4 ms·
That is my reading of the text on the linked page. >We have demonstrated how a clever attacker can use a novel chosen-ciphertext attack against SIKE to perform
by Phlarp 4y ago
That is my reading of the text on the linked page.
>We have demonstrated how a clever attacker can use a novel chosen-ciphertext attack against SIKE to perform full key extraction via remote timing, despite SIKE being implemented as “constant time”.
- hinkley 4y agoThat's a big problem. If you created an algorithm that evaluated all possible 32 bit inputs in parallel and then picked the correct value at the end based on the input, you'd still have some funky corner case where the branch predictor in your x64 processor spilled the beans. Are we going to have to design our crypto algorithms entirely on SIMD instructions to combat this sort of thing?
- Phlarp 4y ago>Are we going to have to design our crypto algorithms entirely on SIMD instructions to combat this sort of thing? There is likely still potential for side channel attacks. From a 'first principles' approach a computer is always going to leak information about it's current state (power, noise, emi, etc) and the methods / tools / techniques for analyzing that leaking information are only getting better. The multi-tenant nature of modern infrastructure is the bigger issue in play here.
- bombcar 4y agoIt sounds like there's some mitigations available for the crypto libraries, but perhaps defense-in-depth is going to require the libraries to do "junk work" to obfuscate what's happening against future attacks like this. (I wonder if one is possible if the same key were to be used on different processors, if that would leak certain information, for example.)