This Article 
 Bibliographic References 
 Add to: 
RSA Speedup with Chinese Remainder Theorem Immune against Hardware Fault Cryptanalysis
April 2003 (vol. 52 no. 4)
pp. 461-472

Abstract—This article considers the problem of how to prevent the fast RSA signature and decryption computation with residue number system (or called the CRT-based approach) speedup from a hardware fault cryptanalysis in a highly reliable and efficient approach. The CRT-based speedup for RSA signature has been widely adopted as an implementation standard ranging from large servers to very tiny smart IC cards. However, given a single erroneous computation result, a hardware fault cryptanalysis can totally break the RSA system by factoring the public modulus. Some countermeasures by using a simple verification function (e.g., raising a signature to the power of public key) or fault detection (e.g., an expanded modulus approach) have been reported in the literature; however, it will be pointed out in this paper that very few of these existing solutions are both sound and efficient. Unreasonably, in these methods, they assume that a comparison instruction will always be fault-free when developing countermeasures against hardware fault cryptanalysis. Researches show that the expanded modulus approach proposed by Shamir is superior to the approach of using a simple verification function when other physical cryptanalysis (e.g., timing cryptanalysis) is considered. So, we intend to improve Shamir's method. In this paper, the new concepts of fault infective CRT computation and fault infective CRT recombination are proposed. Based on the new concepts, two novel protocols are developed with rigorous proof of security. Two possible parameter settings are provided for the protocols. One setting is to select a small public key e and the proposed protocols can have comparable performance to Shamir's scheme. The other setting is to have better performance than Shamir's scheme (i.e., having comparable performance to conventional CRT speedup), but with a large public key. Most importantly, we wish to emphasize the importance of developing and proving the security of physically secure protocols without relying on unreliable or unreasonable assumptions, e.g., always fault-free instructions. In this paper, related protocols are also considered and are carefully examined to point out possible weaknesses.

[1] R.L. Rivest,A. Shamir, and L.A. Adleman,"A Method for Obtaining Digital Signatures and Public Key Cryptosystems," Comm. ACM, vol. 21, pp. 120-126, 1978.
[2] T. ElGamal, A Public-Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms IEEE Trans. Information Theory, vol. 31, no. 4, pp. 469-472, 1985.
[3] R. Anderson and M. Kuhn, “Tamper Resistance—A Cautionary Note,” Proc. Second USENIX Workshop Electronic Commerce, pp. 1-11, 1996.
[4] R. Anderson and M. Kuhn, “Low Cost Attacks on Tamper Resistant Devices,” Pre-proc. 1997 Security Protocols Workshop, Apr. 1997.
[5] Bellcore Press Release, “New Threat Model Breaks Crypto Codes,” Sept. 1996, .
[6] D. Boneh, R.A. DeMillo, and R.J. Lipton, “On the Importance of Checking Cryptographic Protocols for Faults,” Advances in Cryptology—EUROCRYPT '97, pp. 37-51, 1997.
[7] F. Bao, R.H. Deng, Y. Han, A. Jeng, A.D. Narasimbalu, and T. Ngair, “Breaking Public Key Cryptosystems on Tamper Resistant Devices in the Presence of Transient Faults,” Pre-proc. 1997 Security Protocols Workshop, 1997.
[8] Y. Zheng and T. Matsumoto, “Breaking Real-World Implementations of Cryptosystems by Manipulating their Random Number Generation,” Pre-proc. 1997 Symp. Cryptography and Information Security, 29 Jan.-1 Feb. 1997. An earlier version was presented at the rump session of ASIACRYPT '96.
[9] I. Peterson, “Chinks in Digital Armor—Exploiting Faults to Break Smart-Card Cryptosystems,” Science News, vol. 151, no. 5, pp. 78-79, 1997.
[10] M. Joye, J.-J. Quisquater, F. Bao, and R.H. Deng, “RSA-Type Signatures in the Presence of Transient Faults,” Cryptography and Coding, pp. 155-160, Springer-Verlag, 1997.
[11] D.P. Maher, “Fault Induction Attacks, Tamper Resistance, and Hostile Reverse Engineering in Perspective,” Financial Cryptography, pp. 109-121, Berlin: Springer-Verlag, 1997.
[12] E. Biham and A. Shamir, “Differential Fault Analysis of Secret Key Cryptosystems,” Advances in Cryptology—CRYPTO '97, pp. 513-525, 1997.
[13] M. Joye, A.K. Lenstra, and J.-J. Quisquater, “Chinese Remaindering Based Cryptosystems in the Presence of Faults,” J. Cryptology, vol. 12, no. 4, pp. 241-245, 1999.
[14] M. Joye, F. Koeune, and J.-J. Quisquater, “Further Results on Chinese Remaindering,” Technical Report CG-1997/1, UCL Crypto Group, Louvain-la-Neuve, Mar. 1997.
[15] A. Shamir, “How to Check Modular Exponentiation,” presented at the rump session of EUROCRYPT '97, May 1997.
[16] A. Shamir, “Method and Apparatus for Protecting Public Key Schemes from Timing and Fault Attacks,” US Patent 5991415, 23 Nov. 1999.
[17] S.M. Yen and M. Joye, “Checking before Output May Not Be Enough against Fault-Based Cryptanalysis,” IEEE Trans. Computers, vol. 49, no. 9, pp. 967-970, Sept. 2000.
[18] P.J. Smith and M.J.J. Lennon, “LUC: A New Public Key System,” Proc. Ninth IFIP Symp. Computer Security, pp. 103-117, 1993.
[19] A.J. Menezes, Elliptic Curve Public Key Cryptosystems. Kluwer Academic, 1993.
[20] J.-J. Quisquater and C. Couvreur, “Fast Decipherment Algorithm for RSA Public-Key Cryptosystem,” Electronics Letters, vol. 18, no. 21, pp. 905-907, 1982.
[21] A.J. Menezes, P.C. van Oorschot, and S.A. Vanstone, Handbook of Applied Cryptography, CRC Press, Boca Raton, Fla., 1996, pp. 543-590.
[22] P. Kocher, "Timing Attacks on Implementations of Diffie-Hellman, RSA, DSS, and Other Systems," N. Koblitz, ed., Advances in Cryptology (Crypto 96), Springer-Verlag LNCS 1109, pp. 104-113.
[23] B.S. Kaliski Jr. and M.J.B. Robshaw, “Comments on Some New Attacks on Cryptographic Devices,” RSA Laboratories Bulletin, no. 5, July 1997.
[24] W. Schindler, “A Timing Attack against RSA with the Chinese Remainder Theorem,” Proc. Cryptographic Hardware and Embedded Systems—CHES 2000, pp. 109-124, 2000.
[25] C.D. Walter, “Montgomery's Exponentiation Needs No Final Subtractions,” Electronics Letters, vol. 35, no. 21, pp. 1831-1832, 1999.
[26] C. Hachez and J.-J. Quisquater, “Montgomery Exponentiation with No Final Subtractions: Improved Results,” Proc. Cryptographic Hardware and Embedded Systems—CHES 2000, pp. 293-301, 2000.
[27] M. Joye, J.-J. Quisquater, S. M. Yen, and M. Yung, “Observability Analysis: Detecting When Improved Cryptosystems Fail,” Topics in Cryptology—CT-RSA 2002, pp. 17-29, 2002.
[28] Ç.K. Koç, “RSA Hardware Implementation,” Technical Report TR 801, RSA Laboratories, Redwood City, Calif., Apr. 1996.

Index Terms:
Chinese Remainder Theorem (CRT), cryptography, denial of service attack, factorization, fault detection, fault infective CRT, fault tolerance, hardware fault cryptanalysis, physical cryptanalysis, residue number system, side channel attack.
Sung-Ming Yen, Seungjoo Kim, Seongan Lim, Sang-Jae Moon, "RSA Speedup with Chinese Remainder Theorem Immune against Hardware Fault Cryptanalysis," IEEE Transactions on Computers, vol. 52, no. 4, pp. 461-472, April 2003, doi:10.1109/TC.2003.1190587
Usage of this product signifies your acceptance of the Terms of Use.