Exponent Blinding May Not Prevent Timing Attacks on RSA.
Werner Schindler · 2014
Abstract. The references [9, 3, 1] treat timing attacks on RSA with CRT and Montgomery’s multiplication algorithm in unprotected imple-mentations. It has been widely believed that exponent blinding would prevent any timing attack on RSA. At cost of significantly more timing measurements this paper extends the before-mentioned attacks to RSA with CRT, Montgomery’s multiplication algorithm and exponent blind-ing. Simulation experiments are conducted, which confirm the theoretical results. Effective countermeasures exist.