Side Channel Attacks on Message Authentication Codes

Side Channel Attacks on Message Authentication Codes
复制标题

DOI:
10.1007/11601494_17
复制
发表时间:
2005-07
期刊:
--
影响因子:
--
通讯作者:
K. Okeya;Tetsu Iwata
K. Okeya;Tetsu Iwata
中科院分区:
其他
文献类型:
--
作者:
K. Okeya;Tetsu Iwata

文献摘要

相似文献

边信道攻击是传感器网络和adhoc网络中嵌入式密码设备面临的一个严重威胁。在本文中,我们讨论了如何侧信道攻击可以应用到消息认证码,即使采取的对策,以保护底层的分组密码。特别是,我们表明,EMAC,OMAC和PMAC是容易受到我们的攻击。我们还指出,我们的攻击可以适用于对RMAC,TMAC和XCBC。基于简单的功率分析,我们证明了几个关键比特可以提取,并基于差分功率分析,我们提出了一个选择性伪造这些MAC。我们的研究结果表明,保护分组密码免受侧信道攻击是不够的,以及MAC需要对策。侧信道攻击是一个严重的威胁,嵌入式设备的密码应用,这是用于传感器和ad hoc网络。在本文中,我们讨论了如何侧信道攻击可以应用到消息认证码,即使采取的对策,以保护底层的分组密码。特别是,我们表明,EMAC,OMAC和PMAC是容易受到我们的攻击。我们还指出,我们的攻击可以适用于对RMAC,TMAC和XCBC。基于简单的功率分析,我们证明了几个关键比特可以提取,并基于差分功率分析,我们提出了一个选择性伪造这些MAC。我们的研究结果表明,保护分组密码免受侧信道攻击是不够的,以及MAC的对策。
Side channel attacks are a serious menace to embedded devices with cryptographic applications, which are utilized in sensor and ad hoc networks. In this paper, we discuss how side channel attacks can be applied against message authentication codes, even if the countermeasures are taken to protect the underlying block cipher. In particular, we show that EMAC, OMAC, and PMAC are vulnerable to our attacks. We also point out that our attacks can be applied against RMAC, TMAC, and XCBC. Based on simple power analysis, we show that several key bits can be extracted, and based on differential power analysis, we present a selective forgery against these MACs. Our results suggest that protecting block ciphers against side channel attacks is insufficient, and countermeasures are needed for MACs as well.Side channel attacks are a serious menace to embedded devices with cryptographic applications, which are utilized in sensor and ad hoc networks. In this paper, we discuss how side channel attacks can be applied against message authentication codes, even if the countermeasures are taken to protect the underlying block cipher. In particular, we show that EMAC, OMAC, and PMAC are vulnerable to our attacks. We also point out that our attacks can be applied against RMAC, TMAC, and XCBC. Based on simple power analysis, we show that several key bits can be extracted, and based on differential power analysis, we present a selective forgery against these MACs. Our results suggest that protecting block ciphers against side channel attacks is insufficient, and countermeasures are needed for MACs as well.