Differential fault analysis on the SMS4 cipher by inducing faults to the key schedule
|更新时间:2024-10-14
|
Differential fault analysis on the SMS4 cipher by inducing faults to the key schedule
Issue 10, Pages: 135-142(2008)
作者机构:
上海交通大学计算机科学与工程系
作者简介:
基金信息:
DOI:
CLC:TP309.7
Published:2008
稿件说明:
移动端阅览
LI Wei, GU Da-wu. Differential fault analysis on the SMS4 cipher by inducing faults to the key schedule[J]. 2008, (10): 135-142.
DOI:
LI Wei, GU Da-wu. Differential fault analysis on the SMS4 cipher by inducing faults to the key schedule[J]. 2008, (10): 135-142.DOI:
Differential fault analysis on the SMS4 cipher by inducing faults to the key schedule
摘要
提出并讨论了一种针对SMS4密钥编排方案的差分故障攻击方法。该方法采用面向字节的随机故障模型
通过在SMS4算法的密钥编排方案中导入故障
仅需要8个错误密文即可恢复SMS4算法的128bit原始密钥。数学分析和实验结果表明
该方法不仅扩展了故障诱导的攻击范围
而且提高了故障诱导的攻击成功率
减少了错误密文数
为故障攻击其他分组密码提供了一种通用的分析手段。
Abstract
On the basis of the byte-oriented fault model and the differential analysis
a differential fault analysis on the SMS4 cipher by inducing faults in its key schedule was proposed.Mathematical analysis and simulating experiment show that the attack could recover its 128-bit secret key by introducing only eight faulty ciphertexts.Simultaneously
a method of distinguishing effective faults was presented to increase the efficiency of fault injection and decrease the num-ber of faulty ciphertexts.Thus
experiment results are beneficial to the analysis of other iterated block ciphers.