Abstract
This chapter presents a practical case study of side-channel analysis. The work studies the security of the Google Titan Security Key1 (a hardware security token for two-factor authentication) and shows that its secure element, the NXP A700x chip, is susceptible to a side-channel attack (through the observation of its local electromagnetic (EM) activity). Given physical access to a Google Titan Security Key for around 10 hours, this allows us to retrieve a user-specific secret key (there is one key for each remote account) and therefore to clone the security device.