SSFA: Subset fault analysis of ASCON-128 authenticated cipher. (August 2021)
- Record Type:
- Journal Article
- Title:
- SSFA: Subset fault analysis of ASCON-128 authenticated cipher. (August 2021)
- Main Title:
- SSFA: Subset fault analysis of ASCON-128 authenticated cipher
- Authors:
- Joshi, Priyanka
Mazumdar, Bodhisatwa - Abstract:
- Abstract: Present-day IoT systems that capture, process, and transfer real-world data, employ lightweight ciphers in sensor devices for applications with multiple limitations, such as restricted size, power consumption, and processing speed. The largest security threat that such devices incur comprises implementation-based attacks, such as fault attacks, power analysis attacks, etc. Therefore, it is imperative to perform a meticulous security evaluation of lightweight ciphers against such implementation attacks. This paper aims at evaluating the security of ASCON against fault analysis attacks. ASCON is an authenticated cipher, the CAESAR competition winner under lightweight use case portfolio, in February 2019. The use of 128-bit random nonce as part of the input state makes the cipher resistant against classical cryptanalysis techniques such as differential cryptanalysis, linear cryptanalysis, and variants. However, the key whitening operation with the finalization stage's output to produce the tag T (a publicly available value) creates an attack path for an adversary. Based on this vulnerability, we propose a key recovery attack called Preliminary attack, in which we discuss three methods to mount the proposed Preliminary attack. Furthermore, the S-box used in ASCON possesses a component function with zero correlation immunity that renders it vulnerable against subset cryptanalysis. We propose a novel key recovery attack: Subset fault analysis (SSFA) attack that exploitsAbstract: Present-day IoT systems that capture, process, and transfer real-world data, employ lightweight ciphers in sensor devices for applications with multiple limitations, such as restricted size, power consumption, and processing speed. The largest security threat that such devices incur comprises implementation-based attacks, such as fault attacks, power analysis attacks, etc. Therefore, it is imperative to perform a meticulous security evaluation of lightweight ciphers against such implementation attacks. This paper aims at evaluating the security of ASCON against fault analysis attacks. ASCON is an authenticated cipher, the CAESAR competition winner under lightweight use case portfolio, in February 2019. The use of 128-bit random nonce as part of the input state makes the cipher resistant against classical cryptanalysis techniques such as differential cryptanalysis, linear cryptanalysis, and variants. However, the key whitening operation with the finalization stage's output to produce the tag T (a publicly available value) creates an attack path for an adversary. Based on this vulnerability, we propose a key recovery attack called Preliminary attack, in which we discuss three methods to mount the proposed Preliminary attack. Furthermore, the S-box used in ASCON possesses a component function with zero correlation immunity that renders it vulnerable against subset cryptanalysis. We propose a novel key recovery attack: Subset fault analysis (SSFA) attack that exploits the vulnerable S-box. Both the proposed attacks can be mounted with different granularities and can uniquely determine the key of full-round ASCON. We also discuss some probable countermeasures to throttle the proposed attacks. Particularly, we recommend an S-box mapping that is resistant to the proposed attack. The recommended S-box preserves all other essential cryptographic properties of the original S-box used in ASCON. Highlights: The paper accomplishes a fault-based attack that exploits a fault-based vulnerability in the ASCON block cipher. We propose a novel attack called subset fault analysis (SSFA) that combines subset cryptanalysis with fault analysis. The work quantifies the number of queries required to recover the key of ASCON cipher in both types of attacks. We present a modified S-box, immune to the entire class of 1-bit SSFA attacks, keeping all cryptographic properties intact. … (more)
- Is Part Of:
- Microelectronics and reliability. Volume 123(2021)
- Journal:
- Microelectronics and reliability
- Issue:
- Volume 123(2021)
- Issue Display:
- Volume 123, Issue 2021 (2021)
- Year:
- 2021
- Volume:
- 123
- Issue:
- 2021
- Issue Sort Value:
- 2021-0123-2021-0000
- Page Start:
- Page End:
- Publication Date:
- 2021-08
- Subjects:
- Authenticated encryption -- ASCON -- Subset cryptanalysis -- Fault analysis -- Bit set-reset fault
Electronic apparatus and appliances -- Reliability -- Periodicals
Miniature electronic equipment -- Periodicals
Appareils électroniques -- Fiabilité -- Périodiques
Équipement électronique miniaturisé -- Périodiques
Electronic apparatus and appliances -- Reliability
Miniature electronic equipment
Periodicals
621.3815 - Journal URLs:
- http://www.sciencedirect.com/science/journal/00262714 ↗
http://www.elsevier.com/journals ↗
http://www.elsevier.com/homepage/elecserv.htt ↗ - DOI:
- 10.1016/j.microrel.2021.114155 ↗
- Languages:
- English
- ISSNs:
- 0026-2714
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 5758.979000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 17783.xml