On the importance of eliminating errors in cryptographic computations
Practical cryptanalysis need not be restricted just to searching for weaknesses of a particular cryptographic algorithm. Instead, an attacker can make an attempt to determine a cryptographic secret in a particular implementation of a cryptographic algorithm. The paper discusses a class of such attacks against various cryptographic schemes, namely attacks by taking advantage of hardware faults. The authors first describe a number of environments where such attacks may apply, introduce the attack model, and provide a summary of results. Then sections follow on RSA's vulnerability to hardware faults and attacks on identification protocols. Here it is shown that especially RSA implementations based on the Chinese Remainder Theorem are susceptible to hardware or software errors, but other implementations of RSA can be attacked as well, though the attack is not so practical as in the first case. Also it is shown that the secret key used in the Fiat-Shamir identification protocol is exposed after a small number of faulty executions of the protocol, and that similar results hold for Schnorr's identification protocol though a much larger number of erroneous executions is necessary. Several methods for defending against the attacks are then discussed, and the paper ends with brief summary and some open problems.
- Physical attacks and beyond
- Loop-abort faults on lattice-based Fiat-Shamir and hash-and-sign signatures
- Chinese remaindering based cryptosystems in the presence of faults
- Protecting ECC against fault attacks: the ring extension method revisited
- Impossibility on tamper-resilient cryptography with uniqueness properties
- A note on perfect correctness by derandomization
- Continuously non-malleable codes in the split-state model
- Locally decodable and updatable non-malleable codes and their applications
- Elliptic curve cryptosystems in the presence of permanent and transient faults
- Revisiting prime power RSA
- Efficient RKA-Secure KEM and IBE Schemes Against Invertible Functions
- The Chaining Lemma and its application
- Tamper-Proof Circuits: How to Trade Leakage for Tamper-Resilience
- Partial key exposure: generalized framework to attack RSA
- Checking before output may not be enough against fault-based cryptanalysis
- Fault Attacks on Public Key Elements: Application to DLP-Based Schemes
- Montgomery Residue Representation Fault-Tolerant Computation in GF(2 k )
- Bug Attacks
- Fault Attacks on RSA Public Keys: Left-To-Right Implementations Are Also Vulnerable
- An Improved Fault Based Attack of the Advanced Encryption Standard
- Fault based attack of the Rijndael cryptosystem
- Analysis of the fault attack ECDLP over prime field
- scientific article; zbMATH DE number 1759293 (Why is no real title available?)
- Improving Divide and Conquer Attacks against Cryptosystems by Better Error Detection / Correction Strategies
- A fault attack on the LED block cipher
- Witness maps and applications
- Bounded tamper resilience: how to go beyond the algebraic barrier
- A note on perfect correctness by derandomization
- Fault-Tolerant Finite Field Computation in the Public Key Cryptosystems
- Perturbating RSA Public Keys: An Improved Attack
- Fault-injection attacks against NIST's post-quantum cryptography round 3 KEM candidates
- A one-time single-bit fault leaks all previous NTRU-HRSS session keys to a chosen-ciphertext attack
- (Continuous) Non-malleable Codes for Partial Functions with Manipulation Detection and Light Updates
- Glitch and laser fault attacks onto a secure AES implementation on a SRAM-based FPGA
- Fault-based attack on Montgomery's ladder algorithm
- Non-malleable codes from leakage resilient cryptographic primitives
- Efficiently testable circuits without conductivity
- The security of ML-DSA against fault-injection attacks
- Fault attacks on multi-prime RSA signatures
- Key-agreement with perfect completeness from random oracles
- Lightweight fault detection architecture for modular exponentiation in cryptography on ARM and FPGA
- Thwarting side-channel analysis against RSA cryptosystems with additive blinding
- The random oracle model: a twenty-year retrospective
- Fault attacks on hyperelliptic curve discrete logarithm problem over binary field
This page was built for publication: On the importance of eliminating errors in cryptographic computations
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q5934142)