Fault attack on the DVB Common Scrambling Algorithm

Kai Wirt

Abstract: The Common Scrambling Algorithm (CSA) is used to encrypt streams of video data in the Digital Video Broadcasting (DVB) system. The algorithm uses a combination of a stream and a block cipher, apparently for a larger security margin. However these two algorithms share a common key. In this paper we present a fault attack on the block cipher which can be launched without regarding the stream cipher part. This attack allows us to reconstruct the common key and thus breaks the complete Algorithm.

Category / Keywords: secret-key cryptography / block cipher, cryptanalysis, fault attack, dvb, paytv

Date: received 3 Nov 2004, last revised 8 Nov 2004

Contact author: wirt at informatik tu-darmstadt de

Version: 20041108:174617 (All versions of this report)

