Architectural and Micro-architectural Countermeasures against Physical Attack
Architectural and Micro-architectural Countermeasures against Physical Attack
批准号:
EP/H001689/1
负责人:
Daniel Page
金额:
$104.92万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2009
资助国家:
英国
项目状态:
已结题
起止时间:
2009 至 --
中文摘要
密码分析的进步通常是由数学家们创造出来的,他们寻求技术来解开现代密码系统所基于的难题。基于物理安全概念的攻击将密码分析技术从数学领域转移到了实现的实用领域。通过考虑密码系统的实现而不是纯粹的密码系统规范,研究人员发现它们可以发动物理攻击,而且在时间和设备方面成本低,并且在提取有用结果方面非常成功。最近展示了此类攻击对现实世界影响的例子是针对KeeLoq系列RFID设备的攻击,这些设备用于汽车和建筑门禁,以及MIFARE非接触式智能卡(例如,伦敦地铁使用的“牡蛎”卡)。侧通道攻击是一种物理攻击类型,基于这样的假设,即一个人可以被动地观察某个硬件设备正在执行的算法,并从发生的特征中推断出有关计算内部状态的详细信息。典型的侧通道攻击由收集阶段和分析阶段组成,收集阶段向攻击者提供执行配置文件,分析阶段从配置文件中恢复原本保密的信息。尤其关注基于POWER和EM的攻击,针对侧通道攻击的对策在个案的基础上越来越被理解;在高级别上,它们可以被分类为隐藏(断开执行和配置文件之间的链接)或掩蔽(断开执行和算法之间的链接)。隐藏样式对策的方法通常试图使每个配置文件对于所有机密是恒定的,或者完全随机的;在这两种情况下,前提是配置文件不再与机密信息相关联。有许多方法可以实现这种类型的对策。在最高级别,人们可以考虑在软件中实现隐藏或掩蔽的替代算法(或实现方法)。一方面,这种方法是非常特定于算法的,可能意味着显著的性能损失;另一方面,不需要对执行软件的硬件进行任何更改。在最低层,人们可以考虑使用所谓的安全逻辑风格;其基本思想是用替代方案取代CMOS单元库,例如,无论它们计算的结果是什么,这些替代方案都会消耗恒定的功率。这种方法的主要缺点是在面积方面产生的开销;主要优点是这种方法在很大程度上是与算法无关的,即可以自动应用的一般解决方案。在某种意义上,本提案中的研究方案旨在采用介于这两个极端之间的方法。研究的关键是对通用处理器进行改造,使其能够在微体系结构级别上实现抗旁路攻击的对策。处理器将保留相同的指令集体系结构(ISA),并因此保留相同的功能特征,但行为特征将防止信息泄漏,例如,通过功率分析。我们的重点是微体系结构的一些方面,这些方面可以通过某种方式随机化。我们认为,这种方法将提供一定程度的灵活性和算法敏捷性,代表了安全性和其他指标之间有吸引力的权衡。具体地说,它允许强化处理器平台自动支持高级算法对策(与分层对策而不是单一灵丹妙药的理想相匹配),同时在很大程度上避免了传统上与安全逻辑风格相关联的底层处理技术的开销和敏感性。
英文摘要
Advances in cryptanalysis are often produced by mathematicians who seek techniques to unravel the hard problems on which modern cryptosystems are based. Attacks based on the concept of physical security move the art of cryptanalysis from the mathematical domain into the practical domain of implementation. By considering the implementation of cryptosystems rather than purely their specification, researchers have found they can mount physical attacks which are of low cost, in terms of time and equipment, and are highly successful in extracting useful results. Recent examples that demonstrate the real-world impact of such attacks are those against the KeeLoq range of RFID devices used for car and building access control, and MIFARE contactless smart-cards (e.g. the ``Oyster'' cards used by the London Underground).Side-channel attacks are a genre of physical attack based on the assumption that one can passively observe an algorithm being executed by some hardware device, and infer details about the internal state of computation from the features that occur. A typical side-channel attack consists of a collection phase that provides the attacker with profiles of execution, and an analysis phase which recovers otherwise secret information from the profiles. Focusing on power and EM based attacks in particular, countermeasures against side-channel attack are increasingly well understood on a case by case basis; at a high-level they can be classified as either hiding (breaking the link between execution and profiles) or masking (breaking the link between execution and algorithm). Approaches to hiding style countermeasures typically attempt to make each profile constant for all secrets, or entirely random; in both cases the premise is that a profile can no longer be correlated to the secret information.There are a number of approaches to implementing these sorts of countermeasure. At the highest-level, one can consider alternate algorithms (or implementation approaches) that realise hiding or masking in software. On one hand this approach is very algorithm-specific and can imply a significant performance penalty; on the other hand, no alterations are required to the hardware on which the software executes. At the lowest-level, one can consider using so-called secure logic styles; the basic idea is to replace CMOS cell libraries with alternatives which, for example, consume a constant amount of power regardless of the result they compute. The major disadvantage of this approach is the resulting overhead in terms of area; the major advantage is that the approach is largely algorithm-agnostic, i.e. is a general solution which can be automatically applied.The research programme within this proposal aims, in a sense, to adopt an approach between these two extremes. The crux of the research is the alteration of a general purpose processor so that countermeasures against side-channel attack are implemented at the micro-architectural level. The processor will retain the same Instruction Set Architecture (ISA) and hence the same functional characteristics, but the behavioural characteristics will prevent leakage of information via, for example, power analysis. Our focus is on aspects of the micro-architecture which can be randomised in some way. We suggest that this approach will afford a level of flexibility and algorithm agility representing an attractive trade-off between security and other metrics. Specifically, it permits high-level algorithmic countermeasures to be automatically supported by the hardened processor platform (meshing with the ideal of tiered countermeasures rather than a single panacea), while largely avoiding the overhead and sensitivity to underlying process technology traditionally associated with secure logic styles.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
Side-channel attacks on the McEliece and Niederreiter public-key cryptosystems
针对 McEliece 和 Niederreiter 公钥密码系统的旁道攻击
DOI:
10.1007/s13389-011-0024-9
发表时间:
2011
期刊:
Journal of Cryptographic Engineering
影响因子:
1.9
作者:
[Avanzi R]
通讯作者:
Avanzi R
Social norms explain prioritization of climate policy.
社会规范解释了气候政策的优先顺序。
DOI:
10.1007/978-3-319-66399-9_10
发表时间:
2022
期刊:
Climatic change
影响因子:
4.8
作者:
[Cole JC]
通讯作者:
Cole JC
SCARV: a side-channel hardened RISC-V platform
-
批准号:EP/R012288/1
-
项目类别:Research Grant
-
资助金额:$130.52万
-
财政年份:2018
-
负责人:Daniel Page
-
依托单位:
Academic Centre of Excellence in Cyber Security Research - University of Bristol
-
批准号:EP/R006741/1
-
项目类别:Research Grant
-
资助金额:$4.61万
-
财政年份:2017
-
负责人:Daniel Page
-
依托单位:
Leakage Aware Design Automation (LADA): Tools & Techniques for Software Crypto Implementations
-
批准号:EP/N011635/1
-
项目类别:Research Grant
-
资助金额:$146.64万
-
财政年份:2016
-
负责人:Daniel Page
-
依托单位:
Academic Centre of Excellence in Cyber Security Research - University of Bristol
-
批准号:EP/K000675/1
-
项目类别:Research Grant
-
资助金额:$6.09万
-
财政年份:2012
-
负责人:Daniel Page
-
依托单位:
国内基金
海外基金
登录
查看更多内容
半导体micro-oled微显示切割关键技术研发
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2026
-
负责人:孙大明
-
依托单位:
面向 GaN 基 micro-LED/钙钛矿量子点的异质集成与缺陷调控机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:
-
依托单位:
Micro-LED芯片(模组)显示材料的研发及应用
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:张文霞
-
依托单位:
Micro-LED片上集成量子点像素光波导结
构设计与制造研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:100.0万元
-
批准年份:2025
-
负责人:李家声
-
依托单位:
车载领域Micro-LED显示技术研发
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
Micro LED晶圆级缺陷在线检测装备研发
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
Micro-LED全彩化用钙钛矿纳米晶的稳定机理研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
金属氧化物TFT有源模拟PWM驱动Micro-LED显示研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:吴为敬
-
依托单位:
基于非辐射能量传递和胶体电流体微喷印的Micro-LED红光色转换技术
-
批准号:62374142
-
项目类别:面上项目
-
资助金额:48万元
-
批准年份:2023
-
负责人:林岳
-
依托单位:
Mini/Micro-LED显示器件表面功能结构冷冻磨切加工机理及光学性能研究
-
批准号:52375426
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:李宗涛
-
依托单位: