Improved Differential Fault Analysis on Authenticated Encryption of PAEQ-128

Improved Differential Fault Analysis on Authenticated Encryption of PAEQ-128
复制标题

PAEQ-128 认证加密的改进差分故障分析

DOI:
10.1007/978-3-030-14234-6_10
复制
发表时间:
2019
期刊:
Proc. International Conference on Information Security and Cryptology
影响因子:
--
通讯作者:
Wang Jian
Wang Jian
中科院分区:
--
文献类型:
--
作者:
Wang Ruyan;Meng Xiaohan;Li Yang;Wang Jian

文献摘要

相似文献

PAEQ是由Biryukov和Khovratovich在2014年提出的基于AES的认证加密,它将在CAESAR竞争中保持到第二轮。在CHES 2016中,Dhiman Saha和Dipanwita Roy Chowdhury首次讨论了PAEQ的差分故障分析。他们的工作表明,PAEQ中使用的随机数通常被认为是一种自然的DFA对策,可以通过仔细构造加密消息并注入两个错误来克服。本文提出了一种针对PAEQ-128的完全优化的DFA攻击方案。我们将信息论分析和AES的DFA技术应用于PAEQ-128上的DFA密钥恢复。因此,在不改变攻击假设的情况下,PAEQ-128的密钥恢复复杂度从到降低。成功的密钥恢复连同其计算复杂性已被验证与密钥恢复模拟。
PAEQ is an AES-based authenticated encryption proposed by Biryukov and Khovratovich in 2014, which stays in the CAESAR competition until the second round. In CHES 2016, Dhiman Saha and Dipanwita Roy Chowdhury first discussed the differential fault analysis to PAEQ. Their work shows that the nonce used in PAEQ that is usually considered as a natural DFA countermeasure can be overcome by carefully constructing the encryption message and injecting two faults. This work presents a fully optimized DFA attack on PAEQ-128 with regard to the key recovery process. We apply the information theoretical analysis and the DFA techniques for AES into the DFA key recovery on PAEQ-128. As a result, without changing the attack assumption, the key recovery complexity is reduced fromtofor PAEQ-128. The successful key recovery together with its computational complexity have been verified with the key recovery simulations.