On Side Channel Vulnerabilities of Bit Permutations in Cryptographic Algorithms

On Side Channel Vulnerabilities of Bit Permutations in Cryptographic Algorithms
复制标题

DOI:
10.1109/tifs.2019.2932230
复制
发表时间:
2020
影响因子:
6.8
通讯作者:
J. Breier;Dirmanto Jap;Xiaolu Hou;S. Bhasin
J. Breier;Dirmanto Jap;Xiaolu Hou;S. Bhasin
中科院分区:
计算机科学1区
文献类型:
--
作者:
J. Breier;Dirmanto Jap;Xiaolu Hou;S. Bhasin

文献摘要

被引文献

相似文献

轻量级块密码依赖于简单的操作来实现紧凑。由于其效率,比特置换已成为状态扩散的最佳选择。它可以通过简单的硬件布线或软件移位来实现。然而,效率和安全往往是相互对立的。在本文中,我们将展示如何位排列引入一个侧信道漏洞,可以利用它来提取密码的秘密密钥。这种脆弱性是特定的位排列,不会发生在其他国家明智的扩散替代品。我们提出了边信道辅助差分明文攻击(SCADPA),其目标是在位置换操作中的这个漏洞。SCADPA首先在8位微控制器上的PRESENT-80上进行了实验演示,最佳情况下的密钥恢复在17次重复中进行。此外,我们调整SCADPA的国家的最先进的位切片实施从CHES'17与实验评估的32位微控制器。然后将攻击扩展到最新的基于位置换的密码GIFT,允许在36次攻击中恢复全部密钥。还示出了在类似PRESENT的专有密码中秘密S盒的逆向工程的应用。
Lightweight block ciphers rely on simple operations to allow compact implementation. Thanks to its efficiency, bit permutation has emerged as an optimal choice for state-wise diffusion. It can be implemented by simple wiring in hardware or shifts in software. However, efficiency and security often go against each other. In this paper, we show how bit permutations introduce a side-channel vulnerability that can be exploited to extract the secret key from the cipher. Such vulnerabilities are specific to bit permutations and do not occur in other state-wise diffusion alternatives. We propose side-channel assisted differential-plaintext attack (SCADPA) which targets this vulnerability in the bit permutation operation. SCADPA is first experimentally demonstrated on PRESENT-80 on an 8-bit microcontroller, with the best case key recovery in 17 encryptions. In Addition, we adjust SCADPA to state-of-the-art bit sliced implementation from CHES’17 with experimental evaluation on a 32-bit microcontroller. The attack is then extended to latest bit-permutation-based cipher GIFT, allowing full key recovery in 36 encryptions. Application for reverse engineering of secret S-boxes in PRESENT-like proprietary ciphers is also shown.