Differential Fault Analysis on Grøstl
Wieland Fischer, Christian A. Reuter · 2012
This paper presents a DFA on Grøstl-256, a hash algorithm that imitates the main structures of AES. Although our attack is inspired by the classical fault attacks on AES these could not be adapted directly. The attack is able to completely recover the whole input message using a one-bit and a random-byte fault model. It needs 16 errors to invert the output transformation Ωnand on average 280 errors for each compression step. When Grøstl is used in a keyed hash function like HMAC, this attack is able to retrieve the secret key from about 300 faulty outputs in less than three minutes.