The new attacks work provided that a small register can be forced to either zero, or a constant value, or a value with zero high-order bits. We show that these models are quite realistic, as such faults can be achieved against many proposed hardware designs for RSA signatures.
Category / Keywords: public-key cryptography / Fault Attacks, Montgomery Multiplication, RSA-CRT, RSA-PSS Date: received 1 Apr 2012, last revised 2 Apr 2012 Contact author: mehdi tibouchi at normalesup org Available formats: PDF | BibTeX Citation Version: 20120411:155414 (All versions of this report) Discussion forum: Show discussion | Start new discussion