首页> 外文期刊>Information Forensics and Security, IEEE Transactions on >Exploration of Benes Network in Cryptographic Processors: A Random Infection Countermeasure for Block Ciphers Against Fault Attacks
【24h】

Exploration of Benes Network in Cryptographic Processors: A Random Infection Countermeasure for Block Ciphers Against Fault Attacks

机译:密码处理器中Benes网络的探索:针对分组密码器的一种针对故障攻击的随机感染对策

获取原文
获取原文并翻译 | 示例
       

摘要

Traditional detection countermeasures against fault attacks have been criticized as insecure because of the fragile comparison operation that can be maliciously bypassed. In order to avoid the comparison, infection countermeasures have been designed to confuse the faulty ciphertexts so that the output cannot be further explored. This paper presents an infection method that resists fault attacks using the existing Benes network module in high-performance crypto processors. The Benes network is originally used to accelerate permutation operations in block ciphers. The hamming weight of the differential results is balanced by modifying specific network switches, without changing the network topology. A further confusion is performed to destroy the determinacy by configuring part of the network with a random bit-stream. Furthermore, a statistical evaluation method is presented to quantitatively verify the proposed countermeasure in addition to a formal proof of security. This also provides a new concept for the evaluation of future random-enhanced infection methods. Experiments are carried out using Advanced Encryption Standard (AES), triple Data Encryption Standard (DES), and Camellia as examples. Under statistical evaluation, the results show that the proposed countermeasure improves the fault resistance by over four orders of magnitude compared with the unprotected case. Also, the performance and the area overhead are within 10% compared with the original Benes network.
机译:由于脆弱的比较操作会被恶意绕开,因此针对故障攻击的传统检测对策被批评为不安全。为了避免比较,已设计了感染对策以混淆错误的密文,从而无法进一步探索输出。本文提出了一种使用高性能加密处理器中现有的Benes网络模块抵御故障攻击的感染方法。 Benes网络最初用于加速分组密码中的置换操作。通过修改特定的网络交换机,无需更改网络拓扑,就可以平衡差分结果的汉明权重。通过使用随机比特流配置网络的一部分,进一步破坏了确定性。此外,除了正式的安全证明之外,还提出了一种统计评估方法来定量验证所提议的对策。这也为评估未来的随机增强感染方法提供了一个新概念。以高级加密标准(AES),三重数据加密标准(DES)和山茶花为例进行实验。在统计评估下,结果表明,与未保护的情况相比,所提出的对策将故障抵抗力提高了四个数量级。而且,与原始的Benes网络相比,性能和区域开销在10%以内。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号