Hard fault analysis of Trivium
Saved in:
| Title: | Hard fault analysis of Trivium |
|---|---|
| Authors: | Hu, Yu-pu1 yphu@mail.xidian.edu.cn, Zhang, Feng-rong1 zhfl203@163.com, Zhang, Wen-zheng2 zwz85169038@sina.com |
| Source: | Information Sciences. Apr2013, Vol. 229, p142-158. 17p. |
| Subjects: | Stream ciphers, Debugging, Bit allocation analysis, Probability theory, Cyberterrorism, Computer input-output equipment, Information theory |
| Abstract: | Abstract: Fault analysis is an attack on stream ciphers with potential power. Up until now, major efforts on fault analysis have been to simplify the cipher by injecting some soft faults, that is, momentarily changing values of some register bits. We call this soft fault analysis. As a hardware-oriented stream cipher, Trivium is weak under soft fault analysis. In this paper we consider another type of fault analysis. It is to simplify the cipher by injecting some hard faults, that is, permanently setting values of some register bits to be zero. We call this hard fault analysis, and use it to analyze Trivium. We classify the faults positions into seven cases, and in five cases the cipher can be broken or be efficiently simplified. We present the following results about such attack on Trivium. In one case with the probability not smaller than 0.2396, the attacker can obtain 69 bits of the 80-bit key. In another case with the probability not smaller than 0.2292, the attacker can recover the full key. In the third case with the probability not smaller than 0.2292, the attacker can partially solve the key. In the fourth case with non-negligible probability, the attacker can obtain a simplified cipher, with smaller number of state bits and slower non-linearization procedure. In the fifth case with non-negligible probability, the attacker can obtain another simplified cipher. The attacker’s computations are simple and immediate, and the cipher can be broken or be efficiently simplified with the probability not smaller than 0.698. Besides, these five cases can be distinguished by observing the keystream. [Copyright &y& Elsevier] |
| Copyright of Information Sciences is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 85282146 AccessLevel: 6 PubType: Periodical PubTypeId: serialPeriodical PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Hard fault analysis of Trivium – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Hu%2C+Yu-pu%22">Hu, Yu-pu</searchLink><relatesTo>1</relatesTo><i> yphu@mail.xidian.edu.cn</i><br /><searchLink fieldCode="AR" term="%22Zhang%2C+Feng-rong%22">Zhang, Feng-rong</searchLink><relatesTo>1</relatesTo><i> zhfl203@163.com</i><br /><searchLink fieldCode="AR" term="%22Zhang%2C+Wen-zheng%22">Zhang, Wen-zheng</searchLink><relatesTo>2</relatesTo><i> zwz85169038@sina.com</i> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Information+Sciences%22">Information Sciences</searchLink>. Apr2013, Vol. 229, p142-158. 17p. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Stream+ciphers%22">Stream ciphers</searchLink><br /><searchLink fieldCode="DE" term="%22Debugging%22">Debugging</searchLink><br /><searchLink fieldCode="DE" term="%22Bit+allocation+analysis%22">Bit allocation analysis</searchLink><br /><searchLink fieldCode="DE" term="%22Probability+theory%22">Probability theory</searchLink><br /><searchLink fieldCode="DE" term="%22Cyberterrorism%22">Cyberterrorism</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+input-output+equipment%22">Computer input-output equipment</searchLink><br /><searchLink fieldCode="DE" term="%22Information+theory%22">Information theory</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: Abstract: Fault analysis is an attack on stream ciphers with potential power. Up until now, major efforts on fault analysis have been to simplify the cipher by injecting some soft faults, that is, momentarily changing values of some register bits. We call this soft fault analysis. As a hardware-oriented stream cipher, Trivium is weak under soft fault analysis. In this paper we consider another type of fault analysis. It is to simplify the cipher by injecting some hard faults, that is, permanently setting values of some register bits to be zero. We call this hard fault analysis, and use it to analyze Trivium. We classify the faults positions into seven cases, and in five cases the cipher can be broken or be efficiently simplified. We present the following results about such attack on Trivium. In one case with the probability not smaller than 0.2396, the attacker can obtain 69 bits of the 80-bit key. In another case with the probability not smaller than 0.2292, the attacker can recover the full key. In the third case with the probability not smaller than 0.2292, the attacker can partially solve the key. In the fourth case with non-negligible probability, the attacker can obtain a simplified cipher, with smaller number of state bits and slower non-linearization procedure. In the fifth case with non-negligible probability, the attacker can obtain another simplified cipher. The attacker’s computations are simple and immediate, and the cipher can be broken or be efficiently simplified with the probability not smaller than 0.698. Besides, these five cases can be distinguished by observing the keystream. [Copyright &y& Elsevier] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Information Sciences is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=85282146 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1016/j.ins.2012.12.014 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 17 StartPage: 142 Subjects: – SubjectFull: Stream ciphers Type: general – SubjectFull: Debugging Type: general – SubjectFull: Bit allocation analysis Type: general – SubjectFull: Probability theory Type: general – SubjectFull: Cyberterrorism Type: general – SubjectFull: Computer input-output equipment Type: general – SubjectFull: Information theory Type: general Titles: – TitleFull: Hard fault analysis of Trivium Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Hu, Yu-pu – PersonEntity: Name: NameFull: Zhang, Feng-rong – PersonEntity: Name: NameFull: Zhang, Wen-zheng IsPartOfRelationships: – BibEntity: Dates: – D: 20 M: 04 Text: Apr2013 Type: published Y: 2013 Identifiers: – Type: issn-print Value: 00200255 Numbering: – Type: volume Value: 229 Titles: – TitleFull: Information Sciences Type: main |
| ResultId | 1 |