IACR Cryptology ePrint Archive · 2002 · 268 citations · 6 references
Cache memory can leak information during cryptographic operations, allowing attackers to narrow or reveal secret values. The study proposes a cache‑based side‑channel attack that encrypts two chosen plaintexts to recover the cryptographic key. The attack encrypts two chosen plaintexts, collects cache profiles, and uses two computational steps to recover the key, with simulations and discussion of defensive hardware and algorithmic changes.
We expand on the idea, proposed by Kelsey et al. [?], of cache memory being used as a side-channel which leaks information during the run of a cryptographic algorithm. By using this side-channel, an attacker may be able to reveal or narrow the possible values of secret information held on the target device. We describe an attack which encrypts 2 chosen plaintexts on the target processor in order to collect cache profiles and then performs around 2 computational steps to recover the key. As well as describing and simulating the theoretical attack, we discuss how hardware and algorithmic alterations can be used to defend against such techniques.
6
Investigations of power analysis attacks on smartcards
Thomas S. Messerges, Ezzy A. Dabbish, Robert H. Sloan · 1999 · 354 citations
Breaking up is hard to do: modeling security threats for smart cards
Bruce Schneier, Adam Shostack · 1999 · 74 citations
Cold-start vs. warm-start miss ratios
Malcolm C. Easton, Ronald Fagin · Communications of the ACM · 1978 · 49 citations · Full text