The RSA cryptosystem is currently the most widely used public key encryption system. It allows to guarantee the confidentiality, integrity and authenticity of the information transmitted or stored. Moreover, RSA cryptosystem is considered to be mathematically secure against the integer factorization methods, but there are other attacks whose objective is to obtain the private key. In fact, Fault Injection Attacks deliberately induce a fault in the execution of the algorithm to get a wrong output, so that such output permits the attacker to make guesses based on the comparison of different results. In this work, we explain the mathematical concepts of two fault injection attacks and analyze the security of the implementation of the RSA in a digital signature scenario, in particular when the RSA-CRT algorithm is considered. By using the Chipwhisperer platform, we simulate the Bellcore and the Lenstra attacks to factorize the RSA module and to obtain the private key. The first attack compares a faulty signature and the real one, whereas the second one only uses a faulty signature.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Fault Injection Attacks Against RSA-CRT Digital Signature

  • Fernando Contreras Alcalá,
  • Miguel Ángel González de la Torre,
  • Luis Hernández Encinas

摘要

The RSA cryptosystem is currently the most widely used public key encryption system. It allows to guarantee the confidentiality, integrity and authenticity of the information transmitted or stored. Moreover, RSA cryptosystem is considered to be mathematically secure against the integer factorization methods, but there are other attacks whose objective is to obtain the private key. In fact, Fault Injection Attacks deliberately induce a fault in the execution of the algorithm to get a wrong output, so that such output permits the attacker to make guesses based on the comparison of different results. In this work, we explain the mathematical concepts of two fault injection attacks and analyze the security of the implementation of the RSA in a digital signature scenario, in particular when the RSA-CRT algorithm is considered. By using the Chipwhisperer platform, we simulate the Bellcore and the Lenstra attacks to factorize the RSA module and to obtain the private key. The first attack compares a faulty signature and the real one, whereas the second one only uses a faulty signature.