A multiple power analysis breaks the advanced version of the randomized addition-subtraction chains countermeasure against side channel attacks

A multiple power analysis breaks the advanced version of the randomized addition-subtraction chains countermeasure against side channel attacks
复制标题

DOI:
10.1109/itw.2003.1216723
复制
发表时间:
2003-08
期刊:
Proceedings 2003 IEEE Information Theory Workshop (Cat. No.03EX674)
影响因子:
--
通讯作者:
K. Okeya;K. Sakurai
K. Okeya;K. Sakurai
中科院分区:
其他
文献类型:
--
作者:
K. Okeya;K. Sakurai

文献摘要

相似文献

我们证明了针对侧信道攻击的随机加减链对策的高级版本在加法和加倍的可区分性下容易受到多重功率分析攻击(一种新型侧信道攻击)的攻击。侧信道攻击利用加密过程执行期间泄露的信息。随机加减链对策由 E. Oswald 和 M. Aigner 提出(参见 Comp. Sci. 中的 Lect. Notes,第 2162 卷,第 39-50 页,2001),并且基于插入计算中的随机决策。该对策有两个版本;分为基础版和高级版。基本版本已被证明容易受到旁路攻击。这是由于如果秘密标量的某个位为零,则随机化状态会收缩。不过高级版就没有这样的缩水了。多重功率分析使用多个AD序列,其是加法和加倍的序列,并且是通过可区分性和测量获得的。多重功率分析将 AD 序列相互关联,并推导出秘密标量。针对高级版本的多功率分析的一点是,将两种不同的状态组合起来,并视为相同的状态。如果秘密标量的某个位为零,则这会提供状态收缩。
We show that the advanced version of the randomized addition-subtraction chains countermeasure against side channel attacks is vulnerable to a multiple power analysis attack, a new kind of side channel attack, under distinguishability between addition and doubling. The side channel attack takes advantage of information leaked during execution of a cryptographic procedure. The randomized addition-subtraction chains countermeasure was proposed by E. Oswald and M. Aigner (see Lect. Notes in Comp. Sci., vol.2162, p.39-50, 2001), and is based on a random decision inserted into computations. The countermeasure has two versions; the basic version and the advanced version. The basic version has been proved to be vulnerable to a side channel attack. This is due to a shrinkage of states for randomization if a bit of the secret scalar is zero. However, the advanced version does not have such a shrinkage. The multiple power analysis uses plural AD sequences, which are sequences of additions and doublings, and obtained by the distinguishability and measurements. The multiple power analysis relates the AD sequences to each other, and deduces the secret scalar. A point of the multiple power analysis against the advanced version is that two different states are combined, and regarded as the same state. This provides a shrinkage of states if a bit of the secret scalar is zero.