A Correlation Fault Attack on Rotating S-Box Masking AES
Xingxin Wang, Jian Ying Zheng, Lingjuan Wu, Jiacheng Zhu, Wei Hu · 2021
Masking is a commonly used countermeasure for protecting cryptographic implementations from power side channel analysis. Rotating S-Box masking (RSM) is a state-of-the-art masking technique, whose effectiveness has been testified in ongoing worldwide DPA contest. However, masking does not provide sufficient protection against active side channel attacks through fault injection. In this paper, we propose a simple yet effective correlation fault attack on two generations of RSM AES schemes. We demonstrate through mathematical formulations that the random offset and shuffles in RSM do not affect fault fusion. Round keys can be recovered by leveraging the strong linear correlation in fault effects at multiple locations. Experimental results have demonstrated that random fault injections in the penultimate and antepenultimate rounds allow full recovery of the last round key with two correct-faulty ciphertext pairs or four faulty ciphertexts under the same plaintext. Our method has a key search complexity of 216and eliminates the time-consuming fault attack template or model training process.