Abstract
Проводится анализ двух атак на шифр Кузнечик методом искажений. Показано, что если атакующий может искажать случайный байт в 7-м и 8-м раундах, то с помощью разностного метода он может найти ключ, используя в среднем 4 искажения. Другая атака относится к случаю, когда шифр имеет секретный S-бокс, и позволяет в модели искажений типа залипания байта на 0 восстанавливать как ключ, так и параметры секретного S-бокса. Это показывает необходимость защиты схемной и программной реализаций нового стандарта даже в случае применения секретного S-бокса.We present two fault analysis attacks on the new cipher Kuznyechik. In the differential fault attack the attacker is assumed to be able to fault a random byte in rounds seven and eight. It enables the attacker to recover the master key using an average of four faults. Another attack considers the cipher with a secret S-box. Utilizing an ineffective fault analysis in the byte stuck-at-zero fault model, we present an attack to recover both the master key and the secret S-box parameters. Both attacks demonstrate the importance of protecting the hardware and software implementations of the new standard even if its S-box is kept secret.
Cite
CITATION STYLE
AlTawy, R., Duman, O., & Youssef, A. M. (2016). Fault analysis of Kuznyechik. Математические Вопросы Криптографии, 7(2), 21–34. https://doi.org/10.4213/mvk180
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.