引用本文:李玮,秦梦洋,谷大武,连晟,温云华.基于代数关系的轻量级密码DEFAULT统计故障分析.软件学报,2025,36(5):2270-2287
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 1121次   下载 2867 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于代数关系的轻量级密码DEFAULT统计故障分析
李玮1,2,3,4, 秦梦洋1, 谷大武2, 连晟1, 温云华1
1.东华大学 计算机科学与技术学院, 上海 201620;2.上海交通大学 计算机科学与工程系, 上海 200240;3.上海市可扩展计算与系统重点实验室 (上海交通大学), 上海 200240;4.上海市信息安全综合管理技术研究重点实验室 (上海交通大学), 上海 200240
摘要:
DEFAULT是于2021年亚洲密码学年会中提出的一种新型轻量级密码算法, 适用于保护物联网中的微型芯片、微控制器和传感器等设备的信息安全. 基于唯密文的基本假设, 针对DEFAULT密码提出了一种基于代数关系的统计故障分析方法. 该方法使用随机半字节故障模型, 通过对代数关系的构造分析并结合故障注入前后中间状态的统计分布变化来破译密码. 此外, 采用AD检验-平方欧氏距离(AD-SEI)、AD检验-极大似然估计(AD-MLE)和AD检验-汉明重量(AD-HW)等新型区分器, 最少仅需1344个故障即可以99%及以上的成功率破解该算法的128比特原始密钥. 理论分析和实验结果表明, DEFAULT密码不能抵抗基于代数关系的统计故障分析的攻击. 该研究为其他轻量级分组密码算法的安全性分析提供了有价值的参考.
关键词:  DEFAULT  轻量级密码系统  密码分析  统计故障分析  代数关系
DOI:10.13328/j.cnki.jos.007210
分类号:TP309
基金项目:国家重点研发计划(2020YFA0712300); 国家自然科学基金(62172395, 62102077, 62072307); 上海市扬帆计划(21YF1401200); 中央高校基本科研业务费专项资金(223202D-25)
DEFAULT Lightweight Cryptosystem Against Statistical Fault Analysis Based on Algebraic Relationship
LI Wei1,2,3,4, QIN Meng-Yang1, GU Da-Wu2, LIAN Sheng1, WEN Yun-Hua1
1.School of Computer Science and Technology, Donghua University, Shanghai 201620, China;2.Department of Computer Science and Engineering, Shanghai Jiao Tong University, Shanghai 200240, China;3.Shanghai Key Laboratory of Scalable Computing and Systems (Shanghai Jiao Tong University), Shanghai 200240, China;4.Shanghai Key Laboratory of Integrate Administration Technologies for Information Security (Shanghai Jiao Tong University), Shanghai 200240, China
Abstract:
DEFAULT, a new lightweight cryptosystem presented at Asiacrypt in 2021, is designed to protect the information security of Internet of Things (IoT) devices, such as microchips, microcontrollers, and sensors. Based on the ciphertext-only attack assumption, the statistical fault analysis of the DEFAULT cipher with the algebraic relationship is proposed. The statistical fault analysis uses the random nibble-oriented fault model. It not only combines statistical distributions of the intermediate states before and after the fault injections but also takes advantage of the algebraic relationship and novel distinguishers, including Anderson Darling test-square Euclidean imbalance (AD-SEI), Anderson Darling test-maximum likelihood estimate (AD-MLE), and Anderson Darling test-Hamming weight (AD-HW). The analysis requires at least 1344 faults to achieve the reliability of 99% in the recovery of the 128-bit secret key of DEFAULT. The theoretical analysis and experimental results show that the DEFAULT lightweight cryptosystem is not resistant to the statistical fault attack based on the algebraic relationship. This study provides an important reference for the security analysis of the other lightweight cryptosystems.
Key words:  DEFAULT  lightweight cryptosystem  cryptanalysis  statistical fault analysis  algebraic relationship

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: