Attacking exponent blinding in RSA without CRT

  • Authors:
  • Sven Bauer

  • Affiliations:
  • Giesecke & Devrient GmbH, Munich, Germany

  • Venue:
  • COSADE'12 Proceedings of the Third international conference on Constructive Side-Channel Analysis and Secure Design
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

A standard SPA protection for RSA implementations is exponent blinding (see [7]). Fouque et al., [4] and more recently Schindler and Itoh, [8] have described side-channel attacks against such implementations. The attack in [4] requires that the attacker knows some bits of the blinded exponent with certainty. The attack methods of [8] can be defeated by choosing a sufficiently large blinding factor (about 64 bit). In this paper we start from a more realistic model for the information an attacker can obtain by simple power analysis (SPA) than the one that forms the base of the attack in [4]. We show how the methods of [4] can be extended to work in this setting. This new attack works, under certain restrictions, even for long blinding factors (i.e. 64 bit or more).