引用本文:赵新杰,王韬,郭世泽,郑媛媛.AES 访问驱动Cache 计时攻击.软件学报,2011,22(3):572-591
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 6242次   下载 10606 本文二维码信息
码上扫一扫!
分享到: 微信 更多
AES 访问驱动Cache 计时攻击
赵新杰1, 王韬1, 郭世泽2, 郑媛媛1
1.军械工程学院 计算机工程系,河北 石家庄 050003;2.北方电子设备研究所,北京 100083
摘要:
首先给出了访问驱动Cache 计时攻击的模型,提出了该模型下直接分析、排除分析两种通用的AES 加密泄漏Cache 信息分析方法;然后建立了AES 加密Cache 信息泄露模型,并在此基础上对排除分析攻击所需样本量进行了定量分析,给出了攻击中可能遇到问题的解决方案;最后结合OpenSSL v.0.9.8a,v.0.9.8j 中两种典型的AES 实现在Windows 环境下进行了本地和远程攻击共12 个实验.实验结果表明,访问驱动Cache 计时攻击在本地和远程均具有良好的可行性;AES 查找表和Cache 结构本身决定了AES 易遭受访问驱动Cache 计时攻击威胁,攻击最小样本量仅为13;去除T4 表的OpenSSL v.0.9.8j 中AES 最后一轮实现并不能防御该攻击;实验结果多次验证了AES 加密Cache 信息泄露和密钥分析理论的正确性.
关键词:  高级加密标准  访问驱动  Cache 计时攻击  远程攻击  OpenSSL
DOI:10.3724/SP.J.1001.2011.03802
分类号:
基金项目:国家自然科学基金(60772082); 河北省自然科学基金(08M010)
Access Driven Cache Timing Attack Against AES
ZHAO Xin-Jie1, WANG Tao1, GUO Shi-Ze2, ZHENG Yuan-Yuan1
1.Department of Computer Engineering, Ordnance Engineering College, Shijiazhuang 050003, China;2.Institute of North Electronic Equipment, Beijing 100083, China
Abstract:
Firstly, this paper displays an access driven Cache timing attack model, proposes non-elimination and elimination two general methods to analyze Cache information leakage during AES encryption, and builds the Cache information leakage model. Next, it uses quantitative analysis to attack a sample with the above elimination analysis method, and provides some solutions for the potential problems of a real attack. Finally, this paper describes 12 local and remote attacks on AES in OpenSSL v.0.9.8a, v.0.9.8j. Experiment results demonstrate that: the access driven Cache timing attack has strong applicability in both local and remote environments; the AES lookup table and Cache structure decide that AES is vulnerable to this type of attack, the least sample size required to recover a full AES key is about 13; the last round AES implementation in OpenSSL v.0.9.8j, which abandoned the T4 lookup table, cannot secure itself from the access driven Cache timing attack; the attack results strongly verify the correctness of the quantitative Cache information leakage theory and key analysis methods above.
Key words:  AES  access driven  Cache timing attack  remote attack  OpenSSL