{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T04:08:57Z","timestamp":1706760537928},"reference-count":41,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2017,6,13]],"date-time":"2017-06-13T00:00:00Z","timestamp":1497312000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2017,11]]},"DOI":"10.1007\/s13389-017-0167-4","type":"journal-article","created":{"date-parts":[[2017,6,13]],"date-time":"2017-06-13T15:30:01Z","timestamp":1497367801000},"page":"321-330","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Using modular extension to provably protect Edwards curves against fault attacks"],"prefix":"10.1007","volume":"7","author":[{"given":"Margaux","family":"Dugardin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sylvain","family":"Guilley","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Moreau","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zakaria","family":"Najm","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pablo","family":"Rauzy","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,6,13]]},"reference":[{"key":"167_CR1","first-page":"260","volume-title":"CHES, Volume 2523 of Lecture Notes in Computer Science","author":"C Aum\u00fcller","year":"2002","unstructured":"Aum\u00fcller, C., Bier, P., Fischer, W., Hofreiter, P., Seifert, J.-P.: Fault attacks on RSA with CRT: concrete results and practical countermeasures. In: Kaliski Jr., B.S., Ko\u00e7, \u00c7.K., Paar, C. (eds.) CHES, Volume 2523 of Lecture Notes in Computer Science, pp. 260\u2013275. Springer, Berlin (2002)"},{"key":"167_CR2","first-page":"225","volume-title":"Information Security Practice and Experience, Volume 4464 of Lecture Notes in Computer Science","author":"Y-J Baek","year":"2007","unstructured":"Baek, Y.-J., Vasyltsov, I.: How to prevent DPA and fault attack in a unified way for ECC scalar multiplication-ring extension method. In: Dawson, E., Wong, D.S. (eds.) Information Security Practice and Experience, Volume 4464 of Lecture Notes in Computer Science, pp. 225\u2013237. Springer, Berlin (2007)"},{"key":"167_CR3","doi-asserted-by":"crossref","unstructured":"Barthe, G., Dupressoir, F., Fouque, P., Gr\u00e9goire, B., Zapalowicz, J.: Synthesis of fault attacks on cryptographic implementations. In: Ahn, G., Yung, M., Li, N. (eds) Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, Scottsdale, AZ, USA, November 3\u20137, 2014, pp. 1016\u20131027. ACM (2014)","DOI":"10.1145\/2660267.2660304"},{"key":"167_CR4","doi-asserted-by":"crossref","unstructured":"Battistello, A.: Constructive Side-Channel Analysis and Secure Design: 5th International Workshop, COSADE 2014, Paris, France, April 13\u201315, 2014. Revised selected papers, chapter common points on elliptic curves: the achilles\u2019 heel of fault attack countermeasures, pp.69\u201381. Springer International Publishing, Cham (2014)","DOI":"10.1007\/978-3-319-10175-0_6"},{"key":"167_CR5","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Birkner, P., Joye, M., Lange, T., Peters, C.: Twisted edwards curves. In: Vaudenay, S. (ed), Progress in Cryptology - AFRICACRYPT 2008, First International Conference on Cryptology in Africa, Casablanca, Morocco, June 11\u201314, 2008. Proceedings, Volume 5023 of Lecture Notes in Computer Science, pp. 389\u2013405. Springer(2008)","DOI":"10.1007\/978-3-540-68164-9_26"},{"issue":"2","key":"167_CR6","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1007\/s13389-012-0027-1","volume":"2","author":"DJ Bernstein","year":"2012","unstructured":"Bernstein, D.J., Duif, N., Lange, T., Schwabe, P., Yang, B.: High-speed high-security signatures. J. Cryptogr. Eng. 2(2), 77\u201389 (2012)","journal-title":"J. Cryptogr. Eng."},{"key":"167_CR7","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Lange, T.: Faster addition and doubling on elliptic curves. In: Kurosawa, K. (ed) Advances in Cryptology -ASIACRYPT2007, 13th International Conference on the Theory and Application of Cryptology and Information Security, Kuching, Malaysia, December 2\u20136, 2007. Proceedings, Volume 4833 of Lecture Notes in Computer Science, pp. 29\u201350. Springer (2007)","DOI":"10.1007\/978-3-540-76900-2_3"},{"key":"167_CR8","unstructured":"Bernstein, D.J., Lange, T.: Explicit-Formulas Database, March (2015) http:\/\/hyperelliptic.org\/EFD\/"},{"key":"167_CR9","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Lange, T., Schwabe, P.: The security impact of a new cryptographic library. In: Hevia, A., Neven, G. (eds) Progress in Cryptology-LATINCRYPT 2012-2nd International Conference on Cryptology and Information Security in Latin America, Santiago, Chile, October 7\u201310, 2012. Proceedings, Volume 7533 of Lecture Notes in Computer Science, pp. 159\u2013176. Springer (2012)","DOI":"10.1007\/978-3-642-33481-8_9"},{"key":"167_CR10","doi-asserted-by":"crossref","unstructured":"Biehl, I., Meyer, B., M\u00fcller, V.: Differential fault attacks on elliptic curve cryptosystems. In: CRYPTO \u201900: Proceedings of the 20th Annual International Cryptology Conference on Advances in Cryptology, pp. 131\u2013146. Springer-Verlag, London, UK (2000)","DOI":"10.1007\/3-540-44598-6_8"},{"key":"167_CR11","doi-asserted-by":"crossref","unstructured":"Bl\u00f6mer, J., Gomes Da Silva, R., Gunther, P., Kr\u00e4mer, J., Seifert, J.-P.: A practical second-order fault attack against a real-world pairing implementation. In: Fault Diagnosis and Tolerance in Cryptography (FDTC), 2014 Workshop on, pp. 123\u2013136. Busan, Korea Sept (2014)","DOI":"10.1109\/FDTC.2014.22"},{"key":"167_CR12","doi-asserted-by":"crossref","unstructured":"Bl\u00f6mer, J., G\u00fcnther, P., Liske, G.: Tampering attacks in pairing-based cryptography. In: Fault Diagnosis and Tolerance in Cryptography (FDTC), 2014 Workshop on, pp. 1\u20137. Busan, Korea Sept (2014)","DOI":"10.1109\/FDTC.2014.10"},{"key":"167_CR13","doi-asserted-by":"crossref","unstructured":"Bl\u00f6mer, J., Otto, M., Seifert, J.-P. : A new CRT-RSA algorithm secure against bellcore attacks. In: Jajodia, S., Atluri, V., Jaeger, T. (eds) ACM Conference on Computer and Communications Security, pp. 311\u2013320. ACM (2003)","DOI":"10.1145\/948109.948151"},{"key":"167_CR14","first-page":"36","volume-title":"Fault Diagnosis and Tolerance in Cryptography, Volume 4236 of Lecture Notes in Computer Science","author":"J Bl\u00f6mer","year":"2006","unstructured":"Bl\u00f6mer, J., Otto, M., Seifert, J.-P.: Sign change fault attacks on elliptic curve cryptosystems. In: Breveglieri, L., Koren, I., Naccache, D., Seifert, J.-P. (eds.) Fault Diagnosis and Tolerance in Cryptography, Volume 4236 of Lecture Notes in Computer Science, vol. 4236, pp. 36\u201352. Springer, Berlin (2006)"},{"key":"167_CR15","doi-asserted-by":"crossref","unstructured":"Boneh, D., DeMillo, R.A., Lipton, R.J.: On the importance of checking cryptographic protocols for faults (extended abstract). In: Fumy, W. (ed) EUROCRYPT, Volume 1233 of Lecture Notes in Computer Science, pp. 37\u201351. Springer (1997)","DOI":"10.1007\/3-540-69053-0_4"},{"key":"167_CR16","first-page":"229","volume-title":"WISTP, Volume 4462 of Lecture Notes in Computer Science","author":"A Boscher","year":"2007","unstructured":"Boscher, A., Naciri, R., Prouff, E.: CRT RSA algorithm protected against fault attacks. In: Sauveron, D., Markantonakis, C., Bilas, A., Quisquater, J.-J. (eds.) WISTP, Volume 4462 of Lecture Notes in Computer Science, vol. 4462, pp. 229\u2013243. Springer, Berlin (2007)"},{"key":"167_CR17","unstructured":"Ciet, M., Joye, M.: Practical fault countermeasures for chinese remaindering based RSA. In: Fault Diagnosis and Tolerance in Cryptography, pp. 124\u2013131, Friday September 2nd. Edinburgh, Scotland (2005)"},{"key":"167_CR18","doi-asserted-by":"crossref","unstructured":"Clavier, C.: Secret external encodings do not prevent transient fault analysis. In: CHES, Volume 4727 of Lecture Notes in Computer Science, pp.181\u2013194. Springer, Vienna (2007)","DOI":"10.1007\/978-3-540-74735-2_13"},{"key":"167_CR19","first-page":"68","volume-title":"WISTP, Volume 5746 of Lecture Notes in Computer Science","author":"E Dottax","year":"2009","unstructured":"Dottax, E., Girau, C., Rivain, M., Sierra, Y.: On second-order fault analysis resistance for CRT-RSA implementations. In: Markowitch, O., Bilas, A., Hoepman, J.-H., Mitchell, C.J., Quisquater, J.-J. (eds.) WISTP, Volume 5746 of Lecture Notes in Computer Science, pp. 68\u201383. Springer, Berlin (2009)"},{"key":"167_CR20","unstructured":"Dugardin, M., Guilley, S., Moreau, M., Najm, Z., Rauzy, P.: Using modular extension to provably protect Edwards curves against fault attacks. Cryptology ePrint Archive, Report 2015\/882. http:\/\/eprint.iacr.org\/2015\/882 (2015)"},{"key":"167_CR21","doi-asserted-by":"crossref","first-page":"393","DOI":"10.1090\/S0273-0979-07-01153-6","volume":"44","author":"HM Edwards","year":"2007","unstructured":"Edwards, H.M.: A normal form for elliptic curves. Bull. Am. Math. Soc. 44, 393\u2013422 (2007)","journal-title":"Bull. Am. Math. Soc."},{"key":"167_CR22","first-page":"1","volume":"7","author":"N Mrabet El","year":"2014","unstructured":"El Mrabet, N., Fournier, J.J., Goubin, L., Lashermes, R.: A survey of fault attacks in pairing based cryptography. Cryptogr. Commun. 7, 1\u201321 (2014)","journal-title":"Cryptogr. Commun."},{"issue":"9","key":"167_CR23","doi-asserted-by":"crossref","first-page":"1116","DOI":"10.1109\/TC.2006.135","volume":"55","author":"C Giraud","year":"2006","unstructured":"Giraud, C.: An RSA implementation resistant to fault attacks and to simple power analysis. IEEE Trans. Comput. 55(9), 1116\u20131120 (2006)","journal-title":"IEEE Trans. Comput."},{"key":"167_CR24","first-page":"234","volume-title":"Pairing-Based Cryptography\u2014Pairing 2012, Volume 7708 of Lecture Notes in Computer Science","author":"A Guillevic","year":"2013","unstructured":"Guillevic, A., Vergnaud, D.: Genus 2 hyperelliptic curve families with explicit jacobian order evaluation and pairing-friendly constructions. In: Abdalla, M., Lange, T. (eds.) Pairing-Based Cryptography\u2014Pairing 2012, Volume 7708 of Lecture Notes in Computer Science, pp. 234\u2013253. Springer, Berlin (2013)"},{"issue":"1","key":"167_CR25","doi-asserted-by":"crossref","first-page":"36","DOI":"10.1007\/s102070100002","volume":"1","author":"D Johnson","year":"2001","unstructured":"Johnson, D., Menezes, A., Vanstone, S.: The elliptic curve digital signature algorithm (ECDSA). Int. J. Inf. Secur. 1(1), 36\u201363 (2001)","journal-title":"Int. J. Inf. Secur."},{"key":"167_CR26","unstructured":"Joye, M.: Fault-Resistant Calculations on Elliptic Curves, September 15. EP Patent App. EP20,100,155,001; http:\/\/www.google.com\/patents\/EP2228716A1?cl=en (2010)"},{"key":"167_CR27","unstructured":"Joye, M., Paillier, P., Yen, S.-M.: Secure evaluation of modular functions. In: Hwang, R., Wu, C. (eds) International Workshop on Cryptology and Network Security, pp. 227\u2013229, September 26\u201328 . http:\/\/joye.site88.net\/papers\/JPY01dfa.pdf , Taipei, Taiwan(2001)"},{"key":"167_CR28","doi-asserted-by":"publisher","unstructured":"Joye, M., Tunstall, M. (eds.): Fault Analysis in Cryptography. Springer Information Security and Cryptography. ISBN 978-3-642-29655-0. doi: 10.1007\/978-3-642-29656-7 (2012)","DOI":"10.1007\/978-3-642-29656-7"},{"key":"167_CR29","doi-asserted-by":"crossref","unstructured":"Karaklajic, D., Fan, J., Schmidt, J., Verbauwhede, I.: Low-cost fault detection method for ECC using Montgomery powering ladder. In: Design, Automation and Test in Europe, DATE 2011, Grenoble, France, March 14\u201318, 2011, pp. 1016\u20131021. IEEE (2011)","DOI":"10.1109\/DATE.2011.5763165"},{"key":"167_CR30","doi-asserted-by":"crossref","first-page":"1660","DOI":"10.1016\/j.jss.2011.04.026","volume":"84","author":"S-K Kim","year":"2011","unstructured":"Kim, S.-K., Kim, T.H., Han, D.-G., Hong, S.: An efficient CRT-RSA algorithm secure against power and fault attacks. J. Syst. Softw. 84, 1660\u20131669 (2011)","journal-title":"J. Syst. Softw."},{"key":"167_CR31","first-page":"388","volume-title":"CRYPTO, Volume 1666 of Lecture Notes in Computer Science","author":"PC Kocher","year":"1999","unstructured":"Kocher, P.C., Jaffe, J., Jun, B.: Differential power analysis. In: Wiener, M.J. (ed.) CRYPTO, Volume 1666 of Lecture Notes in Computer Science, pp. 388\u2013397. Springer, Berlin (1999)"},{"key":"167_CR32","doi-asserted-by":"crossref","unstructured":"Lashermes, R., Paindavoine, M., El Mrabet, N., Fournier, J.J., Goubin, L.: Practical validation of several fault attacks against the Miller algorithm. In: Fault Diagnosis and Tolerance in Cryptography (FDTC), 2014 Workshop on, pp. 115\u2013122, Sept. Busan, Korea (2014)","DOI":"10.1109\/FDTC.2014.21"},{"key":"167_CR33","first-page":"152","volume-title":"CT-RSA, Volume 8366 of Lecture Notes in Computer Science","author":"D-P Le","year":"2014","unstructured":"Le, D.-P., Rivain, M., Tan, C.H.: On double exponentiation for securing RSA against fault analysis. In: Benaloh, J. (ed.) CT-RSA, Volume 8366 of Lecture Notes in Computer Science, pp. 152\u2013168. Springer, Berlin (2014)"},{"issue":"1\u20132","key":"167_CR34","doi-asserted-by":"crossref","first-page":"300","DOI":"10.1007\/s11006-006-0139-y","volume":"80","author":"V Leont\u2019ev","year":"2006","unstructured":"Leont\u2019ev, V.: Roots of random polynomials over a finite field. Math. Notes 80(1\u20132), 300\u2013304 (2006)","journal-title":"Math. Notes"},{"key":"167_CR35","unstructured":"Moody, D., Shumow, D.: Isogenies on Edwards and Huff curves. In: Computer Security Division. National Institute of Standards and Technology (NIST) (2011)"},{"issue":"3","key":"167_CR36","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1007\/s13389-014-0077-7","volume":"4","author":"N Moro","year":"2014","unstructured":"Moro, N., Heydemann, K., Encrenaz, E., Robisson, B.: Formal verification of a software countermeasure against instruction skip attacks. J. Cryptogr. Eng. 4(3), 145\u2013156 (2014)","journal-title":"J. Cryptogr. Eng."},{"key":"167_CR37","doi-asserted-by":"crossref","unstructured":"Naehrig, M., Niederhagen, R., Schwabe, P.: New software speed records for cryptographic pairings. In: Abdalla, M., Barreto, P.S. (eds) Progress in Cryptology\u2014LATINCRYPT 2010, Volume 6212 of Lecture Notes in Computer Science, pp. 109\u2013123. Springer, Berlin, updated version: http:\/\/cryptojedi.org\/papers\/#dclxvi (2010)","DOI":"10.1007\/978-3-642-14712-8_7"},{"key":"167_CR38","unstructured":"Shamir, A.: Method and apparatus for protecting public key schemes from timing and fault attacks, November 1999. US Patent Number 5,991,415; also presented at the rump session of EUROCRYPT \u201997 (May 11\u201315, Konstanz, Germany) (1997)"},{"key":"167_CR39","unstructured":"University of Sydney. Magma computational algebra system. http:\/\/magma.maths.usyd.edu.au\/magma\/ . Accessed 22 Aug 2014"},{"key":"167_CR40","first-page":"130","volume-title":"CHES, Volume 5154 of Lecture Notes in Computer Science","author":"D Vigilant","year":"2008","unstructured":"Vigilant, D.: RSA with CRT: a new cost-effective solution to Thwart fault attacks. In: Oswald, E., Rohatgi, P. (eds.) CHES, Volume 5154 of Lecture Notes in Computer Science, pp. 130\u2013145. Springer, Berlin (2008)"},{"key":"167_CR41","doi-asserted-by":"crossref","unstructured":"Wagner, D.: Cryptanalysis of a provably secure CRT-RSA algorithm. In: Atluri, V., Pfitzmann, B., McDaniel, P.D. (eds) ACM Conference on Computer and Communications Security, pp. 92\u201397. ACM (2004)","DOI":"10.1145\/1030083.1030097"}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s13389-017-0167-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-017-0167-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-017-0167-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,26]],"date-time":"2019-09-26T01:00:55Z","timestamp":1569459655000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s13389-017-0167-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,6,13]]},"references-count":41,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2017,11]]}},"alternative-id":["167"],"URL":"https:\/\/doi.org\/10.1007\/s13389-017-0167-4","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"value":"2190-8508","type":"print"},{"value":"2190-8516","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,6,13]]}}}