Cache-Collision Timing Attacks Against AES

Cache-Collision Timing Attacks Against AES
复制标题

DOI:
10.1007/11894063_16
复制
发表时间:
2006-10
期刊:
--
影响因子:
--
通讯作者:
Joseph Bonneau;Ilya Mironov
Joseph Bonneau;Ilya Mironov
中科院分区:
其他
文献类型:
--
作者:
Joseph Bonneau;Ilya Mironov

文献摘要

被引文献

相似文献

本文介绍了几种新颖的定时攻击常见的表驱动的软件实现的AES密码。我们定义了一个通用的攻击策略,使用一个简化的模型的该高速缓存来预测由于在加密执行的查找序列中的缓存冲突的时序变化。所提出的攻击应该适用于大多数高速软件AES实现和计算平台,我们已经针对OpenSSL v.0.9.8实现了它们。(a)在Pentium III、Pentium IV Xeon和UltraPentium III+计算机上运行。在最佳条件下,最强大的攻击已经被证明可以可靠地恢复具有213个定时样本的完整128位AES密钥,这比以前发布的最佳此类攻击提高了近四个数量级[Ber05]。虽然保护AES免受所有定时攻击的任务具有挑战性,但一个小补丁可以显着减少这些特定攻击的漏洞,而不会影响性能。
This paper describes several novel timing attacks against the common table-driven software implementation of the AES cipher. We define a general attack strategy using a simplified model of the cache to predict timing variation due to cache-collisions in the sequence of lookups performed by the encryption. The attacks presented should be applicable to most high-speed software AES implementations and computing platforms, we have implemented them against OpenSSL v. 0.9.8.(a) running on Pentium III, Pentium IV Xeon, and UltraSPARC III+ machines. The most powerful attack has been shown under optimal conditions to reliably recover a full 128-bit AES key with 213timing samples, an improvement of almost four orders of magnitude over the best previously published attacks of this type [Ber05]. While the task of defending AES against all timing attacks is challenging, a small patch can significantly reduce the vulnerability to these specific attacks with no performance penalty.