Abstract
Under a simple power leakage model based on Hamming weight, a software implementation of a data-whitening routine is shown to be vulnerable to a first-order Differential Power Analysis (DPA) attack. This routine is modified to resist the first-order DPA attack, but is subsequently shown to be vulnerable to a second-order DPA attack. A second-order DPA attack that is optimal under certain assumptions is also proposed. Experimental results in an ST16 smartcard confirm the practicality of the first and second-order DPA attacks. © Springer-Verlag Berlin Heidelberg 2000.
Cite
CITATION STYLE
Messerges, T. S. (2000). Using Second-Order Power Analysis to attack DPA resistant software. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 1965 LNCS, pp. 238–251). Springer Verlag. https://doi.org/10.1007/3-540-44499-8_19
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.