A Severe Vulnerability and an Effective Defense Against DFA on Ascon
Smita Das, Amit Jana, Debdeep Mukhopadhyay · ACM Transactions on Embedded Computing Systems · 2025
Differential Fault Attack ( DFA ) is a powerful cryptanalytic technique for recovering cryptographic keys by exploiting computational faults. At Indocrypt 2024, the first DFA on Ascon was introduced using a bit-flip fault model to recover a 64-bit key, followed by a bit-set fault model to extract another 64-bit key. However, this attack lacked practical validation. In this work, we revisit their approach and extend it by generalizing the attack to a more practical and widely accepted random fault model. Given that Ascon is implemented using bit-sliced techniques, we validate our attack through real-world experiments on a ChipWhisperer Lite platform using clock glitching. We demonstrate that the structure of Ascon inherently transforms random register faults into single-bit differences within the S-box operation, making it susceptible to DFA . We evaluate our attack under both nonce-misuse and nonce-respecting scenarios. In the nonce-misuse setting, we recover the first 64-bit key with only 50 random register faults and estimate the fault requirements for key recovery in the nonce-respecting case. Additionally, we identify a structural weakness in the Ascon tag selection process that increases its susceptibility to difference-based fault attacks. To counter this vulnerability, we propose an immediate countermeasure to strengthen its resistance against DFA .