A Study of Persistent Fault Analysis

A Study of Persistent Fault Analysis
复制标题

DOI:
10.1007/978-3-030-35869-3_4
复制
发表时间:
2019-12
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Andrea Caforio;S. Banik
Andrea Caforio;S. Banik
中科院分区:
其他
文献类型:
--
作者:
Andrea Caforio;S. Banik

文献摘要

被引文献

相似文献

持久错误标志着一类新的注入,这些注入扰乱了块密码中的查找表,其总体目标是恢复加密密钥。与早期的故障类型不同,持久性故障在许多加密中保持完整,直到受影响的设备重新启动,从而允许攻击者收集大量正确和错误的密文。结果表明,该方法是一种有效的替代置换网络攻击方法。本文进一步拓宽和探讨了持续性断层的范围。更具体地说,我们展示了如何在存在持久错误的情况下对通用Feistel方案构建密钥恢复攻击。在第二步中,我们利用这些错误在选定密钥设置中对类似AES和present的密码进行逆向工程,其中一些计算层(如替换表)是保密的。最后,我们提出了一种新颖的、专用的、低开销的对策,它为硬件实现提供了足够的保护,防止持久的故障注入。
Persistent faults mark a new class of injections that perturb lookup tables within block ciphers with the overall goal of recovering the encryption key. Unlike earlier fault types persistent faults remain intact over many encryptions until the affected device is rebooted, thus allowing an adversary to collect a multitude of correct and faulty ciphertexts. It was shown to be an efficient and effective attack against substitution-permutation networks. In this paper, the scope of persistent faults is further broadened and explored. More specifically, we show how to construct a key-recovery attack on generic Feistel schemes in the presence of persistent faults. In a second step, we leverage these faults to reverse-engineer AES- and PRESENT-like ciphers in a chosen-key setting, in which some of the computational layers, like substitution tables, are kept secret. Finally, we propose a novel, dedicated, and low-overhead countermeasure that provides adequate protection for hardware implementations against persistent fault injections.