Further Security Analysis of XTR

Further Security Analysis of XTR
复制标题

DOI:
10.1007/11689522_4
复制
发表时间:
2006-04
期刊:
--
影响因子:
--
通讯作者:
Dong‐Guk Han;T. Takagi;Jongin Lim
Dong‐Guk Han;T. Takagi;Jongin Lim
中科院分区:
其他
文献类型:
--
作者:
Dong‐Guk Han;T. Takagi;Jongin Lim

文献摘要

被引文献

相似文献

在Crypto 2000和2003年,Lenstra-Verheul和Rubin-Silverberg分别提出了XTR公钥密码体制和基于环面的公钥密码体制CEILIDH。XTR和CEILIDH的共同的主要思想是缩短传输数据的带宽。由于格兰杰等人的贡献,这是CEILIDH和XTR的性能比较结果,XTR是一个很好的替代RSA或ECC在一些应用中,其中计算能力和存储容量都非常有限,如智能卡。在XTR算法家族中,改进的XTR单指数算法(XTR-ISE)是最有效的一种,它只计算单指数。然而,很少有论文研究XTR-ISE的侧信道攻击,即使内存受限的设备遭受最脆弱的侧信道攻击。Chung-Hasan和Page-Stam试图用已知的简单功效分析来分析XTR-ISE,但不幸的是,他们的方法在实践中并不可行。最近,Han等人提出了一种新的碰撞攻击方法,当密钥长度为160位时,其分析复杂度为O(240)。在本文中,我们分析XTR-ISE从另一个角度,即差分功率分析(DPA)。一个简单的结果是XTR-ISE可以从原始DPA中解放出来。然而,一个重要的结果是,本文提出的增强DPA威胁到XTR-ISE。此外,我们显示了XTR-ISE结构的几个弱点。从我们的模拟结果,我们表明,该攻击需要约584次查询DPA_Oracle检测整个160位的秘密值。该结果表明,XTR-ISE易受所提出的增强DPA的影响。
In Crypto 2000 and 2003, Lenstra-Verheul and Rubin- Silverberg proposed XTR public key system and torus based public key cryptosystem CEILIDH, respectively. The common main idea of XTR and CEILIDH is to shorten the bandwidth of transmission data. Due to the contribution of Granger et al., that is the comparison result of the performance of CEILIDH and XTR, XTR is an excellent alternative to either RSA or ECC in some applications, where computational power and memory capacity are both very limited, such as smart-cards. Among the family of XTR algorithm, Improved XTR Single Exponentiation (XTR-ISE) is the most efficient one, which computes single exponentiation. However, there are few papers investigating the side channel attacks of XTR-ISE, even though the memory constraint devices suffer most from vulnerability to side channel attacks. Chung-Hasan and Page-Stam tried to analyze XTR-ISE with the known simple power analysis, but unfortunately their approach were not practically feasible. Recently, Han et al. proposed new collision attack on it with analysis complexityO(240) when the key size is 160-bit. In this paper we analyze XTR-ISE from other point of view, namely differential power analysis (DPA). One straightforward result is that XTR-ISE can be free from the original DPA. However, a non-trivial result is that an enhancing DPA proposed in this paper threatens XTR-ISE. Furthermore, we show several weak points of the structure of XTR-ISE. From our simulation results, we show the proposed attack requires about 584 times queries to DPA_Oracleto detect the whole 160-bit secret value. This result shows that XTR-ISE is vulnerable to the proposed enhancing DPA.