Séminaire de Cryptographie

Roberto Avanzi

Countermeasures Against Leaked-Emission Analysis for Curve-Based Cryptosystems

Power Analysis (and, more generally, Leaked-Emission Analysis) is a technique for guessing the flow of cryptographic algorithms implemented on embedded devices, in particular smart cards. If a single input is used, the process is referred to as a Simple Power Analysis (SPA), and if several different inputs are used together with statistical tools, it is called Differential Power Analysis (DPA). Other attacks include Fault Analysis and Goubin's recent approach.

We review these attacks and some of the contermeasures operating at the algorithmic level devised to thwart them.