2016/03/01 by Masahiro Kaminaga, Hideki Yoshikawa, Kaminaga, Masahiro +5
Computer Science · #94A60 #Coding theory and cryptography #Cryptographic Implementations and Security #Cryptography and Residue Arithmetic #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #cs.CR #msc:94A60
paper · pdf · doi:10.48550/arxiv.1603.00100
18 pages, 2 figures
arxiv created 2016/03/01 · openalex publication_date 2016/03/01 · arxiv updated 2016/03/02 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
The Rabin cryptosystem has been proposed protect the unique ID (UID) in radio-frequency identification tags. The Rabin cryptosystem is a type of lightweight public key system that is theoretetically quite secure; however it is vulnerable to several side-channel attacks. In this paper, a crashing modulus attack is presented as a new fault attack on modular squaring during Rabin encryption. This attack requires only one fault in the public key if its perturbed public key can be factored. Our simulation results indicate that the attack is more than 50% successful with several faults in practical time. A complicated situation arises when reconstrucing the message, including the UID, from ciphertext, i.e., the message and the perturbed public key are not relatively prime. We present a complete and mathematically rigorous message reconstruction algorithm for such a case. Moreover, we propose an exact formula to obtain a number of candidate messages. We show that the number is not generally equal to a power of two.