3 ms·
Maybe, instead of taking precautions like trying to always take the same amount of time for some computation (which sounds like a pain!) we could take advantage
by mjbs 11y ago
Maybe, instead of taking precautions like trying to always take the same amount of time for some computation (which sounds like a pain!) we could take advantage of some unique properties of async chips. I'm thinking of something like randomly varying the voltage as the computations take place so that time differences will not correlate to data.
- babsa65 11y agoAlpha test test
- javcasas 11y agoWell, if you are able to predict that random voltage generator (we have seen recently some failures in pseudo-random generators that allow attackers to predict next numbers) we can correlate again time with data. So now you have to ensure your random generator is truly random, and not biased at all. For every weird property you try to use to obfuscate the computation, there is some kind of counter to try to de-obfuscate it. That's why crypto is really hard. If you really want to succeed, the only way is use as many tricks as possible, in order to make the attack really hard, hoping to discourage the attacker into doing something more productive with his life.
- Gankro 11y agoExcept if it's really random, after enough trials you'll have some clearly random distribution, with some distortion related to the actual cost. Figuring out the cost is just some statistical analysis away. See e.g. https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf for this principle applied to performing timing attacks on a remote server (so network latency serves as a handy-dandy rng).