资源描述:
《security analysis and fault injection experiment on aesnew》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、SecurityanalysisandfaultinjectionexperimentonAESOlivierFaurax1,2,TraianMuntean21EcoledesMinesdeSt´Etienne-SiteGeorgesCharpak,LaboratoireSESAM,AvenuedesAn´emones,13120GAR-´DANNE,FRANCE2UniversitedelaM´editerran´ee,”Syst´emesInformatiquesCommunicants”,13288MARSEILLE,FRANCE`E-mail:faurax@ems
2、e.frRobustnessofcryptographiccircuitsagainstfaultattacksisagreatconcerntoensuresecurity.Inthispaper,wepresentasecurityanalysisofsuchcircuitsandafaultinjectionmethodologyandtool(PAFI).WeapplythemtoAESasacasestudyandshowthatinjectedfaultsthatleadtoknownfaultattacksmatchouranalysis.Mots-cles
3、:´faultattacks,cryptography,AES1IntroductionCryptographiccircuitsareoftenafoundationofsecurityinnowadayssystems.Asaconsequence,attacksonthemarecriticalandcanbeusedtodefeatsecuritypolicies.Inthiscontext,theprotectionagainstattacksisamajorconcern.Afaultattackusesaphysicalperturba-tionofthec
4、ircuitinordertoobtainfaultycomputations.Thesemiscomputedresultscanenablecryptanal-ysisandrevealsecretdata.Severalcryptosystemsareconcernedbythistypeofattacks:RSA[BDL97],DES[BS97]andAES[Gir04][DLV03][PQ03].Therobustnessagainstfaultattacksmustbeevaluatedtoensurefaulttoleranceandsecurity.Thi
5、scanbeachievedbyinjectingfaultsinthesysteminordertovalidateitsbehaviorunderfaultattacks.Itispossibletodothisusingphysicalfault[GKT89][AAA+90][MRMS94],butthiscanalsobedoneusingbuilt-indebugmechanisms[FSK97][BPRR98].Anotherapproachistousefaultinjectionduringsimulationtoproviderobustnesseval
6、utationbeforesiliconICmanufacturinginanrelativelyunexpensivemanner.Simulatingthecircuitpermitstoinjectfaultbymodifyingitsdescription[JAR+94][LH00][ZME03]ortoaddacustomfaultinjectorinthedesign[FMR06].Ourapproachistouseanunmodifieddescriptionofthecircuittobeveryaccurateregardingtothecorrespo
7、ndingphysicalcircuit.However,somepropertiesofcryptographicalgorithmcanbeusedtopredictthetemporalsensitivityofcircuits.Inthispaper,weproposeametricofsensitivityagainstfaultattacksforcircuitsandvalidateitusingfaultinjectioninsimulationonAES.Thispaperisorganizedasfollo