A Silicon-Level Countermeasure Against Fault Sensitivity Analysis and Its Evaluation

A Silicon-Level Countermeasure Against Fault Sensitivity Analysis and Its Evaluation
复制标题

DOI:
10.1109/tvlsi.2014.2339892
复制
发表时间:
2015-08
影响因子:
2.8
通讯作者:
S. Endo;Yang Li;N. Homma;K. Sakiyama;K. Ohta;Daisuke Fujimoto;M. Nagata;T. Katashita;J. Danger;T. Aoki
S. Endo;Yang Li;N. Homma;K. Sakiyama;K. Ohta;Daisuke Fujimoto;M. Nagata;T. Katashita;J. Danger;T. Aoki
中科院分区:
工程技术2区
文献类型:
--
作者:
S. Endo;Yang Li;N. Homma;K. Sakiyama;K. Ohta;Daisuke Fujimoto;M. Nagata;T. Katashita;J. Danger;T. Aoki

文献摘要

被引文献

相似文献

本文提出了一种有效的基于可配置延迟块(cdb)的故障灵敏度分析(FSA)对策。FSA是一种新型的故障攻击,它利用了故障敏感性与秘密信息之间的关系。先前的研究报道,它可以破坏配备常规差分故障分析(DFA)对策的加密模块,如冗余计算、掩码与或和波动态差分逻辑。所提出的对策可以同时挫败基于设置时间违反错误的DFA和FSA攻击。提出的想法是使用CDB作为检测的时间基础,并将该技术与Li的对策概念相结合,该概念消除了fs和秘密数据之间的依赖关系。cdb的制造后配置允许最小化由制造变异性引起的工作频率开销。本文还介绍了该对策在专用集成电路中的实现,并描述了其配置方法。然后,我们研究了针对高级加密标准处理器所提出的对策的硬件开销,并通过实验证明了其有效性。
In this paper, we present an efficient countermeasure against fault sensitivity analysis (FSA) based on configurable delay blocks (CDBs). FSA is a new type of fault attack, which exploits the relationship between fault sensitivity (FS) and secret information. Previous studies reported that it could break cryptographic modules equipped with conventional countermeasures against differential fault analysis (DFA), such as redundancy calculation, masked and-or, and wave dynamic differential logic. The proposed countermeasure can thwart both DFA and FSA attacks based on setup time violation faults. The proposed ideas are to use a CDB as a time base for detection and to combine the technique with Li's countermeasure concept that removes the dependency between FSs and secret data. The postmanufacture configuration of the CDBs allows minimization of the overhead in operating frequency that comes from manufacture variability. In this paper, we also present an implementation of the proposed countermeasure in application-specified integrated circuit, and describe its configuration method. We then investigate the hardware overhead of the proposed countermeasure for an advanced encryption standard processor and demonstrate its validity through an experiment.