Recovering CRT-RSA Secret Keys from Noisy Square-and-Multiply Sequences in the Sliding Window Method

Recovering CRT-RSA Secret Keys from Noisy Square-and-Multiply Sequences in the Sliding Window Method
复制标题

DOI:
10.1007/978-3-030-55304-3_34
复制
发表时间:
2020-11
期刊:
--
影响因子:
--
通讯作者:
Kento Oonishi;N. Kunihiro
Kento Oonishi;N. Kunihiro
中科院分区:
其他
文献类型:
--
作者:
Kento Oonishi;N. Kunihiro

文献摘要

相似文献

讨论了利用滑动窗口方法实现的CRT-RSA加密或签名方案(具有中国剩余定理的RSA方案)的边信道攻击。滑动窗口方法通过重复的平方和乘法来计算幂。这些平方乘序列可以通过侧信道攻击获得,并且存在从这些序列恢复CRT-RSA密钥的风险。特别地,在CHES 2017中,证明了当窗口大小小于4时,我们可以在多项式时间内从正确的平方乘序列中恢复密钥。然而,在所获得的序列中存在误差。Oonishi和Kunihiro提出了一种从噪声序列中恢复密钥的方法。虽然这项工作只解决了w的情况,但应该可以恢复更大w值的密钥。在本文中,我们提出了一种新的方法,从噪声序列中恢复密钥的滑动窗口方法。此外,我们澄清了我们的方法工作的错误量。
We discuss side-channel attacks on CRT-RSA encryption or signature scheme (the RSA scheme with the Chinese remainder theorem) implemented via the sliding window method. The sliding window method calculates exponentiations through repeated squaring and multiplication. These square-and-multiply sequences can be obtained by side-channel attacks, and there is the risk of recovering CRT-RSA secret keys from these sequences. Especially, in CHES 2017, it is proved that we can recover secret keys from the correct square-and-multiply sequences in polynomial time when the window sizewis less than 4. However, there are errors in the obtained sequences. Oonishi and Kunihiro proposed a method for recovering secret keys from noisy sequences when. Although this work only addresses the case with, it should be possible to recover secret keys for larger values ofw. In this paper, we propose a new method for recovering secret keys from noisy sequences in the sliding window method. Moreover, we clarify the amount of errors for which our method works.