Information leakage through passive timing attacks on RSA decryption system

Information leakage through passive timing attacks on RSA decryption system
复制标题

DOI:
10.1587/transfun.2022tap0006
复制
发表时间:
2020-10
期刊:
2020 International Symposium on Information Theory and Its Applications (ISITA)
影响因子:
--
通讯作者:
Tomonori Hirata;Y. Kaji
Tomonori Hirata;Y. Kaji
中科院分区:
其他
文献类型:
--
作者:
Tomonori Hirata;Y. Kaji

文献摘要

相似文献

当攻击者主动控制目标程序的输入时,计时攻击的威胁尤其严重。为了阻止这种主动攻击,研究了一些对策,但攻击者仍然有机会通过被动地观察目标程序的运行时间来了解一些隐藏的信息。被动定时攻击的风险可以通过隐藏信息与运行时间之间的互信息来衡量。然而,除了玩具示例之外,互信息的计算几乎是不可能的。本文重点研究了RSA解密的三种算法,推导了几种假设和近似下的互信息公式,并对实际安全参数的互信息进行了数值计算。
The threat of timing attacks is especially serious when an attacker actively controls the input to a target program. Countermeasures are studied to deter such active attacks, but the attacker still has the chance to learn something about the concealed information by passively watching the running time of the target program. The risk of passive timing attacks can be measured by the mutual information between the concealed information and the running time. However, the computation of the mutual information is hardly possible except for toy examples. This study focuses on three algorithms for RSA decryption, derives formulas of the mutual information under several assumptions and approximations, and calculates the mutual information numerically for practical security parameters.