Partial key exposure attacks, introduced by Boneh, Durfee and Frankel in 1998, aim at retrieving an RSA private key when a fraction of its bits is known. These attacks are of particular interest in the context of side-channel attacks, where the attacker can retrieve bits of the key exploiting leakages in the implementation. In this work we analyze the effectiveness of partial key exposure when a countermeasure for side-channel attacks is adopted. In particular, we consider the exponent blinding technique, which consists in randomizing the private exponent at each execution. We address our analysis to both RSA and CRT-RSA, providing theoretical proofs and experimental results.

Partial key exposure attacks on RSA with exponent blinding / S. Cimato, S. Mella, R. Susella - In: E-Business and Telecommunications / [a cura di] M.S. Obaidat, P. Lorenz. - Prima edizione. - [s.l] : Springer, 2016. - ISBN 9783319302218. - pp. 364-385 (( Intervento presentato al 12. convegno ICETE tenutosi a Colmar nel 2015.

Partial key exposure attacks on RSA with exponent blinding

S. Cimato
Primo
;
S. Mella
;
2016

Abstract

Partial key exposure attacks, introduced by Boneh, Durfee and Frankel in 1998, aim at retrieving an RSA private key when a fraction of its bits is known. These attacks are of particular interest in the context of side-channel attacks, where the attacker can retrieve bits of the key exploiting leakages in the implementation. In this work we analyze the effectiveness of partial key exposure when a countermeasure for side-channel attacks is adopted. In particular, we consider the exponent blinding technique, which consists in randomizing the private exponent at each execution. We address our analysis to both RSA and CRT-RSA, providing theoretical proofs and experimental results.
RSA; Partial key exposure; Coppersmith's method; Exponent blinding; Horizontal attack
Settore INF/01 - Informatica
2016
Book Part (author)
File in questo prodotto:
File Dimensione Formato  
ICETE-2015.pdf

accesso riservato

Tipologia: Publisher's version/PDF
Dimensione 331.51 kB
Formato Adobe PDF
331.51 kB Adobe PDF   Visualizza/Apri   Richiedi una copia
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2434/460221
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 1
  • ???jsp.display-item.citation.isi??? 0
social impact