Cryptographic Hardware and Embedded Systems - CHES 2007: 9th by Josh Jaffe (auth.), Pascal Paillier, Ingrid Verbauwhede

By Josh Jaffe (auth.), Pascal Paillier, Ingrid Verbauwhede (eds.)

CHES2007,theninthworkshoponCryptographicHardwareandEmbeddedS- tems, used to be backed through the overseas organization for Cryptologic study (IACR) and held in Vienna, Austria, September 10–13, 2007. The workshop - ceived ninety nine submissions from 24 international locations, of which this system Committee (39 participants from 15 nations) chosen 31 for presentation. For the ?rst time within the historical past of CHES, every one submission used to be reviewed by means of no less than 4 reviewers rather than 3 (and no less than ?ve for submissions via workstation participants, these now being constrained to 2 according to member) and plenty of submitted papers have acquired lots of additional reports (some papers acquired as much as 9 reviews), therefore totalling the exceptional list of 483 experiences total. Thepaperscollectedinthisvolumerepresentcutting-edgeworldwideresearch within the quickly evolving ?elds of crypto-hardware, fault-based and side-channel cryptanalysis, and embedded cryptography, on the crossing of educational and - dustrial learn. The broad variety of matters showing in those court cases covers nearly all similar parts and indicates our e?orts to increase the scope of CHES greater than ordinary. even supposing a comparatively younger workshop, CHES is now ?rmlyestablishedasascienti?ceventofreferenceappreciatedbymoreandmore popular specialists of thought and perform: many top quality works have been subm- ted, all of which, unfortunately, couldn't be approved. picking out from such a lot of strong worksis no effortless job and our private thank you visit the individuals of this system Committee for his or her involvement, excellence, and cohesion. we're thankful to the varied exterior reviewers indexed less than for his or her services and information in our deliberations.

In: Abe, M. ) CT-RSA 2007. LNCS, vol. 4377, pp. 243–256. Springer, Heidelberg (2006) 17. : Practical Second-Order DPA Attacks for Masked Smart Card Implementations of Block Ciphers. In: Pointcheval, D. ) CT-RSA 2006. LNCS, vol. 3860, pp. 192–207. Springer, Heidelberg (2006) 18. : Feature Representation and Discrimination Based on Gaussian Mixture Model Probability Densities – Practices and Algorithms. pdf 19. : Improved HigherOrder Side-Channel Attacks with FPGA Experiments. , Sunar, B. ) CHES 2005.

When a d-th order masking is used, a d-th order DPA can be performed to combine the leakage signals L(Vi ) resulting from the manipulation of the d shares Vi . This enables the construction of a signal that is correlated to the targeted sensitive variable Y . Such an attack can theoretically bypass any d-th order masking. However, the noise effects imply that the difficulty of carrying out a HO-DPA in practice increases exponentially with its order and an attacker has to deal with several issues. The main issue of HO-DPA is to determine how to combine the d leakage signals L(Vi ) in such a way that the combination is highly correlated to the sensitive variable Y .

In the new solution, d successive re-computations are still preformed to process the first masked S-Box in the first round. Then, each time S must be applied d ∗ , satisfying on a new byte M0 = Y ⊕ i=1 Mi , a new masked S-Box Snew d d ∗ Snew (x) = S(x ⊕ i=1 Mi ) ⊕ i=1 Ni for every byte x, is derived from the previous S ∗ with a single re-computation. This re-computation firstly requires to process two values called chains of masks in [19] and denoted here by ICM and OCM : d d Mi ⊕ ICM = i=1 d i=1 (7) Ni .

