Side-Channel Secure Designs and Implementations of Cryptographic Algorithms in Embedded Systems
Side-Channel Secure Designs and Implementations of Cryptographic Algorithms in Embedded Systems
批准号:
RGPIN-2020-06492
负责人:
Taha, Mostafa
金额:
$2.04万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2020
资助国家:
加拿大
项目状态:
已结题
起止时间:
2020-01-01 至 2021-12-31
中文摘要
嵌入式系统和物联网(IoT)在我们的家庭、汽车、工作场所、生产线、医院和发电厂中的广泛部署至关重要地依赖于它们的安全运行。尽管流行的密码算法的基本数学基础是可靠的,并且很容易理解,但它们作为密码芯片的实际实现是不安全的。最近的研究表明,密码算法的典型实现可以通过几个旁路和秘密通道泄露敏感信息。这些通道包括功耗、电磁辐射、执行时间、光子发射、声波、对感应故障的响应等方面的变化。这组攻击称为实现攻击,在这种攻击中,对手利用加密算法的底层实现中的弱点,而不是其数学结构。实现攻击可以是被动的(称为侧通道分析),也可以是主动的(称为故障攻击)。
建议的研究计划寻求对针对关键嵌入式和物联网系统的侧通道分析和实施攻击进行更深入和更量化的了解,并提出新的设计方法和稳健的实施,以在不违反可用性、成本或实时约束的情况下确保这些攻击的安全。
该计划的目标包括:1-建立一个公平、统一、标准化的评估平台,用于分析和量化嵌入式和物联网系统密码芯片的信息泄露。该评估平台不仅对于本研究计划中提出的新设计和实现的安全评估至关重要,而且对于分析政府服务和行业使用的密码芯片也是必不可少的。2-提出当前使用的标准密码算法的新的、更高效的实现。这是一个正在进行的研究主题,正在重建所有当前的实现,包括硬件和软件,以纳入针对实现攻击的安全性。3-开发新的量子抵抗加密(QRC)的安全实现,也称为后量子加密(PQC),作为加拿大政府的研究目标。目前,有26种新的PQC算法正在评估中,每种算法都有几个目标安全级别。这些算法需要在实现攻击的框架内进行分析,并且需要提出安全的实现方案。4-提出新的设计方法,以拥有旁路感知的新密码算法。在这个研究目标中,我们将提出在新算法的设计阶段防止信息泄漏的工具,而不是作为后果来解决问题。这项研究计划是多学科的,因为它涉及科学和工程领域。
英文摘要
The widespread deployment of embedded systems and the Internet of Things (IoT), in our homes, cars, workplaces, manufacturing lines, hospitals, and power plants rely critically on their secure operation. Although the underlying mathematical foundations of the popular cryptographic algorithms are sound and well-understood, their actual realizations as cryptographic chips are not secure. Recent research has shown that the typical implementations of cryptographic algorithms can leak sensitive information through several side and covert channels. These channels include variations in the power consumption, electromagnetic radiation, execution time, photonic emissions, acoustic waves, response to induced faults, along with others. This group of attacks is called Implementation Attacks, where the adversary exploits weaknesses in the underlying implementation of a cryptographic algorithm rather than its mathematical structure. Implementation Attacks can be passive (known as Side-Channel Analysis) or active (known as Fault Attacks).
The proposed research program seeks a deeper and more quantified understanding of side channel analysis and implementation attacks against critical embedded and IoT systems and proposes novel design methodologies and robust implementations that are secured against these attacks without violating usability, cost or real-time constraints.
The objectives of this program include: 1- Building a fair, uniform and standardized evaluation platform for the analysis and quantification of information leakage in the cryptographic chips of embedded and IoT systems. This evaluation platform is essential not only to the security assessment of the new designs and implementations to be proposed in this research program, but also to analyze cryptographic chips used by government services and the industry. 2- Proposing new, more efficient, implementations of the currently used standard cryptographic algorithms. This is an ongoing research topic, where all the current implementations, both in hardware and software, are being rebuilt to incorporate security against implementation attacks. 3- Developing secure implementations for the new Quantum Resistant Cryptography (QRC), also called Post-Quantum Cryptography (PQC), as a research goal of the Government of Canada. Currently, there are 26 new PQC algorithms that are being evaluated, each with several target security levels. These algorithms need to be analyzed within the framework of implementation attacks, and secure implementations need to be proposed. 4- Proposing novel design methodologies toward having new cryptographic algorithms that are side-channel-aware. In this research objective, we will propose tools to prevent information leakage in the design phase of new algorithms, rather than addressing the problem as an aftermath. This research program is multidisciplinary as it overlaps between science and engineering fields.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Side-Channel Secure Designs and Implementations of Cryptographic Algorithms in Embedded Systems
-
批准号:RGPIN-2020-06492
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2022
-
负责人:Taha, Mostafa
-
依托单位:
Side-Channel Secure Designs and Implementations of Cryptographic Algorithms in Embedded Systems
-
批准号:RGPIN-2020-06492
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2021
-
负责人:Taha, Mostafa
-
依托单位:
Side-Channel Secure Designs and Implementations of Cryptographic Algorithms in Embedded Systems
-
批准号:DGECR-2020-00449
-
项目类别:Discovery Launch Supplement
-
资助金额:$0.91万
-
财政年份:2020
-
负责人:Taha, Mostafa
-
依托单位:
国内基金
海外基金
同步辐射光源 channel-cut 晶体窄缝的游离微珠辅助化学机械抛光研究
-
批准号:21ZR1467700
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2021
-
负责人:王昆
-
依托单位:
经颅磁刺激对 Alzheimer病小鼠脑内homer1a-BK channel信号通路的影响及疗效评估
-
批准号:81371222
-
项目类别:面上项目
-
资助金额:70.0万元
-
批准年份:2013
-
负责人:王芙蓉
-
依托单位: