Back to Search Start Over

Efficient Persistent Fault Analysis with Small Number of Chosen Plaintexts

Authors :
Fan Zhang
Run Huang
Tianxiang Feng
Xue Gong
Yulong Tao
Kui Ren
Xinjie Zhao
Shize Guo
Source :
Transactions on Cryptographic Hardware and Embedded Systems, Vol 2023, Iss 2 (2023)
Publication Year :
2023
Publisher :
Ruhr-Universität Bochum, 2023.

Abstract

In 2018, Zhang et al. introduced the Persistent Fault Analysis (PFA) for the first time, which uses statistical features of ciphertexts caused by faulty Sbox to recover the key of block ciphers. However, for most of the variants of PFA, the prior knowledge of the fault (location and value) is required, where the corresponding analysis will get more difficult under the scenario of multiple faults. To bypass such perquisite and improve the analysis efficiency for multiple faults, we propose Chosen-Plaintext based Persistent Fault Analysis (CPPFA). CPPFA introduces chosen-plaintext to facilitate PFA and can reduce the key search space of AES-128 to extremely small. Our proposal requires 256 ciphertexts, while previous state-of-the-art work still requires 1509 and 1448 ciphertexts under 8 and 16 faults, respectively, at the only cost of requiring 256 chosen plaintexts. In particular, CPPFA can be applied to the multiple faults scenarios where all fault locations, values and quantity are unknown, and the worst time complexity of CPPFA is O(28+nf ) for AES-128, where nf represents the number of faults. The experimental results show that when nf > 4, 256 pairs of plaintext-ciphertext can recover the master key of AES-128. As for LED-64, only 16 pairs of plaintext-ciphertext reduce the remaining key search space to 210.

Details

Language :
English
ISSN :
25692925
Volume :
2023
Issue :
2
Database :
Directory of Open Access Journals
Journal :
Transactions on Cryptographic Hardware and Embedded Systems
Publication Type :
Academic Journal
Accession number :
edsdoj.18a46bc7e24a4cd0a388b4efb046fa70
Document Type :
article
Full Text :
https://doi.org/10.46586/tches.v2023.i2.519-542