An Improved Differential Fault Attack on the Stream Cipher Espresso
摘要
A recent paper by Bathe et al. proposed a differential fault injection attack on the stream cipher Espresso. The authors claimed that the injection of 4 random faults in the internal state was enough for state recovery. In this article we present an improved implementation of their technique - with modifications in both the pre-processing and the online phases. As a result we report internal state recovery of Espresso using only 3 injected faults in comparable time. Our experimental data also leads to some interesting observations regarding the dependence of the stages of the Espresso state.