Scan-based attack against DES cryptosystems using scan signatures

Scan-based attack against DES cryptosystems using scan signatures
复制标题

DOI:
10.1109/apccas.2012.6419106
复制
发表时间:
2012-12
期刊:
2012 IEEE Asia Pacific Conference on Circuits and Systems
影响因子:
--
通讯作者:
Hirokazu Kodera;M. Yanagisawa;N. Togawa
Hirokazu Kodera;M. Yanagisawa;N. Togawa
中科院分区:
其他
文献类型:
--
作者:
Hirokazu Kodera;M. Yanagisawa;N. Togawa

文献摘要

相似文献

近年来,随着大规模集成电路的高度集成化,面向工艺设计的重要性日益增加。扫描路径测试是一种有效的可测性设计技术,测试人员可以直接观察和控制目标LSI芯片内部的寄存器。另一方面,已经指出了针对加密LSI和模块的侧信道攻击的风险。特别是,基于扫描的攻击,通过分析从扫描链获得的扫描数据检索密钥已经引起了人们的注意。在本文中,我们提出了一种基于扫描的攻击方法对DES使用扫描签名。我们提出的方法是基于专注于特定的位列数据在一组扫描数据,并观察它们的变化时,给定几个明文。我们可以通过将S-BOX过程划分为8个独立的子过程并将轮密钥候选者的数量从248减少到26×8 = 512来检索密钥。我们提出的方法可以检索秘密密钥,即使扫描链包括除了加密模块和攻击者不知道什么时候加密真正完成的加密模块的寄存器。实验结果表明,我们成功地检索DES密码系统的密钥使用最多32明文。
With the high integration of LSI in recent years, the importance of design-for-techniques has been increasing. A scan-path test is one of the useful design-for-test techniques, in which testers can observe and control registers inside the target LSI chip directly. On the other hand, the risk of side-channel attacks against cryptographic LSIs and modules has been pointed out. In particular, scan-based attacks which retrieve secret keys by analyzing scan data obtained from scan chains has been attracting attention. In this paper, we propose a scan-based attack method against DES using scan signatures. Our proposed method are based on focusing on particular bit-column-data in a set of scan data and observing their changes when given several plaintexts. We can retrieve secret keys by partitioning the S-BOX process into eight independent sub-processes and reducing the number of the round key candidates from 248 to 26×8 = 512. Our proposed methods can retrieve secret keys even if a scan chain includes registers except a crypto module and attackers do not know when the encryption is really done in the crypto module. Experimental results demonstrate that we successfully retrieve the secret keys of a DES cryptosystem using at most 32 plaintexts.