Zero-Value Register Attack on Elliptic Curve Cryptosystem
Zero-Value Register Attack on Elliptic Curve Cryptosystem
复制标题
椭圆曲线密码系统的零值寄存器攻击
DOI:
10.1093/ietfec/e88-a.1.132
复制
发表时间:
2005
期刊:
影响因子:
--
通讯作者:
T. Takagi
中科院分区:
文献类型:
--
作者:
Toru Akishita;T. Takagi
Differential power analysis (DPA) might break implementations of elliptic curve cryptosystem (ECC) on memory constraint devices. Goubin proposed a variant of DPA using a point (0, y), which is not randomized in Jacobian coordinates or in an isomorphic class. This point often exists in standardized elliptic curves, and we have to care this attack. In this paper, we propose zero-value register attack as an extension of Goubin's attack. Note that even if a point has no zero-value coordinate, auxiliary registers might take zero value. We investigate these zero-value registers that cannot be randomized by the above randomization. Indeed, we have found several points P = (x, y) which cause the zero-value registers, e.g., (1) 3x 2 +a = 0, (2) 5x 4 + 2ax 2 -4bx + a 2 = 0, (3) P is y-coordinate self-collision point, etc. We demonstrate the elliptic curves recommended in SECG that have these points. Interestingly, some conditions required for zero-value register attack depend on explicit implementation of addition formulae - in order to resist this type of attacks, we have to care how to implement the addition formulae. Finally, we note that Goubin's attack and the proposed attack assume that a base point P can be chosen by attackers and a secret scalar d is fixed, so that they are not applicable to ECDSA.