Side-channel attacks aim at retrieving cryptographic secrets from a device by exploiting involuntary information channels, such as power consumption or electromagnetic emissions, measured in traces. Among them, horizontal attacks are particularly powerful as they require only a single measurement of an algorithm execution from the target device. In our work, we propose a horizontal attack technique that autonomously detects intermediate value reuses, and extracts cryptographic secret information without needing to analyze or know the implementation of the cryptographic algorithm being run. Our technique, which only assumes the basic a-priori knowledge that the algorithm computes iteratively using a portion of the cryptographic secret in each iteration, both allows successful attacks, and provides the secure software developers with feedback on the vulnerable spots. We validate our attack through a case study on a square-and-multiply-always RSA implementation using the production grade mbedtls cryptographic library. Experimental results demonstrate that our approach can retrieve the entire secret RSA exponent from a single execution trace.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Unprofiled Single Trace Side-Channel Attack for Asymmetric Cryptosystems

  • Isabella Piacentini,
  • Alessandro Barenghi,
  • Gerardo Pelosi,
  • Ruggero Susella

摘要

Side-channel attacks aim at retrieving cryptographic secrets from a device by exploiting involuntary information channels, such as power consumption or electromagnetic emissions, measured in traces. Among them, horizontal attacks are particularly powerful as they require only a single measurement of an algorithm execution from the target device. In our work, we propose a horizontal attack technique that autonomously detects intermediate value reuses, and extracts cryptographic secret information without needing to analyze or know the implementation of the cryptographic algorithm being run. Our technique, which only assumes the basic a-priori knowledge that the algorithm computes iteratively using a portion of the cryptographic secret in each iteration, both allows successful attacks, and provides the secure software developers with feedback on the vulnerable spots. We validate our attack through a case study on a square-and-multiply-always RSA implementation using the production grade mbedtls cryptographic library. Experimental results demonstrate that our approach can retrieve the entire secret RSA exponent from a single execution trace.