Simple backdoors for RSA key generation

  • Authors:
  • Claude Crépeau;Alain Slakmon

  • Affiliations:
  • School of Computer Science, McGill University, Montréal, Québec, Canada;Département de Mathématiques, Collège de Bois-de-Boulogne, Montréal, Québec, Canada

  • Venue:
  • CT-RSA'03 Proceedings of the 2003 RSA conference on The cryptographers' track
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

In smartcard encryption and signature applications, randomised algorithms are used to increase tamper resistance against attacks based on side channel leakage. Mist is one of these. As is the case with the classical m-ary and slidingwin dows exponentiation algorithms, the most significant half of the public modulus yields information which can be used to halve the number of key digits which need to be guessed to recover the secret key from a Mist side channel trace. Lattice based methods are used to reduce this to just one quarter of the least significant digits. This enables the strength of the Mist exponentiation algorithm to be guaged more accurately under several threat models.