← 返回 JSSC 论文列表
📄 下载 JSSC 原文 PDF
JSSC 2024第1期Clocking & PLLsIntel 4 CMOS

A 100-Gbps Fault-Injection Attack-Resistant AES-256 Engine With 99.1%–99.99% Error Coverage in Intel 4 CMOS

一款抗故障注入攻击的AES-256加密引擎,采用Intel 4 CMOS工艺,实现100Gbps吞吐量和99.1%错误覆盖率。
Intel 4 CMOS, 100Gbps, 99.1% error coverage, 13,400× laser injection margin
故障注入攻击AES-256激光检测奇偶校验加密加速器
算术和基于奇偶校验的检测电路分别检测AES非线性和线性部分的运行时故障
复合域GF(2^4)^2逆校验器和冗余仿射奇偶校验电路
全数字激光检测电路(LDC)提供13,400倍抗激光脉冲注入能力
Abstract
Fault-injection (FI) attacks exploit corrupted ciphertexts from cryptographic hardware to extract the embed- ded secret key using directed laser pulses or voltage/clock glitches. Laser FI attacks mounted on an unprotected fully unrolled advanced encryption standard (AES)-256 engine in Intel 4 CMOS process demonstrate a minimum-time-to- disclosure (MTD) of 6.6 M encryptions to generate eight exploitable ciphertexts, reducing AES key search space to a single guess with differential fault analysis (DFA). In this article, we present a source-agnostic FI-attack-resistant AES-256 accel- erator fabricated in Intel 4 CMOS. Arithmetic and parity-based checker circuits detect runtime faults in the nonlinear and linear portions of AES, respectively. Composite-field GF(2 4)2 inverse checker, redundant affine parity circuits, and byte-interleaved register placement optimizations enable 99.1% error coverage against raster and box-scan laser FI attacks. The AES round datapath augmented with an all-digital laser detection circuit (LDC) provides a 13 400× higher margin for raster-based laser pulse injections. Finally, additional timing slack introduced on the checker datapath enables a 40-mV measured margin on parity predictor paths, ensuring that timing violations are first observed at critical round output bytes, leaving the parity signals uncor- rupted during undervoltage attacks. Intel 4 CMOS measurements show a 0% performance impact from FI countermeasures while providing 111× and 10 000