Leakage Resilient Value Comparison with Application to Message Authentication
Christoph Dobraunig, Bart Mennink
Abstract
Side-channel attacks are a threat to secrets stored on a device, especially if an adversary has physical access to the device. As an effect of this, countermeasures against such attacks for cryptographic algorithms are a well-researched topic. In this work, we deviate from the study of cryptographic algorithms and instead focus on the side-channel protection of a much more basic operation, the comparison of a known attacker-controlled value with a secret one. Comparisons sensitive to side-channel leakage occur in tag comparisons during the verification of message authentication codes (MACs) or authenticated encryption, but are typically omitted in security analyses. Besides, also comparisons performed as part of fault countermeasures might be sensitive to side-channel attacks. In this work, we present a formal analysis on comparing values in a leakage resilient manner by utilizing cryptographic building blocks that are typically part of an implementation anyway. Our results indicate that there is no need to invest additional resources into implementing a protected comparison operation itself if a sufficiently protected implementation of a public cryptographic permutation, or a (tweakable) block cipher, is already available. We complement our contribution by applying our findings to the SuKS message authentication code used by lightweight authenticated encryption scheme ISAP, and to the classical Hash-then-PRF construction.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 835242d5-fee9-4107-ac0b-71da2c49d4dcCited by top-tier papers1
Ask how each one uses itRelated papers
- Mode-Level vs. Implementation-Level Physical Security in Symmetric Cryptography - A Practical Guide Through the Leakage-Resistance JungleDavide Bellizia, Olivier Bronchain, Gaëtan Cassiers, Vincent Grosso et al.CRYPTO 2020 · 38 citations
- Prouff and Rivain's Formal Security Proof of Masking, Revisited - Tight Bounds in the Noisy Leakage ModelLoïc Masure, François-Xavier StandaertCRYPTO 2023 · 10 citations
- Leakage and Tamper Resilient Permutation-Based CryptographyChristoph Dobraunig, Bart Mennink, Robert PrimasCCS 2022 · 7 citations
- A Thorough Evaluation of RAMBAMDaniel Lammers, Amir Moradi, Nicolai Müller, Aein Rezaei ShahmirzadiCCS 2023 · 1 citation
- Secure Wire Shuffling in the Probing ModelJean-Sébastien Coron, Lorenzo SpignoliCRYPTO 2021 · 13 citations
