Attacking an Obfuscated Cipher by Injecting Faults

Attacking an Obfuscated Cipher by Injecting Faults
复制标题

DOI:
10.1007/978-3-540-44993-5_2
复制
发表时间:
2002-11
期刊:
--
影响因子:
--
通讯作者:
M. Jacob;D. Boneh;E. Felten
M. Jacob;D. Boneh;E. Felten
中科院分区:
其他
文献类型:
--
作者:
M. Jacob;D. Boneh;E. Felten

文献摘要

被引文献

相似文献

我们研究了用于保护软件免受逆向工程和篡改的某些混淆技术的强度。我们表明,一些常见的混淆方法可以击败使用故障注入攻击,即攻击程序执行过程中的攻击者注入错误到程序环境中。通过观察程序在某些错误下如何失败,攻击者可以推断程序代码中的混淆信息,而不必解开混淆机制。我们应用这种技术来提取一个秘密的密钥,从一个块密码混淆使用商业混淆工具,并得出结论,防止这个弱点。
We study the strength of certain obfuscation techniques used to protect software from reverse engineering and tampering. We show that some common obfuscation methods can be defeated using a fault injection attack, namely an attack where during program execution an attacker injects errors into the program environment. By observing how the program fails under certain errors the attacker can deduce the obfuscated information in the program code without having to unravel the obfuscation mechanism. We apply this technique to extract a secret key from a block cipher obfuscated using a commercial obfuscation tool and draw conclusions on preventing this weakness.