DocumentCode
1169918
Title
RSA speedup with Chinese remainder theorem immune against hardware fault cryptanalysis
Author
Yen, Sung-Ming ; Kim, Seungjoo ; Lim, Seongan ; Moon, Sang-Jae
Author_Institution
Dept. of Comput. Sci. & Inf. Eng., Nat. Central Univ., Chung-li, Taiwan
Volume
52
Issue
4
fYear
2003
fDate
4/1/2003 12:00:00 AM
Firstpage
461
Lastpage
472
Abstract
This article considers the problem of how to prevent RSA signature and decryption computation with a residue number system (CRT-based approach) speedup from a hardware fault cryptanalysis in a highly reliable and efficient approach. CRT-based speedup for an RSA signature has been widely adopted as an implementation standard ranging from large servers to very tiny smart IC cards. However, given a single erroneous computation result, hardware fault cryptanalysis can totally break the RSA system by factoring the public modulus. Countermeasures using a simple verification function (e.g., raising a signature to the power of a public key) or fault detection (e.g., an expanded modulus approach) have been reported in the literature; however, it is pointed out that very few of these existing solutions are both sound and efficient. Unreasonably, in these methods, they assume that a comparison instruction will always be fault-free when developing countermeasures against hardware fault cryptanalysis. Research shows that the expanded modulus approach proposed by Shamir (1997, 1999) is superior to the approach using a simple verification function when another physical cryptanalysis (e.g., timing cryptanalysis) is considered. So, we intend to improve Shamir´s method. In this paper, the new concepts of fault infective CRT computation and fault infective CRT recombination are proposed. Based on the new concepts, two novel protocols are developed with a rigorous proof of security. Two possible parameter settings are provided for the protocols. One setting selects a small public key and the proposed protocols can have comparable performance to Shamir´s scheme. The other setting has better performance than Shamir´s scheme (i.e., having comparable performance to conventional CRT speedup), but with a large public key. Most importantly, we wish to emphasize the importance of developing and proving the security of physically secure protocols without relying on unreliable or unreasonable assumptions, e.g., always fault-free instructions. In this paper, related protocols are also considered and carefully examined to point out possible weaknesses.
Keywords
fault tolerant computing; protocols; public key cryptography; residue number systems; Chinese remainder theorem; RSA speedup; expanded modulus approach; fast RSA decryption computation; fast RSA signature computation; fault detection; fault infective CRT computation; fault infective CRT recombination; immune hardware fault cryptanalysis; protocols; public key; residue number system speedup; verification function; Cathode ray tubes; Cryptographic protocols; Data security; Elliptic curve cryptography; Fault detection; Hardware; Moon; Public key; Public key cryptography; Reliability theory;
fLanguage
English
Journal_Title
Computers, IEEE Transactions on
Publisher
ieee
ISSN
0018-9340
Type
jour
DOI
10.1109/TC.2003.1190587
Filename
1190587
Link To Document