发明名称 Method and device for countering fault attacks
摘要 The public exponent e of an RSA key is embedded in a RSA key object that lacks this exponent. During exponentiation, the public exponent e may be extracted and used to verify that the result of the exponentiation is correct. The result is output only if this is the case. The invention counters fault-attacks. Also provided are an apparatus and a computer program product.
申请公布号 US8744074(B2) 申请公布日期 2014.06.03
申请号 US20100658990 申请日期 2010.02.18
申请人 Thomson Licensing 发明人 Joye Marc
分类号 H04L9/00;H04L9/30;H04L9/28;H04L29/06;H04L9/32;H04K1/00;H04K1/04;H04K1/06 主分类号 H04L9/00
代理机构 代理人
主权项 1. A method for calculating an exponentiation, the method being resistant against fault-attacks and comprising the steps, in a device, of: obtaining a RSA private key object, the RSA private key object being associated with a matching public exponent; obtaining a result of an exponentiation using the RSA private key object; obtaining the matching public exponent; and verifying, using the matching public exponent, that the result of the exponentiation is correct; wherein, in standard mode: the RSA private key object comprises the RSA modulus N, the matching public exponent e being obtained by extraction from the RSA modulus N in which it is embedded; and wherein, in CRT mode: the RSA private key object comprises the factors of the RSA modulus N, the matching public exponent e being obtained by extraction from one of the factors of the RSA modulus N or from a product of the factors of the RSA modulus N.
地址 Issy les Moulineaux FR