ご案内 入会して研究会活動をもっとお得に!研究会参加費・年間登録費が会員価格になります。
お知らせ 【重要】研究会参加費の支払いおよび原稿アップロード手続きの変更に関するご案内
電子情報通信学会 研究会発表申込システム
講演論文 詳細
技報閲覧サービス
[ログイン]
技報アーカイブ
 トップに戻る 前のページに戻る   [Japanese] / [English] 

講演抄録/キーワード
講演名 2006-09-13 13:25
ハッシュ関数構成法を考慮したHMACに対するサイドチャネル攻撃
桶屋勝幸日立
抄録 (和) 鍵付きハッシュ関数のひとつとしてHMAC があり、広く用いられている。安全なハッシュ関数の構成方法のひとつとして、PGV 構成法がある。PGV 構成法はブロック暗号に基づき圧縮関数を構成する手法で、ブロック暗号が理想的とすると、12 個の圧縮関数が衝突耐性を有すると結論付けられている。本稿では、それらの圧縮関数に対して、サイドチャネル攻撃の観点から安全性評価を行う。その結果、ブロック暗号がサイドチャネル攻撃に安全であったとしても、12 個のうち11 個の圧縮関数が脆弱であることを示す。これらの脆弱圧縮関数は、その脆弱性により二つのグループに分けることができる。第一のグループは8 つの圧縮関数を含み、HMAC に用いた場合、攻撃者は選択的偽造ができる。第二のグループは3 つの圧縮関数を含み、圧縮関数内の演算順序が安全性にとって重要である。間違った演算順序を選択した場合、攻撃者はHMAC の鍵の一部を特定することができる。これらの圧縮関数を用いたHMAC は、実装安全性が必要とされる場面での使用は推奨されない。 
(英) HMAC is one of the most famous keyed hash functions, and widely utilized. In order to design secure hash functions, we often use PGV construction consisting of 64 schemes, each of which utilizes a block cipher. If the underlying block cipher is ideal, 12 schemes are proven to be secure. In this paper, we evaluate the security of these schemes in view of side channel attacks. As it turns out, HMACs based on 11 out of 12 secure PGV schemes are vulnerable to side channel attacks, even if the underlying block cipher is secure against side channel attacks. These schemes are classified into two groups based on their vulnerabilities. For the first group which contains 8 schemes, we show that the attacker can reveal the whole key of HMAC, and selectively forge in consequence. For the other group which contains 3 schemes, we specify the importance of the execution sequence for the inner operations of the scheme, and refine it. If wrong orders of operations are used, the attacker can reveal a portion of the key of HMAC. Hence, the use of HMACs based on such PGV schemes as they are is not recommended when the resistance against side channel attacks is necessary.
キーワード (和) ハッシュ関数 / 鍵付きハッシュ関数 / HMAC / PGV構成法 / サイドチャネル攻撃 / 差分電力解析 / DPA / リバースDPA  
(英) hash function / keyed hash function / HMAC / PGV construction / side channel attacks / differential power analysis / DPA / reverse DPA  
文献情報 信学技報, vol. 106, no. 235, ISEC2006-79, pp. 53-60, 2006年9月.
資料番号 ISEC2006-79 
発行日 2006-09-06 (ISEC) 
ISSN Print edition: ISSN 0913-5685
PDFダウンロード

研究会情報
研究会 ISEC  
開催期間 2006-09-13 - 2006-09-13 
開催地(和) 機械振興会館 
開催地(英) Kikai-Shinko-Kaikan Bldg. 
テーマ(和) 一般 
テーマ(英)  
講演論文情報の詳細
申込み研究会 ISEC 
会議コード 2006-09-ISEC 
本文の言語 日本語 
タイトル(和) ハッシュ関数構成法を考慮したHMACに対するサイドチャネル攻撃 
サブタイトル(和)  
タイトル(英) Side Channel Attacks against HMACs with Design for Hash Functions 
サブタイトル(英)  
キーワード(1)(和/英) ハッシュ関数 / hash function  
キーワード(2)(和/英) 鍵付きハッシュ関数 / keyed hash function  
キーワード(3)(和/英) HMAC / HMAC  
キーワード(4)(和/英) PGV構成法 / PGV construction  
キーワード(5)(和/英) サイドチャネル攻撃 / side channel attacks  
キーワード(6)(和/英) 差分電力解析 / differential power analysis  
キーワード(7)(和/英) DPA / DPA  
キーワード(8)(和/英) リバースDPA / reverse DPA  
第1著者 氏名(和/英/ヨミ) 桶屋 勝幸 / Katsuyuki Okeya /
第1著者 所属(和/英) 日立製作所 (略称: 日立)
Hitachi, Ltd. (略称: Hitachi)
第2著者 氏名(和/英/ヨミ) / /
第2著者 所属(和/英) (略称: )
(略称: )
第3著者 氏名(和/英/ヨミ) / /
第3著者 所属(和/英) (略称: )
(略称: )
第4著者 氏名(和/英/ヨミ) / /
第4著者 所属(和/英) (略称: )
(略称: )
第5著者 氏名(和/英/ヨミ) / /
第5著者 所属(和/英) (略称: )
(略称: )
第6著者 氏名(和/英/ヨミ) / /
第6著者 所属(和/英) (略称: )
(略称: )
第7著者 氏名(和/英/ヨミ) / /
第7著者 所属(和/英) (略称: )
(略称: )
第8著者 氏名(和/英/ヨミ) / /
第8著者 所属(和/英) (略称: )
(略称: )
第9著者 氏名(和/英/ヨミ) / /
第9著者 所属(和/英) (略称: )
(略称: )
第10著者 氏名(和/英/ヨミ) / /
第10著者 所属(和/英) (略称: )
(略称: )
第11著者 氏名(和/英/ヨミ) / /
第11著者 所属(和/英) (略称: )
(略称: )
第12著者 氏名(和/英/ヨミ) / /
第12著者 所属(和/英) (略称: )
(略称: )
第13著者 氏名(和/英/ヨミ) / /
第13著者 所属(和/英) (略称: )
(略称: )
第14著者 氏名(和/英/ヨミ) / /
第14著者 所属(和/英) (略称: )
(略称: )
第15著者 氏名(和/英/ヨミ) / /
第15著者 所属(和/英) (略称: )
(略称: )
第16著者 氏名(和/英/ヨミ) / /
第16著者 所属(和/英) (略称: )
(略称: )
第17著者 氏名(和/英/ヨミ) / /
第17著者 所属(和/英) (略称: )
(略称: )
第18著者 氏名(和/英/ヨミ) / /
第18著者 所属(和/英) (略称: )
(略称: )
第19著者 氏名(和/英/ヨミ) / /
第19著者 所属(和/英) (略称: )
(略称: )
第20著者 氏名(和/英/ヨミ) / /
第20著者 所属(和/英) (略称: )
(略称: )
第21著者 氏名(和/英/ヨミ) / /
第21著者 所属(和/英) (略称: )
(略称: )
第22著者 氏名(和/英/ヨミ) / /
第22著者 所属(和/英) (略称: )
(略称: )
第23著者 氏名(和/英/ヨミ) / /
第23著者 所属(和/英) (略称: )
(略称: )
第24著者 氏名(和/英/ヨミ) / /
第24著者 所属(和/英) (略称: )
(略称: )
第25著者 氏名(和/英/ヨミ) / /
第25著者 所属(和/英) (略称: )
(略称: )
第26著者 氏名(和/英/ヨミ) / /
第26著者 所属(和/英) (略称: )
(略称: )
第27著者 氏名(和/英/ヨミ) / /
第27著者 所属(和/英) (略称: )
(略称: )
第28著者 氏名(和/英/ヨミ) / /
第28著者 所属(和/英) (略称: )
(略称: )
第29著者 氏名(和/英/ヨミ) / /
第29著者 所属(和/英) (略称: )
(略称: )
第30著者 氏名(和/英/ヨミ) / /
第30著者 所属(和/英) (略称: )
(略称: )
第31著者 氏名(和/英/ヨミ) / /
第31著者 所属(和/英) (略称: )
(略称: )
第32著者 氏名(和/英/ヨミ) / /
第32著者 所属(和/英) (略称: )
(略称: )
第33著者 氏名(和/英/ヨミ) / /
第33著者 所属(和/英) (略称: )
(略称: )
第34著者 氏名(和/英/ヨミ) / /
第34著者 所属(和/英) (略称: )
(略称: )
第35著者 氏名(和/英/ヨミ) / /
第35著者 所属(和/英) (略称: )
(略称: )
第36著者 氏名(和/英/ヨミ) / /
第36著者 所属(和/英) (略称: )
(略称: )
講演者 第1著者 
発表日時 2006-09-13 13:25:00 
発表時間 25分 
申込先研究会 ISEC 
資料番号 ISEC2006-79 
巻番号(vol) vol.106 
号番号(no) no.235 
ページ範囲 pp.53-60 
ページ数
発行日 2006-09-06 (ISEC) 


[研究会発表申込システムのトップページに戻る]

[電子情報通信学会ホームページ]


IEICE / 電子情報通信学会