A Comprehensive FPGA-Based Assessment on Fault-Resistant AES against Correlation Power Analysis Attack

A Comprehensive FPGA-Based Assessment on Fault-Resistant AES against Correlation Power Analysis Attack
复制标题

DOI:
10.1007/s10836-016-5598-9
复制
发表时间:
2016-10-01
影响因子:
0.9
通讯作者:
Yu, Qiaoyan
Yu, Qiaoyan
中科院分区:
工程技术4区
文献类型:
--
作者:
Dofe, Jaya;Pahlevanzadeh, Hoda;Yu, Qiaoyan

文献摘要

被引文献

相似文献

密码系统中使用的密钥可以通过诸如侧信道分析(SCA)和故障分析(FA)攻击等物理攻击来检索。传统上,针对不同物理攻击的对策是以不同的方式开发的。深入研究一种攻击的对策对其他攻击效率的影响,是为新兴的组合攻击的对策发展奠定坚实基础的必要条件。在这项工作中,我们使用基于fpga的平台来研究FA对抗是否以及如何影响相关功率分析(CPA)攻击的效率。与之前仅在S-Box上使用仿真的工作不同,我们的评估是基于整个AES的FPGA仿真。除了考虑不同的错误检测码外,我们还比较了CPA攻击在使用不同功率模型、故障检测冗余类型、故障保护模块以及实际FPGA综合优化等场景下的密钥检索速度。此外,我们还提出了一种集成动态掩蔽和错误偏转的新对策,以同时阻止CPA和FA攻击。实验结果表明,对于10万个电源走线,我们的方法成功地防止了密钥泄漏,而其他方法至少泄漏了5个AES子密钥字节。与此同时,我们的仿真也证实了该方法比其他方法将FA攻击的成功率降低了90%。
The secret key used in a cryptosystem can be retrieved by physical attacks such as side-channel analysis (SCA) and fault analysis (FA) attacks. Traditionally, countermeasures for different physical attacks are developed in a separate fashion. To lay a solid foundation for countermeasure development for the emerging combined attacks, it is imperative to thoroughly study how the countermeasure for one attack affects the efficiency of other attack. In this work, we use a FPGA-based platform to investigate whether and how the FA countermeasure can influence the efficiency of the correlation power analysis (CPA) attack. Unlike the previous work using simulations on the S-Box only, our assessments are based on the FPGA emulation of the entire AES. In addition to considering different error detection codes, we compare the key retrieval speed of the CPA attack in the scenarios of using different power models, redundancy types for fault detection, modules under fault protection, and practical FPGA synthesis optimization. Furthermore, we propose a new countermeasure that integrates dynamic masking and error deflection to simultaneously thwart CPA and FA attacks. Experimental results show that for 100,000 power traces, our method successfully prevents the key leakage while other methods leak at least five AES subkey bytes. Meanwhile, our simulation also confirms that the proposed method reduces the success rate of FA attacks by up to 90 % over the other methods.