Software Implementation Level Countermeasures against the Cache Timing Attack on Advanced Encryption Standard

No Thumbnail Available
File version
Author(s)
Herath, Udyani
Alawatugoda, Janaka
Ragel, Roshan
Griffith University Author(s)
Primary Supervisor
Other Supervisors
Editor(s)
Date
2013
Size
File type(s)
Location

Peradeniya, Sri Lanka

License
Abstract

Advanced Encryption Standard (AES) is a symmetric key encryption algorithm which is extensively used in secure electronic data transmission. When introduced, although it was tested and declared as secure, in 2005, a researcher named Bernstein claimed that it is vulnerable to side channel attacks. The cache-based timing attack is the type of side channel attack demonstrated by Bernstein, which uses the timing variation in cache hits and misses. This kind of attacks can be prevented by masking the actual timing information from the attacker. Such masking can be performed by altering the original AES software implementation while preserving its semantics. This paper presents possible software implementation level countermeasures against Bernstein's cache timing attack. Two simple software based countermeasures based on the concept of 'constant-encryption-time' were demonstrated against the remote cache timing attack with positive outcomes, in which we establish a secured environment for the AES encryption.

Journal Title
Conference Title

2013 IEEE 8th International Conference on Industrial and Information Systems

Book Title
Edition
Volume
Issue
Thesis Type
Degree Program
School
Publisher link
Patent number
Funder(s)
Grant identifier(s)
Rights Statement
Rights Statement
Item Access Status
Note
Access the data
Related item(s)
Subject

Data security and protection

Science & Technology

Technology

Computer Science, Information Systems

Engineering, Electrical & Electronic

Computer Science

Persistent link to this record
Citation

Herath, U; Alawatugoda, J; Ragel, R, Software Implementation Level Countermeasures against the Cache Timing Attack on Advanced Encryption Standard, 2013 IEEE 8th International Conference on Industrial and Information Systems, 2013, pp. 75-80