首页> 外文期刊>Journal of computer security >Towards the optimal performance of integrating Warm and DELAY against remote cache timing side channels on block ciphers
【24h】

Towards the optimal performance of integrating Warm and DELAY against remote cache timing side channels on block ciphers

机译:取得针对分组密码上的远程缓存定时侧通道集成Warm和DELAY的最佳性能

获取原文
获取原文并翻译 | 示例

摘要

Cache timing side channels allow a remote attacker to disclose the cryptographic keys, by repeatedly invoking the encryption/decryption functions and measuring the execution time. Warm and Delay are two algorithm-independent and implementation-transparent countermeasures against remote cache-based timing side channels for block ciphers. They destroy the relationship between the execution time and the cache misses/hits which are determined by the secret key, but bring remarkable performance overhead. In this paper, we investigate the performance of cryptographic functions protected by Warm and Delay , and attempt to find the best strategy to integrate these two countermeasures with the optimal performance while effectively eliminate remote cache timing side channels for block ciphers implementations with lookup tables. To the best of our knowledge, this work is the first to systematically analyze the performance of integrating Warm and Delay against cache side channels.We derive the optimal scheme to integrate Warm and Delay , and apply it to AES. It is proven that the integration scheme achieves the optimal performance with the least extra operations on commodity systems. Finally, we implement it on Linux with Intel CPUs. Experimental results confirm that, (a ) the execution time does not leak information on cache access, (b ) the scheme outperforms other integration strategies of Warm and Delay , and (c ) the implementation works without any privileged operations on the computer.
机译:缓存定时侧通道允许远程攻击者通过重复调用加密/解密功能并测量执行时间来公开加密密钥。 “暖和延迟”是针对块密码的基于远程高速缓存的定时侧信道的两种与算法无关和透明的对策。它们破坏了执行时间与由密钥确定的缓存未命中/命中之间的关系,但带来了显着的性能开销。在本文中,我们研究了受“温暖”和“延迟”保护的密码功能的性能,并试图找到最佳策略,将这两种对策与最佳性能集成在一起,同时通过查找表有效消除用于块密码实现的远程缓存定时侧通道。据我们所知,这项工作是第一个系统地分析针对缓存侧通道集成Warm和Delay的性能的方法,我们得出了将Warm和Delay集成的最佳方案,并将其应用于AES。事实证明,该集成方案可以在商品系统上以最少的额外操作获得最佳性能。最后,我们在具有Intel CPU的Linux上实现它。实验结果证实,(a)执行时间不会泄漏有关缓存访问的信息,(b)该方案的性能优于Warm和Delay的其他集成策略,并且(c)该实现在计算机上无需任何特权操作即可工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号