CRT RSA Cryptography DFA Attack Protection via Pre-computed Lookup Tables
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for preventing differential fault analysis (DFA) attacks on Chinese Remainder Theorem (CRT) Rivest, Shamir, and Adleman (RSA) cryptography are time-consuming and ineffective, allowing unauthorized access to sensitive information.
Innovation Solution
The system performs modular exponentiation using composites of a private key and reconstructs the original message, incorporating a verification component that determines equivalence between received and reconstructed messages through CRT computations, thereby preventing DFA attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods are used to prevent DFA attacks, then security against attacks is improved, but processing time increases and effectiveness decreases
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing lookup tables containing pre-calculated modular exponentiation results and CRT reconstruction values before actual cryptographic operations. When a signature operation is needed, the system retrieves pre-computed values from these lookup tables rather than performing time-consuming real-time calculations, thus maintaining security while significantly reducing processing time.
Solution Approach 2:
The system performs preliminary computation of multiple candidate private key components and stores them in lookup tables indexed by public key parameters. During actual operations, these pre-computed candidates are quickly retrieved and verified, eliminating the need for time-consuming iterative computations while maintaining resistance against DFA attacks through the use of multiple pre-vetted candidates.
2Reliability
If conventional methods are used to prevent DFA attacks, then security against attacks is improved, but attack effectiveness increases due to multiple executions requirement
Solution Approach 1:
The patent pre-computes multiple candidate private key components and stores them in lookup tables with indexes based on public key parameters. During cryptographic operations, the system retrieves these pre-computed candidates and performs verification using CRT reconstruction, eliminating the need for attackers to rely on multiple executions to detect faults, thus significantly improving resistance efficiency against DFA attacks.
Solution Approach 2:
The system implements feedback mechanisms where CRT reconstruction results are verified against expected values, and lookup tables are dynamically updated based on verification outcomes. This feedback loop ensures that only valid private key candidates are used, providing immediate detection and rejection of faulty computations, thereby enhancing productivity in resisting DFA attacks without requiring multiple external executions.
3Adaptability or versatility
If CRT RSA cryptography is implemented on embedded devices, then device functionality is improved, but vulnerability to DFA attacks increases
Solution Approach 1:
The patent pre-computes and stores multiple candidate private key components in lookup tables specifically optimized for embedded device constraints. These pre-computed candidates incorporate CRT parameters and are indexed for quick retrieval based on public key information. During operations on embedded devices, the system retrieves these pre-vetted candidates and performs verification, maintaining embedded device compatibility while eliminating vulnerability to DFA attacks through the use of pre-validated candidates.
Solution Approach 2:
The system introduces lookup tables as an intermediary structure between the embedded device's cryptographic operations and the security requirements. These lookup tables store pre-computed CRT parameters and candidate values that mediate between the limited computational resources of embedded devices and the need for robust DFA attack resistance, enabling secure operations without requiring complex real-time computations.
Data Source
AI summary
Systems and methods for effectively protecting data against differential fault analysis involved in Rivest, Shamir, and Adleman (“RSA”) cryptography using the Chinese Remainder Theorem (“CRT”) are described herein. A CRT RSA component facilitates modular exponentiation of a received message, and a verification component reconstructs the received message. An exponentiation component performs a first modular exponentiation and a second modular exponentiation of the received message. A recombination component performs a recombination step utilizing CRT computation as a function of the first and second modular exponentiations. A modular exponentiation component performs first and second public exponent derivations as a function of a private exponent. The verification component can reconstructs the received message as a function of the first and second public exponent derivations. The verification component calculates the received message utilizing Chinese Remainder Theorem computation.


