R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

New threat forces cryptography rethink

Hackers start using 'side-channel' attacks

Iain Thomson Paris, France, vnunet.com 10 Oct 2002
ADVERTISEMENT

Side-channel attacks are the next big threat from hackers, according to the head of RSA Labs.

Normal attacks on code are conducted by looking at the unencrypted message and the encrypted message and attempt to recover the encryption key.

But side-channel attacks look at other information in an attempt to crack the code, such as the time taken to perform an operation and how power consumption changes.

Bert Kaliski, head of RSA Labs, told vnunet.com that these methods are forcing the industry to think again.

"Side-channel attacks are causing a fundamental rethink in the way we write encryption software," he said. "As the methods used become automated, our job is getting tougher."

In order to counter the side-channel threat encryption software is being designed to mislead anyone who is monitoring the process.

Until recently the focus of research was to cut processing time and minimise memory use. Now the encryption engine must camouflage itself, for example by varying the time taken to perform identical functions.

At the recent Cryptography Research conference in San Francisco over half the speakers' time was dedicated to side-channel attacks. Attendees were shown adapted credit card readers that could be used for such an attack.

Kaliski explained that encryption algorithms are still advancing. "The move from triple-Data Encryption Standard to the Advanced Encryption Standard [AES] should ensure that we're ahead of the crackers on one level. AES could be considered overkill," he said.

There had been fears that AES could be broken after cryptographers Nicolas Courtois and Josef Pieprzyk published an attack which could theoretically work.

However, the attacks would be impossible for years to come because of the complexity needed to cope with long key lengths.

See also:

Code keys sent as stream of photons over fibre optic cable  04 Nov 2002
But no need to panic. Yet.  18 Sep 2002
Advanced Encryption Standard is based on Rijndael formula  05 Dec 2001

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
Job Title: PHP Developer/Web Developer Location: Suffolk Notice: Immediate Salary Expectations: £35,000 A personable team player with PHP and web development skills is being offered an excellent opportunity to join an organisation based in the ... more >
| Computer People
Job Title: Senior Java Technical Architect Location: Sheffield Salary Expectations: £70,000 - £80,000 plus Share options A rare opportunity has recently been registered for a Senior Java Technical Architect to join what will be a ... more >
| Computer People
Job Title: Test Team Leader Location: Cambridge Salary Expectations: £20,000 - £45,000 An exciting and expanding consultancy in the Cambridge area is actively seeking to recruit a Test Team Leader who will take responsibility for ... more >
| Computer People
Job Title: Autonomy Search Database Developer Location: North Cambridgeshire Salary: £28,000 - £30,000 My client is a large, North Cambridgeshire based organisation with nearly 6000 users based from multiple sites. With on site parking and ... more >
More job opportunities