用深度学习提升轻量级流密码的故障攻击效率,精准定位故障点并减少破解所需次数。
Deep Learning-Assisted Improved Differential Fault Attacks on Lightweight Stream Ciphers
- 用多层感知机识别未知位置的单比特故障,准确率超99%。
- 对ACORN和MORUS的密钥恢复只需21至248次故障注入,复杂度更低。
- 首次实现对ATOM的差分故障攻击实验,揭示其更强的安全性。
轻量级密码原语广泛部署于资源受限环境,尤其在物联网设备中。由于其公开可访问性,这些设备易受物理攻击,尤其是故障攻击。近年来,基于深度学习的密码分析技术表现优异,但其在故障攻击中的应用仍有限,尤其针对流密码。本文研究了在单比特翻转故障注入且位置未知的宽松模型下,对三种轻量级流密码——ACORNv3、MORUSv2和ATOM——进行深度学习辅助的差分故障攻击的可行性。我们构建并训练了多层感知机(MLP)模型以识别故障位置,实验表明,各模型对ACORNv3、MORUSv2和ATOM的识别准确率分别为0.999880、0.999231和0.823568,显著优于传统签名方法。在密钥恢复阶段,引入阈值法优化故障注入次数:ACORN的初始状态可在21至34次故障下恢复,而MORUS需213至248次,最多猜测6位;两攻击均降低复杂度。对于ATOM,结果表明其具备更高安全边际,多数非线性反馈移位寄存器(NFSR)状态位仅在精确控制模型下可恢复。据我们所知,本工作首次提供了对ATOM的差分故障攻击实验结果。
原文摘要 · Abstract (English)
Lightweight cryptographic primitives are widely deployed in resource-constrained environments, particularly in Internet of Things (IoT) devices. Due to their public accessibility, these devices are vulnerable to physical attacks, especially fault attacks. Recently, deep learning-based cryptanalytic techniques have demonstrated promising results; however, their application to fault attacks remains limited, particularly for stream ciphers. In this work, we investigate the feasibility of deep learning assisted differential fault attacks on three lightweight stream ciphers, namely ACORNv3, MORUSv2, and ATOM, under a relaxed fault model in which a single-bit bit-flipping fault is injected at an unknown location. We develop and train multilayer perceptron (MLP) models to identify the fault locations. Experimental results show that the trained models achieve high identification accuracies of 0.999880, 0.999231, and 0.823568 for ACORNv3, MORUSv2 and ATOM, respectively, and outperform traditional signature-based methods. For the secret recovery process, we introduce a threshold-based method to optimize the number of fault injections required to recover the secret information. The results show that the initial state of ACORN can be recovered with 21 to 34 faults, while MORUS requires 213 to 248 faults, with at most 6 bits of guessing. Both attacks reduce the attack complexity compared to existing works. For ATOM, the results show that it possesses a higher security margin, as the majority of state bits in the Nonlinear Feedback Shift Register (NFSR) can only be recovered under a precise control model. To the best of our knowledge, this work provides the first experimental results of differential fault attacks on ATOM.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。