Bakalářská práce
Získaná ocenění: Cena děkana FI za vynikající závěrečnou práci

An RSA cryptolibrary resistant to side-channel and fault injections attacks

Jan Janásek
Anotace

Tato bakalářská práce se zabývá zásadními zranitelnostmi implementací RSA-CRT souvisejícími se side-channel útoky a fault-injection útoky, přičemž se zaměřuje na vylepšení kryptografické knihovny BearSSL. Přestože se RSA-CRT stále běžně používá pro digitální podpisy a výměnu klíčů, je náchylný k fyzickým útokům zneužívajícím charakteristiky zařízení, jako jsou spotřeba energie či doba běhu. K omezení …více

Abstract

This thesis addresses critical vulnerabilities in RSA-CRT implementations related to side-channel and fault-injection attacks, focusing on enhancing the BearSSL cryptographic library. Although RSA-CRT remains prevalent for digital signatures and key exchanges, it is susceptible to physical attacks exploiting device characteristics such as power consumption and execution time. To mitigate these threats …více

Zadání práce
Physical security threats appear at the chip level, where an attacker can measure or physically influence a cryptographic operation performed by the chip's circuit. The side-channel analysis exploits additional sources of information (called physical observations), including timing, power consumption, or electromagnetic emissions (EM), among others. Malicious data modifications can be caused by fault injection, which can be performed using optical, electromagnetic, power, and clock glitches. These attacks pose a serious threat to modern cryptographic implementations.

The project aims to implement the first secure RSA crypto library resistant to side-channel and fault injection attacks. We consider classical side-channel attacks like correlation power analysis and more powerful techniques like template attacks. 

The project consists of five parts:
  1. Analysis of existing crypto libraries and choosing the most suitable implementation for implementing protections. The base implementation should be efficient and reasonably easy to extend. 
  2. Literature Review and choice of countermeasures to implement: identifying relevant attacks and choosing the best countermeasures to stop them. The student will need to figure out how to combine different countermeasures efficiently. In this stage, new countermeasures can also be designed. 
  3. Implementation - the chosen design needs to be implemented for an embedded target based on ARM-Cortex M4.
  4. Performance Evaluation: the new protected implementation should be compared against the unprotected original implementation as well as other RSA implementations from commonly used crypto-librarires. 
  5. Optional step: if there is time, a side-channel evaluation/testing can be performed.

The project approach is similar to what was done for Curve25119 in:
https://github.com/sca-secure-library-sca25519/sca25519

The division of the tasks within the projects is approximately: 60% programming and 40% literature study.
Práce zkontrolována:
26. 5. 2025 18:59, Lukasz Michal Chmielewski, PhD, učo 247858
Jazyk práce
angličtina angličtina
Termín obhajoby
26. 6. 2025
Práce byla úspěšně obhájena

Vedoucí

Lukasz Michal Chmielewski, PhD, učo 247858
KPSK FI MU

Oponent

RNDr. Milan Šorf, učo 500362
KPSK FI MU

  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.