A Type of Differential Fault Attacks of the Stream Cipher SNOW-V Based on AES Structure

IF 2 4区 计算机科学 Q3 COMPUTER SCIENCE, INFORMATION SYSTEMS
Shaoyu Du, Bin Zhang, Lin Jiao, Hongfang Li
{"title":"A Type of Differential Fault Attacks of the Stream Cipher SNOW-V Based on AES Structure","authors":"Shaoyu Du,&nbsp;Bin Zhang,&nbsp;Lin Jiao,&nbsp;Hongfang Li","doi":"10.1049/ise2/9918170","DOIUrl":null,"url":null,"abstract":"<p>SNOW-V is a member in the SNOW family of stream ciphers designed for the 5G mobile communication system. In order to have a high speed, both the linear feedback shift register (LFSR) and finite state machine (FSM) are updated to better align with vectorized implementations and the update function is based on the round function of AES. In this paper, we find the 512-bit LFSR can be approximately divided into four parts and each clock one 128-bit part updates the FSM, another 128-bit part masks the 128-bit keystream. Differences in different bytes of the LFSR have distinguishable propagations in the keystream, which all behaves not randomly. Under the assumption that the cipher can be reset several times with the same key and IV to permit the adversary to inject different one-byte faults in the higher 16 bytes of LFSR-B during the keystream-generating phase, the state of SNOW-V can be revealed. For the simplified version of SNOW-V that addition with carry is replaced by XOR, the 384-bit FSM state can be revealed from the faulty and fault-free keystreams of seven faults with evenly 2<sup>23</sup> computational complexity, and then the 512-bit LFSR state can be revealed with no more complexity. For the full version of SNOW-V, we can conduct another fault attack with 2<sup>48</sup> computational complexity and 64 faults on average.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0000,"publicationDate":"2026-07-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/9918170","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Information Security","FirstCategoryId":"94","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1049/ise2/9918170","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

Abstract

SNOW-V is a member in the SNOW family of stream ciphers designed for the 5G mobile communication system. In order to have a high speed, both the linear feedback shift register (LFSR) and finite state machine (FSM) are updated to better align with vectorized implementations and the update function is based on the round function of AES. In this paper, we find the 512-bit LFSR can be approximately divided into four parts and each clock one 128-bit part updates the FSM, another 128-bit part masks the 128-bit keystream. Differences in different bytes of the LFSR have distinguishable propagations in the keystream, which all behaves not randomly. Under the assumption that the cipher can be reset several times with the same key and IV to permit the adversary to inject different one-byte faults in the higher 16 bytes of LFSR-B during the keystream-generating phase, the state of SNOW-V can be revealed. For the simplified version of SNOW-V that addition with carry is replaced by XOR, the 384-bit FSM state can be revealed from the faulty and fault-free keystreams of seven faults with evenly 223 computational complexity, and then the 512-bit LFSR state can be revealed with no more complexity. For the full version of SNOW-V, we can conduct another fault attack with 248 computational complexity and 64 faults on average.

Abstract Image

基于AES结构的流密码SNOW-V差分故障攻击
SNOW- v是为5G移动通信系统设计的SNOW流密码家族中的一员。为了获得较高的速度,线性反馈移位寄存器(LFSR)和有限状态机(FSM)都进行了更新,以更好地与矢量化实现保持一致,更新函数基于AES的轮函数。在本文中,我们发现512位的LFSR可以大致分为四个部分,每个时钟一个128位的部分更新FSM,另一个128位的部分掩码128位的密钥流。LFSR的不同字节的差异在密钥流中具有不同的传播,它们的行为都不是随机的。假设可以使用相同的密钥和IV多次重置密码,以允许攻击者在密钥流生成阶段在LFSR-B的较高16字节中注入不同的1字节错误,则可以揭示SNOW-V的状态。对于用异或代替进位加法的简化版SNOW-V,可以从计算复杂度为223的7个故障的故障和无故障密钥流中显示384位的FSM状态,然后以不增加复杂度的方式显示512位的LFSR状态。对于完整版本的SNOW-V,我们可以进行另一次故障攻击,其计算复杂度为248,平均故障数为64。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
IET Information Security
IET Information Security 工程技术-计算机:理论方法
CiteScore
3.80
自引率
7.10%
发文量
47
审稿时长
8.6 months
期刊介绍: IET Information Security publishes original research papers in the following areas of information security and cryptography. Submitting authors should specify clearly in their covering statement the area into which their paper falls. Scope: Access Control and Database Security Ad-Hoc Network Aspects Anonymity and E-Voting Authentication Block Ciphers and Hash Functions Blockchain, Bitcoin (Technical aspects only) Broadcast Encryption and Traitor Tracing Combinatorial Aspects Covert Channels and Information Flow Critical Infrastructures Cryptanalysis Dependability Digital Rights Management Digital Signature Schemes Digital Steganography Economic Aspects of Information Security Elliptic Curve Cryptography and Number Theory Embedded Systems Aspects Embedded Systems Security and Forensics Financial Cryptography Firewall Security Formal Methods and Security Verification Human Aspects Information Warfare and Survivability Intrusion Detection Java and XML Security Key Distribution Key Management Malware Multi-Party Computation and Threshold Cryptography Peer-to-peer Security PKIs Public-Key and Hybrid Encryption Quantum Cryptography Risks of using Computers Robust Networks Secret Sharing Secure Electronic Commerce Software Obfuscation Stream Ciphers Trust Models Watermarking and Fingerprinting Special Issues. Current Call for Papers: Security on Mobile and IoT devices - https://digital-library.theiet.org/files/IET_IFS_SMID_CFP.pdf
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信
小红书