Principle of a Kind of Differential Fault Analysis on AES-128
Shen Jing · Jisuanji gongcheng · 2006
The principle of a kind of differential fault analysis on AES-128 is described.The attacking algorithm is given.The probability of accomplishing the algorithm is analyzed.The intermediate encrypted result M9 is obtained by the algorithm,the last round key of AES-128 can be deduced from M9 and a correct cipher text,the initial key of AES-128 is then recovered.The result of software emulation shows that if one induces 140 bit faults into M9 repeatedly and randomly,the probability of recovering the initial key is more than 90%,when physical techniques are available.It is presented that AES with CBC mode can counter the attack mentioned above.