首页> 外文OA文献 >Side-Channel Attacks meet Secure Network Protocols
【2h】

Side-Channel Attacks meet Secure Network Protocols

机译:侧信道攻击符合安全网络协议

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Side-channel attacks are powerful tools for breaking systems that implement cryptographic algorithms. The Advanced Encryption Standard (AES) is widely used to secure data, including the communication within various network protocols. Major cryptographic libraries such as OpenSSL or ARM mbed TLS include at least one implementation of the AES. In this paper, we show that most implementations of the AES present in popular open-source cryptographic libraries are vulnerable to side-channel attacks, even in a network protocol scenario when the attacker has limited control of the input. We present an algorithm for symbolic processing of the AES state for any input configuration where several input bytes are variable and known, while the rest are fixed and unknown as is the case in most secure network protocols. Then, we classify all possible inputs into 25 independent evaluation cases depending on the number of bytes controlled by attacker and the number of rounds that must be attacked to recover the master key. Finally, we describe an optimal algorithm that can be used to recover the master key using Correlation Power Analysis (CPA) attacks. Our experimental results raise awareness of the insecurity of unprotected implementations of the AES used in network protocol stacks.
机译:边信道攻击是用于破坏实现密码算法的系统的强大工具。高级加密标准(AES)被广泛用于保护数据安全,包括各种网络协议内的通信。诸如OpenSSL或ARM mbed TLS之类的主要密码库至少包括AES的一种实现。在本文中,我们证明了流行的开放源代码加密库中存在的大多数AES实现都容易受到旁通道攻击,即使在网络协议场景中,攻击者对输入的控制也有限。我们提出了一种算法,用于对任何输入配置进行AES状态的符号处理,其中几个输入字节是可变的并且是已知的,而其余的则是固定的并且是未知的(与大多数安全网络协议一样)。然后,根据攻击者控制的字节数和恢复主密钥必须受到攻击的回合数,我们将所有可能的输入分为25个独立的评估案例。最后,我们描述了一种最佳算法,该算法可用于使用相关功率分析(CPA)攻击来恢复主密钥。我们的实验结果提高了人们对网络协议栈中未受保护的AES实现的不安全性的认识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号