Differential Fault Analysis of Streebog

Differential Fault Analysis of Streebog
复制标题

DOI:
10.1007/978-3-319-17533-1_3
复制
发表时间:
2015-05
期刊:
--
影响因子:
--
通讯作者:
Riham Altawy;A. Youssef
Riham Altawy;A. Youssef
中科院分区:
其他
文献类型:
--
作者:
Riham Altawy;A. Youssef

文献摘要

被引文献

相似文献

2012年8月,Streebog哈希函数被选为新的俄罗斯联邦哈希函数标准(GOST R 34.11-2012)。在本文中,我们提出了一个故障分析攻击这个新的哈希标准。特别地,我们的攻击考虑了密钥设置中的压缩函数,其中输入链接值和消息块都是未知的。所采用的故障模型是其中攻击者被假定为能够在压缩函数的底层密码的内部状态中的随机字节处引起位翻转的模型。我们还考虑了攻击者可以选择故障字节的位置的情况。在续集中,我们提出了一个两阶段的方法,恢复的两个秘密输入的压缩功能,使用的平均故障数在338-1640之间变化,这取决于我们所采用的故障模型的假设。此外,我们表明,攻击可以扩展到迭代哈希函数使用一个可行的预计算阶段。最后,我们分析了Streebog在不同的MAC设置,并演示了我们的攻击可以用来恢复HMAC/NMAC-GOST的秘密密钥。
In August 2012, the Streebog hash function was selected as the new Russian federal hash function standard (GOST R 34.11-2012). In this paper, we present a fault analysis attack on this new hashing standard. In particular, our attack considers the compression function in the secret key setting where both the input chaining value and the message block are unknown. The fault model adopted is the one in which an attacker is assumed to be able to cause a bit-flip at a random byte in the internal state of the underlying cipher of the compression function. We also consider the case where the position of the faulted byte can be chosen by the attacker. In the sequel, we propose a two-stage approach that recovers the two secret inputs of the compression function using an average number of faults that varies between 338-1640, depending on the assumptions of our employed fault model. Moreover, we show that the attack can be extended to the iterated hash function using a feasible pre-computation stage. Finally, we analyze Streebog in different MAC settings and demonstrate how our attack can be used to recover the secret key of HMAC/NMAC-GOST.