首页> 外文期刊>IEICE Transactions on fundamentals of electronics, communications & computer sciences >Information leakage through passive timing attacks on RSA decryption system
【24h】

Information leakage through passive timing attacks on RSA decryption system

机译:RSA解密系统被动定时攻击导致信息泄露

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

A side channel attack is a means of security attacks thattries to restore secret information by analyzing side-information such aselectromagnetic wave, heat, electric energy and running time that are unin-tentionally emitted from a computer system. The side channel attack thatfocuses on the running time of a cryptosystem is specifically named a “tim-ing attack”. Timing attacks are relatively easy to carry out, and particularlythreatening for tiny systems that are used in smart cards and IoT devicesbecause the system is so simple that the processing time would be clearlyobserved from the outside of the card/device. The threat of timing attacksis especially serious when an attacker actively controls the input to a targetprogram. Countermeasures are studied to deter such active attacks, but theattacker still has the chance to learn something about the concealed infor-mation by passively watching the running time of the target program. Therisk of passive timing attacks can be measured by the mutual informationbetween the concealed information and the running time. However, thecomputation of the mutual information is hardly possible except for toy ex-amples. This study focuses on three algorithms for RSA decryption, derivesformulas of the mutual information under several assumptions and approx-imations, and calculates the mutual information numerically for practicalsecurity parameters.
机译:侧信道攻击是一种安全攻击手段,它试图通过分析计算机系统无意中发出的电磁波、热量、电能和运行时间等侧信息来恢复秘密信息。专注于密码系统运行时间的侧信道攻击被特别称为“定时攻击”。定时攻击相对容易执行,对于智能卡和物联网设备中使用的微型系统尤其具有威胁性,因为该系统非常简单,可以从卡/设备的外部清楚地观察到处理时间。当攻击者主动控制目标程序的输入时,定时攻击的威胁尤其严重。研究了对策来阻止这种主动攻击,但攻击者仍然有机会通过被动观察目标程序的运行时间来了解隐藏的信息。被动定时攻击的风险可以通过隐藏信息与运行时间之间的相互信息来衡量。然而,除了玩具示例外,几乎不可能计算互信息。本研究重点介绍了3种RSA解密算法,推导了几种假设和近似下的互信息公式,并对互信息进行了数值计算,得出了实际的安全参数。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号