Engineering topics
Cordwell, William R.
Publications and source records attributed to Cordwell, William R..
Side Channel Considerations for SHA-512
We consider a theoretical side-channel attack on SHA-512; the attack should easily generalize to other algorithms in the SHA-2 family. Rather than looking at a side-channel attack on an HMAC, which has been done in various papers, we assume that the targeted device is applying the hash function as a pseudo-random function (prf) in order to generate a secret key from a secret seed, as recommended by NIST. The analyst uses side-channel information to try to recover the secret seed. We use entropy/information theory to show how one might judge whether or not a side-channel attack might be possible and/or feasible, and we show how the design of the implementation can affect the feasibility of an attack.
Side Channel Considerations for AES Intermediate Rounds
We illustrate a theoretical side-channel analysis on the intermediate rounds of AES, using only the Hamming weights of the bytes registered after the S-box operation. Input and output state values are unknown. Simulations and a blind test were used to show the feasibility of the analysis under ideal conditions. General applicability of the idea and possible extensions are discussed, as well as limiting assumptions. Some implementation approaches are described in Appendix A, in the case of constrained computing capabilities (desktop or laptop).