Qorivva JTAG password - timing analysis

Does anyone have experience with bruteforcing the Qorivva JTAG password using power analysis? I’m trying to sketch up an attack for dumping firmware out of a MCU and evaluating possible attack surfaces.

Any info will be useful!