文章对一款基于特征2域实现的椭圆曲线密码ASIC芯片进行了差分功耗分析。其中分析的目标为实现椭圆曲线层多倍点运算的Montgomery Ladder算法。通过详细的差分功耗分析发现,Montgomery Ladder算法并不能抗MESD差分功耗分析,从而从实践的角度证明Montgomery Ladder算法并不安全,椭圆曲线密码芯片的实际应用还需要其它抗功耗分析手段来保证其安全。
This paper describes a differential power analysis (DPA) against an implementation of elliptic curve cryptosystem (ECC) on an ASIC chip. In the chip, the method used for scalar multiplication of ECC is Montgomery Ladder which is a basic algorithm used to resist DPA. We perform a detailed MESD differential power analysis attack the ECC chip, the result shows that Montgomery Ladder is vulnerable to MESD. So, K.hoh is wrong and the ECC chip with Montgomery Ladder is not secure enough, some other countermeasures must be adopted to enhance the ECC chip.