Hardware Countermeasures Benchmarking against Fault Attacks
收藏资源简介:
Abstract: The development of differential fault analysis (DFA) techniques and mechanisms to inject faults into cryptographic circuits brings with it the need to use protection mechanisms that guarantee the expected level of security. The AES cipher, as a standard, has been the target of numerous DFA techniques, where its security has been compromised through different formulations and types of fault injections. These attacks have shown vulnerabilities of different AES implementations and building blocks. Consequently, several solutions have been proposed that provide additional protection to cover the identified vulnerabilities. In this paper, an extensive analysis has been carried out covering the existing fault injection techniques, the types of faults, and the requirements needed to apply DFA. Additionally, an analysis of the countermeasures reported in the literature is also presented, considering the protection provided, the type of faults considered, and the coverage against fault attacks. The eight different types of fault that allow us to perform DFAs on the AES cipher have been differentiated, as well as the vulnerabilities of the cipher. On the other hand, two comparisons have been made considering frequency penalty vs. area and fault coverage vs. area and frequency overhead. A metric has been proposed to compare the fault coverage of all the proposed solutions. To conclude, a final analysis is presented discussing the key aspects when choosing a particular solution and the possible development of new countermeasures to provide further protection against DFA.
摘要:差分故障分析(Differential Fault Analysis, DFA)技术的发展,以及面向密码电路的故障注入各类机制,使得保障预期安全等级的防护机制成为必要需求。作为通用标准的高级加密标准(Advanced Encryption Standard, AES)密码算法,始终是各类DFA技术的重点攻击目标,研究者可通过不同的故障注入形式与攻击范式攻破其多种实现方案与构建模块的安全性。此类攻击暴露了AES不同实现方式与组成模块的安全漏洞。为此,学界已提出多种防护方案,以针对已识别的漏洞提供额外安全防护。 本文开展了全面的系统性分析,涵盖当前已有的故障注入技术、故障类型,以及开展DFA所需的各项前提条件。此外,本文还对文献中报道的各类防护对策展开分析,综合考量其提供的防护能力、适配的故障类型,以及对故障攻击的覆盖范围。本文明确区分了可用于对AES密码算法开展DFA攻击的八种不同故障类型,同时梳理了该密码算法的各类安全漏洞。另一方面,本文完成了两项对比研究:分别围绕频率开销与面积开销的权衡,以及故障覆盖范围与面积、频率开销的权衡展开。同时,本文提出了一项量化指标,用于对比各类已提出防护方案的故障覆盖能力。最后,本文开展总结性分析,探讨了选定特定防护方案时需考量的核心要点,以及开发新型防护对策以进一步增强针对DFA攻击的防护能力的可行方向。



