser branches, buffer occupancy). Matching those fingerprints to models or templates yields sensitive facts without direct access to the protected data. In space systems, vantage points span proximity assets (for EM/thermal), ground testing and ATLO (for direct probing), compromised on-board modules that can sample rails or sensors, and remote observation of link-layer timing behaviors.
The attacker infers secrets by measuring instantaneous power consumption of target devices, often crypto engines or controllers, and correlating traces with hypothesized internal operations. Simple power analysis (SPA) extracts structure (operation sequences, key-dependent branches); differential/correlation power analysis (DPA/CPA) uses many traces and statistics to recover key bits from tiny data-dependent variations. Practically, measurements may come from instrumented rails during I&T, from a compromised payload monitoring local supplies, or from co-located hardware that senses current/voltage fluctuations. With sufficient traces and alignment (triggering on command/crypto invocation), internal values become observable through their power signatures.
The [spacecraft] shall protect system components, associated data communications, and communication buses in accordance with: (i) national emissions and TEMPEST policies and procedures, and (ii) the security category or sensitivity of the transmitted information, and shall demonstrate compliance via pre‑launch TEMPEST‑like evaluation for co‑located payload configurations.{SV-CF-2,SV-MA-2}{PE-14,PE-19,PE-19(1),RA-5(4),SA-8(18),SA-8(19),SC-8(1)}
The measures taken to protect against compromising emanations must be in accordance with DODD S-5200.19, or superseding requirements. The concerns addressed by this control during operation are emanations leakage between multiple payloads within a single space platform, and between payloads and the bus.
SPR-38
The [spacecraft] shall be designed so that it protects itself from information leakage due to electromagnetic signals emanations.{SV-CF-2,SV-MA-2}{PE-19,PE-19(1),RA-5(4),SA-8(19)}
This requirement applies if system components are being designed to address EMSEC and the measures taken to protect against compromising emanations must be in accordance with DODD S-5200.19, or superseding requirements.
SPR-115
The [organization] shall describe (a) the separation between RED and BLACK cables, (b) the filtering on RED power lines, (c) the grounding criteria for the RED safety grounds, (d) and the approach for dielectric separators on any potential fortuitous conductors, and shall provide quantitative separation distances, filter specifications, grounding resistance criteria, and dielectric separator material properties.{SV-CF-2,SV-MA-2}{PE-19,PE-19(1)}
Physical separation of classified (RED) and unclassified (BLACK) signal paths prevents compromising emanations. Defined separation distances, filtering, and grounding reduce leakage risk. Quantitative criteria ensure repeatable and verifiable implementation. This protects against unintended signal coupling and data leakage.