A DPA Attack on the Implementation of RSA-CRT with Montgomery Reduction

被引:0
作者
Lien, Wei-Chih [1 ]
Yen, Sung-Ming [1 ]
机构
[1] Natl Cent Univ, Dept Comp Sci & Informat Engn, Chungli 32054, Taiwan
关键词
differential power analysis; message blinding; montgomery reduction; RSA-CRT; side-channel analysis; POWER ANALYSIS;
D O I
10.1587/transfun.E97.A.354
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The implementation security of the RSA cryptosystem, under the threat of side-channel analysis, has attracted the attentions of many researchers. Boer et al., had proposed the MRED-DPA attack on RSA-CRT by choosing ciphertexts of equi-distant data., Their attack can be applied to RSA-OAEP decryption but not RSA-PSS signing because of the PSS random padding. We propose a new DPA attack on an implementation of RSA-CRT, with the Montgomery reduction. The proposed attack assumes only known ciphertexts, and can be applied to both RSA-OAEP decryption and RSA-PSS signing even if a random padding technique is used in practice. This study also presents experimental results to verify the proposed attack. Finally, this study proposes a CRT-based message blinding technique as a low-cost DPA countermeasure.
引用
收藏
页码:354 / 364
页数:11
相关论文
共 23 条
[1]  
[Anonymous], 2016, HDB APPL CRYPTOGRAPH
[2]  
[Anonymous], PUBL KEY CRYPT STAND
[3]  
Coron JS, 1999, LECT NOTES COMPUT SC, V1717, P292
[4]  
den Boer B., 2003, CRYPTOGRAPHIC HARDWA, V2523, P228
[5]  
Fouque PA, 2003, LECT NOTES COMPUT SC, V2779, P254, DOI 10.1007/978-3-540-45238-6_21
[6]  
Fouque PA, 2003, LECT NOTES COMPUT SC, V2779, P269, DOI 10.1007/978-3-540-45238-6_22
[7]  
Garner L., 1959, IRE Trans. Electron. Comput., VEC-8, P140, DOI DOI 10.1109/TEC.1959.5219515
[8]  
Kocher P., 1999, Advances in Cryptology - CRYPTO'99. 19th Annual International Cryptology Conference. Proceedings, P388
[9]  
Kocher P., 1998, INTRO DIFFERENTIAL P
[10]  
Kocher P. C., 1996, Advances in Cryptology - CRYPTO'96. 16th Annual International Cryptology Conference. Proceedings, P104