ROSETTA for Single Trace Analysis Recovery Of Secret Exponent by Triangular Trace Analysis

In most efficient exponentiation implementations, recovering the secret exponent is equivalent to disclosing the sequence of squaring and multiplication operations. Some known attacks on the RSA exponentiation apply this strategy, but cannot be used against classical blinding countermeasures. In thi...

Full description

Saved in:
Bibliographic Details
Published inProgress in Cryptology - INDOCRYPT 2012 pp. 140 - 155
Main Authors Clavier, Christophe, Feix, Benoit, Gagnerot, Georges, Giraud, Christophe, Roussellet, Mylène, Verneuil, Vincent
Format Book Chapter
LanguageEnglish
Published Berlin, Heidelberg Springer Berlin Heidelberg
SeriesLecture Notes in Computer Science
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:In most efficient exponentiation implementations, recovering the secret exponent is equivalent to disclosing the sequence of squaring and multiplication operations. Some known attacks on the RSA exponentiation apply this strategy, but cannot be used against classical blinding countermeasures. In this paper, we propose new attacks distinguishing squaring from multiplications using a single side-channel trace. It makes our attacks more robust against blinding countermeasures than previous methods even if both exponent and message are randomized, whatever the quality and length of random masks. We demonstrate the efficiency of our new techniques using simulations in different noise configurations.
ISBN:9783642349300
3642349307
ISSN:0302-9743
1611-3349
DOI:10.1007/978-3-642-34931-7_9