Hard fault analysis of Trivium

Saved in:
Bibliographic Details
Title: Hard fault analysis of Trivium
Authors: Hu, Yu-pu1 yphu@mail.xidian.edu.cn, Zhang, Feng-rong1 zhfl203@163.com, Zhang, Wen-zheng2 zwz85169038@sina.com
Source: Information Sciences. Apr2013, Vol. 229, p142-158. 17p.
Subjects: Stream ciphers, Debugging, Bit allocation analysis, Probability theory, Cyberterrorism, Computer input-output equipment, Information theory
Abstract: Abstract: Fault analysis is an attack on stream ciphers with potential power. Up until now, major efforts on fault analysis have been to simplify the cipher by injecting some soft faults, that is, momentarily changing values of some register bits. We call this soft fault analysis. As a hardware-oriented stream cipher, Trivium is weak under soft fault analysis. In this paper we consider another type of fault analysis. It is to simplify the cipher by injecting some hard faults, that is, permanently setting values of some register bits to be zero. We call this hard fault analysis, and use it to analyze Trivium. We classify the faults positions into seven cases, and in five cases the cipher can be broken or be efficiently simplified. We present the following results about such attack on Trivium. In one case with the probability not smaller than 0.2396, the attacker can obtain 69 bits of the 80-bit key. In another case with the probability not smaller than 0.2292, the attacker can recover the full key. In the third case with the probability not smaller than 0.2292, the attacker can partially solve the key. In the fourth case with non-negligible probability, the attacker can obtain a simplified cipher, with smaller number of state bits and slower non-linearization procedure. In the fifth case with non-negligible probability, the attacker can obtain another simplified cipher. The attacker’s computations are simple and immediate, and the cipher can be broken or be efficiently simplified with the probability not smaller than 0.698. Besides, these five cases can be distinguished by observing the keystream. [Copyright &y& Elsevier]
Copyright of Information Sciences is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 85282146
AccessLevel: 6
PubType: Periodical
PubTypeId: serialPeriodical
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Hard fault analysis of Trivium
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Hu%2C+Yu-pu%22">Hu, Yu-pu</searchLink><relatesTo>1</relatesTo><i> yphu@mail.xidian.edu.cn</i><br /><searchLink fieldCode="AR" term="%22Zhang%2C+Feng-rong%22">Zhang, Feng-rong</searchLink><relatesTo>1</relatesTo><i> zhfl203@163.com</i><br /><searchLink fieldCode="AR" term="%22Zhang%2C+Wen-zheng%22">Zhang, Wen-zheng</searchLink><relatesTo>2</relatesTo><i> zwz85169038@sina.com</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Information+Sciences%22">Information Sciences</searchLink>. Apr2013, Vol. 229, p142-158. 17p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Stream+ciphers%22">Stream ciphers</searchLink><br /><searchLink fieldCode="DE" term="%22Debugging%22">Debugging</searchLink><br /><searchLink fieldCode="DE" term="%22Bit+allocation+analysis%22">Bit allocation analysis</searchLink><br /><searchLink fieldCode="DE" term="%22Probability+theory%22">Probability theory</searchLink><br /><searchLink fieldCode="DE" term="%22Cyberterrorism%22">Cyberterrorism</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+input-output+equipment%22">Computer input-output equipment</searchLink><br /><searchLink fieldCode="DE" term="%22Information+theory%22">Information theory</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Abstract: Fault analysis is an attack on stream ciphers with potential power. Up until now, major efforts on fault analysis have been to simplify the cipher by injecting some soft faults, that is, momentarily changing values of some register bits. We call this soft fault analysis. As a hardware-oriented stream cipher, Trivium is weak under soft fault analysis. In this paper we consider another type of fault analysis. It is to simplify the cipher by injecting some hard faults, that is, permanently setting values of some register bits to be zero. We call this hard fault analysis, and use it to analyze Trivium. We classify the faults positions into seven cases, and in five cases the cipher can be broken or be efficiently simplified. We present the following results about such attack on Trivium. In one case with the probability not smaller than 0.2396, the attacker can obtain 69 bits of the 80-bit key. In another case with the probability not smaller than 0.2292, the attacker can recover the full key. In the third case with the probability not smaller than 0.2292, the attacker can partially solve the key. In the fourth case with non-negligible probability, the attacker can obtain a simplified cipher, with smaller number of state bits and slower non-linearization procedure. In the fifth case with non-negligible probability, the attacker can obtain another simplified cipher. The attacker’s computations are simple and immediate, and the cipher can be broken or be efficiently simplified with the probability not smaller than 0.698. Besides, these five cases can be distinguished by observing the keystream. [Copyright &y& Elsevier]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Information Sciences is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=85282146
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1016/j.ins.2012.12.014
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 17
        StartPage: 142
    Subjects:
      – SubjectFull: Stream ciphers
        Type: general
      – SubjectFull: Debugging
        Type: general
      – SubjectFull: Bit allocation analysis
        Type: general
      – SubjectFull: Probability theory
        Type: general
      – SubjectFull: Cyberterrorism
        Type: general
      – SubjectFull: Computer input-output equipment
        Type: general
      – SubjectFull: Information theory
        Type: general
    Titles:
      – TitleFull: Hard fault analysis of Trivium
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Hu, Yu-pu
      – PersonEntity:
          Name:
            NameFull: Zhang, Feng-rong
      – PersonEntity:
          Name:
            NameFull: Zhang, Wen-zheng
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 20
              M: 04
              Text: Apr2013
              Type: published
              Y: 2013
          Identifiers:
            – Type: issn-print
              Value: 00200255
          Numbering:
            – Type: volume
              Value: 229
          Titles:
            – TitleFull: Information Sciences
              Type: main
ResultId 1