| Statistics and secret leakage |
| Full text |
Pdf
(219 KB)
|
| Source
|
ACM Transactions on Embedded Computing Systems (TECS)
archive
Volume 3 , Issue 3 (August 2004)
table of contents
Pages: 492 - 508
Year of Publication: 2004
ISSN:1539-9087
|
|
Authors
|
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 11, Downloads (12 Months): 81, Citation Count: 5
|
|
|
ABSTRACT
In addition to its usual complexity assumptions, cryptography silently assumes that information can be physically protected in a single location. As one can easily imagine, real-life devices are not ideal and information may leak through different physical channels.This paper gives a rigorous definition of leakage immunity and presents several leakage detection tests. In these tests, failure confirms the probable existence of secret-correlated emanations and indicates how likely the leakage is. Success does not refute the existence of emanations but indicates that significant emanations were not detected on the strength of the evidence presented, which of course, leaves the door open to reconsider the situation if further evidence comes to hand at a later date.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Anderson, R. and Kuhn, M. 1996. Tamper resistance---a cautionary note. In The Second usenix Workshop on Electronic Commerce. 1--11.
|
| |
2
|
Bennett, C. 1973. Logical reversibility of computation. IBM J. R&D 17, 525--532.
|
| |
3
|
|
| |
4
|
Boneh, D., DeMillo, R., and Lipton, R. 1997. On the importance of checking cryptographic protocols for faults. In Proceedings of Eurocrypt' 97. 37--51.
|
| |
5
|
|
| |
6
|
|
| |
7
|
Edgeworth, F. 1885. Observations and statistics: an essay on the theory of errors of observation and the first principles of statistics. Trans. Cambridge Philos. Soc. 138--169.
|
| |
8
|
ISO/IEC 15408-1:1999(E). 1999. Information technology--security techniques--evaluation criteria for it security. International Organization for Standardization and International Electrotechnical Commission.
|
| |
9
|
Jun, B. and Kocher, P. 1999. The intel random number generator. Cryptography Research white paper. Available at http://www.cryptography.com/intelRNG.pdf.
|
| |
10
|
Keyes, R. 1975. Physical limits in digital electronics. Proc. IEEE 63.
|
| |
11
|
|
| |
12
|
|
| |
13
|
|
| |
14
|
Kommerling, O. and Kuhn, M. 1999. Design principles for tamper-resistant smart-card processors. Proceedings of the USENIX Workshop on Smartcard Technology.
|
| |
15
|
Langley, R. 1968. Practical Statistics. Dover, New York.
|
| |
16
|
|
| |
17
|
|
| |
18
|
|
| |
19
|
Miller, I., Freund, J., and Johnson, R. 1990. Probability and statistics for enginners. Prentice Hall, Englewood Cliffs, NJ.
|
| |
20
|
NIST. 1994. Security requirements for cryptographic modules. National Institute of Standards and Technology, Federal Information Processing Standards Publication 140--1.
|
| |
21
|
SEPI'91. 1991. Symposium on Electromagnetic Security for Information Protection, Rome, Italy.
|
| |
22
|
SPI'88. 1988. Primo simposio nazionale su sicurezza elettromagnetica nella protezione dell'informazione, Rome, Italy.
|
| |
23
|
|
| |
24
|
|
CITED BY 5
|
|
|
|
|
R. Muresan , H. Vahedi , Y. Zhanrong , S. Gregori, Power-smart system-on-chip architecture for embedded cryptosystems, Proceedings of the 3rd IEEE/ACM/IFIP international conference on Hardware/software codesign and system synthesis, September 19-21, 2005, Jersey City, NJ, USA
|
|
|
Nachiketh R. Potlapally , Anand Raghunathan , Srivaths Ravi , Niraj K. Jha , Ruby B. Lee, Satisfiability-based framework for enabling side-channel attacks on cryptographic software, Proceedings of the conference on Design, automation and test in Europe: Designers' forum, March 06-10, 2006, Munich, Germany
|
|
|
|
|
|
|
|