Controlling Faulty Byte Outputs with IEMI against Cryptographic ICs

Hikaru Nishiyama, Daisuke Fujimoto, Yu‐ichi Hayashi · 2024

Intentional electromagnetic interference (IEMI) for cryptographic integrated circuit (IC) has been reported as a threat for fault injection attack that extracts secret key information by inducing temporary fault in a specific number of bytes in the cryptographic process. And the previous studies on IEMI fault injection have focused on whether it is possible to generate only 1-byte fault, which is necessary for Piret’s Differential Fault Analysis (DFA), a secret key analysis method. On the other hand, some methods have been proposed that use multiple-byte faults to enable secret key analysis even under attack conditions where DFA is difficult to apply. If multiple-byte faults that are applicable to such analysis methods can be generated, the threat of IEMI fault injection may increase. In this paper, we show that the number of faulty bytes can be precisely controlled by varying the parameter of the EM waves injected to the cryptographic IC with high resolution, and that the faults output by IEMI fault injection can be used for analysis methods other than DFA. Specifically, we use impulses as the EM waves, measure the electrical changes that occur in the cryptographic IC when the amplitude and pulse width are manipulated, and investigate the relationship between the number of faulty bytes and the electrical changes.

Read the paper · More papers on PaperTik