Further Improved Deep Differential Fault Analysis on Camellia

Zhao Xinjie, Wang Tao, Guo Shize · 2012

This paper presents a further improved deep differential fault analysis (DFA) on Camellia. The proposed method can extend the single byte based fault depth into the r-2thround, recover full 8 bytes of the rth round equivalent key, 5-6 bytes of the r-1thround equivalent key, and 1 byte of the r-2thround equivalent key at one time. Experimental results show that: due to the Feistel structure and permutation function design, Camellia is vulnerable to deep DFA attack. 4 and 20 faulty ciphertexts can reduce the key space of Camellia-128 and Camellia-192/256 to 222.2and 221.2respectively.

Read the paper · More papers on PaperTik