Fault Diagnosis and Tolerance in Cryptography: Third by Shay Gueron, Jean-Pierre Seifert (auth.), Luca Breveglieri,

In contemporary years utilized cryptography has constructed significantly to fulfill the - creasing safeguard requisites of assorted info know-how disciplines, similar to telecommunications, networking, database structures, cellular purposes and others. Cryptosystems are inherently computationally complicated and on the way to fulfill the excessive throughput requisites of many functions, they can be carried out through both VLSI units (cryptographic accelerators) or hugely optimized software program workouts (cryptographic libraries) and are used through appropriate (network) protocols. The sophistication of the underlying cryptographic algorithms, the excessive complexity of the implementations, and the simple entry and occasional price of cryptographic units led to elevated matters in regards to the reliability and defense of crypto-devices. The effectiveness of aspect channel assaults on cryptographic units, like timing and power-based assaults, has been identified for it slow. a number of fresh investigations have validated the necessity to advance methodologies and strategies for designing strong cryptographic platforms (both and software program) to guard them opposed to either unintentional faults and maliciously injected faults with the aim of extracting the key key. This pattern has been quite influenced by means of the truth that the apparatus had to perform a profitable aspect channel assault in keeping with fault injection is definitely available at a comparatively comparatively cheap (for instance, laser beam technology), and that the abilities had to use it are very common. The id of part channel assaults in keeping with fault injections and the improvement of applicable counter-measures have hence turn into an energetic box of clinical and commercial research.

Quality: Vector (converted from nice scan), Searchable, Bookmarked

Details of proofs have been confined to Appendix A. 2 Preliminary Notions Recall (see [16]) that for a given prime p, x is a quadratic residue mod p if gcd(x, p) = 1 and x = y2 mod p for some y. If gcd(x, p) = 1 and x is not a quadratic residue mod p, then x is called quadratic non-residue mod p. m , for m and n integers, n ≥ 3 odd, is defined as follows. If The Jacobi symbol n n = p is prime (in this case one also speaks of Legendre symbol), then ⎧ 1 if m is a quadratic residue mod p m def ⎨ = −1 if m is a quadratic non-residue mod p ⎩ p 0 otherwise.

These extensions will be the subject of further study. References 1. J. Anderson, M. Bond, J. Clulow, S. Skorobogatov. Cryptographic processors – a survey, Technical Report UCAM-CL-TR-641, University of Cambridge, Computer Laboratory, August 2005. 2. J. Kuhn, Tamper resistance − a cautionary note. The second USENIX Workshop on Electronic Commerce proceedings, Nov. 1996. 3. J. J. Kuhn, Low cost attacks on tamper-resistant devices, Security protocols, 5th International Workshop, Paris, 1997. 4. C.

2, 101–119. J. Bl¨ omer, M. -P. Seifert, A new CRT-RSA algorithm secure against Bellcore attacks, Conference on Computer and Communications Security — CCS 2003 (V. Atluri and P. ), ACM SIGSAC, ACM Press, 2003, pp. 311–320. C. -S. Coron, and N. Dabbous, Differential power analysis in the presence of hardware countermeasures, Cryptographic Hardware and Embedded Systems – Proceedings of CHES 2000, Worcester, MA, USA, Lecture Notes in Computer Science, vol. 1965, Springer-Verlag, 2000, pp. 252– 263.

