TY - GEN
T1 - Persistent Fault Analysis with Few Encryptions
AU - Carré, Sébastien
AU - Guilley, Sylvain
AU - Rioul, Olivier
N1 - Publisher Copyright:
© 2021, Springer Nature Switzerland AG.
PY - 2021/1/1
Y1 - 2021/1/1
N2 - Persistent fault analysis (PFA) consists in guessing block cipher secret keys by biasing their substitution box. This paper improves the original attack of Zhang et al. on AES-128 presented at CHES 2018. By a thorough analysis, the exact probability distribution of the ciphertext (under a uniformly distributed plaintext) is derived, and the maximum likelihood key recovery estimator is computed exactly. Its expression is turned into an attack algorithm, which is shown to be twice more efficient in terms of number of required encryptions than the original attack of Zhang et al. This algorithm is also optimized from a computational complexity standpoint. In addition, our optimal attack is naturally amenable to key enumeration, which expedites full 16-bytes key extraction. Various tradeoffs between data and computational complexities are investigated.
AB - Persistent fault analysis (PFA) consists in guessing block cipher secret keys by biasing their substitution box. This paper improves the original attack of Zhang et al. on AES-128 presented at CHES 2018. By a thorough analysis, the exact probability distribution of the ciphertext (under a uniformly distributed plaintext) is derived, and the maximum likelihood key recovery estimator is computed exactly. Its expression is turned into an attack algorithm, which is shown to be twice more efficient in terms of number of required encryptions than the original attack of Zhang et al. This algorithm is also optimized from a computational complexity standpoint. In addition, our optimal attack is naturally amenable to key enumeration, which expedites full 16-bytes key extraction. Various tradeoffs between data and computational complexities are investigated.
KW - Key enumeration
KW - Maximum likelihood distinguisher
KW - Persistent fault analysis
KW - Substitution box
U2 - 10.1007/978-3-030-68773-1_1
DO - 10.1007/978-3-030-68773-1_1
M3 - Conference contribution
AN - SCOPUS:85102257624
SN - 9783030687724
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 3
EP - 24
BT - Constructive Side-Channel Analysis and Secure Design - 11th International Workshop, COSADE 2020, Revised Selected Papers
A2 - Bertoni, Guido Marco
A2 - Regazzoni, Francesco
PB - Springer Science and Business Media Deutschland GmbH
T2 - 11th International Workshop on Constructive Side-Channel Analysis and Secure Design, COSADE 2020
Y2 - 1 April 2020 through 3 April 2020
ER -