Paper 2024/1458
Providing Integrity for Authenticated Encryption in the Presence of Joint Faults and Leakage
Abstract
Passive (leakage sensing) and active (fault injection) physical attacks pose a significant threat to cryptographic schemes. Although leakage-resistant cryptography has been well studied, little work has been done on mode-level security in the presence of adversaries that exploit both faults and leakage. In this paper, we focus on mode-level integrity for authenticated encryption (AE). First, we identify an inherent attack in the fault resilience model presented at ToSC 2023. This highlights how fragile the freshness condition of a forgery becomes when faults are injected into either the tag-generation or the encryption algorithm. Second, we provide new integrity definitions for AE in the presence of leakage and faults, following the atomic model, in which the scheme is divided into atoms (or components, e.g. a call to a block cipher) and the adversary is allowed to inject a fault only into the inputs of an atom. We envision this model as a first step toward leveled implementations in the faults scenario, the granularity of atoms can be made finer or coarser (for example, instead of considering a call to a block cipher, we could consider atoms to be rounds of the block cipher). We believe that protecting smaller blocks is easier than securing an entire scheme. The proposed model is highly flexible and allows us to understand where to apply countermeasures for faults. As we discuss, in some very interesting cases this model can reduce faults inside atoms to faults on their outputs. The proposed model, in addition to addressing the previous attack, models an adversary who can inject faults throughout the entire security game. This contrasts with the fault-resilience model, where the adversary first executes a phase in which faults can be injected into the real scheme, and then, in the second phase, no further faults are allowed and the adversary must distinguish the real scheme from an ideal one that outputs random ciphertexts. Third, we show that CONCRETE (presented at Africacrypt 2019), an AE-scheme using a single call to a highly leakage-protected (and thus very expensive) component, maintains integrity in the presence of leakage in both encryption and decryption, and faults only in decryption. On the other hand, a single fault in encryption is enough to forge. Therefore, we first introduce a weaker definition (which restricts the meaning of freshness), weak integrity, which CONCRETE achieves even if the adversary can introduce faults in the encryption queries (subject to certain limitations on the number and type of faults). Finally, we propose a variant, CONCRETE2, which is only slightly more computationally expensive, but still uses a single call to a strongly protected component, and which provides full integrity in the presence of leakage and faults (also in encryption).
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Preprint.
- Keywords
- AE · Fault InjectionFault-resistanceIntegrityLeakage-resistanceModel-Level SecuritySide ChannelsSCA
- Contact author(s)
-
francesco berti @ biu ac il
itamar levi @ biu ac il - History
- 2025-09-04: revised
- 2024-09-18: received
- See all versions
- Short URL
- https://ia.cr/2024/1458
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/1458,
author = {Francesco Berti and Itamar Levi},
title = {Providing Integrity for Authenticated Encryption in the Presence of Joint Faults and Leakage},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/1458},
year = {2024},
url = {https://eprint.iacr.org/2024/1458}
}