Passer à la navigation principale Passer à la recherche Passer au contenu principal

Combined attack on CRT-RSA: Why public verification must not be public?

  • Guillaume Barbu
  • , Alberto Battistello
  • , Guillaume Dabosville
  • , Christophe Giraud
  • , Guénaël Renault
  • , Soline Renner
  • , Rina Zeitoun
  • Oberthur Technologies
  • INRIA Rocquencourt
  • IMB UMR 5251

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

This article introduces a new Combined Attack on a CRT-RSA implementation resistant against Side-Channel Analysis and Fault Injection attacks. Such implementations prevent the attacker from obtaining the signature when a fault has been induced during the computation. Indeed, such a value would allow the attacker to recover the RSA private key by computing the gcd of the public modulus and the faulty signature. The principle of our attack is to inject a fault during the signature computation and to perform a Side-Channel Analysis targeting a sensitive value processed during the Fault Injection countermeasure execution. The resulting information is then used to factorize the public modulus, leading to the disclosure of the whole RSA private key. After presenting a detailed account of our attack, we explain how its complexity can be significantly reduced by using lattice reduction techniques. We also provide simulations that confirm the efficiency of our attack as well as two different countermeasures having a very small impact on the performance of the algorithm. As it performs a Side-Channel Analysis during a Fault Injection countermeasure to retrieve the secret value, this article recalls the need for Fault Injection and Side-Channel Analysis countermeasures as monolithic implementations.

langue originaleAnglais
titrePublic-Key Cryptography, PKC 2013 - 16th International Conference on Practice and Theory in Public-Key Cryptography, Proceedings
EditeurSpringer Verlag
Pages198-215
Nombre de pages18
ISBN (imprimé)9783642363610
Les DOIs
étatPublié - 1 janv. 2013
Modification externeOui
Evénement16th International Conference on Practice and Theory in Public-Key Cryptography, PKC 2013 - Nara, Japon
Durée: 26 févr. 20131 mars 2013

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7778 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence16th International Conference on Practice and Theory in Public-Key Cryptography, PKC 2013
Pays/TerritoireJapon
La villeNara
période26/02/131/03/13

Empreinte digitale

Examiner les sujets de recherche de « Combined attack on CRT-RSA: Why public verification must not be public? ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation