Side-channel analysis of the modular inversion step in the RSA key generation algorithm

This paper studies the security of the RSA key generation algorithm with regard to side-channel analysis and presents a novel approach that targets the simple power analysis (SPA) vulnerabilities that may exist in an implementation of the binary extended Euclidean algorithm (BEEA). The SPA vulnerabi...

Descripción completa

Detalles Bibliográficos
Autores: Cabrera Aldaya, Alejandro, Cuiman Márquez, Raudel, Cabrera Sarmiento, Alejandro José, Sánchez Solano, Santiago
Tipo de recurso: artículo
Estado:Versión enviada para evaluación y publicación
Fecha de publicación:2016
País:España
Institución:Universidad de Sevilla (US)
Repositorio:idUS. Depósito de Investigación de la Universidad de Sevilla
OAI Identifier:oai:idus.us.es:11441/73804
Acceso en línea:https://hdl.handle.net/11441/73804
https://doi.org/10.1002/cta.2283
Access Level:acceso abierto
Palabra clave:Side-channel analysis
SPA
Binary Euclidean algorithm
RSA key generation
Descripción
Sumario:This paper studies the security of the RSA key generation algorithm with regard to side-channel analysis and presents a novel approach that targets the simple power analysis (SPA) vulnerabilities that may exist in an implementation of the binary extended Euclidean algorithm (BEEA). The SPA vulnerabilities described, together with the properties of the values processed by the BEEA in the context of RSA key generation, represent a serious threat for an implementation of this algorithm. It is shown that an adversary can disclose the private key employing only one power trace with a success rate of 100 % – an improvement on the 25% success rate achieved by the best side-channel analysis carried out on this algorithm. Two very different BEEA implementations are analyzed, showing how the algorithm’s SPA leakages could be exploited. Also, two countermeasures are discussed that could be used to reduce those SPA leakages and prevent the recovery of the RSA private key