Practical second-order correlation power analysis on the message blinding method and its novel countermeasure for RSA

Hee Seok Kim, Tae Hyun Kim, Joong Chul Yoon, Seokhie Hong

Research output: Contribution to journalArticle

15 Citations (Scopus)


Recently power attacks on RSA cryptosystems have been widely investigated, and various countermeasures have been proposed. One of the most efficient and secure countermeasures is the message blinding method, which includes the RSA derivative of the binary-with-randominitial-point algorithm on elliptical curve cryptosystems. It is known to be secure against first-order differential power analysis (DPA); however, it is susceptible to second-order DPA. Although second-order DPA gives some solutions for defeating message blinding methods, this kind of attack still has the practical difficulty of how to find the points of interest, that is, the exact moments when intermediate values are being manipulated. In this paper, we propose a practical second-order correlation power analysis (SOCPA). Our attack can easily find points of interest in a power trace and find the private key with a small number of power traces. We also propose an efficient countermeasure which is secure against the proposed SOCPA as well as existing power attacks.

Original languageEnglish
Pages (from-to)102-111
Number of pages10
JournalETRI Journal
Issue number1
Publication statusPublished - 2010 Feb 1



  • BRIP
  • Message blinding method
  • RSA cryptosystems
  • Second-order DPA
  • Side channel attacks

ASJC Scopus subject areas

  • Electronic, Optical and Magnetic Materials
  • Computer Science(all)
  • Electrical and Electronic Engineering

Cite this