{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T15:44:25Z","timestamp":1780069465596,"version":"3.54.0"},"publisher-location":"Berlin, Heidelberg","reference-count":36,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540792628","type":"print"},{"value":"9783540792635","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-79263-5_16","type":"book-chapter","created":{"date-parts":[[2008,4,4]],"date-time":"2008-04-04T12:18:54Z","timestamp":1207311534000},"page":"256-273","source":"Crossref","is-referenced-by-count":42,"title":["A Vulnerability in RSA Implementations Due to Instruction Cache Analysis and Its Demonstration on OpenSSL"],"prefix":"10.1007","author":[{"given":"Onur","family":"Ac\u0131i\u00e7mez","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Werner","family":"Schindler","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"16_CR1","unstructured":"Ac\u0131i\u00e7mez, O., Schindler, W.: A Major Vulnerability in RSA Implementations due to MicroArchitectural Analysis Threat. Cryptology ePrint Archive, Report 2007\/336 (August 2007)"},{"key":"16_CR2","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1145\/1314466.1314469","volume-title":"ACM Workshop on Computer Security Architecture","author":"O. Ac\u0131i\u00e7mez","year":"2007","unstructured":"Ac\u0131i\u00e7mez, O.: Yet Another MicroArchitectural Attack: Exploiting I-cache. In: ACM Workshop on Computer Security Architecture, pp. 11\u201318. ACM Press, New York (2007)"},{"key":"16_CR3","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/FDTC.2007.16","volume-title":"4 th Workshop on Fault Diagnosis and Tolerance in Cryptography \u2014 FDTC 2007","author":"O. Ac\u0131i\u00e7mez","year":"2007","unstructured":"Ac\u0131i\u00e7mez, O., Seifert, J.-P.: Cheap Hardware Parallelism Implies Cheap Security. In: 4 th Workshop on Fault Diagnosis and Tolerance in Cryptography \u2014 FDTC 2007, pp. 80\u201391. IEEE Computer Society, Los Alamitos (2007)"},{"key":"16_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/978-3-540-77272-9_12","volume-title":"Cryptography and Coding","author":"O. Ac\u0131i\u00e7mez","year":"2007","unstructured":"Ac\u0131i\u00e7mez, O., Gueron, S., Seifert, J.-P.: New Branch Prediction Vulnerabilities in OpenSSL and Necessary Software Countermeasures. In: Galbraith, S.D. (ed.) Cryptography and Coding 2007. LNCS, vol.\u00a04887, pp. 185\u2013203. Springer, Heidelberg (2007), Cryptology ePrint Archive, Report 2007\/039, (February 2007)"},{"key":"#cr-split#-16_CR5.1","doi-asserted-by":"crossref","unstructured":"Ac\u0131i\u00e7mez, O., Ko\u00e7, \u00c7.K., Seifert, J.-P.: On The Power of Simple Branch Prediction Analysis. In: Deng, R., Samarati, P. (eds.) ACM Symposium on InformAtion, Computer and Communications Security (ASIACCS 2007), pp. 312\u2013320 (2006);","DOI":"10.1145\/1229285.1266999"},{"key":"#cr-split#-16_CR5.2","unstructured":"Cryptology ePrint Archive, Report 2006\/351 (October 2006)"},{"key":"16_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1007\/11967668_15","volume-title":"Topics in Cryptology \u2013 CT-RSA 2007","author":"O. Ac\u0131i\u00e7mez","year":"2006","unstructured":"Ac\u0131i\u00e7mez, O., Ko\u00e7, \u00c7.K., Seifert, J.-P.: Predicting Secret Keys via Branch Prediction. In: Abe, M. (ed.) CT-RSA 2007. LNCS, vol.\u00a04377, pp. 225\u2013242. Springer, Heidelberg (2006), Cryptology ePrint Archive, Report 2006\/288, (August 2006)"},{"key":"16_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1007\/11967668_18","volume-title":"Topics in Cryptology \u2013 CT-RSA 2007","author":"O. Ac\u0131i\u00e7mez","year":"2006","unstructured":"Ac\u0131i\u00e7mez, O., Schindler, W., Ko\u00e7, \u00c7.K.: Cache Based Remote Timing Attack on the AES. In: Abe, M. (ed.) CT-RSA 2007. LNCS, vol.\u00a04377, pp. 271\u2013286. Springer, Heidelberg (2006)"},{"key":"16_CR8","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1145\/1102120.1102140","volume-title":"Proceedings of the 12 th ACM Conference on Computer and Communications Security","author":"O. Ac\u0131i\u00e7mez","year":"2005","unstructured":"Ac\u0131i\u00e7mez, O., Schindler, W., Ko\u00e7, \u00c7.K.: Improving Brumley and Boneh Timing Attack on Unprotected SSL Implementations. In: Meadows, C., Syverson, P. (eds.) Proceedings of the 12 th ACM Conference on Computer and Communications Security, pp. 139\u2013146. ACM Press, New York (2005)"},{"key":"16_CR9","unstructured":"Bernstein, D. J.: Cache-timing attacks on AES. Technical Report, 37 pages, (April 2005), http:\/\/cr.yp.to\/antiforgery\/cachetiming-20050414.pdf"},{"key":"16_CR10","unstructured":"Brumley, D., Boneh, D.: Remote Timing Attacks are Practical. In: Proceedings of the 12 th Usenix Security Symposium, pp. 1\u201314 (2003)"},{"key":"16_CR11","series-title":"Lecture Notes in Computer Science","first-page":"175","volume-title":"Smart Card. Research and Applications","author":"J.-F. Dhem","year":"2000","unstructured":"Dhem, J.-F., Koeune, F., Leroux, P.-A., Mestr\u00e9, P.-A., Quisquater, J.-J., Willems, J.-L.: A Practical Implementation of the Timing Attack. In: Schneier, B., Quisquater, J.-J. (eds.) CARDIS 1998. LNCS, vol.\u00a01820, pp. 175\u2013191. Springer, Heidelberg (2000)"},{"key":"16_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1007\/3-540-36400-5_5","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2002","author":"S. Gueron","year":"2003","unstructured":"Gueron, S.: Enhanced Montgomery Multiplication. In: Kaliski Jr., B.S., Ko\u00e7, \u00c7.K., Paar, C. (eds.) CHES 2002. LNCS, vol.\u00a02523, pp. 46\u201356. Springer, Heidelberg (2003)"},{"key":"16_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1007\/3-540-44499-8_23","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2000","author":"G. Hachez","year":"2000","unstructured":"Hachez, G., Quisquater, J.-J.: Montgomery Exponentiation with no Final Subtractions: Improved Results. In: Paar, C., Ko\u00e7, \u00c7.K. (eds.) CHES 2000. LNCS, vol.\u00a01965, pp. 91\u2013100. Springer, Heidelberg (2000)"},{"key":"16_CR14","unstructured":"Kocher, P.C., Jaffe, J.M.: Secure Modular Exponentiation with Leak Minimization for Smartcards and other Cryptosystems. United States Patent, Patent No.: US 6,298,442 B1 (October 2001)"},{"key":"16_CR15","volume-title":"Handbook of Applied Cryptography","author":"A.J. Menezes","year":"1997","unstructured":"Menezes, A.J., van Oorschot, P.C., Vanstone, S.C.: Handbook of Applied Cryptography. CRC Press, New York (1997)"},{"key":"16_CR16","unstructured":"Neve, M.: Cache-based Vulnerabilities and SPAM Analysis. Ph.D. Thesis, Applied Science, UCL (July 2006)"},{"key":"16_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/978-3-540-74462-7_11","volume-title":"Selected Areas in Cryptography","author":"M. Neve","year":"2007","unstructured":"Neve, M., Seifert, J.-P.: Advances on Access-driven Cache Attacks on AES. In: Biham, E., Youssef, A.M. (eds.) SAC 2006. LNCS, vol.\u00a04356, pp. 147\u2013162. Springer, Heidelberg (2007)"},{"key":"16_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11605805_1","volume-title":"Topics in Cryptology \u2013 CT-RSA 2006","author":"D.A. Osvik","year":"2006","unstructured":"Osvik, D.A., Shamir, A., Tromer, E.: Cache Attacks and Countermeasures: The Case of AES. In: Pointcheval, D. (ed.) CT-RSA 2006. LNCS, vol.\u00a03860, pp. 1\u201320. Springer, Heidelberg (2006)"},{"key":"16_CR19","unstructured":"Page, D.: Theoretical Use of Cache Memory as a Cryptanalytic Side-Channel. Technical Report, Department of Computer Science, University of Bristol (June 2002)"},{"key":"16_CR20","unstructured":"Percival, C.: Cache missing for fun and profit. BSDCan 2005, Ottawa (2005), http:\/\/www.daemonology.net\/hyperthreading-considered-harmful\/"},{"key":"16_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"85","DOI":"10.1007\/978-3-540-30580-4_7","volume-title":"Public Key Cryptography - PKC 2005","author":"W. Schindler","year":"2005","unstructured":"Schindler, W.: On the Optimization of Side-Channel Attacks by Advanced Stochastic Methods. In: Vaudenay, S. (ed.) PKC 2005. LNCS, vol.\u00a03386, pp. 85\u2013103. Springer, Heidelberg (2005)"},{"key":"16_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1007\/978-3-540-40974-8_20","volume-title":"Cryptography and Coding","author":"W. Schindler","year":"2003","unstructured":"Schindler, W., Walter, C.D.: More Detail for a Combined Timing and Power Attack against Implementations of RSA. In: Paterson, K.G. (ed.) Cryptography and Coding 2003. LNCS, vol.\u00a02898, pp. 245\u2013263. Springer, Heidelberg (2003)"},{"key":"16_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"263","DOI":"10.1007\/3-540-45664-3_19","volume-title":"Public Key Cryptography","author":"W. Schindler","year":"2002","unstructured":"Schindler, W.: A Combined Timing and Power Attack. In: Naccache, D., Paillier, P. (eds.) PKC 2002. LNCS, vol.\u00a02274, pp. 263\u2013279. Springer, Heidelberg (2002)"},{"key":"16_CR24","first-page":"191","volume":"20","author":"W. Schindler","year":"2002","unstructured":"Schindler, W.: Optimized Timing Attacks against Public Key Cryptosystems. Statistics and Decisions\u00a020, 191\u2013210 (2002)","journal-title":"Statistics and Decisions"},{"key":"16_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1007\/3-540-45325-3_22","volume-title":"Cryptography and Coding","author":"W. Schindler","year":"2001","unstructured":"Schindler, W., Koeune, F., Quisquater, J.-J.: Improving Divide and Conquer Attacks Against Cryptosystems by Better Error Detection \/ Correction Strategies. In: Honary, B. (ed.) Cryptography and Coding 2001. LNCS, vol.\u00a02260, pp. 245\u2013267. Springer, Heidelberg (2001)"},{"key":"16_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1007\/3-540-44499-8_8","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2000","author":"W. Schindler","year":"2000","unstructured":"Schindler, W.: A Timing Attack against RSA with the Chinese Remainder Theorem. In: Paar, C., Ko\u00e7, \u00c7.K. (eds.) CHES 2000. LNCS, vol.\u00a01965, pp. 110\u2013125. Springer, Heidelberg (2000)"},{"key":"16_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"192","DOI":"10.1007\/3-540-45353-9_15","volume-title":"Topics in Cryptology - CT-RSA 2001","author":"C.D. Walter","year":"2001","unstructured":"Walter, C.D., Thompson, S.: Distinguishing Exponent Digits by Observing Modular Subtractions. In: Naccache, D. (ed.) CT-RSA 2001. LNCS, vol.\u00a02020, pp. 192\u2013207. Springer, Heidelberg (2001)"},{"issue":"21","key":"16_CR28","doi-asserted-by":"publisher","first-page":"1831","DOI":"10.1049\/el:19991230","volume":"35","author":"C.D. Walter","year":"1999","unstructured":"Walter, C.D.: Montgomery exponentiation needs no final subtractions. IEE Electronics Letters\u00a035(21), 1831\u20131832 (1999)","journal-title":"IEE Electronics Letters"},{"key":"16_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/3-540-48059-5_9","volume-title":"Cryptographic Hardware and Embedded Systems","author":"C.D. Walter","year":"1999","unstructured":"Walter, C.D.: Montgomery\u2019s Multiplication Technique: How to Make It Smaller and Faster. In: Ko\u00e7, \u00c7.K., Paar, C. (eds.) CHES 1999. LNCS, vol.\u00a01717, pp. 80\u201393. Springer, Heidelberg (1999)"},{"key":"16_CR30","unstructured":"http:\/\/www.ntt.co.jp\/news\/news06e\/0611\/061108a.html"},{"key":"16_CR31","unstructured":"http:\/\/cvs.openssl.org\/chngview?cn=16275"},{"key":"16_CR32","unstructured":"ftp:\/\/ftp.openssl.org\/snapshot\/"},{"key":"16_CR33","unstructured":"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-3108"},{"key":"16_CR34","unstructured":"http:\/\/www.cert.org\/"},{"key":"16_CR35","unstructured":"US CERT vulnerability note, http:\/\/www.kb.cert.org\/vuls\/id\/724968"}],"container-title":["Lecture Notes in Computer Science","Topics in Cryptology \u2013 CT-RSA 2008"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-79263-5_16.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,5,17]],"date-time":"2023-05-17T13:16:52Z","timestamp":1684329412000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-79263-5_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540792628","9783540792635"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-79263-5_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[]}}