2012 · 21 citations · 7 references
EngineeringInformation SecurityBlock CipherSoftware AnalysisReliability EngineeringFault AnalysisSystems EngineeringHash AlgorithmCryptanalytic AttackCryptanalysisData Encryption StandardKeyed Hash FunctionComputer EngineeringComputer ScienceCompression StepData SecurityCryptographySoftware TestingDifferential Fault AnalysisFault AttackFault Injection
This paper presents a DFA on Grøstl-256, a hash algorithm that imitates the main structures of AES. Although our attack is inspired by the classical fault attacks on AES these could not be adapted directly. The attack is able to completely recover the whole input message using a one-bit and a random-byte fault model. It needs 16 errors to invert the output transformation Ω <sub xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">n</sub> and on average 280 errors for each compression step. When Grøstl is used in a keyed hash function like HMAC, this attack is able to retrieve the secret key from about 300 faulty outputs in less than three minutes.
7
The Sorcerer's Apprentice Guide to Fault Attacks
Hagai Bar-El, Hamid Choukri, David Naccache et al. · Proceedings of the IEEE · 2006 · 720 citations
DFA Mechanism on the AES Key Schedule
Junko Takahashi, Toshinori Fukunaga, K. Yamakoshi · 2007 · 65 citations
Hardware Security, Dfa Mechanism, Data Encryption Standard +11
On Corrective Patterns for the SHA-2 Family.
Philip Hawkes, Michael Paddon, Gregory G. Rose · IACR Cryptology ePrint Archive · 2004 · 45 citations