TIMING ATTACK: WHAT CAN BE ACHIEVED BY A POWERFUL ADVERSARY?
Gaël Hachez, François Koeune, Jean-Jacques Quisquater · 2000
INTRODUCTION Implementations of cryptographic algorithms tend to perform computations in non-constanttime, due to performance optimizations. If such operations involve secret parameters, these timing variations can leak some information and, provided enough knowledge of the implementation is at hand, a careful statistical analysis could even lead to the total recovery of these secret parameters. This idea, due to Kocher [Koc96], was developed in [DKL +98], were a timing attack against an actual smart card implementation of the RSA 1 was conducted. The paper's conclusion was that, however impressive, the obtained results could be improved even further in several aspects, especially regarding the errorcorrection policy. The paper first presents the basic principle of the timing attack, then briefly discusses several error-correction policies and describes the results we obtain implementing them on a parallel architecture on 4 processors PA8000 @ 180Mhz