• 제목/요약/키워드: Side Channel

검색결과 926건 처리시간 0.026초

On Recovering Erased RSA Private Key Bits

  • Baek, Yoo-Jin
    • International Journal of Internet, Broadcasting and Communication
    • /
    • 제10권3호
    • /
    • pp.11-25
    • /
    • 2018
  • While being believed that decrypting any RSA ciphertext is as hard as factorizing the RSA modulus, it was also shown that, if additional information is available, breaking the RSA cryptosystem may be much easier than factoring. For example, Coppersmith showed that, given the 1/2 fraction of the least or the most significant bits of one of two RSA primes, one can factorize the RSA modulus very efficiently, using the lattice-based technique. More recently, introducing the so called cold boot attack, Halderman et al. showed that one can recover cryptographic keys from a decayed DRAM image. And, following up this result, Heninger and Shacham presented a polynomial-time attack which, given 0.27-fraction of the RSA private key of the form (p, q, d, $d_p$, $d_q$), can recover the whole key, provided that the given bits are uniformly distributed. And, based on the work of Heninger and Shacham, this paper presents a different approach for recovering RSA private key bits from decayed key information, under the assumption that some random portion of the private key bits is known. More precisely, we present the algorithm of recovering RSA private key bits from erased key material and elaborate the formula of describing the number of partially-recovered RSA private key candidates in terms of the given erasure rate. Then, the result is justified by some extensive experiments.

블록 암호 LEA에 대한 차분 오류 공격 (Differential Fault Analysis of the Block Cipher LEA)

  • 박명서;김종성
    • 정보보호학회논문지
    • /
    • 제24권6호
    • /
    • pp.1117-1127
    • /
    • 2014
  • 차분 오류 공격(Differential Fault Analysis)은 블록 암호 알고리즘의 안전성 분석에 널리 사용되는 부채널 기법 중 하나이다. 차분 오류 공격은 대표적인 블록 암호인 DES, AES, ARIA, SEED와 경량 블록 암호인 PRESENT, HIGHT 등에 적용되었다[1,2,3,4,5,6]. 본 논문에서는 최근 주목 받고 있는 국내 경량 블록 암호 LEA(Lightweight Encryption Algorithm)에 대한 차분 오류 공격을 최초로 제안한다. 본 논문에서 제안하는 LEA에 대한 차분 오류 공격은 300개의 선택적 오류 주입 암호문을 이용하여 $2^{35}$의 시간 복잡도로 128 비트 마스터키 전체를 복구한다. 본 연구의 실험 결과, Intel Core i5 CPU, 메모리 8 GB의 일반 PC 환경에서 수집한 오류 주입 암호문을 이용하여, 평균 40분 이내에 마스터 키를 찾을 수 있음을 확인하였다.

연관키 차분 특성을 이용한 Fantomas와 Robin의 키 복구 공격 (Key Recovery Attacks on Fantomas and Robin Using Related-Key Differentials)

  • 김한기;김종성
    • 정보보호학회논문지
    • /
    • 제28권4호
    • /
    • pp.803-807
    • /
    • 2018
  • Fantomas와 Robin은 FSE 2014에서 제안된 경량 블록암호 패밀리 LS-designs에 포함되는 블록암호로, 비트슬라이스 구현이 가능한 L-Box와 S-Box를 사용하여 부채널 분석 대응기법인 마스킹 기법을 효율적으로 적용할 수 있도록 설계되었다. 본 논문은 연관키 차분경로 분석을 통한 Fantomas와 Robin의 전체 128비트 키의 복구공격이 각각 $2^{56}$, $2^{72}$의 시간 복잡도와 $2^{52}$, $2^{69}$개의 선택 평문으로 가능함을 보인다.

웨이브렛 변환을 이용한 실시간 모니터링 ECG 텔레미트리 시스템 구현 (Implementation of Wavelet Transform for a Real time Monitoring ECG Telemetry System)

  • 박차훈;서희돈
    • 융합신호처리학회논문지
    • /
    • 제3권1호
    • /
    • pp.27-32
    • /
    • 2002
  • 본 논문에서 제안한 텔레미트리 시스템은 생체신호를 중거리로 전송하기 위한 RF 송신기와 전자파 간섭의 영향이 없는 광을 매체로한 수신기이다. 텔레미트리 시스템은 of 65$\times$125$\times$45mm크기이며, RF 송신부, 광 수신부와 생체신호 처리를 위한 CMOS 칩으로 구성되어 있다. 제안된 텔레메트리 장점은 전자파에 노출을 최소화하면서 중거리(50m) 텔레메트리가 가능하여, 자유로운 상태에서의 모니터링이 가능하다. 관측 시스템은 실시간 처리를 위해 dual-processor구조로 설계했다. 본 연구에서는 1 채널 360Hz, 16 Bits의 심전도 데이터를 1.42초 간격으로 실시간 웨이브렛 변환할 수 있었다.

  • PDF

재활 훈련중인 환자를 위한 다채널 무구속 심박동수 모니터링 시스템 (Multi-channel Unconstrained Heart Rate Monitoring System for Exercising Rehabilitation Patients)

  • 조종만;최정현;박준호;남태우;은종민
    • 대한의용생체공학회:의공학회지
    • /
    • 제29권3호
    • /
    • pp.191-197
    • /
    • 2008
  • This research focused on the development of wireless telemetry system that can monitor heart rates of multiple rehabilitation patients in real time without constraint. The whole system consists of the multiple patient's side devices (PSDs) and one central monitoring system (CMS). The PSD consists of a microphone, amplifier, filter, microcontroller, and RF (Radio Frequency) modem. In addition, the PSD was designed to be wearable and low power consumption. The CMS consists of an RF modem and general PC and it was designed to monitor heart rates from multiple patients simultaneously. The system warns an alarm signal when a patient's heart rate exceeds the pre-set range for each patient. This system can be useful to monitor the heart rate of exercising rehabilitation patients and control the patients condition and the exercising level.

FEM에 의한 NUDFET의 특성해석에 관한 연구 (A Study on the Characteristic Analysis of NUDFET by FEM)

  • 김종열;정종척;김영식;성만영;조호열
    • 대한전기학회:학술대회논문집
    • /
    • 대한전기학회 1993년도 하계학술대회 논문집 B
    • /
    • pp.1247-1249
    • /
    • 1993
  • In this paper, NUDFET(NonUniformly Doped Field Effect Transistor) is presented as an alternative which offers the possibility of reducing the power necessary to operate switching circuits without a substantial loss in speed. The purpose of this NUDFET is to modify the electric field profile in order to cause carrier velocity saturation to occur at a lower voltage than it would occur in the uniformly doped device of the same channel length. The more MESFET and NUDFET circuits are realized, the more accurate model ins the performance of these devices become required. Analytic model ins was replaced by numerical analysis because of the complexity of device configuration. In this paper, FEM is selected because of simpler local mesh refinement and smaller computer memory than FDM. For accurate analysis, this paper has applied the Scharfetter-Gummel(S-G) Scheme and seven-point Gaussian Quadrature rule to assembly of the finite-element stiffness matrices and right-hand side vector of the semiconductor equations.

  • PDF

개수로 흐름에서 측벽 수직줄눈의 수리효과 (Hydraulic Effect of Vertical-Strip Side Wall in Open Channel Flow)

  • 박상덕;지민규;남아름;우태영;양은익
    • 한국수자원학회:학술대회논문집
    • /
    • 한국수자원학회 2012년도 학술발표회
    • /
    • pp.700-700
    • /
    • 2012
  • 산지유역은 하천을 따라서 도로가 발달되어 있어서 대부분의 도로가 홍수시 하천의 영향을 많이 받는다. 산지하천은 경사가 급하고 만곡수충부가 많이 발달되어 있기 때문에 홍수시 유속이 빠르고 만곡수충부의 편수위가 매우 크다. 이는 만곡부 호안 파괴와 도로 유실의 피해를 일으키는 경우가 많다. 따라서 대부분의 산지하천 만곡수충부에는 홍수피해 방지를 위해 콘크리트 옹벽호안으로 되어 있다. 그러나 콘크리트 옹벽은 조도가 작기 때문에 유속이 더 빠르게 되고 편수위를 한층 증대시킬 수 있다. 산지하천 만곡수충부의 편수위를 줄이기 위해서는 접근유속을 줄여야 하나 산지하천 특성으로 볼 때 접근유속 저감을 위한 공학적 방법은 제한적이다. 따라서 만곡수충부의 유속을 줄이는 방법으로 콘크리트 옹벽호안의 조도계수를 증대시키는 것이 효과적일 수 있다. 본 연구에서는 개수로 측벽에 수직돌출줄눈이 설치되었을 때 흐름에 미치는 수리효과를 개수로 수리실험으로 파악하고자 한 것이다. 실험결과 돌출줄눈의 간격이 수직돌출줄눈의 무차원 폭이 9일 때 평균유속이 가장 작게 나타났다. 이는 돌출줄눈의 간격이 개수로 내부흐름의 유속분포, 최대유속발생 위치, 유수단 면적의 크기에 영향이 미치기 때문이다. 따라서 개수로 측벽 수직돌출줄눈의 간격을 조절함으로써 개수로 유수저항의 크기를 조절할 수 있다.

  • PDF

고분자전해질형 단위 연료전지의 주요 작동 조건이 공기극 플러딩 현상에 미치는 영향 (Effect of Main Operating Conditions on Cathode Flooding Characteristics in a PEM Unit Fuel Cell)

  • 민경덕;김한상
    • 대한기계학회논문집B
    • /
    • 제30권5호
    • /
    • pp.489-495
    • /
    • 2006
  • Proton exchange membrane (PEM) should be sufficiently hydrated with a careful consideration of heat and water management. Water management has been a critical operation issue for better understanding the operation and optimizing the performance of a PEM fuel cell. The flooding on cathode side resulting from excess water can limit the fuel cell performance. In this study, the visual cell was designed and fabricated fur the visualization of liquid water droplet dynamics related to cathode flooding in flow channels. The experiment was carried out to observe the formation, growth and removal of water droplets using CCD imaging system. Effects of operating conditions such as cell temperature, air flow rate and air relative humidity on cathode flooding characteristics were mainly investigated. Based on this study, we can get the basic insight into flooding phenomena and its two-phase flow nature. It is expected that data obtained can be effectively used fur the setup and validation of two-phase PEM fuel cell models considering cathode flooding.

Study on an Electrode Attachment Method Suitable for Underwater Electromyography Measurements

  • Han, Seul-ki;Park, Jung-seo;Nam, Taek-gil
    • 대한물리의학회지
    • /
    • 제10권2호
    • /
    • pp.95-98
    • /
    • 2015
  • PURPOSE: This study was conducted to devise a method of preventing water infiltration into the surface electrodes during EMG measurements underwater and on the ground and to check the reliability of Electromyography (EMG) measurements when underwater. METHODS: Six healthy adults were selected as subjects in this study. The measurements in this study were conducted in pool dedicated to underwater exercise and physical therapy room in the hospital building. An MP150 (Biopac Systems, US, 2010) and a BioNomadix 2-channel wireless EMG transmitter (Biopac Systems, US, 2012) was used to examine the muscle activity of rectus femoris, biceps femoris, tibialis anterior, gastrocnemius of dominant side. The subjects repeated circulation tasks on the ground for more than 10 min for enough surface electrode attachment movement. After a 15-min break, subjects performed the circulation task underwater(water depth 1.1m, water temperature $33.5^{\circ}C$, air temperature $27^{\circ}C$), as on the ground, for more than 10 min, and the MVIC of each muscle was measured again. SPSS v20.0 was used for all statistical computations. RESULTS: The maximum voluntary isometric contraction (MVIC) values between the underwater and on the ground measurements showed no significant differences in all four muscles and showed a high intraclass correlation coefficient (ICC) of >0.80. CONCLUSION: We determined that EMG measurements obtained underwater could be used with high reliability, comparable to ground measurements.

Joint Spatial-Temporal Quality Improvement Scheme for H.264 Low Bit Rate Video Coding via Adaptive Frameskip

  • Cui, Ziguan;Gan, Zongliang;Zhu, Xiuchang
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제6권1호
    • /
    • pp.426-445
    • /
    • 2012
  • Conventional rate control (RC) schemes for H.264 video coding usually regulate output bit rate to match channel bandwidth by adjusting quantization parameter (QP) at fixed full frame rate, and the passive frame skipping to avoid buffer overflow usually occurs when scene changes or high motions exist in video sequences especially at low bit rate, which degrades spatial-temporal quality and causes jerky effect. In this paper, an active content adaptive frame skipping scheme is proposed instead of passive methods, which skips subjectively trivial frames by structural similarity (SSIM) measurement between the original frame and the interpolated frame via motion vector (MV) copy scheme. The saved bits from skipped frames are allocated to coded key ones to enhance their spatial quality, and the skipped frames are well recovered based on MV copy scheme from adjacent key ones at the decoder side to maintain constant frame rate. Experimental results show that the proposed active SSIM-based frameskip scheme acquires better and more consistent spatial-temporal quality both in objective (PSNR) and subjective (SSIM) sense with low complexity compared to classic fixed frame rate control method JVT-G012 and prior objective metric based frameskip method.