<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fault injection: Ataque a RSA-CRT</title>
	<atom:link href="http://www.limited-entropy.com/fault-injection-ataque-a-rsa-crt/feed" rel="self" type="application/rss+xml" />
	<link>http://www.limited-entropy.com/fault-injection-ataque-a-rsa-crt</link>
	<description>Not so random thoughts on security featured by Eloi Sanfèlix</description>
	<lastBuildDate>Fri, 27 Jan 2012 03:06:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Crypto04 challenge write-up from Campus Party Europe &#124; It should work...</title>
		<link>http://www.limited-entropy.com/fault-injection-ataque-a-rsa-crt/comment-page-1#comment-13890</link>
		<dc:creator>Crypto04 challenge write-up from Campus Party Europe &#124; It should work...</dc:creator>
		<pubDate>Mon, 19 Apr 2010 22:20:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.limited-entropy.com/?p=75#comment-13890</guid>
		<description>[...] From those hints we get that it is actually using the RSA-CRT algorithm, which is a RSA variation to reduce computational costs using the Chinese Remainder Theorem. The point is that instead of using the 2048 bit modular exponentation it splits them into two modular operations, aproximately half the size, make the calculations and then recombine the results as needed to obtain the regular RSA result. But here&#8217;s the trick, if we inject a fault in one of these two exponentiations, via power glitching for example, there&#8217;s a way to recover the private RSA key. The use of RSA-CRT is common in embedded devices such as smart cards, mainly because of the hardware limitations. You can read a post about it at Eloi&#8217;s blog, it&#8217;s in spanish though: RSA-CRT Fault Injection. [...]</description>
		<content:encoded><![CDATA[<p>[...] From those hints we get that it is actually using the RSA-CRT algorithm, which is a RSA variation to reduce computational costs using the Chinese Remainder Theorem. The point is that instead of using the 2048 bit modular exponentation it splits them into two modular operations, aproximately half the size, make the calculations and then recombine the results as needed to obtain the regular RSA result. But here&#8217;s the trick, if we inject a fault in one of these two exponentiations, via power glitching for example, there&#8217;s a way to recover the private RSA key. The use of RSA-CRT is common in embedded devices such as smart cards, mainly because of the hardware limitations. You can read a post about it at Eloi&#8217;s blog, it&#8217;s in spanish though: RSA-CRT Fault Injection. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vierito5</title>
		<link>http://www.limited-entropy.com/fault-injection-ataque-a-rsa-crt/comment-page-1#comment-1889</link>
		<dc:creator>vierito5</dc:creator>
		<pubDate>Mon, 12 May 2008 02:28:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.limited-entropy.com/?p=75#comment-1889</guid>
		<description>jajjajaja me has hecho darle varias vueltas al post :)

muy interesante !!</description>
		<content:encoded><![CDATA[<p>jajjajaja me has hecho darle varias vueltas al post <img src='http://www.limited-entropy.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>muy interesante !!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

