A Cautionary Note Regarding Evaluation of AES Candidateson
نویسندگان
چکیده
NIST has considered the performance of AES candidates on smart-cards as an important selection criterion and many submitters have highlighted the compactness and eeciency of their submission on low end smart cards. However, in light of recently discovered power based attacks, we strongly argue that evaluating smart-card suitability of AES candidates requires a very cautious approach. We demonstrate that straightforward implementations of AES candidates on smart cards, are highly vulnerable to power analysis and readily leak away all secret keys. To illustrate our point, we describe a power based attack on the Twoosh Reference 6805 code which we implemented on a ST16 smart card. The attack required power samples from only 100 independent block encryptions to fully recover the 128-bit secret key. We also describe how all other AES candidates are susceptible to similar attacks. We review the basis of power attacks and suggest countermeasures for a secure implementation. Unfortunately, it appears that these software countermeasures result in signiicant memory and eeciency overhead and therefore the most eecient smart card implementation cannot serve as a guide in evaluating AES candidates.
منابع مشابه
A Cautionary Note Regarding Evaluation of AES Candidates on Smart-Cards
NIST has considered the performance of AES candidates on smart-cards as an important selection criterion and many submitters have highlighted the compactness and e ciency of their submission on low end smart cards. However, in light of recently discovered power based attacks, we strongly argue that evaluating smart-card suitability of AES candidates requires a very cautious approach. We demonst...
متن کاملA Commentary On: “NFκB-Activated Astroglial Release of Complement C3 Compromises Neuronal Morphology and Function Associated with Alzheimer’s Disease”. A cautionary note regarding C3aR
Citation: Woodruff TM and Tenner AJ (2015) A commentary on: “NFκB-activated astroglial release of complement C3 compromises neuronal morphology and function associated with Alzheimer’s disease”. A cautionary note regarding C3aR. Front. Immunol. 6:220. doi: 10.3389/fimmu.2015.00220 A commentary on: “NF B-activated astroglial release of complement C3 compromises neuronal morphology and function a...
متن کاملA Cautionary Note on Weak Implementations of Block Ciphers
An easy way to mount an attack on software binaries without error checking for the AES, DES and other block ciphers is presented. It is detailed how full key recovery is possible and how common cipher modes of operation are then circumvented. The application of this method to recover key material and data from security systems is then discussed along with a number of possible countermeasures.
متن کاملHardware Implementation of Dynamic S-BOX to Use in AES Cryptosystem
One of the major cipher symmetric algorithms is AES. Its main feature is to use S-BOX step, which is the only non-linear part of this standard possessing fixed structure. During the previous studies, it was shown that AES standard security was increased by changing the design concepts of S-BOX and production of dynamic S-BOX. In this paper, a change of AES standard security is studied by produc...
متن کاملEffects of Dynamic Neuromuscular Stabilization and Aquatic Exercises on the Pain, Disability, Lumbopelvic Control, and Spinal Posture of Patients With Non-specific Low Back Pain
Objectives: Using an exercise intervention to improve lumbopelvic control (LPC) can enhance the pain severity and disability of participants with non-specific low back pain (NSLBP). The present study aimed to compare dynamic neuromuscular stabilization (DNS) exercises and common aquatic exercises (AEs) in terms of improving the pain, disability, LPC, and spinal posture of patients with non-spec...
متن کامل