Fault Based Cryptanalysis of the Advanced Encryption Standard (AES)
Fault Based Cryptanalysis of the Advanced Encryption Standard (AES)
复制标题
DOI:
10.1007/978-3-540-45126-6_12
复制
发表时间:
2003-01
期刊:
影响因子:
--
通讯作者:
Johannes Blömer;Jean-Pierre Seifert
中科院分区:
文献类型:
--
作者:
Johannes Blömer;Jean-Pierre Seifert
In this paper we describe several fault attacks on the Advanced Encryption Standard (AES). First, using optical/eddy current fault induction attacks as recently publicly presented by Skorobogatov, Anderson and Quisquater, Samyde [SA, QS], we present an implementation independent fault attack on AES. This attack is able to determine the complete 128-bit secret key of a sealed tamper-proof smartcard by generating 128 faulty cipher texts. Second, we present several implementation-dependent fault attacks on AES. These attacks rely on the observation that due to the AES’s known timing analysis vulnerability (as pointed out by Koeune and Quisquater [KQ]), any implementation of the AES must ensure a data independent timing behavior for the so called AES’sxtimeoperation. We present fault attacks on AES based on various timing analysis resistant implementations of thextime-operation. Our strongest attack in this direction uses a very liberal fault model and requires only 256 faulty encryptions to determine a 128-bit key.