• DocumentCode
    2382530
  • Title

    Further Cryptanalysis of a Provably Secure CRT-RSA Algorithm

  • Author

    Qin, Baodong ; Li, Ming ; Kong, Fanyu

  • fYear
    2007
  • fDate
    1-3 Nov. 2007
  • Firstpage
    327
  • Lastpage
    331
  • Abstract
    At CCS 2003, a new fault immune CRT-RSA signature algorithm, namely BOS scheme was proposed by Bl¨omer, Otto, and Seifert. Unfortunately, one year later, Wagner presented a practical fault attack on the BOS scheme. How- ever, Wagner\´s attack itself contains a flaw in the most re- alistic "random fault model". Though it has been fixed by Liu et al. at DASC 2006, it is still of interest to see other possible and efficient attacks against the BOS scheme. Re- cently, Ming Li et al. proposed an efficient fault attack on the BOS scheme which targets the secret key dp and some related messages. In this paper, a new fault attack on the BOS scheme is presented. Our attack is similar to but dif- ferent from Li et al.\´s attack and is still more efficient than Wagner\´s attack. To completely break the security of the BOS scheme, the adversaries first induce a permanent fault on the secret RSA key dp or dq and then run the BOS scheme to obtain four faulty RSA signatures. Lastly, the adversaries can obtain the factorization of the RSA modulus by using the Greatest Common Divisor algorithm.
  • Keywords
    Carbon capture and storage; Computer science; Computer security; Cryptography; Data privacy; Data security; Educational institutions; Hardware; Information security; Laboratories;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Data, Privacy, and E-Commerce, 2007. ISDPE 2007. The First International Symposium on
  • Conference_Location
    Chengdu
  • Print_ISBN
    978-0-7695-3016-1
  • Type

    conf

  • DOI
    10.1109/ISDPE.2007.100
  • Filename
    4402703