Fault Based Cryptanalysis of the Advanced Encryption Standard (AES)

Fault Based Cryptanalysis of the Advanced Encryption Standard (AES)
复制标题

DOI:
10.1007/978-3-540-45126-6_12
复制
发表时间:
2003-01
期刊:
--
影响因子:
--
通讯作者:
Johannes Blömer;Jean-Pierre Seifert
Johannes Blömer;Jean-Pierre Seifert
中科院分区:
其他
文献类型:
--
作者:
Johannes Blömer;Jean-Pierre Seifert

文献摘要

被引文献

相似文献

本文描述了几种针对高级加密标准(AES)的错误攻击。首先,使用最近公开提出的Skorobogatov,安德森和Quisquater,Samyde [SA,QS]的光/涡流故障感应攻击,我们提出了一个实现独立的故障攻击AES。这种攻击能够通过生成128个错误密码文本来确定密封防篡改加密器的完整128位密钥。其次,我们提出了几个实现依赖于AES的故障攻击。这些攻击依赖于这样的观察:由于AES的已知时序分析漏洞(如Koeune和Quisquater [KQ]所指出的),AES的任何实现都必须确保所谓的AES的xtime操作的数据独立时序行为。我们提出了对AES的故障攻击的基础上,各种时间分析的抗实现的xtime-operation。我们在这个方向上最强的攻击使用了一个非常自由的故障模型,只需要256个故障排除来确定一个128位的密钥。
In this paper we describe several fault attacks on the Advanced Encryption Standard (AES). First, using optical/eddy current fault induction attacks as recently publicly presented by Skorobogatov, Anderson and Quisquater, Samyde [SA, QS], we present an implementation independent fault attack on AES. This attack is able to determine the complete 128-bit secret key of a sealed tamper-proof smartcard by generating 128 faulty cipher texts. Second, we present several implementation-dependent fault attacks on AES. These attacks rely on the observation that due to the AES’s known timing analysis vulnerability (as pointed out by Koeune and Quisquater [KQ]), any implementation of the AES must ensure a data independent timing behavior for the so called AES’sxtimeoperation. We present fault attacks on AES based on various timing analysis resistant implementations of thextime-operation. Our strongest attack in this direction uses a very liberal fault model and requires only 256 faulty encryptions to determine a 128-bit key.