Predicting Secret Keys Via Branch Prediction

Predicting Secret Keys Via Branch Prediction
复制标题

DOI:
10.1007/11967668_15
复制
发表时间:
2007-02
期刊:
--
影响因子:
--
通讯作者:
O. Aciiçmez;Ç. Koç;Jean-Pierre Seifert
O. Aciiçmez;Ç. Koç;Jean-Pierre Seifert
中科院分区:
其他
文献类型:
--
作者:
O. Aciiçmez;Ç. Koç;Jean-Pierre Seifert

文献摘要

被引文献

相似文献

本文提出了一种新的软件侧信道攻击——利用所有现代高性能cpu通用的分支预测能力。错误预测分支所付出的代价(额外的时钟周期)可用于使用依赖于数据的程序流的加密原语的密码分析。与最近描述的基于缓存的侧通道攻击类似,我们的攻击也允许无特权进程攻击在同一处理器上并行运行的其他进程,尽管使用了复杂的分区方法,如内存保护、沙箱甚至虚拟化。在本文中,我们将以RSA为例讨论几种这样的攻击,并通过实验证明它们在实际系统(如OpenSSL和Linux)中的适用性。此外,我们还将演示分支预测侧信道攻击的强度,在这种情况下,通过将明显的对策(带有虚拟减少的蒙哥马利乘法)呈现为无用的。尽管后一种结果的更深层次的后果使得编写高效和安全的模幂运算(或椭圆曲线上的标量乘法)的任务具有挑战性,但我们最终将提出一些对策来减轻分支预测侧信道攻击。
This paper announces a new software side-channel attack — enabled by the branch prediction capability common to all modern high-performance CPUs. The penalty paid (extra clock cycles) for a mispredicted branch can be used for cryptanalysis of cryptographic primitives that employ a data-dependent program flow. Analogous to the recently described cache-based side-channel attacks our attacks also allow an unprivileged process to attack other processes running in parallel on the same processor, despite sophisticated partitioning methods such as memory protection, sandboxing or even virtualization. In this paper, we will discuss several such attacks for the example of RSA, and experimentally show their applicability to real systems, such as OpenSSL and Linux. Moreover, we will also demonstrate the strength of the branch prediction side-channel attack by rendering the obvious countermeasure in this context(Montgomery Multiplication with dummy-reduction)as useless. Although the deeper consequences of the latter result make the task of writing an efficient and secure modular exponentiation (or scalar multiplication on an elliptic curve) a challenging task, we will eventually suggest some countermeasures to mitigate branch prediction side-channel attacks.