Abstract
Random delays are often inserted in embedded software to protect against side-channel and fault attacks. At CHES 2009 a new method for generation of random delays was described that increases the attacker's uncertainty about the position of sensitive operations. In this paper we show that the CHES 2009 method is less secure than claimed. We describe an improved method for random delay generation which does not suffer from the same security weakness. We also show that the paper's criterion to measure the security of random delays can be misleading, so we introduce a new criterion for random delays which is directly connected to the number of acquisitions required to break an implementation. We mount a power analysis attack against an 8-bit implementation of the improved method verifying its higher security in practice. © 2010 Springer-Verlag Berlin Heidelberg.
Author supplied keywords
Cite
CITATION STYLE
Coron, J. S., & Kizhvatov, I. (2010). Analysis and improvement of the random delay countermeasure of CHES 2009. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 6225 LNCS, pp. 95–109). Springer Verlag. https://doi.org/10.1007/978-3-642-15031-9_7
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.