...
首页> 外文期刊>Journal of cryptographic engineering >Multi-level formal verification A new approach against fault injection attack
【24h】

Multi-level formal verification A new approach against fault injection attack

机译:多层次的形式验证一种针对故障注入攻击的新方法

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Fault injection attack is an extremely powerful technique to extract secrets from an embedded system. Since their introduction, a large number of countermeasures have been proposed. Unfortunately, they suffer from two major drawbacks: a very high cost on system performance and a security frequently questioned. The first point can be explained by their design, based on techniques from reliability domain, which result in solutions protecting against fault models either highly improbable in a context of attack, or that do not permit secret extraction. At the opposite, the second point is due to the use of an incomplete attacker model for the security evaluation at design step. In this paper, we propose a new approach: multi-level formal verification, based on models encompassing the capabilities of the attacker, the susceptibility to faults of the hardware platform hosting the implementation, and the constraints imposed by the algorithm used for secret extraction. We first explain that the success of a fault injection attack depends solely on races between signals, which can be analyzed automatically. Then, we perform a multi-level evaluation on a hardware implementation of AES-128, which shows that the overhead of a countermeasure can be divided by eight while maintaining an almost identical level of security. Finally, we extend the model to electromagnetic injection.
机译:故障注入攻击是从嵌入式系统中提取秘密的极其强大的技术。自从引入以来,已经提出了许多对策。不幸的是,它们遭受两个主要缺点:系统性能的很高成本和经常受到质疑的安全性。可以通过基于可靠性域技术的设计来解释第一点,这将导致解决方案可以防御故障模型,这些模型在攻击的情况下极不可能发生,或者不允许秘密提取。相反,第二点是由于在设计步骤使用了不完整的攻击者模型进行安全评估。在本文中,我们提出了一种新方法:基于包含攻击者能力,托管实现的硬件平台的故障敏感性以及用于秘密提取的算法所施加的约束的模型,进行多层次形式验证。我们首先解释故障注入攻击的成功仅取决于信号之间的竞争,可以自动对其进行分析。然后,我们对AES-128的硬件实现进行了多级评估,这表明对策的开销可以除以八,同时保持几乎相同的安全级别。最后,我们将模型扩展到电磁注入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号