New Fault-Based Physical Attacks and Their Countermeasures

Li Yang · Institutional Repositories DataBase (IRDB) · 2012

With IC card as a representative, the systems with built-in cryptographic functions have been widely used in security sensitive applications. The security of these devices is threatened by the cryptanalytic attacks from both the mathematical and physical approaches. The physical cryptanalytic attacks mainly consist of the side-channel analysis and the fault analysis. This work focuses on the security evaluation against the fault-based attacks that use intentionally injected faults to exploit the secret. Specifically, this work is dedicated to the non-invasive fault injections, which are feasible using off-the-shelf equipments and leave almost no attack evidence. We introduce several new perspectives to improve the security evaluation against the fault analysis. First, we consider the injected fault as a special fault-based information leakage and evaluate it from an information theoretic approach. Second, instead of considering the fault injection as a 1-bit information, i.e. injected or not, we consider the fault injection can be applied with various intensities. By doing so, we extend the fault-based leakage, find new vulnerabilities and propose new fault-based attacks and their countermeasures The detailed contributions of this thesis are summarized as follows. 1. In the perspective of the attackers, we attempt to use fault injections to recover the secret information for Advanced Encryption Standard (AES) that is currently a world-widely standardized block cipher. We propose a method to evaluate the vulnerability quantitatively by deriving the information-theoretic maximum amount of information leakage for fault injections. The fault-based attacks are categorized as active attacks since some computational faults are required to be injected to retrieve the secret internal information, e.g., secret key of ciphers. Here, we consider Differential Fault Analysis (DFA) attacks as equivalent to a special kind of passive attack where attackers can obtain leaked information without measurement noise. The DFA attacks are regarded as a conversion process from the leaked information to the secret key. Each fault model defines an upper bound for the amount of leaked information. The optimal DFA attacks should be able to fully exploit the leaked information for the key retrieval and have a practical level of computational complexity. We review several DFA attacks on AES variants to check the optimality of them. 2. By considering the fault injections can be performed with various intensities, we extend the leakage for fault analyses and propose several new fault-based attacks. Based on these new fault-based attacks, we demonstrate that several fault-resistant implementations are not secure enough as believed. Specifically, the following evaluation results are obtained. (a) For the countermeasures that conceal the faulty output, which is resistant against the DFA attacks, we propose fault sensitivity analysis (FSA) that can invalidate this countermeasure. Unlike most existing fault-based attacks including the DFA attack, the proposed FSA attack does not use the values of faulty outputs. In the FSA attack, fault injections are used to test out the sensitive information leakage called fault sensitivity. The FSA attack assumes that attackers are in physical possession of the cryptographic device and they can repeat the same calculation under a controlled faulty environment. By repeatedly testing the behavior of the device under different fault injection intensities, attackers can obtain the critical fault injection intensity corresponding to the threshold between the device’s normal and abnormal behaviors. Then the attackers store the fault sensitivity (FS) data as the pair of the critical fault injection intensity and the corresponding public values, e.g., the ciphertext. We explain that the fault sensitivity exhibits sensitive-data dependency and it can be used to retrieve the secret key. We verify and apply the proposed attacks to various cryptosystems including several hardware implementations of AES even with physical attack countermeasures and an implementation of Elliptic Curve Cryptography (ECC). (b) For AES, when the attackers cannot precisely control the timing of fault injections and difficult to arbitrarily set the input, we show there is still a risk of key recovery for the fault-based attacks. In this work, we consider the faulty output value under a certain fault injection intensity as a new type of leakage called faulty behavior. We show that the faulty behavior depends on the processed data and we propose a related fault analysis called fault behavior analysis (FBA). The proposed FBA attack is verified based on a non-countermeasure AES implementation and two other AES implementations with masking countermeasures. We extend the FBA attack and propose a non-uniform faulty value analysis (NU-FVA) that can recover the key without repeatedly using the same input. This can be achieved by observing the fault behavior for a set of random inputs instead of observing the fault behavior for a fixed input. For the security of block ciphers, an S-box mapping is designed to be a uniform function. However, the uniform mapping cannot hold when the S-box is in a faulty environment. We revisit the leakage from fault-based attacks considering that the S-box mapping becomes a non-uniform function. Take the AES using composite field based S-box as a case study, we verify our proposal based on theoretical modelling, circuit delay simulations and clockglitch based experiments. We demonstrate the vulnerability against fault injections without any access to the input and without complex requirements for the injected faults. 3. Finally, with the proposed fault analyses 2(a) and 2(b) in consideration, a highly fault-resistant countermeasure for AES is proposed. Our countermeasure is based on preventing attackers from getting the access of the fault-based leakage. For example, we use the enable signal to hide the fault sensitivity and use the random number to hide the intermediate calculation result. The series of studies contribute the enhancement of security evaluation for cryptographic systems against the fault-based physical attacks. The correct evaluation of the leakage and the discovery of new leakage can help to understand the potential vulnerabilities, and finally help to achieve more effective countermeasures.

Read the paper · More papers on PaperTik