Practical Second-Order Correlation Power Analysis on the Message Blinding Method and Its Novel Countermeasure for RSA
- Authors
- Kim, HeeSeok; Kim, Tae Hyun; Yoon, Joong Chul; Hong, Seokhie
- Issue Date
- 2월-2010
- Publisher
- WILEY
- Keywords
- RSA cryptosystems; side channel attacks; message blinding method; BRIP; second-order DPA
- Citation
- ETRI JOURNAL, v.32, no.1, pp.102 - 111
- Indexed
- SCIE
SCOPUS
KCI
- Journal Title
- ETRI JOURNAL
- Volume
- 32
- Number
- 1
- Start Page
- 102
- End Page
- 111
- URI
- https://scholar.korea.ac.kr/handle/2021.sw.korea/117051
- DOI
- 10.4218/etrij.10.0109.0249
- ISSN
- 1225-6463
- Abstract
- Recently power attacks on RSA cryptosystems have been widely investigated, and various countermeasures have been proposed. One of the most efficient and secure countermeasures is the message blinding method, which includes the RSA derivative of the binary-with-random-initial-point algorithm on elliptical curve cryptosystems. It is known to be secure against first-order differential power analysis (DPA); however, it is susceptible to second-order DPA. Although second-order DPA gives some solutions for defeating message blinding methods, this kind of attack still has the practical difficulty of how to find the points of interest, that is, the exact moments when intermediate values are being manipulated. In this paper, we propose a practical second-order correlation power analysis (SOCPA). Our attack can easily find points of interest in a power trace and find the private key with a small number of power traces. We also propose an efficient countermeasure which is secure against the proposed SOCPA as well as existing power attacks.
- Files in This Item
- There are no files associated with this item.
- Appears in
Collections - Graduate School > Department of Cyber Security > 1. Journal Articles
- School of Cyber Security > Department of Information Security > 1. Journal Articles
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.