CAREER: Practical Leakage Resilience: Provable Side-Channel Resistance for Embedded Systems
CAREER: Practical Leakage Resilience: Provable Side-Channel Resistance for Embedded Systems
批准号:
1054776
负责人:
Thomas Eisenbarth
金额:
$51.33万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-01-15 至 2012-11-30
中文摘要
普适性计算设备的安全性依赖于加密引擎,而加密引擎通常被认为是系统中最可信的部分。对嵌入式加密引擎的内在威胁是物理攻击。针对物理攻击的实际对策并不是完全安全的,而且对于大多数应用程序来说过于昂贵。然而,理论方法仍然倾向于具有不完善的泄漏模型和关于加密子基元能力的错误或不切实际的假设。然而,泄漏弹性的理论概念大多被从业者所忽视,它具有构建抵御物理攻击并允许更有效地实现资源的加密原语的巨大潜力。该项目研究了基本加密服务的解决方案,这些解决方案(i)在存在物理攻击的情况下是安全的,(ii)在性能和成本上与最先进的加密实现相当。这是通过增强泄漏弹性的概念来实现的,使它们适用于嵌入式普及系统的约束机制。理论概念被提出,并在实际实施中付诸实践。实际评估揭示了目前使用的泄漏模型中存在的不足。通过结合两种方法的优点?对应用方法进行彻底的实际评估,并明确定义理论方法的泄漏弹性?由此衍生出更强大、更可靠、更实用的解决方案。除了提高各种嵌入式产品的安全性外,这些发现还为理论密码学家和实际安全架构师提供了有价值的反馈。只有具有防泄漏能力、经得起实际评估并符合经济预期的安全解决方案才能保证广泛使用,从而保证更安全的普及系统。
英文摘要
The security of pervasive computing devices relies on cryptographic engines which are usually considered the most trusted part of the system. An immanent threat to embedded cryptographic engines are physical attacks. Practical countermeasures against physical attacks are not completely fail-safe and overly expensive for most applications. Theoretical approaches, however, still tend to have imperfect leakage models and wrong or impractical assumptions about the abilities of cryptographic sub-primitives. Yet, the theoretical concepts of leakage resilience, which have been mostly disregarded by practitioners, carry a great potential to construct cryptographic primitives that resist physical attacks and allow for more resource-efficient implementations.The project investigates solutions for basic cryptographic services that are (i) secure in the presence of physical attacks and (ii) are comparable in performance and costs to state-of-the-art implementations of cryptography. This is achieved by enhancing the concepts of leakage resilience to make them applicable in the constrained regimes of embedded pervasive systems. Theoretical concepts are advanced and brought into practice by actual implementation. Practical evaluation uncovers remaining weaknesses in the currently used leakage models. By combining the advantages of both approaches ? a thorough practical evaluation of the applied methods and the well-defined leakage-resilience of the theoretical approaches ? stronger, more reliable, and practical solutions are derived. Besides an increased security for the wide range of embedded products, the findings give valuable feedback to both theoretic cryptographers and practical security architects. Only security solutions that are leakage resilient, withstand practical evaluation and match economic expectations guarantee a widespread use and hence more secure pervasive systems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: Small: MIST: Systematic Analysis of Microarchitectural Information Leakage on Mobile Platforms
-
批准号:1618837
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2016
-
负责人:Thomas Eisenbarth
-
依托单位:
TWC: Medium: Collaborative: A Unified Statistics-Based Framework for Side-Channel Attack Analysis and Security Evaluation of Cryptosystems
-
批准号:1314770
-
项目类别:Standard Grant
-
资助金额:$27.6万
-
财政年份:2013
-
负责人:Thomas Eisenbarth
-
依托单位:
CAREER: Practical Leakage Resilience: Provable Side-Channel Resistance for Embedded Systems
-
批准号:1261399
-
项目类别:Continuing Grant
-
资助金额:$38.87万
-
财政年份:2012
-
负责人:Thomas Eisenbarth
-
依托单位:
海外基金