Zur Kurzanzeige

dc.contributor.authorLauradoux, Cédric
dc.contributor.editorWulf, Christopher
dc.contributor.editorLucks, Stefan
dc.contributor.editorYau, Po-Wah
dc.date.accessioned2019-08-26T12:42:23Z
dc.date.available2019-08-26T12:42:23Z
dc.date.issued2005
dc.identifier.isbn3-88579-403-9
dc.identifier.issn1617-5468
dc.identifier.urihttp://dl.gi.de/handle/20.500.12116/24852
dc.description.abstractImplementing cryptographic algorithms is a difficult problem since additional secret information can be recovered from some physical characteristics of a cryptographic device. Among all side-channel attacks, collision attacks and cache attacks are the most recent ones. The first technique uses side-channel information to detect internal collisions related to the algorithm. The second one exploits timing or power consumptions related to the memory accesses. This paper presents a new attack on the first round of AES based on power analysis, which combines both collision attacks and cache attacks. It provides many linear relations between the secret key bits from the encryption of a few chosen plaintexts. For instance, for a classical implementation using 4 lookup tables on a processor with 64-byte cache blocks, 48 linear relations involving half of the key bits are derived. Some countermeasures which defeat such attacks are also presented.en
dc.language.isoen
dc.publisherGesellschaft für Informatik e.V.
dc.relation.ispartofWEWoRC 2005 – Western European Workshop on Research in Cryptology
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P-74
dc.titleCollision attacks on processors with cache and countermeasuresen
dc.typeText/Conference Paper
dc.pubPlaceBonn
mci.reference.pages76-85
mci.conference.sessiontitleRegular Research Papers
mci.conference.locationLeuven, Belgium
mci.conference.date5.-7. July 2005


Dateien zu dieser Ressource

Thumbnail

Zur Kurzanzeige