A New Attack with Side Channel Leakage During Exponent Recoding Computations

A New Attack with Side Channel Leakage During Exponent Recoding Computations
复制标题

DOI:
10.1007/978-3-540-28632-5_22
复制
发表时间:
2004-08
期刊:
--
影响因子:
--
通讯作者:
Yasuyuki Sakai;K. Sakurai
Yasuyuki Sakai;K. Sakurai
中科院分区:
其他
文献类型:
--
作者:
Yasuyuki Sakai;K. Sakurai

文献摘要

相似文献

在本文中,我们提出了一种新的侧通道攻击,其中考虑了 RSA 和 ECDSA 等公钥密码系统的指数重新编码。公钥密码系统的已知侧信道攻击和对策是针对模幂运算(或椭圆曲线上的点乘法)的主要阶段(平方和乘法阶段)。我们有许多算法可以实现快速求幂计算。当我们计算幂时,指数重新编码必须在主阶段之前进行。有一些指数重新编码算法包括条件分支,其中指令取决于给定的指数值。因此,指数重新编码可以构成信息通道,为攻击者提供有关秘密指数的有价值的信息。在本文中,我们展示了攻击指数重新编码的新算法。当使用宽度 wNAF [9] 和无符号/有符号分数窗口表示 [5] 时,所提出的算法可以恢复秘密指数。
In this paper we propose a new side channel attack, where exponent recodings for public key cryptosystems such as RSA and ECDSA are considered. The known side channel attacks and countermeasures for public key cryptosystems were against the main stage (square and multiply stage) of the modular exponentiation (or the point multiplication on an elliptic curve). We have many algorithms which achieve fast computation of exponentiations. When we compute an exponentiation, the exponent recoding has to be carried out before the main stage. There are some exponent recoding algorithms including conditional branches, in which instructions depend on the given exponent value. Consequently exponent recoding can constitute an information channel, providing the attacker with valuable information on the secret exponent. In this paper we show new algorithms of attack on exponent recoding. The proposed algorithms can recover the secret exponent, when the width-wNAF [9] and the unsigned/signed fractional window representation [5] are used.