Correlated extra-reductions defeat blinded regular exponentiation

Margaux Dugardin, Sylvain Guilley, Jean Luc Danger, Zakaria Najm, Olivier Rioul

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Walter and Thomson (CT-RSA ’01) and Schindler (PKC ’02)It should be emphasized that that have shown that extra-reductions allow to break RSA-CRT even with message blinding. Indeed, the extrareduction probability depends on the type of operation (square, multiply, or multiply with a constant). Regular exponentiation schemes can be regarded as protections since the operation sequence does not depend on the secret. In this article, we show that there exists a strong negative correlation between extra-reductions of two consecutive operations, provided that the first feeds the second. This allows to mount successful attacks even against blinded asymmetrical computations with a regular exponentiation algorithm, such as Square-and-Multiply Always or Montgomery Ladder. We investigate various attack strategies depending on the context— known or unknown modulus, known or unknown extra-reduction detection probability, etc.—and implement them on two devices: a single core ARM Cortex-M4 and a dual core ARM Cortex M0-M 4.

Original languageEnglish
Title of host publicationCryptographic Hardware and Embedded Systems, CHES 2016 - 18th International Workshop, Proceedings
EditorsBenedikt Gierlichs, Axel Y. Poschmann
PublisherSpringer Verlag
Pages3-22
Number of pages20
ISBN (Print)9783662531396
DOIs
Publication statusPublished - 1 Jan 2016
Externally publishedYes
Event18th International Conference on Cryptographic Hardware and Embedded Systems, CHES 2016 - Santa Barbara, United States
Duration: 17 Aug 201619 Aug 2016

Publication series

NameLecture Notes in Computer Science
Volume9813 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference18th International Conference on Cryptographic Hardware and Embedded Systems, CHES 2016
Country/TerritoryUnited States
CitySanta Barbara
Period17/08/1619/08/16

Keywords

  • Extra-reduction leakage
  • Message blinding
  • Montgomery modular multiplication
  • Regular exponentiation
  • Side-channel analysis

Fingerprint

Dive into the research topics of 'Correlated extra-reductions defeat blinded regular exponentiation'. Together they form a unique fingerprint.

Cite this