Juan C. Grados Vásquez, Fábio Borges, R. Portugal, P. Lara
{"title":"西蒙族差分故障分析中一位有效模型","authors":"Juan C. Grados Vásquez, Fábio Borges, R. Portugal, P. Lara","doi":"10.1109/FDTC.2015.18","DOIUrl":null,"url":null,"abstract":"In this paper, we describe a family of symmetric cryptographic algorithms and present its cryptanalysis. Specifically, we use differential fault analysis to show a fault attack threat to the block cipher family named Simon. In addition, we present the improvement of a fault attack based on a differential attack method. Moreover, we are the first to to extract the entire secret key using only one round. This property is important because an attacker has to control the hardware to inject faults. However, if the attacker has control of only few hardware components and they compute only one round, previous attacks are not able to recover the entire key. With this side-channel analysis, an attacker can inject faults in one round of Simon with block of 96 or 128 bits to recover therespective entire key of 96 or 128 bits without using SAT solver neither computing Grobner bases. The key can be recoveredusing only differential fault analysis.","PeriodicalId":444709,"journal":{"name":"2015 Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC)","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-09-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":"{\"title\":\"An Efficient One-Bit Model for Differential Fault Analysis on Simon Family\",\"authors\":\"Juan C. Grados Vásquez, Fábio Borges, R. Portugal, P. Lara\",\"doi\":\"10.1109/FDTC.2015.18\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In this paper, we describe a family of symmetric cryptographic algorithms and present its cryptanalysis. Specifically, we use differential fault analysis to show a fault attack threat to the block cipher family named Simon. In addition, we present the improvement of a fault attack based on a differential attack method. Moreover, we are the first to to extract the entire secret key using only one round. This property is important because an attacker has to control the hardware to inject faults. However, if the attacker has control of only few hardware components and they compute only one round, previous attacks are not able to recover the entire key. With this side-channel analysis, an attacker can inject faults in one round of Simon with block of 96 or 128 bits to recover therespective entire key of 96 or 128 bits without using SAT solver neither computing Grobner bases. The key can be recoveredusing only differential fault analysis.\",\"PeriodicalId\":444709,\"journal\":{\"name\":\"2015 Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC)\",\"volume\":\"14 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-09-13\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"10\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2015 Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/FDTC.2015.18\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/FDTC.2015.18","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
An Efficient One-Bit Model for Differential Fault Analysis on Simon Family
In this paper, we describe a family of symmetric cryptographic algorithms and present its cryptanalysis. Specifically, we use differential fault analysis to show a fault attack threat to the block cipher family named Simon. In addition, we present the improvement of a fault attack based on a differential attack method. Moreover, we are the first to to extract the entire secret key using only one round. This property is important because an attacker has to control the hardware to inject faults. However, if the attacker has control of only few hardware components and they compute only one round, previous attacks are not able to recover the entire key. With this side-channel analysis, an attacker can inject faults in one round of Simon with block of 96 or 128 bits to recover therespective entire key of 96 or 128 bits without using SAT solver neither computing Grobner bases. The key can be recoveredusing only differential fault analysis.