维普中文期刊产品整合服务

Fault Analysis on a New Block Cipher DBlock with at Most Two Fault Injections

查看全文 作  者:FENG [1,2]Jingyi;CHEN [1]Hua;GAO [1,2]Si;CAO [1,2]Weiqiong;FAN [1]Limin;ZHU [1,2]Shaofeng 高影响力作者 机构地区:[1]Trusted Computing and Information Assurance Laboratory, Institute of Software Chinese Academy of Sciences, Beijing 100190, China;[2]University of Chinese Academy of Sciences, Beijing 100080, China高影响力机构 出  处:《Chinese Journal of Electronics》索引2018年第27卷第6期,共6页高影响力期刊 基  金:supported by the National Basic Research Program of China(973 Program)(No.2013CB338002) 摘  要:DBlock is a new family of block ciphers proposed by Wu et al. in Science China in 2015, which consists of three variants specified as DBlock-128/192/256.DBlock-n employs a 20-round Feistel-type structure with n-bit block size and n-bit key size. We propose the first fault analysis on DBlock and show that no more than 2 pairs of correct/faulty ciphertexts are needed to retrieve the master key. In the attack, a byte-oriented fault is injected in round 16, and three properties including differential distribution of the Sbox, bijection nature of the linear function and Feistel-type key scheduling are fully utilized to distinguish between the correct and wrong keys. A fault position guessing strategy based on known intermediates is adopted, which efficiently makes the known-fault attack apply to the random fault model. The experimental results show that, with a pair of ciphertexts, 11.820-bit exhaustive search is needed to derive the whole 128-bit key on average. With 2 pairs of ciphertexts, the unique key can be determined within 6.5 minutes. 关 键 词:差错分析 注射 钥匙 体组成 密文 试验性 尺寸 类型
相关文献

参考文献(15)

引证文献(3)

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费