• DocumentCode
    571472
  • Title

    Combined Fault and Side-Channel Attacks on the AES Key Schedule

  • Author

    Dassance, François ; Venelli, Alexandre

  • Author_Institution
    Inside Secure, Rousset, France
  • fYear
    2012
  • fDate
    9-9 Sept. 2012
  • Firstpage
    63
  • Lastpage
    71
  • Abstract
    We present combined attacks on the AES key schedule based on the work of Roche et al. [1]. The main drawbacks of the original attack are: the need for high repeatability of the fault, a very particular fault model and a very high complexity of the key recovery algorithm. We consider more practical fault models, we obtain improved key recovery algorithms and we present more attack paths for combined attacks on AES. We propose to inject faults on the different operations of the key schedule instead of the key state of round 9 or the corresponding data state. We also consider fault injections in AES constants such as the RCon or the affine transformation of the SubWord. By corrupting these constants, the attacker can easily deduce the value of the error. The key recovery complexity can then be greatly improved. Notably, we can obtain a complexity identical to a classical differential side-channel attack. Our attacks defeat most AES implementations secure against both high-order side-channel attacks and fault attacks.
  • Keywords
    cryptography; fault diagnosis; AES key schedule; advanced encryption standard; combined fault and side-channel attacks; fault attacks; high repeatability; Circuit faults; Complexity theory; Computational modeling; Cryptography; Equations; Mathematical model; Schedules; AES; Combined attack; Fault analysis; Side-channel analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Fault Diagnosis and Tolerance in Cryptography (FDTC), 2012 Workshop on
  • Conference_Location
    Leuven
  • Print_ISBN
    978-1-4673-2900-2
  • Type

    conf

  • DOI
    10.1109/FDTC.2012.10
  • Filename
    6305230