Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Differential fault analysis

From Wikipedia, the free encyclopedia
Type of active side channel attack

Differential fault analysis (DFA) is a type of activeside-channel attack in the field ofcryptography, specificallycryptanalysis. The principle is to inducefaults—unexpected environmental conditions—into cryptographic operations to reveal their internal states.

Principles

[edit]

Taking asmartcard containing an embeddedprocessor as an example, some unexpected environmental conditions it could experience include being subjected to high temperature, receiving unsupportedsupply voltage or current, being excessivelyoverclocked, experiencing strongelectric ormagnetic fields, or even receivingionizing radiation to influence the operation of the processor. When stressed like this, the processor may begin to output incorrect results due to physicaldata corruption, which may help acryptanalyst deduce the instructions that the processor is running, or what the internal state of its data is.[1][2]

ForDES andTriple DES, about 200 single-flipped bits are necessary to obtain a secretkey.[3] DFA has also been applied successfully to theAES cipher.[4]

Many countermeasures have been proposed to defend from these kinds of attacks. Most of them are based on error detection schemes.[5][6]

Fault injection

[edit]

A fault injection attack involves stressing thetransistors responsible forencryption tasks to generate faults that will then be used as input for analysis. The stress can be an electromagnetic pulse (EM pulse orlaser pulse).

Practical fault injection consists of using an electromagnetic probe connected to a pulser or a laser generating a disturbance of a similar length to the processor'scycle time (of the order of a nanosecond). The energy transferred to the chip may be sufficient to burn out certain components of the chip, so the voltage of the pulser (a few hundred volts) and the positioning of the probe must be finely calibrated. For greater precision, the chips are often decapsulated (chemically eroded to expose the bare silicon).[7]

References

[edit]
  1. ^Eli Biham,Adi Shamir: The next Stage of Differential Fault Analysis: How to break completely unknown cryptosystems (1996)
  2. ^Dan Boneh and Richard A. DeMillo and Richard J. Lipton: On the Importance of Checking Cryptographic Protocols for Faults, Eurocrypt (1997)
  3. ^Ramesh Karri, et al.: Fault-Based Side-Channel Cryptanalysis Tolerant Rijndael Symmetric Block Cipher Architecture (2002)
  4. ^Christophe Giraud: DFA on AES (2005)
  5. ^Xiaofei Guo, et al.:Invariance-based Concurrent Error Detection for Advanced Encryption Standard (2012)
  6. ^Rauzy and Guilley:Countermeasures against High-Order Fault-Injection Attacks on CRT-RSA (2014) (Open Access version)
  7. ^"Fault Injection".eshard.com. 2021-11-01. Retrieved2021-11-23.
General
Mathematics


Stub icon

This cryptography-related article is astub. You can help Wikipedia byadding missing information.

Retrieved from "https://en.wikipedia.org/w/index.php?title=Differential_fault_analysis&oldid=1237706308"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp