arrow
Return

Fault Rate Analysis: Breaking Masked AES Hardware Implementations Efficiently

delete2013-08-01
delete25
PRE
AI
王安 (An Wang) *
陈满生 (Man Chen)
王宗跃 cover
王宗跃 (Zongyue Wang)
王小云 cover
王小云 (Xiaoyun Wang)
DOI:10.1109/TCSII.2013.2268379delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In 2011, Li et al. presented clockwise collision analysis on nonprotected Advanced Encryption Standard (AES) hardware implementation. In this brief, we first propose a new clockwise collision attack, called fault rate analysis (FRA), on masked AES. Then, we analyze the critical and noncritical paths of the S-box and find that, for its three input bytes, namely, the input value, the input mask, and the output mask, the path relating to the output mask is much shorter than those relating to the other two inputs. Therefore, some sophisticated glitch cycles can be chosen such that the values in the critical path of the whole S-box are destroyed but this short path is not affected. As a result, the output mask does not offer protection to the S-box, which leads to a more efficient attack. Compared with three attacks on masking countermeasures at the Workshop on Cryptographic Hardware and Embedded Systems 2010 and 2011, our method only costs about 8% of their time and 4% of their storage space.
Keywords:
Collision attack
fault rate analysis (FRA)
masking
path delay
side-channel attack
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

I
IEEE Transactions on Circuits and Systems and Express Briefs
IF:
4.9
Papers:
8.8K
Citations:
2.5W

Organization

T
tsinghua university
Scholars:
11.8W
Papers: 10.0W
Citations: 137
S
shandong university
Scholars:
9.3W
Papers: 6.4W
Citations: 94