Journals / Turkish Journal of Electrical Engineering and Computer Sciences / 2018 / Cilt: 26 - Sayı: 4
Cache-timing attacks without a profiling phase
- Pages
- 1953–1966
- DOI
- —
Abstract
Theoretically secure cryptographic algorithms can be vulnerable to attacks due to their implementation flaws.Bernstein’s attack is a well-known cache-timing attack that uses execution times as the side-channel. The major drawbackof this attack is that it needs an identical target machine to perform its profiling phase where the attacker models thecache timing-behavior of the target machine. This assumption makes the attack unrealistic in many circumstances. Inthis work, we present an effective method to eliminate the profiling phase. We propose a methodology to model the cachetiming-behavior of the target machine by trying hypothetical cache behaviors exhaustively. Our implementation resultsshow that the proposed nonprofiled Bernstein’s attack has comparable (and better in some test instances) performanceto the original attack with the profiling phase.