| Marc Joye, Jean-Jacques Quisquater, Feng Bao, and Robert H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, ed., Cryptography and Coding, vol. 1355 of Lecture Notes in Computer Science, pp. 155--160, SpringerVerlag, 1997. |
No context found.
Marc Joye, Jean-Jacques Quisquater, Feng Bao, and Robert H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, ed., Cryptography and Coding, vol. 1355 of Lecture Notes in Computer Science, pp. 155--160, SpringerVerlag, 1997.
No context found.
Marc Joye, Jean-Jacques Quisquater, Feng Bao, and Robert H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, ed., Cryptography and Coding, vol. 1355 of Lecture Notes in Computer Science, pp. 155--160, SpringerVerlag, 1997.
No context found.
M. Joye, J.-J. Quisquater, F. Bao, and R.H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, editor, Cryptography and Coding, volume 1355 of Lecture Notes in Computer Science, pages 155--160. Springer-Verlag, 1997.
No context found.
Marc Joye, Jean-Jacques Quisquater, Feng Bao, and Robert H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, ed., Cryptography and Coding, vol. 1355 of Lecture Notes in Computer Science, pp. 155--160, SpringerVerlag, 1997.
No context found.
Marc Joye, Jean-Jacques Quisquater, Feng Bao, and Robert H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, ed., Cryptography and Coding, vol. 1355 of Lecture Notes in Computer Science, pp. 155--160, SpringerVerlag, 1997.
No context found.
Marc Joye, Jean-Jacques Quisquater, Feng Bao, and Robert H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, ed., Cryptography and Coding, vol. 1355 of Lecture Notes in Computer Science, pp. 155--160, SpringerVerlag, 1997.
No context found.
M. Joye, J.-J. Quisquater, F. Bao, and R.H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, editor, Cryptography and Coding, volume 1355 of Lecture Notes in Computer Science, pages 155--160. Springer-Verlag, 1997.
No context found.
M. Joye, J.-J. Quisquater, F. Bao, and R.H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, editor, Cryptography and Coding, volume 1355 of Lecture Notes in Computer Science, pages 155--160. Springer-Verlag, 1997.
....mod n, one recovers the plaintext as m = mod n. Suppose that an error occurs during the computation of m = c mod n; more precisely, suppose that one bit of d, say bit d j , has flipped (let d # denote the corrupted value of d) It is then very easy to recover the flipped bit and its value [3, 8, 17]. The decryption process will yield m # = c d # mod n instead of m. Let d = P i=0 d i 2 denote the binary expansion of d. Since d # = X i=0 (i#=j) d i 2 d j 2 = d (d j d j )2 it follows that (m # ) c # e(d j d j )2 ( mod n) if d j = 0 , 1 c (mod ....
Marc Joye, Jean-Jacques Quisquater, Feng Bao, and Robert H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, ed., Cryptography and Coding, vol. 1355 of Lecture Notes in Computer Science, pp. 155--160, SpringerVerlag, 1997.
....mod n, one recovers the plaintext as m = mod n. Suppose that an error occurs during the computation of m = c mod n; more precisely, suppose that one bit of d, say bit d j , has flipped (let d # denote the corrupted value of d) It is then very easy to recover the flipped bit and its value [3, 8, 17]. The decryption process will yield m # = c d # mod n instead of m. Let d = P i=0 d i 2 denote the binary expansion of d. Since d # = X i=0 (i#=j) d i 2 d j 2 = d (d j d j )2 it follows that (m # ) c # e(d j d j )2 # ( mod n) if d j = 0 , 1 c (mod ....
Marc Joye, Jean-Jacques Quisquater, Feng Bao, and Robert H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, ed., Cryptography and Coding, vol. 1355 of Lecture Notes in Computer Science, pp. 155--160, SpringerVerlag, 1997.
....the value of 2 e P can be obtained as d e P d e P where = d ( d i d i ) 2 : Successively halving 2 e P on e E(a 1 ; a 2 ; a 3 ; a 4 ; ea 6 ) eventually yields the value of e P . Then, once e P is retrieved, the value of d mod r can be recovered. This extends the attacks of [3, 12] in the sense that more information on secret d (i.e. d mod r) can be recovered. 3.2 Faults in the de nition eld We now suppose that the representation of eld K in non volatile memory is faulty (permanent fault) or that an error occurred in the transfer from nonvolatile memory to working ....
Marc Joye, Jean-Jacques Quisquater, Feng Bao, and Robert H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, editor, Cryptography and Coding, volume 1355 of Lecture Notes in Computer Science, pages 155-160. Springer-Verlag, 1997.
....modular reduction, diminished radix representation 1 Introduction In September 1996, newspaper publications cited a Bellcore press release New Threat Model Breaks Crypto Codes: a new Potential Serious Problem was reported. This launched a new type of cryptanalysis, the so called Fault Analysis [1, 2, 3, 5, 6, 10, 11, 12, 13, 15, 19, 25]: the presence of faults may leak some secret information. This paper presents a simple method of protection against fault analysis when the underpinning cryptosystem uses modular arithmetic. This method thus applies to almost all public key systems (RSA [22] ElGamal [9] etc. and also to ....
M. Joye, J.-J. Quisquater, F. Bao, and R.H. Deng. RSA-type signatures in the presence of transient faults. In M. Darnell, editor, Cryptography and Coding, volume 1355 of Lecture Notes in Computer Science, pages 155--160. Springer-Verlag, 1997.
No context found.
M. Joye, J.-J. Quisquater, F. Bao, R. H. Deng, \RSA-type signatures in the presence of transient faults", Cryptography and Coding, Springer LNCS vol. 1335, pp. 155-160, 1997.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC