Active hardware attacks and proactive countermeasures

A.G. Voyiatzis1, D.N. Serpanos1
1Department of Electrical and Computer Engineering, University of Patras, Patras, Greece

Tóm tắt

Active hardware attacks succeed in deriving cryptographic secrets from target devices. They were originally proposed for systems implementing RSA, Fiat-Shamir (1988) scheme, and Schnorr's scheme. Common targets for these attacks are systems used for client authentication in order to access services, e.g., pay-per view TV, video distribution and cellular telephony. These client systems hold secrets, typically cryptographic keys, owned by the service provider and often implement the Fiat-Shamir identification scheme. Given the strength of active attacks and the increasingly wide deployment of client systems, it is desirable to design proactive countermeasures for them. We focus on the Fiat-Shamir scheme. We prove that the conventional active attack can be easily avoided through appropriate system and protocol configuration; we denote this configuration as the precautious Fiat-Shamir Scheme. We argue that proactive countermeasures against active attacks are feasible and lead to systems that are inherently resistant to active attacks by careful protocol design, rather than ad hoc solutions.

Từ khóa

#Hardware #Cryptography #Authentication #Cryptographic protocols #Public key #TV #Telephony #Algorithm design and analysis #Power measurement #Electromagnetic measurements

Tài liệu tham khảo

rao, 2001, Empowering side-channel attacks, Cryptology ePrint Archive messerges, 1999, Investigations of power analysis attacks on smartcards, Proceedings of the First USENIX Workshop on Smartcard Technology quisquater, 2001, Electromagnetic analysis (ema): Measures and countermeasures for smart cards, E-smart 2001 LNCS 2140, 200 kocher, 1999, Differential power analysis, Proceedings of Crypto '99 LNCS 1666, 388 lenstra, 0, Memo on RSA Signature Generation in the Presense of FaultsManuscript kelsey, 1998, Side channel cryptanalysis of product ciphers, ESORICS 98 LNCS 1485, 97 kocher, 1996, Timing attacks on implementations of diffie-hellman, rsa, dss and other systems, Proceedings of the Crypto '96 LNCS 1109, 104 antoniadis, 2001, Software Simulation of Active Attacks on Cryptographic Systems anderson, 1997, Low cost attacks on tamper resistance devices, Security Protocol Workshop '97 LNCS 1361, 125 anderson, 1996, Tamper resistance-A cautionary note, Proceedings of the Second Usenix Workshop on Electronic Commerce gandolfi, 2001, Electromagnetic analysis: Concrete results, CHES 2001 LNCS 2162, 251 10.1007/s001450010016 boneh, 1997, On the importance of checking cryptographic protocols for faults, EUROCRYPT '97 LNCS 1233, 37 biham, 1997, Differential fault analysis of secret key cryptosystems, CRYPTO '97 LNCS 1294, 513 bao, 1997, Breaking public key cryptosystems on tamper resistant devices in the presence of transient faults, Security Protocol Workshop '97 LNCS, 1361 10.1007/BF02351717 dhem, 1998, A practical implementation of the timing attack, Technical Report CG-1998/1 UCL Crypto Group DICE