[Cryptech Tech] CHES 2014 so far

Joachim Strömbergson joachim at secworks.se
Wed Sep 24 07:01:56 UTC 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Aloha!

Aloha!

Short status from CHES.

* Yesterday there was a really good tutorial by Viktor Fischer about
random number generators. Among the interesting things was the need to
test entropy sources (esp FPGA internal ones such as our ROSC based one)
with really good power supplies (or a battery). He and his team have
seen entropy sources that seem to work on dev boards with cheap, noisy
power supplies that fail in target systems.

Also he talked alot about on-line testing, test systems, the need for
doing models etc.

Finally he presented his PLL based entropy source that can be proven to
work. We might want to look into that later on.


* We have had talks with DJB, Lange etc. Looks promising. Now I know who
to nag about Curve25519 implementations.

* Some really interesting presentations at the conference. There are som
seriously scare side-channel attacks presented here. On the other side,
the stealthy dopant method of attacking chips during manufacturing turns
out to be visible. One just have to polish off the metal layers and use
an electron microscope to see the difference in colors.


* The Cryptech TRNG is progressing. Not done yet, but jetlag has left me
with
some extra hours so...


Randy can probably chime in on status.

- -- 
Med vänlig hälsning, Yours

Joachim Strömbergson - Alltid i harmonisk svängning.
========================================================================
 Joachim Strömbergson          Secworks AB          joachim at secworks.se
========================================================================
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.22 (Darwin)
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBCAAGBQJUImxkAAoJEF3cfFQkIuyNrP0P+wWN0DHnFbl2fcWaIT+PghlX
zGFNrsOHlHaQyqVRLOrXRYSGljDe5S4Ml+4SBD9qGBOgfGCzvHyi7/nrfHVHdmlR
0lRDRAxqSPDdyO5kf1aL2p9oT9nBeNv+RoK5w7NSzGPQeFBZQCG+nxBXaIxNVN27
kwrIwcX8OPkkDj16HTOsvoaWwCNQaEunXBuISCkeQ92eyVoNq0zvAwPb6etWiw+G
OKE11kCXmP4NU6JYagqCyRxAG963zchSrSn8Uwm4R6mUAb2JeN7a45nnHtIhoZ7Y
nTeteFvd5EcPCHxV/CjAuphNML+hXxnP573qhIzO727knhIa8aRBvC6qHgPcPmAc
Hvu3dE3O/TZ9HcVGQREbis6g4tvU65iLafSG7rBdM8paUvuryXUd4Z6ufeMGvEIf
7f9m695KMV3r+Qi9z52u/1wf+2Xuxzy94JBhfXtvpxiymlrfxEAoY62fP1h89K6C
7yKZXUnVm1XjC758M78RA816Bv9tTcc0WWaij5u4hZGCOHE60zCQwlXKHC3OjVhZ
IsXROTo/+Lwjfr7RrLYb8PxRL871io+sLIkagsA09m9jKByH/9QYpP5Zd862WFw5
P6dJlvRc6a21Hrn5c8YG0WDD54x2t3szhRpTmWRyWEiuOHAHo0VGFqHuZqPeP4Zx
ftt7BcQTjSIDSzJjTRuG
=bkUj
-----END PGP SIGNATURE-----


More information about the Tech mailing list