Cryptology ePrint Archive: Report 2012/678

Infective Computation and Dummy Rounds: Fault Protection for Block Ciphers without Check-before-Output

Benedikt Gierlichs and Jorn-Marc Schmidt and Michael Tunstall

Abstract: Implementation attacks pose a serious threat for the security of cryptographic devices and there are a multitude of countermeasures that are used to prevent them. Two countermeasures used in implementations of block ciphers to increase the complexity of such attacks are the use of dummy rounds and redundant computation with consistency checks to prevent fault attacks. In this paper we present several countermeasures based on the idea of infective computation. Our countermeasures ensure that a fault injected into a cipher, dummy, or redundant round will infect the ciphertext such that an attacker cannot derive any information on the secret key being used. This has one clear advantage: the propagation of faults prevents an attacker from being able to conduct any fault analysis on any corrupted ciphertexts. As a consequence, there is no need for any test at the end of an implementation to determine if a fault has been injected and a ciphertext can always be returned.

Category / Keywords: implementation / Implementation Attacks, Dummy Rounds, Infective Computation

Publication Info: Published at Latincrypt 2012

Date: received 30 Nov 2012

Contact author: mike tunstall at yahoo co uk

Available format(s): PDF | BibTeX Citation

Note: This is a corrected version eliminating some errors in the proposed algorithms.

Version: 20121201:000848 (All versions of this report)

Discussion forum: Show discussion | Start new discussion

[ Cryptology ePrint archive ]