A recent paper by Bathe et al. proposed a differential fault injection attack on the stream cipher Espresso. The authors claimed that the injection of 4 random faults in the internal state was enough for state recovery. In this article we present an improved implementation of their technique - with modifications in both the pre-processing and the online phases. As a result we report internal state recovery of Espresso using only 3 injected faults in comparable time. Our experimental data also leads to some interesting observations regarding the dependence of the stages of the Espresso state.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Improved Differential Fault Attack on the Stream Cipher Espresso

  • Debendranath Das,
  • Anirban Ghatak,
  • Indivar Gupta,
  • Sabyasachi Karati,
  • Arindam Mandal

摘要

A recent paper by Bathe et al. proposed a differential fault injection attack on the stream cipher Espresso. The authors claimed that the injection of 4 random faults in the internal state was enough for state recovery. In this article we present an improved implementation of their technique - with modifications in both the pre-processing and the online phases. As a result we report internal state recovery of Espresso using only 3 injected faults in comparable time. Our experimental data also leads to some interesting observations regarding the dependence of the stages of the Espresso state.