CAST-128的差分功率分析

K. Boey, Yingxi Lu, Máire O’Neill, Roger Francis Woods
{"title":"CAST-128的差分功率分析","authors":"K. Boey, Yingxi Lu, Máire O’Neill, Roger Francis Woods","doi":"10.1109/ISVLSI.2010.14","DOIUrl":null,"url":null,"abstract":"Power analysis is used to reveal the secret key of security devices by monitoring the power consumption of certain cryptographic algorithm operations through a statistical analysis approach known as Differential Power Analysis (DPA). Whilst this has been applied extensively to attacks on FPGA devices, there has been little research into attacks on ASIC devices. Although standard DPAs are essentially independent of the block cipher that they target, some are less susceptible than others due to algorithm’s structure, and therefore more difficult to attack such as the CAST-128. In this paper, we outline the first reported power analysis attack of CAST-128 as it falls into the category just outlined and it is the only algorithm that has not been practically broken either on FPGA or ASIC, it is also a common block cipher used in Canada. The paper outlines an approach that reveals all 128 bits of the secret key within 300,500 power traces, highlighting insights on attacking the registers rather than the Sbox. Finally, the effect of applying the Hamming weight power model on different widths of the target register under attack in ASIC device is evaluated.","PeriodicalId":187530,"journal":{"name":"2010 IEEE Computer Society Annual Symposium on VLSI","volume":"27 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2010-07-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"26","resultStr":"{\"title\":\"Differential Power Analysis of CAST-128\",\"authors\":\"K. Boey, Yingxi Lu, Máire O’Neill, Roger Francis Woods\",\"doi\":\"10.1109/ISVLSI.2010.14\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Power analysis is used to reveal the secret key of security devices by monitoring the power consumption of certain cryptographic algorithm operations through a statistical analysis approach known as Differential Power Analysis (DPA). Whilst this has been applied extensively to attacks on FPGA devices, there has been little research into attacks on ASIC devices. Although standard DPAs are essentially independent of the block cipher that they target, some are less susceptible than others due to algorithm’s structure, and therefore more difficult to attack such as the CAST-128. In this paper, we outline the first reported power analysis attack of CAST-128 as it falls into the category just outlined and it is the only algorithm that has not been practically broken either on FPGA or ASIC, it is also a common block cipher used in Canada. The paper outlines an approach that reveals all 128 bits of the secret key within 300,500 power traces, highlighting insights on attacking the registers rather than the Sbox. Finally, the effect of applying the Hamming weight power model on different widths of the target register under attack in ASIC device is evaluated.\",\"PeriodicalId\":187530,\"journal\":{\"name\":\"2010 IEEE Computer Society Annual Symposium on VLSI\",\"volume\":\"27 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2010-07-05\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"26\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2010 IEEE Computer Society Annual Symposium on VLSI\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ISVLSI.2010.14\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2010 IEEE Computer Society Annual Symposium on VLSI","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISVLSI.2010.14","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 26

摘要

功率分析是通过一种称为差分功率分析(DPA)的统计分析方法,通过监控某些加密算法操作的功耗来揭示安全设备的密钥。虽然这已被广泛应用于对FPGA设备的攻击,但对ASIC设备的攻击研究很少。虽然标准dpa基本上独立于它们所针对的分组密码,但由于算法的结构,一些dpa比其他dpa更不容易受到影响,因此更难攻击,例如CAST-128。在本文中,我们概述了首次报道的CAST-128功率分析攻击,因为它属于刚刚概述的类别,并且它是唯一没有在FPGA或ASIC上实际被破坏的算法,它也是加拿大使用的常见分组密码。这篇论文概述了一种方法,可以在300,500个电源跟踪中显示所有128位密钥,突出了攻击寄存器而不是Sbox的见解。最后,评估了在ASIC器件中不同宽度目标寄存器受到攻击时,应用汉明加权功率模型的效果。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Differential Power Analysis of CAST-128
Power analysis is used to reveal the secret key of security devices by monitoring the power consumption of certain cryptographic algorithm operations through a statistical analysis approach known as Differential Power Analysis (DPA). Whilst this has been applied extensively to attacks on FPGA devices, there has been little research into attacks on ASIC devices. Although standard DPAs are essentially independent of the block cipher that they target, some are less susceptible than others due to algorithm’s structure, and therefore more difficult to attack such as the CAST-128. In this paper, we outline the first reported power analysis attack of CAST-128 as it falls into the category just outlined and it is the only algorithm that has not been practically broken either on FPGA or ASIC, it is also a common block cipher used in Canada. The paper outlines an approach that reveals all 128 bits of the secret key within 300,500 power traces, highlighting insights on attacking the registers rather than the Sbox. Finally, the effect of applying the Hamming weight power model on different widths of the target register under attack in ASIC device is evaluated.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信