3 ms·
I'm confused by this. Can you explain further or provide a link please?
by mjbs 11y ago
I'm confused by this. Can you explain further or provide a link please?
- javcasas 11y agoWhen your processor does computations, it consumes power and radiates electromagnetic waves depending on many parameters, such as the kind of computation, the parameters, the amount of ones vs zeros in the registers and many other "silly" details. When you do crypto on such systems, part of the information that should be hidden is leaked in the form of EM waves, longer or shorter response times, and current consumption (among others). These leaks of information are called "side channels", and have been successfully used to hack some systems. Some of the current tricks of proper cryptography include things such as "always do the same amount of computation", "always take the same time", "always consume the same current" in order to try to hide this leak of information. It is tricky with standard "clocked" processors. So it will be even trickier with asynchronous processors.
- mjbs 11y agoMaybe, instead of taking precautions like trying to always take the same amount of time for some computation (which sounds like a pain!) we could take advantage of some unique properties of async chips. I'm thinking of something like randomly varying the voltage as the computations take place so that time differences will not correlate to data.
- babsa65 11y agoAlpha test test
- javcasas 11y agoWell, if you are able to predict that random voltage generator (we have seen recently some failures in pseudo-random generators that allow attackers to predict next numbers) we can correlate again time with data. So now you have to ensure your random generator is truly random, and not biased at all. For every weird property you try to use to obfuscate the computation, there is some kind of counter to try to de-obfuscate it. That's why crypto is really hard. If you really want to succeed, the only way is use as many tricks as possible, in order to make the attack really hard, hoping to discourage the attacker into doing something more productive with his life.
- Gankro 11y agoExcept if it's really random, after enough trials you'll have some clearly random distribution, with some distortion related to the actual cost. Figuring out the cost is just some statistical analysis away. See e.g. https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf for this principle applied to performing timing attacks on a remote server (so network latency serves as a handy-dandy rng).
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]