Závěrečná práce: Jan Janásek: An RSA cryptolibrary resistant to side-channel and fault injections attacks
Bakalářská práce
An RSA cryptolibrary resistant to side-channel and fault injections attacks
Anotace
Tato bakalářská práce se zabývá zásadními zranitelnostmi implementací RSA-CRT souvisejícími se side-channel útoky a fault-injection útoky, přičemž se zaměřuje na vylepšení kryptografické knihovny BearSSL. Přestože se RSA-CRT stále běžně používá pro digitální podpisy a výměnu klíčů, je náchylný k fyzickým útokům zneužívajícím charakteristiky zařízení, jako jsou spotřeba energie či doba běhu. K omezení …více
Abstract
This thesis addresses critical vulnerabilities in RSA-CRT implementations related to side-channel and fault-injection attacks, focusing on enhancing the BearSSL cryptographic library. Although RSA-CRT remains prevalent for digital signatures and key exchanges, it is susceptible to physical attacks exploiting device characteristics such as power consumption and execution time. To mitigate these threats …více
Zadání práce
The project aims to implement the first secure RSA crypto library resistant to side-channel and fault injection attacks. We consider classical side-channel attacks like correlation power analysis and more powerful techniques like template attacks.
The project consists of five parts:
- Analysis of existing crypto libraries and choosing the most suitable implementation for implementing protections. The base implementation should be efficient and reasonably easy to extend.
- Literature Review and choice of countermeasures to implement: identifying relevant attacks and choosing the best countermeasures to stop them. The student will need to figure out how to combine different countermeasures efficiently. In this stage, new countermeasures can also be designed.
- Implementation - the chosen design needs to be implemented for an embedded target based on ARM-Cortex M4.
- Performance Evaluation: the new protected implementation should be compared against the unprotected original implementation as well as other RSA implementations from commonly used crypto-librarires.
- Optional step: if there is time, a side-channel evaluation/testing can be performed.
The project approach is similar to what was done for Curve25119 in:
https://github.com/sca-secure-library-sca25519/sca25519
The division of the tasks within the projects is approximately: 60% programming and 40% literature study.
26. 5. 2025 18:59, Lukasz Michal Chmielewski, PhD, učo 247858
Práce na příbuzné téma
Seznam prací, které mají shodná klíčová slova.
-
GPU implementation of algorithms for side-channel attacks
Mgr. Tomáš Jusko -
Ukrajinská protiopatření vůči ruské informační válce
Bc. Anastasiia Bondar -
Methods for software failure-data collection and prediction
RNDr. Stanislav Chren, Ph.D., učo 255471 -
Analyzing fault injection resistance of a modern open-source crypto-wallet
Bc. Oliver Šimoník -
Trajektorie akutního i chronického stresu u člověka se specifickým zaměřením na izolační experimenty (kosmický výzkum + izolované geografické oblasti)
Mgr. Bc. Lucie Ráčková, Ph.D., učo 451145 -
Protiopatření cílená na obchod s lidmi skrze internet a sociální sítě
Mgr. Veronika Spáčilová -
Implementing Ed25519 cryptolibrary resistant to side-channel and fault injections attacks
Mgr. Lubomír Hrbáček -
Testování pomocí Fault Injection v jazyce Java
Mgr. Jiří Sedláček, učo 139558




