A new CRT-RSA algorithm resistant to powerful fault attacks

  • Authors:
  • Nevine Ebeid;Rob Lambert

  • Affiliations:
  • Certicom Corp., Mississauga, Ontario, Canada;Certicom Corp., Mississauga, Ontario, Canada

  • Venue:
  • WESS '10 Proceedings of the 5th Workshop on Embedded Systems Security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

CRT-RSA is widely deployed in embedded devices to accelerate the RSA signature generation by about four times compared to regular RSA. However, since the Bellcore attack of 1996, research into securing CRT-RSA has remained active as countermeasures are themselves attacked. In this paper, we propose a new countermeasure designed with a powerful attacker in mind. The attacker may inject multiple precise/random faults and may alter the program counter to skip one or more instructions. The strength of our countermeasure derives from combining signature validation with signature unblinding modulo n.