⚡ 本页包含 AI 生成的分析内容,仅供参考
该论文提出了一种在Intel 4 CMOS工艺上实现的抗故障注入攻击的AES-256引擎,通过创新的错误检测机制实现了99.1%至99.99%的错误覆盖率,解决了传统冗余计算和线性校验器在非线性Sbox逆操作中覆盖率不足的问题。该引擎在100Gbps吞吐量下有效抵御差分故障分析攻击。
from cryptographic engines to extract secret keys. A single fault injected into the penultimate AES round using directed laser pulses or voltage/clock glitches corrupts 4 output bytes (Fig. 15.5.1), reducing key search space to a single guess with differential fault analysis (DFA) on 8 exploitable ciphertexts. FI countermeasures using redundant concurrent/time-interleaved computations incur 2× area/performance overheads [1,3]. Conventional linear parity checkers [2] provide insufficient fault coverage due to the non-linear characteristics of Sbox inverse operations. FI detection-based countermeasures, employing source-specific detectors such as substrate-current sensors [4] for laser attacks and frequency-locked loops [5] to detect clock glitches, respectively are ineffective against generic FI attacks.
Raghavan Kumar1, Avinash Varna2, Carlos Tokunaga1, Sachin Taneja1,
Vivek De1, Sanu Mathew1 Intel, Hillsboro, OR Intel, Chandler, AZ 1 2 Fault-injection (FI) attacks exploit corrupted ciphertexts