Font Size: a A A

Research On Aes Attack Technology Based On Biased Fault

Posted on:2024-04-21Degree:MasterType:Thesis
Country:ChinaCandidate:H F WangFull Text:PDF
GTID:2568306941995379Subject:Cyberspace security
Abstract/Summary:
The Advanced Encryption Standard(AES)is one of the most widely used block cipher algorithms that can be used extensively in hardware and software.This algorithm was published by the National Institute of Standards and Technology in 2003,and since then,researchers have proposed various attack methods against AES and corresponding protection schemes.One such attack is the biased fault attack,which utilizes injected faults that are presented as a special distribution.In order to explore the wider application scenarios of biased fault attacks and investigate whether the ideas of traditional fault attacks can be further optimized under this new fault model,this paper analyzes the implementation of AES and its corresponding protection scheme using biased fault attacks.Firstly,a new biased fault discriminator model is proposed to address the issue of key extraction errors in the current biased fault discriminator.This paper employs mathematical statistical theories such as relative entropy,cross entropy,chi-square test,and skewed distribution to characterize the distribution of fault values’ Hamming weight in fault injection scenarios.Four novel fault discriminators are designed based on these theories.In the experiments,clock glitch faults are induced during AES encryption and the corresponding ciphertexts are collected.The new fault discriminators are applied successfully to recover the correct AES key.Physical experimental data demonstrate that the new fault discriminator can successfully recover the correct key with no more than 3300 pairs of correct/incorrect ciphertexts,and in the best case scenario,only 1100 pairs of ciphertexts are needed to recover all the correct keys.The experimental results show that this model can effectively reduce the number of ciphertexts required for the attack and improve the success rate of biased fault attacks.Secondly,in the aforementioned biased attack process,it is necessary to collect both the correct/incorrect ciphertext pairs corresponding to the plaintext,which increases the difficulty of ciphertext collection and ultimately increases the difficulty of successful attacks.To address this issue,this paper further proposes a new biased fault injection model.This model utilizes software combined with intermediate states and random nibble faults for XOR and AND operations,introducing faults and obtaining the corresponding incorrect ciphertexts.In the experiments,the new fault discriminators are applied successfully to recover all the correct AES keys.Simulation experimental data demonstrate that with this biased fault model,only 160 incorrect ciphertexts need to be collected to recover all the correct AES keys.As this approach only requires the collection of incorrect ciphertexts,it effectively reduces the difficulty of ciphertext collection.Thirdly,to address the issue of requiring a large number of fault ciphertexts for AES differential fault analysis,a biased statistical pattern-based differential analysis scheme is designed.This paper combines the biased fault model with differential analysis to further explore the application space of the biased fault model.For clock glitch faults,the input differential values are mainly concentrated around 1.Therefore,during the attack process,the search space for the differential values can be reduced,thereby reducing the exhaustive key search space.Physical experimental data demonstrate that the traditional differential analysis scheme requires approximately 9000 pairs of correct/incorrect ciphertexts,while the proposed differential attack scheme in this paper only requires 3000 pairs of correct/incorrect ciphertexts.The experimental results show that this scheme can effectively reduce the number of ciphertexts required for the attack.Finally,due to the significant threat of biased fault attacks on unprotected AES encryption algorithms,this paper first modified the unprotected AES code by using time redundancy protection,parity check protection,and inverse S-box check protection.Then,by conducting statistical analysis on the distribution of clock glitches and simulating biased fault injection,this paper aims to find feasible protection schemes to prevent biased fault attacks.The experimental results show that time redundancy protection,parity check protection,and inverse S-box detection can effectively resist biased fault attacks.Therefore,this paper suggests adding time redundancy protection,inverse S-box check,or parity check protection measures to the AES encryption algorithm to protect it from the threat of biased fault attacks.
Keywords/Search Tags:biased fault, AES, fault attack, clock glitch
Related items