AI 中文总结
本文提出基于混合整数线性规划(MILP)的DFA框架,可攻击更深轮次并减少故障注入次数,还能确定高效故障注入位置,对DEFAULT算法可通过特定轮次的故障注入将密钥空间缩至1。
AI 中文摘要
2021年亚洲密码学会议(ASIACRYPT 2021)上,Baksi等人提出了DEFAULT算法,这是一种旨在通过算法设计抵抗差分故障攻击(DFA)的分组密码,声称无论注入多少个故障,都能达到64位的DFA安全性。2022年欧洲密码学会议(EUROCRYPT 2022)上,Nageler等人证明DEFAULT声称的DFA抗性可通过应用信息组合技术被破解。更近的2024年亚洲密码学会议(ASIACRYPT 2024)上,Jana等人改进了DFA,通过搜索具有单个解的差分轨迹,他们表明对于密钥调度简单的DEFAULT,在倒数第五轮注入5个故障可将密钥空间缩小至1;而对于BAKSHEESH算法,在倒数第三轮注入12个故障可达到相同效果。本文提出一种利用混合整数线性规划(MILP)求解器的新型DFA框架,该框架可攻击比以往更深的轮次,减少密钥恢复所需的故障注入次数;此外,本文提出一种方法,通过系统分析所有可能的单比特翻转故障的输入差异,确定最高效的故障注入比特位置,进一步减少所需故障数量,这种系统分析的显著优势在于可理论计算所需故障数量。应用本文框架,对DEFAULT算法,在倒数第六轮注入3个故障、倒数第七和第八轮各注入2个故障,即可将密钥空间缩小至1。
英文摘要
At ASIACRYPT 2021, Baksi et al. introduced DEFAULT, a block cipher designed to algorithmically resist Differential Fault Attack (DFA), claiming 64-bit DFA security regardless of the number of injected faults. At EUROCRYPT 2022, Nageler et al. demonstrated that DEFAULT's claimed DFA resistance can be broken by applying an information-combining technique. More recently, at ASIACRYPT 2024, Jana et al. improved DFA by searching for differential trails with a single solution. They showed that, for DEFAULT with a simple key schedule, injecting five faults at the fifth-to-last round reduces the key space to one, and for BAKSHEESH, injecting twelve faults at the third-to-last round achieves the same result. In this paper, we propose a new DFA framework that utilizes a Mixed-Integer Linear Programming (MILP) solver. This framework makes it possible to attack deeper rounds than previously achieved, reducing the number of fault injections required for key recovery. Furthermore, we present a method to determine the most efficient fault injection bit positions by systematically analyzing the input differences from all possible single bit-flip faults, thereby further reducing the required number of faults. This systematic analysis has the significant advantage of allowing us to theoretically calculate the required number of faults. Applying our framework, for DEFAULT, injecting three faults at the sixth-to-last round and two faults at the seventh- and eighth-to-last rounds reduces the key space to one.
Comments24 pages, 2 figures
Journal refIACR Transactions on Cryptographic Hardware and Embedded Systems, Vol. 2026, No. 3, pp. 465-488, 2026
DOI:10.46586/tches.v2026.i3.465-488