Side-Channel Attack on Substitution Blocks

Side-Channel Attack on Substitution Blocks
复制标题

DOI:
10.1007/978-3-540-45203-4_24
复制
发表时间:
2003-10
期刊:
--
影响因子:
--
通讯作者:
R. Novak
R. Novak
中科院分区:
其他
文献类型:
--
作者:
R. Novak

文献摘要

被引文献

相似文献

我们描述了对替换块的侧信道攻击,它通常被实现为表查找操作。特别是,我们研究了智能卡的实现。攻击是基于从功率测量中识别相等的中间结果,而这些中间值的实际值仍然未知。如果在多个迭代中使用相同的表,并且可以进行交叉迭代比较,则可以对替换块进行强大的攻击。攻击者可以使用该方法作为秘密算法的逆向工程工具的一部分。除了上述方法之外,还必须采用其他方法来完全恢复算法及其附带的密钥。我们已经成功地将该方法用于演示攻击在GSM网络中的SIM卡上实现的秘密认证和会话密钥生成算法。研究结果为设计安全的智能卡解决方案提供了指导,以防止此类攻击。
We describe a side-channel attack on a substitution block, which is usually implemented as a table lookup operation. In particular, we have investigated smartcard implementations. The attack is based on the identifying equal intermediate results from power measurements while the actual values of these intermediates remain unknown. A powerful attack on substitution blocks can be mounted if the same table is used in multiple iterations and if cross-iteration comparisons are possible. Adversaries can use the method as a part of reverse engineering tools on secret algorithms. In addition to the described method, other methods have to be employed to completely restore the algorithm and its accompanying secret key. We have successfully used the method in a demonstration attack on a secret authentication and session-key generation algorithm implemented on SIM cards in GSM networks. The findings provide guidance for designing smartcard solutions that are secure against this kind of attack.