4 ms·
...how about a random-power-consumer? would it help?
by devdoomari 9y ago
...how about a random-power-consumer? would it help?
- Klathmon 9y agoGenerally mitigations like adding random things only delay attacks like this, they don't prevent them. Like adding random timings won't prevent timing attacks, adding random sized strings won't prevent chosen plaintext or padding attacks, etc...
- dom0 9y agoNo, not at all. A raised SNR can be overcome in almost all circumstances by making more measurements, i.e. correlation, since noise is not correlated, it is removed. For the same reason random delays don't help against timing attacks.
- tinus_hn 9y agoPerhaps you could quantize the level.
- Ferofluid 9y agoNot if you calculate keys nonstop, then have another machine pick from a huge list later.
- Cyph0n 9y agoThat's how DPA works as far as I understand.
- Drdrdrq 9y agoCurious: how about generating noise which is correlated to signal and actively tries to modify output to some "random" noise?
- laydn 9y agoCryptography Research (now RAMBUS) developed solutions against these DPA attacks. Real solutions are much more complex than just "random-power-consuming" See: https://www.rambus.com/security/dpa-countermeasures/ https://www.rambus.com/security/dpa-countermeasures/