Improvement of trace-driven I-Cache timing attack on the RSA algorithm

Improvement of trace-driven I-Cache timing attack on the RSA algorithm
复制标题

RSA算法跟踪驱动的I-Cache定时攻击的改进

DOI:
10.1016/j.jss.2012.07.020
复制
发表时间:
2013
影响因子:
3.5
通讯作者:
Li, Xiong
Li, Xiong
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wang, Tao;Kou, YingZhan;Chen, XiaoCen;Li, Xiong

文献摘要

参考文献

被引文献

相似文献

之前针对RSA算法的利用密码指令路径的I-Cache定时攻击大多是概念验证,并且比D-Cache定时攻击更难付诸实践。通过分析之前针对 RSA 算法的 I-Cache 时序攻击的复杂性,我们提出了一种针对 RSA 算法的跟踪驱动时序攻击模型,该模型通过监视整个 I-Cache,而不是乘法函数映射到的部分指令缓存。然后,利用SWE算法中窗口大小的特点,提出了一种改进的指数分析算法,与前者相比,可以进一步减少密钥位的搜索空间。通过论证一些结论并通过实验验证,我们进一步演示了如何从 dp 和 dq 的分散已知位中恢复私钥 d。另外,还提供了错误检测机制,用于检测操作序列的一些错误判决,以减少错误恢复比特的数量,提高判决的精度。我们在实际环境中对OpenSSL的RSA实现了I-Cache定时攻击,实验结果表明,可以提高I-Cache定时攻击的可行性和有效性。
The previous I-Cache timing attacks on the RSA algorithm which exploit the instruction path of a cipher are mostly proof-of-concept, and it is harder to put them into practice than D-Cache timing attacks. We propose a trace-driven timing attack model on the RSA algorithm via spying on the whole I-Cache, instead of the partial instruction cache to which the multiplication function mapped, by analyzing the complications in the previous I-Cache timing attack on the RSA algorithm. Then, an improved analysis algorithm of the exponent using the characteristic of the window size in SWE algorithm is provided, which could further reduce the search space of the key bits than the former. We further demonstrate how to recover the private key d from the scattered known bits of dpand dq, through demonstrating some conclusions and validating it by experimentation. In addition, an error detection mechanism to detect some erroneous decisions of the operation sequences is provided to reduce the number of the erroneous recovered bits, and improve the precision of decision. We implement an I-Cache timing attack on RSA of OpenSSL in a practical environment, the experimental results show that the feasibility and effectiveness of I-Cache timing attack can be improved.
DOI: 10.1007/11967668_15
发表时间: 2007-02
期刊: --
影响因子: --
作者:
O. Aciiçmez;Ç. Koç;Jean-Pierre Seifert
通讯作者: O. Aciiçmez;Ç. Koç;Jean-Pierre Seifert
DOI: 10.1109/fdtc.2007.4318988
发表时间: 2007-09
期刊: Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC 2007)
影响因子: --
作者:
O. Aciiçmez;Jean-Pierre Seifert
通讯作者: O. Aciiçmez;Jean-Pierre Seifert
DOI: 10.1007/3-540-68339-9_16
发表时间: 1996-05
期刊: The Auk
影响因子: --
作者:
D. Coppersmith
通讯作者: D. Coppersmith
DOI: --
发表时间: 2011
期刊: --
影响因子: --
作者:
B. Brumley;Nicola Tuveri
通讯作者: B. Brumley;Nicola Tuveri
DOI: 10.1016/j.cose.2012.05.002
发表时间: 2012-07
期刊: Comput. Secur.
影响因子: --
作者:
J. Bayuk
通讯作者: J. Bayuk