首页> 外文会议>International workshop on cryptographic hardware and embedded systems >Who Watches the Watchmen?: Utilizing Performance Monitors for Compromising Keys of RSA on Intel Platforms
【24h】

Who Watches the Watchmen?: Utilizing Performance Monitors for Compromising Keys of RSA on Intel Platforms

机译:谁在监视守望者?:利用性能监视器来破坏英特尔平台上RSA的密钥

获取原文

摘要

Asymmetric-key cryptographic algorithms when implemented on systems with branch predictors, are subjected to side-channel attacks exploiting the deterministic branch predictor behavior due to their key-dependent input sequences. We show that branch predictors can also leak information through the hardware performance monitors which are accessible by an adversary at the user-privilege level. This paper presents an iterative attack which target the key-bits of 1024 bit RSA, where in offline phase, the system's underlying branch predictor is approximated by a theoretical predictor in literature. Subsimula-tions are performed to classify the message-space into distinct partitions based on the event branch misprediction and the target key bit value. In online phase, we ascertain the secret key bit using branch mispredic-tions obtained from the hardware performance monitors which reflect the behavior of the underlying predictor hardware. We theoretically prove that the probability of success is equivalent to the accurate modelling of the theoretical predictor to the underlying system predictor. Experimentations reveal that the success-rate increases with message-count and reaches such a significant value so as to consider side-channel from the performance counters as a real threat to RSA-like ciphers due to the underlying branch predictors and needs to be considered for developing secured-systems.
机译:当在具有分支预测变量的系统上实施非对称密钥密码算法时,由于其依赖于密钥的输入序列,它们会利用确定性分支预测变量的行为遭受侧信道攻击。我们证明分支预测器还可以通过硬件性能监视器泄漏信息,而这些性能监视器可以由用户在用户特权级别访问。本文提出了一种针对1024位RSA密钥位的迭代攻击,其中在离线阶段,系统的基础分支预测变量由文献中的理论预测变量来近似。执行子仿真,以基于事件分支预测错误和目标密钥位值将消息空间分类为不同的分区。在在线阶段,我们使用从硬件性能监控器获得的分支错误预测来确定秘密比特,该分支错误预测反映了基础预测器硬件的行为。从理论上讲,我们证明成功的概率等同于理论预测器对基础系统预测器的精确建模。实验表明,成功率随着消息数的增加而增加,并达到如此重要的值,从而由于性能预测的基础分支预测因素而将性能计数器的旁信道视为对RSA类密码的真正威胁,因此需要考虑开发安全系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号