Abstract
Differential Fault Attack (DFA) is a powerful cryptanalytic technique for recovering cryptographic keys by exploiting computational faults. At Indocrypt 2024, the first DFA on Ascon was introduced using a bit-flip fault model to recover a 64-bit key, followed by a bit-set fault model to extract another 64-bit key. However, this attack lacked practical validation. In this work, we revisit their approach and extend it by generalizing the attack to a more practical and widely accepted random fault model. Given that Ascon is implemented using bit-sliced techniques, we validate our attack through real-world experiments on a ChipWhisperer Lite platform using clock glitching. We demonstrate that the structure of Ascon inherently transforms random register faults into single-bit differences within the S-box operation, making it susceptible to DFA. We evaluate our attack under both nonce-misuse and nonce-respecting scenarios. In the nonce-misuse setting, we recover the first 64-bit key with only 50 random register faults and estimate the fault requirements for key recovery in the nonce-respecting case. Additionally, we identify a structural weakness in the Ascon tag selection process that increases its susceptibility to difference-based fault attacks. To counter this vulnerability, we propose an immediate countermeasure to strengthen its resistance against DFA.
Author supplied keywords
Cite
CITATION STYLE
Das, S., Jana, A., & Mukhopadhyay, D. (2025). A Severe Vulnerability and an Effective Defense Against DFA on Ascon. ACM Transactions on Embedded Computing Systems, 24(5). https://doi.org/10.1145/3762192
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.