| 講演抄録/キーワード |
| 講演名 |
2024-11-01 15:15
統計故障解析における1bit-faultモデルの有効性の検討 ○林 俊吾(産総研/横浜国大)・坂本純一・西山 輝・松本 勉(産総研) HWS2024-68 ICD2024-39 |
| 抄録 |
(和) |
CHES2018で提案されたStatistical Ineffective Fault Analysis (SIFA)は,フォールト注入時に得られるエラーのない暗号文のみを使用するフォールト攻撃である.SIFAとその派生方式は検算対策を回避できる反面,鍵解析に必要な暗号文が集まる前に多数の誤り暗号文が検知されるという問題がある.そこで本研究は1ビット誤りモデルでの誤り注入を想定し,より少ない暗号化回数と誤り検出回数で鍵解析が可能な手法を提案し,シミュレーションと実験により提案手法の有効性を評価する.シミュレーションの結果,提案手法は1ビットのフォールトを仮定した場合において平均150回の暗号化で鍵を特定した.さらに,クロックグリッチを用いた実験により,提案手法が従来手法よりも少ない暗号化回数と少ない誤り検出回数で鍵を特定できる場合があることを確認した. |
| (英) |
Statistical Ineffective Fault Analysis (SIFA), proposed in CHES2018, is a fault attack that uses only error-free ciphertext obtained during fault injection. While SIFA and its derivatives can avoid countermeasures by Duplication, they have the problem that a large number of error ciphertexts are detected before the ciphertexts necessary for key analysis are collected. Then, we propose a method that enables key analysis with less faulty encryptions and detections of faults, assuming fault injection in a 1bit fault model. We evaluate the effectiveness of the proposed method through simulations and experiments. Simulation results show that the proposed method can identify the correct key with an average of 150 encryptions under the assumption of a 1bit fault. Furthermore, experiments with clock glitches show that in some cases the proposed method can identify the key with fewer encryptions and fewer error detections than the conventional method. |
| キーワード |
(和) |
フォールト攻撃 / クロックグリッチ / SIFA / SEFA / AES / / / |
| (英) |
fault injection attack / clock glitch / SIFA / SEFA / AES / / / |
| 文献情報 |
信学技報, vol. 124, no. 229, HWS2024-68, pp. 32-37, 2024年11月. |
| 資料番号 |
HWS2024-68 |
| 発行日 |
2024-10-25 (HWS, ICD) |
| ISSN |
Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
HWS2024-68 ICD2024-39 |
|