{"id":2303,"date":"2022-03-07T09:10:49","date_gmt":"2022-03-07T16:10:49","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/?p=2303"},"modified":"2022-03-07T09:13:50","modified_gmt":"2022-03-07T16:13:50","slug":"side-channel-attacks-could-prove-disastrous-for-some-corporations","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/07\/side-channel-attacks-could-prove-disastrous-for-some-corporations\/","title":{"rendered":"Side Channel Attacks could prove disastrous for some corporations."},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">What is homomorphic encryption?<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/download.jpg\" alt=\"\" class=\"wp-image-2373 lazyload\" width=\"764\" height=\"429\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 764px; --smush-placeholder-aspect-ratio: 764\/429;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Encryption is useful for communication when 3rd parties are present. A key pair(or sometimes one key) is used to encrypt and decrypt messages\/information so that these malicious 3rd parties cannot read the information, or get any hints about what the information can contain. We still see developments in this field, from both attackers and defenders.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Homomorphic encryption is one type of encryption, it is not too common these days though. It allows for users to perform operations on the encrypted data without decrypting it. That is, after the information is encrypted into ciphertext, operations can be done on this ciphertext before decrypting it back into information. This limits the number of possible algorithms which is probably why it is not common; few effective methods exist. It does have useful applications though just because you do not need the key to decrypt the message if you want to change it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What&#8217;s the problem?<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1000\" height=\"600\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Homomorphic-encryption-1.png\" alt=\"\" class=\"wp-image-2372 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Homomorphic-encryption-1.png 1000w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Homomorphic-encryption-1-300x180.png 300w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Homomorphic-encryption-1-768x461.png 768w\" data-sizes=\"(max-width: 1000px) 100vw, 1000px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1000px; --smush-placeholder-aspect-ratio: 1000\/600;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Researchers from North Carolina State University and Dokuz Eylul University have found a way to gather information while it is being encrypted. They called it a first side channel attack. Essentially, they look at power consumption by the computers encrypting the data to gather clues about the data. They were able to fine tune their analysis until they were able to directly read all the encrypted data.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"556\" height=\"307\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/112620-2.png\" alt=\"\" class=\"wp-image-2371 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/112620-2.png 556w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/112620-2-300x166.png 300w\" data-sizes=\"(max-width: 556px) 100vw, 556px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 556px; --smush-placeholder-aspect-ratio: 556\/307;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This is quite clever, because they are not directly looking at the encrypted data. With infinite possible keys that could encrypt a specific message into a specific ciphertext, it is quite difficult to get any information about the encrypted message by observing the ciphertext. However, looking at the power consumption of the encrypting device does tell you how many steps the algorithm takes, and diving deeper tells you when the algorithm takes the most steps. Since homomorphic encryption is limited in terms of possible algorithms, it is more vulnerable when any information about the algorithms are leaked. This type of attack could certainly help against other encryption methods too; it reveals some information and that\u2019s all an attacker needs. As an attacker, you could combine a first side channel attack with another strategy, and the two combined might give enough info. Attackers can and will try anything.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who is at risk?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The big companies are at risk here, because homomorphic encryption is most common when large databases are involved. This makes sense because it is not efficient to decrypt a large amount of information just to tweak it, homomorphic encryption is much faster. These companies will have to change something about their encryption practices, because they are huge targets with lots of cash on hand.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">References<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2022\/03\/researchers-demonstrate-new-side.html\">https:\/\/thehackernews.com\/2022\/03\/researchers-demonstrate-new-side.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is homomorphic encryption? Encryption is useful for communication when 3rd parties are present. A key pair(or sometimes one key) is used to encrypt and decrypt messages\/information so that these malicious 3rd parties cannot read the information, or get any hints about what the information can contain. We still see developments in this field, from &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/07\/side-channel-attacks-could-prove-disastrous-for-some-corporations\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Side Channel Attacks could prove disastrous for some corporations.&#8221;<\/span><\/a><\/p>\n","protected":false},"author":283,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-2303","post","type-post","status-publish","format-standard","hentry","category-cpsc-329-602-w22","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Victor Han","author_link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/author\/victor-han\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/users\/283"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/comments?post=2303"}],"version-history":[{"count":3,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2303\/revisions"}],"predecessor-version":[{"id":2375,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2303\/revisions\/2375"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/media?parent=2303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/categories?post=2303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/tags?post=2303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}