小型密码泄露的一般分析

Itai Dinur, A. Shamir
{"title":"小型密码泄露的一般分析","authors":"Itai Dinur, A. Shamir","doi":"10.1109/FDTC.2010.11","DOIUrl":null,"url":null,"abstract":"Side channel attacks are typically divided into two phases: In the{\\it collection phase} the attacker tries to measure some physical property of the implementation, and in the {\\it analysis phase} he tries to derive the cryptographic key from the measured information. The field is highly fragmented, since there are many types of leakage, and each one of them usually requires a different type of analysis. In this paper we formalize a general notion of {\\it leakage attacks} on iterated cryptosystems, in which the attacker can collect (via physical probing, power measurement, or any other type of side channel) one bit of information about the intermediate state of the encryption after each round. Since bits computed during the early rounds can be usually represented by low degree multivariate polynomials in the plaintext and key bits, we can use the recently discovered cube attack as a generic analysis phase which can be applied in principle to any type of leaked data. However, the original cube attack requires extremely clean data, whereas the information provided by side channel attacks can be quite noisy. To address this problem, we develop in this paper a new type of {\\it robust cube attack}, which can recover the key even when some of the leaked bits are unreliable. In particular, we show how to exploit{\\it trivial equations} (of the form $0=0$, which are plentiful but useless in standard cube attacks) in order to correct a fraction of measurement errors which can be arbitrarily close to1. Finally, we demonstrate our approach by describing efficient leakage attacks on Serpent (requiring only $2^{18}$ time for full key recovery when the leaked state bits are clean) and on AES (requiring $2^{35}$ time in the same scenario), and show how to make them robust with a small additional complexity.","PeriodicalId":127275,"journal":{"name":"2010 Workshop on Fault Diagnosis and Tolerance in Cryptography","volume":"26 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2010-08-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":"{\"title\":\"Generic Analysis of Small Cryptographic Leaks\",\"authors\":\"Itai Dinur, A. Shamir\",\"doi\":\"10.1109/FDTC.2010.11\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Side channel attacks are typically divided into two phases: In the{\\\\it collection phase} the attacker tries to measure some physical property of the implementation, and in the {\\\\it analysis phase} he tries to derive the cryptographic key from the measured information. The field is highly fragmented, since there are many types of leakage, and each one of them usually requires a different type of analysis. In this paper we formalize a general notion of {\\\\it leakage attacks} on iterated cryptosystems, in which the attacker can collect (via physical probing, power measurement, or any other type of side channel) one bit of information about the intermediate state of the encryption after each round. Since bits computed during the early rounds can be usually represented by low degree multivariate polynomials in the plaintext and key bits, we can use the recently discovered cube attack as a generic analysis phase which can be applied in principle to any type of leaked data. However, the original cube attack requires extremely clean data, whereas the information provided by side channel attacks can be quite noisy. To address this problem, we develop in this paper a new type of {\\\\it robust cube attack}, which can recover the key even when some of the leaked bits are unreliable. In particular, we show how to exploit{\\\\it trivial equations} (of the form $0=0$, which are plentiful but useless in standard cube attacks) in order to correct a fraction of measurement errors which can be arbitrarily close to1. Finally, we demonstrate our approach by describing efficient leakage attacks on Serpent (requiring only $2^{18}$ time for full key recovery when the leaked state bits are clean) and on AES (requiring $2^{35}$ time in the same scenario), and show how to make them robust with a small additional complexity.\",\"PeriodicalId\":127275,\"journal\":{\"name\":\"2010 Workshop on Fault Diagnosis and Tolerance in Cryptography\",\"volume\":\"26 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2010-08-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"5\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2010 Workshop on Fault Diagnosis and Tolerance in Cryptography\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/FDTC.2010.11\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2010 Workshop on Fault Diagnosis and Tolerance in Cryptography","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/FDTC.2010.11","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

摘要

侧信道攻击通常分为两个阶段:在{\it收集阶段},攻击者试图测量实现的一些物理属性,在{\it分析阶段},攻击者试图从测量的信息中导出加密密钥。该领域是高度分散的,因为有许多类型的泄漏,每一种泄漏通常需要不同类型的分析。在本文中,我们形式化了迭代密码系统上的{\it泄漏攻击}的一般概念,其中攻击者可以在每轮之后收集(通过物理探测,功率测量或任何其他类型的侧信道)关于加密中间状态的一位信息。由于在前几轮中计算的比特通常可以用明文和密钥位中的低次多元多项式表示,我们可以使用最近发现的立方体攻击作为通用分析阶段,原则上可以应用于任何类型的泄露数据。然而,原始的立方体攻击需要非常干净的数据,而侧信道攻击提供的信息可能相当嘈杂。为了解决这个问题,我们在本文中开发了一种新型的{\it鲁棒立方体攻击},即使在一些泄露的比特不可靠的情况下也可以恢复密钥。特别是,我们展示了如何利用{\it平凡方程}(形式为$0=0$,在标准立方体攻击中大量但无用)来纠正测量误差的一小部分,这些误差可以任意接近1。最后,我们通过描述对Serpent(当泄露的状态位干净时,完全恢复密钥只需要$2^{35}$时间)和AES(在相同的场景中需要$2^{35}$时间)的有效泄漏攻击来演示我们的方法,并展示如何在增加少量复杂性的情况下使它们变得健壮。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Generic Analysis of Small Cryptographic Leaks
Side channel attacks are typically divided into two phases: In the{\it collection phase} the attacker tries to measure some physical property of the implementation, and in the {\it analysis phase} he tries to derive the cryptographic key from the measured information. The field is highly fragmented, since there are many types of leakage, and each one of them usually requires a different type of analysis. In this paper we formalize a general notion of {\it leakage attacks} on iterated cryptosystems, in which the attacker can collect (via physical probing, power measurement, or any other type of side channel) one bit of information about the intermediate state of the encryption after each round. Since bits computed during the early rounds can be usually represented by low degree multivariate polynomials in the plaintext and key bits, we can use the recently discovered cube attack as a generic analysis phase which can be applied in principle to any type of leaked data. However, the original cube attack requires extremely clean data, whereas the information provided by side channel attacks can be quite noisy. To address this problem, we develop in this paper a new type of {\it robust cube attack}, which can recover the key even when some of the leaked bits are unreliable. In particular, we show how to exploit{\it trivial equations} (of the form $0=0$, which are plentiful but useless in standard cube attacks) in order to correct a fraction of measurement errors which can be arbitrarily close to1. Finally, we demonstrate our approach by describing efficient leakage attacks on Serpent (requiring only $2^{18}$ time for full key recovery when the leaked state bits are clean) and on AES (requiring $2^{35}$ time in the same scenario), and show how to make them robust with a small additional complexity.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
A Continuous Fault Countermeasure for AES Providing a Constant Error Detection Rate Fault Attacks and Countermeasures on Vigilant's RSA-CRT Algorithm Multi Fault Laser Attacks on Protected CRT-RSA Generic Analysis of Small Cryptographic Leaks Low Cost Built in Self Test for Public Key Crypto Cores
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1