Protecting symmetric encryption devices against multiple fault injections

Pierre-Antoine Tissot · theses.fr (ABES) · 2023

Fault injection attacks are one of the main threats to encryption algorithms embedded in hardware targets. These attacks are based on fault injections, carried out using physical threats, which disrupt the operation of the encryption. These injections, coupled with analyses of the disruptions caused, can enable an adversary to recover information from the system. Several defense solutions against these attacks already exist, based mainly on redundancy applied to the encryption, to prevent the adversary from disrupting the operation without being detected. However, in the context of lightweight cryptography, these countermeasures are costly to implement. This thesis will continue the study of these countermeasures against fault injections, by taking a stand on countermeasures applied at the level of the cryptographic primitive, in order to make these solutions generalizable to all implementations, with a focus on the additional cost generated by these countermeasures. Firstly, an improvement to a countermeasure based on the principle of code abiding is proposed. This countermeasure, based on an error detection code, is generalized with an example to show how it can be applied to any encryption algorithm. Next, a substitution box classification method (used for the non-linear layer of block ciphers) is introduced. This method, based on equivalence relations, will enable a cryptographic primitive designer to optimize his choice of S-box, maintaining good cryptographic properties while reducing the hardware implementation cost of the S-box. Finally, a brand new countermeasure designed to counter analyses based on persistent fault injections on the S-box of an encryption is presented. This countermeasure, which focuses on the permutation properties of a substitution box, enables 100% detection of faults that could be exploited by an attacker seeking to apply a persistent fault analysis proposed in the literature. A physical implementation proposal is also given to limit the extra cost generated by this countermeasure while maintaining a high level of security.

Read the paper · More papers on PaperTik