A DPA countermeasure by randomized frobenius decomposition

Tae Jun Park, Mun Kyu Lee, Dowon Hong, Kyoil Chung

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

There have been various methods to prevent DPA (Differential Power Analysis) on elliptic curve cryptosystems. As for the curves with efficient endomorphisms, Hasan suggested several countermeasures on anomalous binary curves, and Ciet, Quisquater and Sica proposed a countermeasure on GLV curves. Ciet et al.'s method is based on random decomposition of a scalar, and it is a two-dimensional generalization of Coron's method. Hasan's and Ciet et al.'s countermeasures are applied only to a small class of elliptic curves. In this paper, we enlarge the class of DPA-resistant curves by proposing a DPA countermeasure applicable to any curve where the Frobenius expansion method can be used. Our analysis shows that our countermeasure can produce a probability of collision around script O sign(2-20) with only 15.4-34.0% extra computation for scalar multiplications on various practical settings.

Original languageEnglish
Title of host publicationInformation Security Applications - 6th International Workshop, WISA 2005, Revised Selected Papers
Pages271-282
Number of pages12
StatePublished - 2005
Event6th International Workshop on Information Security Applications, WISA 2005 - Jeju Island, Korea, Republic of
Duration: 22 Aug 200524 Aug 2005

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume3786 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference6th International Workshop on Information Security Applications, WISA 2005
Country/TerritoryKorea, Republic of
CityJeju Island
Period22/08/0524/08/05

Keywords

  • DPA
  • Elliptic curve
  • Frobenius expansion
  • GLV decomposition
  • Scalar multiplication

Fingerprint

Dive into the research topics of 'A DPA countermeasure by randomized frobenius decomposition'. Together they form a unique fingerprint.

Cite this