Adil Khan 1 year ago
AdiKhanOfficial #FYP Ideas

Crypto Timing Attack Analysis and Countermeasures

Confidential information shared through any transmission line or network can be read by an eavesdropper or even worse can be modified in such a way that the person receiving the information would not even be able to detect the manipulation. Cyber security threat is a malicious act that seeks to dama

Project Title

Crypto Timing Attack Analysis and Countermeasures

Project Area of Specialization

Cyber Security

Project Summary

Confidential information shared through any transmission line or network can be read by an eavesdropper or even worse can be modified in such a way that the person receiving the information would not even be able to detect the manipulation. Cyber security threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. This sort of attack can cause great harm to any organization or even to the nation as it can break the system. There are many ways in which we can prevent these attacks through algorithms and codes which are available, but there is a possibility of the code to be leaky.

 Timing attacks are a category of side channel analysis (SCA) attacks that exploit the differences in the execution time of a security algorithm. The execution time measurements from the device can lead to the recovery of the secret information, which can break the whole system. The weakness of an algorithm is one of the major reasons behind the manipulation of confidential information. Outdated software systems and easily accessible algorithms makes any certain code leaky. To overcome all these hurdles is a necessity to make a system secure. 

Project Objectives

  1. Understand the concepts of cryptology which includes cryptography and cryptanalysis.
  2. Develop a good understanding of the existing algorithms, symmetric and asymmetric algorithms. Study the protocols of cryptography. 
  3. Gain a good understanding of the SCA attacks in general and timing attacks in particular and block ciphers.
  4. Setup the software for calculating execution times of various cryptographic kernels, e.g., Block ciphers.
  5. Analyse timing attack vulnerabilities and investigate possible countermeasures against these leakages
  6. Detailed exploration and understanding of leaky and non-leaky coding styles in terms of execution profiles to judge the timing attack vulnerability of a code.
  7. Upgrade the cryptographic kernels according to the countermeasure(s) and prove the effectiveness of the upgraded algorithms in terms of execution time overhead and time constant execution profile.

Project Implementation Method

This project will investigate the basic ingredients of cryptography in their common coding styles for timing leakage analysis. The execution profiles of these codes will categorize them as leaky or non-leaky in nature. The leaky codes will be redesigned via techniques like parallelization/ masking or the method of appending a dummy variable and distributing etc. so as to make them non-leaky. Methods, techniques and coding styles for non-leaky codes with minimum execution overhead benchmarked will be preferred and published. We will use the general purpose Intel processors and evaluate the execution time profiles for common cryptographic kernels like random number generators (RNGs), block ciphers, stream ciphers etc.

Based on the on-device evaluation, the fitness of an algorithm being prone to timing leakages can be evaluated, since algorithms with constant execution time is least likely to be timing attack vulnerable and vice versa. Consequently, recommendations/ coding styles for minimizing timing leakages will be proposed and evaluated.

Furthermore, we will try to make our performance better in real-time, and reduce overhead. We will be working and doing research on AES (Advanced Encryption Standard) as it is a symmetric algorithm and is considered one of the most secure algorithm, the key bit chosen encrypts and decrypts blocks in 128 bits, 192 bits and so on. In addition to all this we will also try to implement this project on hardware by using FPGA (Field Programmable gate array) or logic analyser to check the symmetric behaviour.

Benefits of the Project

In today’s time Information security is one of the up-to-the-minute areas with new technological advancements and a career in information security management is fruitful. Looking at the initiatives by government on digital economy and the frequent hacking incidents all companies will need cyber security professionals. Information Security job is one of the most well paid careers in the market.                                                                                    Our project will make a contribution to the World of Information security as the leaky codes will be redesigned via techniques like parallelization/ masking or the method of appending a dummy variable and distributing etc. so as to make them non-leaky. Methods, techniques and coding styles for non-leaky codes with minimum execution overhead benchmarked will be preferred and published. To provide secure transmission with minimum overhead will make a mark in the market. This project will give us the opportunity to explore a new field and it might even lead to a thesis paper which can be further published.

Technical Details of Final Deliverable

Our project will be able to make the AES 128 bit symmetric so it can have contant  timing profile. with the help of which it will not be able to get hacked from timing attacks.

Final Deliverable of the Project

HW/SW integrated system

Core Industry

Security

Other Industries

Core Technology

Others

Other Technologies

Sustainable Development Goals

Responsible Consumption and Production

Required Resources

Item Name Type No. of Units Per Unit Cost (in Rs) Total (in Rs)
FPGA Equipment13000030000
Total in (Rs) 30000
If you need this project, please contact me on contact@adikhanofficial.com
0
110
Surveillance System

Automobiles have a great importance in our daily life because they are not only resourcefu...

1675638330.png
Adil Khan
1 year ago
Customer segmentation for business promotion

Customer are like snowflakes: No two customers are same. Even customer purchasing similar...

1675638330.png
Adil Khan
1 year ago
Smart Cart

With the increasing reliability and cost effectiveness of?Internet of Things (IoT) based c...

1675638330.png
Adil Khan
1 year ago
Machines Trends Predictor

A web based smart platform that would analyze historic patterns of a machine states using...

1675638330.png
Adil Khan
1 year ago
DESIGN AND FABRICATION OF HYBRID POWER GENERATION USING PHOTO VOLTAIC...

Solar and wind are more importance in the present world. This project aims to develop a hy...

1675638330.png
Adil Khan
1 year ago