{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,6]],"date-time":"2026-02-06T00:20:02Z","timestamp":1770337202213,"version":"3.49.0"},"publisher-location":"Berlin, Heidelberg","reference-count":27,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642320088","type":"print"},{"value":"9783642320095","type":"electronic"}],"license":[{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-32009-5_36","type":"book-chapter","created":{"date-parts":[[2012,8,6]],"date-time":"2012-08-06T06:40:28Z","timestamp":1344235228000},"page":"608-625","source":"Crossref","is-referenced-by-count":41,"title":["Efficient Padding Oracle Attacks on Cryptographic Hardware"],"prefix":"10.1007","author":[{"given":"Romain","family":"Bardou","sequence":"first","affiliation":[]},{"given":"Riccardo","family":"Focardi","sequence":"additional","affiliation":[]},{"given":"Yusuke","family":"Kawamoto","sequence":"additional","affiliation":[]},{"given":"Lorenzo","family":"Simionato","sequence":"additional","affiliation":[]},{"given":"Graham","family":"Steel","sequence":"additional","affiliation":[]},{"given":"Joe-Kai","family":"Tsay","sequence":"additional","affiliation":[]}],"member":"297","reference":[{"key":"36_CR1","doi-asserted-by":"crossref","unstructured":"Bardou, R., Focardi, R., Kawamoto, Y., Simionato, L., Steel, G., Joe-Kai-Tsay: The million message attack in 15 000 messages, or efficient padding oracle attacks on cryptographic hardware. Cryptology ePrint Archive (to appear, 2012), \n                  http:\/\/eprint.iacr.org\/","DOI":"10.1007\/978-3-642-32009-5_36"},{"key":"36_CR2","unstructured":"Black, J., Urtubia, H.: Side-channel attacks on symmetric encryption schemes: The case for authenticated encryption. In: Boneh, D. (ed.) USENIX Security Symposium, pp. 327\u2013338. USENIX (2002)"},{"key":"36_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/BFb0055716","volume-title":"Advances in Cryptology - CRYPTO \u201998","author":"D Bleichenbacher","year":"1998","unstructured":"Bleichenbacher, D.: Chosen Ciphertext Attacks against Protocols Based on the RSA Encryption Standard PKCS #1. In: Krawczyk, H. (ed.) CRYPTO 1998. LNCS, vol. 1462, pp. 1\u201312. Springer, Heidelberg (1998)"},{"key":"36_CR4","unstructured":"Bond, M., French, G.: Hidden semantics: why? how? and what to do? Presentation at Fourth Analysis of Security APIs Workshop, ASA-4 (July 2010)"},{"key":"36_CR5","doi-asserted-by":"crossref","unstructured":"Bortolozzo, M., Centenaro, M., Focardi, R., Steel, G.: Attacking and fixing PKCS#11 security tokens. In: Proceedings of the 17th ACM Conference on Computer and Communications Security (CCS 2010), Chicago, Illinois, USA. ACM Press (October 2010)","DOI":"10.1145\/1866307.1866337"},{"key":"36_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"411","DOI":"10.1007\/978-3-540-45238-6_32","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2003","author":"J Clulow","year":"2003","unstructured":"Clulow, J.: On the Security of PKCS #11. In: Walter, C.D., Ko\u00e7, \u00c7.K., Paar, C. (eds.) CHES 2003. LNCS, vol. 2779, pp. 411\u2013425. Springer, Heidelberg (2003)"},{"key":"36_CR7","doi-asserted-by":"crossref","unstructured":"Degabriele, J.P., Paterson, K.G.: On the (in)security of ipsec in mac-then-encrypt configurations. In: Al-Shaer, E., Keromytis, A.D., Shmatikov, V. (eds.) ACM Conference on Computer and Communications Security, pp. 493\u2013504. ACM (2010)","DOI":"10.1145\/1866307.1866363"},{"key":"36_CR8","doi-asserted-by":"crossref","unstructured":"Delaune, S., Kremer, S., Steel, G.: Formal analysis of PKCS#11. In: Proceedings of the 21st IEEE Computer Security Foundations Symposium (CSF 2008), Pittsburgh, PA, USA, pp. 331\u2013344. IEEE Computer Society Press (June 2008)","DOI":"10.1109\/CSF.2008.16"},{"key":"36_CR9","doi-asserted-by":"crossref","unstructured":"Dworkin, M.: Recommendation for block cipher modes of operation: Modes and techniques. NIST Special Publication 800-38A (December 2001)","DOI":"10.6028\/NIST.SP.800-38a"},{"key":"36_CR10","unstructured":"Estonian Certification Center. The estonian ID card and digital signature concept, principles and solutions (March 2003), \n                  http:\/\/www.id.ee\/public\/The_Estonian_ID_Card_and_Digital_Signature_Concept.pdf"},{"key":"36_CR11","unstructured":"Estonian Informatics Center. Estonian ID-software, \n                  https:\/\/installer.id.ee\/?lang=eng"},{"key":"36_CR12","doi-asserted-by":"crossref","unstructured":"Housley, R.: Cryptographic Message Syntax (CMS). RFC 5652 (Standard) (September 2009)","DOI":"10.17487\/rfc5652"},{"key":"36_CR13","unstructured":"ID S\u00fcsteemide AS. EstEID specification v2.01, \n                  http:\/\/www.id.ee\/public\/EstEID_Spetsifikatsioon_v2.01.pdf"},{"key":"36_CR14","doi-asserted-by":"crossref","unstructured":"Jager, T., Somorovsky, J.: How to break XML encryption. In: Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS), pp. 413\u2013422 (2011)","DOI":"10.1145\/2046707.2046756"},{"key":"36_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"230","DOI":"10.1007\/3-540-44647-8_14","volume-title":"Advances in Cryptology - CRYPTO 2001","author":"J Manger","year":"2001","unstructured":"Manger, J.: A Chosen Ciphertext Attack on RSA Optimal Asymmetric Encryption Padding (OAEP) as Standardized in PKCS #1 v2.0. In: Kilian, J. (ed.) CRYPTO 2001. LNCS, vol. 2139, pp. 230\u2013238. Springer, Heidelberg (2001)"},{"key":"36_CR16","unstructured":"Martens, T.: eID interoperability for PEGS, national profile estonia, European Commission\u2019s IDABC programme (November 2007), \n                  http:\/\/ec.europa.eu\/idabc\/en\/document\/6485\/5938"},{"key":"36_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"244","DOI":"10.1007\/11556992_18","volume-title":"Information Security","author":"CJ Mitchell","year":"2005","unstructured":"Mitchell, C.J.: Error Oracle Attacks on CBC Mode: Is There a Future for CBC Mode Encryption? In: Zhou, J., L\u00f3pez, J., Deng, R.H., Bao, F. (eds.) ISC 2005. LNCS, vol. 3650, pp. 244\u2013258. Springer, Heidelberg (2005)"},{"key":"36_CR18","unstructured":"National Institute of Standards and Technology. NIST special publication 800-57, recommendation for key management (March 2007), \n                  http:\/\/csrc.nist.gov\/publications\/PubsSPs.html"},{"key":"36_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"340","DOI":"10.1007\/978-3-540-85855-3_23","volume-title":"Security and Cryptography for Networks","author":"KG Paterson","year":"2008","unstructured":"Paterson, K.G., Watson, G.J.: Immunising CBC Mode Against Padding Oracle Attacks: A Formal Security Treatment. In: Ostrovsky, R., De Prisco, R., Visconti, I. (eds.) SCN 2008. LNCS, vol. 5229, pp. 340\u2013357. Springer, Heidelberg (2008)"},{"key":"36_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"305","DOI":"10.1007\/978-3-540-24660-2_24","volume-title":"Topics in Cryptology \u2013 CT-RSA 2004","author":"KG Paterson","year":"2004","unstructured":"Paterson, K.G., Yau, A.: Padding Oracle Attacks on the ISO CBC Mode Encryption Standard. In: Okamoto, T. (ed.) CT-RSA 2004. LNCS, vol. 2964, pp. 305\u2013323. Springer, Heidelberg (2004)"},{"key":"36_CR21","unstructured":"Minutes from the April, 2003 PKCS workshop (2003), \n                  ftp:\/\/ftp.rsa.com\/pub\/pkcs\/03workshop\/minutes.txt"},{"key":"36_CR22","unstructured":"Rizzo, J., Duong, T.: Practical padding oracle attacks. In: Proceedings of the 4th USENIX Conference on Offensive Technologies, WOOT 2010, pp. 1\u20138. USENIX Association, Berkeley (2010)"},{"key":"36_CR23","unstructured":"Rogaway, P.: Evaluation of some blockcipher modes of operation (February 2011), \n                  http:\/\/www.cs.ucdavis.edu\/~rogaway\n                  \n                ; Evaluation carried out for the Cryptography Research and Evaluation Committees (CRYPTREC) for the Government of Japan"},{"key":"36_CR24","unstructured":"RSA Security Inc.,  v2.1. PKCS #1: RSA Cryptography Standard (June 2002)"},{"key":"36_CR25","unstructured":"RSA Security Inc., v2.20. PKCS #11: Cryptographic Token Interface Standard (June 2004)"},{"key":"36_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"426","DOI":"10.1007\/978-3-540-45238-6_33","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2003","author":"V Kl\u00edma","year":"2003","unstructured":"Kl\u00edma, V., Pokorn\u00fd, O., Rosa, T.: Attacking RSA-Based Sessions in SSL\/TLS. In: Walter, C.D., Ko\u00e7, \u00c7.K., Paar, C. (eds.) CHES 2003. LNCS, vol. 2779, pp. 426\u2013440. Springer, Heidelberg (2003)"},{"key":"36_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"534","DOI":"10.1007\/3-540-46035-7_35","volume-title":"Advances in Cryptology - EUROCRYPT 2002","author":"S Vaudenay","year":"2002","unstructured":"Vaudenay, S.: Security Flaws Induced by CBC Padding - Applications to SSL, IPSEC, WTLS... In: Knudsen, L.R. (ed.) EUROCRYPT 2002. LNCS, vol. 2332, pp. 534\u2013545. Springer, Heidelberg (2002)"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2012"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-32009-5_36","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,6]],"date-time":"2019-05-06T22:56:17Z","timestamp":1557183377000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-32009-5_36"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642320088","9783642320095"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-32009-5_36","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012]]}}}