The Doubling Attack - Why Upwards Is Better than Downwards
Résumé
The recent developments of side channel attacks have lead implementers to use more and more sophisticated countermeasures in critical operations such as modular exponentiation, or scalar multiplication in the elliptic curve setting. In this paper, we propose a new attack against a classical implementation of these operations that only requires two queries to the device. The complexity of this so-called doubling attack is much smaller than previously known ones. Furthermore, this approach defeats two of the three countermeasures proposed by Coron at CHES '99. Keywords. SPA-based analysis, modular exponentiation, scalar multiplication, DPA countermeasures, multiple exponent single data attack.