4 ms·
I think it's worth noting that the main attack described in the paper, against SIKE, depends on exploiting some behavior peculiar to that particular algorithm (
by dkbrk 4y ago
I think it's worth noting that the main attack described in the paper, against SIKE, depends on exploiting some behavior peculiar to that particular algorithm (what the paper calls "anomalous 0s"):
> The attacker simultaneously sends n requests with a challenge ciphertext meant to trigger an anomalous 0 and measures the time t it takes to receive responses for all no requests. When an anomalous 0 is triggered, power decreases, frequency increases, SIKE decapsulation executes faster, and t should be smaller. Based on the observed t and the previously recovered secret key bits, the attacker can infer the value of the target bit, then repeat the attack for the next bit.
While any leakage of information can in be exploited in principle, it might be that this technique is impractical against a target which doesn't exhibit some sort of behavior that facilitates it.
- staticassertion 4y agoI think SIKE was just chosen because of its relevance, not because it has any particular issues that make it more susceptible. I'd be curious to hear from an expert on this.
- avianes 4y agoSIKE is definitely not the most widely used cryptographic algorithm. And as the paper points out: > In our attack, we show that, when provided with a specially-crafted input, SIKE’s decapsulation algorithm produces anomalous 0 values that depend on single bits of the key. It was clearly selected for this property. The attack allows to determines the number of 0s and 1s in words processed by an algorithm, so they chose an algorithm that has specific data outcomes which will produce a measurable power effect.
- staticassertion 4y agoI didn't think it was widely used, I'm sure it's very very rarely used. I was saying it was relevant because it represents the "future" of cryptography. I would think that any kind of key exchange algorithm that relies on a constant time algorithm is vulnerable to this. I could be wrong.
- avianes 4y agoNot a cryptography specialist, but I doubt that all crypto algorithms have the same property of causing 0s (or 1s) to massively appear for some inputs in a way that could lead to a key leakage with this attack. I believe that SIKE is an extrem case which allows to perform this attack with more ease. However I suspect that by refining the attack then it could be extended to other algorithms less sensitive to power side-channel.