Profiling attack against rsa key generation based on a euclidean algorithm

A profiling attack is a powerful variant among the noninvasive side channel attacks. In this work, we target RSA key generation relying on the binary version of the extended Euclidean algorithm for modular inverse and GCD computations. To date, this algorithm has only been exploited by simple power...

ver descrição completa

Detalhes bibliográficos
Autores: de la Fé, Sadiel|||0000-0003-2346-2163, Park, Han-Byeol, Sim, Bo-Yeon, Han, Dong-Guk, Ferrer, Carles|||0000-0002-1475-8790
Formato: artículo
Fecha de publicación:2021
País:España
Recursos:Universitat Autònoma de Barcelona
Repositorio:Dipòsit Digital de Documents de la UAB
Idioma:inglés
OAI Identifier:oai:ddd.uab.cat:255030
Acesso em linha:https://ddd.uab.cat/record/255030
https://dx.doi.org/urn:doi:10.3390/info12110462
Access Level:acceso abierto
Palavra-chave:Euclidean algorithm
GCD
RSA key generation
Side channel attack
Profiling attack
Machine learning-based attack
Descrição
Resumo:A profiling attack is a powerful variant among the noninvasive side channel attacks. In this work, we target RSA key generation relying on the binary version of the extended Euclidean algorithm for modular inverse and GCD computations. To date, this algorithm has only been exploited by simple power analysis; therefore, the countermeasures described in the literature are focused on mitigating only this kind of attack. We demonstrate that one of those countermeasures is not effective in preventing profiling attacks. The feasibility of our approach relies on the extraction of several leakage vectors from a single power trace. Moreover, because there are known relationships between the secrets and the public modulo in RSA, the uncertainty in some of the guessed secrets can be reduced by simple tests. This increases the effectiveness of the proposed attack.