Protected RSA Implementations
Mylène Roussellet, Yannick Teglia, David Vigilant · 2025
Building a resistant RSA implementation is still a practical challenge when considering skilled experts in labs applying all state-of-the-art attack techniques. The best known method to solve the RSA problem is the factorization of the RSApublic modulus, which is the product of two large secret prime numbers. As no quantum computer is available yet, it provides sufficient practical security today if RSA keys are large enough and generated carefully. This chapter aims to review the way up to a protected RSA implementation. By starting from a selection of attacks, the RSA-CRT signature pseudo-code has been scanned step by step, and countermeasures have been presented for each phase. It discusses the timing and simple side channel analysis and combined attacks on exponentiations. A complete methodology to build a protected RSA could also comprise a formal verification phase.