Genral Web Comments
Tuesday, June 21, 2005
Crypto-Gram: June 15, 1998
Crypto-Gram: June 15, 1998: "Side-Channel Attacks Against Cryptosystems
In the last few years, new kinds of cryptanalytic attack have begun to appear in the literature: attacks that target specific implementation details. The 'timing attack' made a big press splash in 1995: RSA private keys could be recovered by measuring the relative times cryptographic operations took. This attack has been successfully implemented against smart cards and other security tokens, and against electronic commerce servers across the Internet.
Researchers have generalized these methods to include attacks on a system by measuring power consumption, radiation emissions, and other 'side channels,' and have implemented them against a variety of public-key and symmetric algorithms in 'secure' tokens. Related research has looked at fault analysis: deliberately introducing faults into cryptographic processors in order to determine the secret keys. The effects of this attack can be devastating. "
