Improving DFA attacks on AES with unknown and random faults

Improving DFA attacks on AES with unknown and random faults
复制标题

改进对具有未知和随机故障的 AES 的 DFA 攻击

DOI:
10.1007/s11432-016-0071-7
复制
发表时间:
2016-12
期刊:
Science China Information Sciences
影响因子:
--
通讯作者:
Cui, Xiaole
Cui, Xiaole
中科院分区:
其他
文献类型:
--
作者:
Liao, Kai;Wang, Tian;Yu, Dunshan;Cui, Xiaole

文献摘要

参考文献

被引文献

相似文献

针对高级加密标准(AES)硬件实现的差分故障分析(DFA)已成为一个广泛的研究课题。与理论模型不同,在真实的攻击场景中,流行和实用的故障注入方法(如电源电压变化)会引入位置随机、值未知和多字节的故障。为了分析这类故障,以前的故障模型需要六对正确和错误的密文来恢复秘密轮密钥。本文在保证准确性的前提下,提出了一种更有效的具有未知随机故障的DFA攻击。在故障分析中引入了理论候选数的概念。基于这一概念,正确的轮密钥可以提前确定,所以所提出的攻击方法总是可以使用最少的正确和错误的密文对来完成DFA攻击。为了进一步支持我们的观点,在FPGA板上进行了基于电压违规的随机故障攻击。实验结果表明,约97.3%的攻击可以在3对正确和错误的密文内完成。此外,平均只需要2.17对正确和错误的密文找到正确的轮密钥,显示出显着的效率优势,与以往的故障模型。另一方面,我们的模型可以以很高的概率实现更少的分析计算量,这也有效地提高了在未知和随机故障的DFA攻击的时间效率。
Differential fault analysis (DFA) aiming at the advanced encryption standard (AES) hardware implementations has become a widely research topic. Unlike theoretical model, in real attack scenarios, popular and practical fault injection methods like supply voltage variation will introduce faults with random locations, unknown values and multibyte. For analyzing this kind of faults, the previous fault model needed six pairs of correct and faulty ciphertexts to recover the secret round-key. In this paper, on the premise of accuracy, a more efficient DFA attack with unknown and random faults is proposed. We introduce the concept of theoretical candidate number in the fault analysis. Based on this concept, the correct round-key can be identified in advance, so the proposed attack method can always use the least pairs of correct and faulty ciphertexts to accomplish the DFA attacks. To further support our opinion, random fault attacks based on voltage violation were taken on an FPGA board. Experiment results showed that about 97.3% of the attacks can be completed within 3 pairs of correct and faulty ciphertexts. Moreover, on average only 2.17 pairs of correct and faulty ciphertexts were needed to find out the correct round-key, showing significant advantage of efficiency compared with previous fault models. On the other hand, less amount of computation in the analyses can be realized with a high probability with our model, which also effectively improves the time efficiency in DFA attacks with unknown and random faults.
DOI: 10.1109/ths.2010.5655079
发表时间: 2010-12
期刊: 2010 IEEE International Conference on Technologies for Homeland Security (HST)
影响因子: --
作者:
M. Agoyan;J. Dutertre;A. Mirbaha;D. Naccache;Anne-Lise Ribotta;A. Tria
通讯作者: M. Agoyan;J. Dutertre;A. Mirbaha;D. Naccache;Anne-Lise Ribotta;A. Tria
DOI: 10.1007/978-3-540-45126-6_12
发表时间: 2003-01
期刊: --
影响因子: --
作者:
Johannes Blömer;Jean-Pierre Seifert
通讯作者: Johannes Blömer;Jean-Pierre Seifert
DOI: 10.1007/978-3-540-45238-6_7
发表时间: 2003-09
期刊: --
影响因子: --
作者:
G. Piret;J. Quisquater
通讯作者: G. Piret;J. Quisquater
DOI: --
发表时间: 2010
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
Alessandro Barenghi;G. Bertoni;L. Breveglieri;M. Pellicioli;Gerardo Pelosi
通讯作者: Alessandro Barenghi;G. Bertoni;L. Breveglieri;M. Pellicioli;Gerardo Pelosi
DOI: 10.1109/edcc-7.2008.11
发表时间: 2008-05
期刊: 2008 Seventh European Dependable Computing Conference
影响因子: --
作者:
Nidhal Selmane;S. Guilley;J. Danger
通讯作者: Nidhal Selmane;S. Guilley;J. Danger