Evaluation of Statistical Fault Analysis Using Input Timing Violation of Sequential Circuit on Cryptographic Module Under IEMI

Evaluation of Statistical Fault Analysis Using Input Timing Violation of Sequential Circuit on Cryptographic Module Under IEMI
复制标题

IEMI 下密码模块时序电路输入时序违规统计故障分析评估

DOI:
10.1109/temc.2022.3215583
复制
发表时间:
2023
影响因子:
2.1
通讯作者:
Hayashi Yuichi
Hayashi Yuichi
中科院分区:
计算机科学3区
文献类型:
--
作者:
Fujimoto Daisuke;Okamoto Takumi;Li Yang;Kim Youngwoo;Hayashi Yuichi

文献摘要

相似文献

在加密电路中,故障注入分析的威胁仍然是一个相当大的问题。更具体地说,由故意的电磁(EM)照射产生的时钟故障会导致错误的操作和估计内部密钥。通过有意的电磁干扰(IEMI)产生时钟故障可以在不打开设备的情况下执行,这使得它成为一个真正的威胁。以前通过IEMI进行的秘密密钥分析主要集中在设置时间违规上。它要求时钟故障发生在加密电路的关键路径延迟附近。本文研究了由于时序电路输入违反时序而导致的故障,并讨论了从故障密文的输出中获取密钥的可能性。时序电路的输入时序违例涵盖了运行过程中的所有时间。利用一种单独提取时序电路的测量系统来评估由于输入时序违规而导致的时序电路输出值的偏置。利用输出值的偏置对加密电路进行了秘密密钥分析,并对三种不同的高级加密标准实现进行了验证,以证明其可行性。结果表明,无论采用何种实现方法,都可以在较短的时钟周期内进行密钥分析。
In encryption circuits, the threat of fault injection analysis remains a considerable problem. More specifically, clock glitches generated by intentional electromagnetic (EM) irradiation cause faulty operations and estimate internal secret keys. Generating clock glitches via intentional EM interference (IEMI) can be performed without opening the equipment, which makes it a real threat. Previous secret key analysis via IEMI has focused on setup time violations. It requires the clock glitch to occur near the critical path delay of the encryption circuit. This article examines the faults owing to timing violations of inputs to the sequential circuit and discusses the possibility of obtaining the secret key from the output of the faulty ciphertext. The input timing violation of the sequential circuit covers all times during the operation. The bias of the output value of the sequential circuit owing to input timing violations is evaluated using a measurement system in which the sequential circuit alone was extracted. Secret key analysis of encryption circuits using the bias of output values is performed for three different implementations of the advanced encryption standard to demonstrate its feasibility. The results indicate that secret key analysis is possible over a wide range of shortened clock period, regardless of the implementation method.