Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

37 results about "Fault attack" patented technology

What is Fault Attack. 1. A fault attack is an intentional manipulation of the integrated circuit or its state, with the aim to provoke an error within the integrated circuit in order to move the device into an unintended state. The goal is to access security critical information or to disable internal protection mechanisms.

Method for evaluating anti-differential fault analysis capability of five S-box candidates in NIST LWC competition

The invention belongs to the technical field of information security, and discloses a method for evaluating the anti-differential fault analysis capability of 5-bit S box candidates in an NIST LWC competition, which comprises the following steps of: 1, injecting a fault into the input of a 5-bit S box applied to a target lightweight encryption algorithm, deducing the input of the 5-bit S box through an output authentication tag obtained through analysis, and determining the input of the 5-bit S box according to the input of the 5-bit S box; the middle state in the password operation process is reconstructed before the 5-bit S box layer, and the key is indirectly obtained through the middle state; 2, evaluating the anti-differential fault analysis capability of the target lightweight encryption algorithm according to the differential fault attack result in the step 1; and step 3, designing the target lightweight encryption algorithm according to the anti-differential fault analysis capability evaluation result of the target lightweight encryption algorithm. According to the invention, the security of the LWC algorithm in the face of differential fault attack is improved.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Circuitry and methods for efficient side-channel and fault attack countermeasures for cryptographic execution circuitry

Efficient side-channel and fault attack countermeasures for cryptographic execution circuitry are described. In certain examples, a system includes a processor core; and an accelerator coupled to the processor core, the accelerator comprising: execution circuitry to generate a cryptographic signature for a first input of a message value and a second input of a secret key value, and countermeasure circuitry to, in response to a request to generate the cryptographic signature, cause the execution circuitry to perform multiple sequential executions for the first input of the message value, the second input of the secret key value, and a third input of a different uniformly random value for each execution to generate a plurality of cryptographic signatures, and output, as a resultant for the request, one of the plurality of cryptographic signatures as the cryptographic signature.
Owner:INTEL CORP

A behavior reasoning and AI intelligent handling method and system for communication anomalies

ActiveCN122247760BAttackAnomaly detection
The application relates to the fields of network communication anomaly detection and intelligent operation and maintenance, in particular to a behavior reasoning and AI intelligent disposal method and system for communication anomalies, which comprises the following steps: collecting communication interaction time sequence data and protocol stack resource state data; constructing an ideal communication state model based on interface contract analysis results, protocol specification analysis results and queuing rules, and generating an ideal communication track benchmark according to a service request sequence in a preset time window; respectively performing fault attack knowledge injection and service load fluctuation rule injection to generate abnormal scene simulation tracks and service tide simulation tracks; performing difference calculation on real observation features and the ideal communication track benchmark to obtain a real residual space, and generating an abnormal theoretical residual space and a service tide theoretical residual space; generating abnormal type results and root cause results based on the topological similarity between the residual spaces, and outputting corresponding intelligent disposal instructions; and the application can accurately identify high-concurrency legal tides and real attacks.
Owner:ZHEJIANG SCI-TECH UNIV

Triplication-based fault attack countermeasure

Systems and techniques are provided for secure processing. For instance, a process can include: providing an input value to generate a first output value; obtaining a plurality of first intermediate output values based on a function of the first output value and a tweak value; embedding the plurality of first intermediate output values into a mathematical structure; obtaining a plurality of second intermediate output values, wherein the plurality of second intermediate output values are a function of the plurality of first intermediate output values, a random number, and an inverse of the tweak value; determining a most common value of the plurality of second intermediate output values; obtaining a third intermediate value, the third intermediate value based on a function of the most common value and an inverse of the random number; projecting the third intermediate value from the mathematical structure to obtain a second output value for output.
Owner:QUALCOMM INC

Method for improving the resilience of an electronic device to fault attacks, corresponding computer program product and devices

Method for improving the resilience of an electronic device to fault attacks, corresponding computer program product and devices A method is proposed for improving the resilience of an electronic device to fault attacks, the electronic device implementing a fault detection mechanism during the execution of a command. According to such method, the electronic device executes: - executing a command; and - executing, after a predetermined period of time counted from the end of the execution of the command, at least one operation changing the internal state of the electronic device to an internal state indicative that a fault was detected or not during the execution of the command.
Owner:NAGRAVISION SA

Stream Cipher Implementation Method Based on FSR and Fourth-Order CA

This invention discloses a stream cipher implementation method based on FSR and fourth-order CA, including designing the stream cipher algorithm structure, component design of LFSR and NFSR, setting CA rules for register updates, designing a keystream generation function, algorithm initialization, keystream generation, and algorithm encryption / decryption. CA rules are used to update registers, and each internal state bit is a bitwise feedback bit at each stage of algorithm execution. In the initial loading stage, the LFSR and NFSR are loaded using an initial key and initial vector, and the remaining bits of the LFSR are padded with the initial key. The keystream initialization stage uses 32 iterations, ensuring the key and vector are fully obfuscated within the register's internal state. This invention uses fourth-order CA rules combined with register design to provide good differential properties and nonlinearity for the cryptographic algorithm. The key expansion used to padded the LFSR during the initialization stage effectively resists differential analysis and fault attacks.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Data processing component and computer processor

PendingUS20260187291A1Computer hardwareEngineering
A data processing component includes a fault attack shielding and detection arrangement. Specifically, the data processing component includes a first layer and a second layer. The first layer includes a first data processing element, the first data processing element configured to receive a control input and to execute a predetermined operation on the control input to generate a control output; and a first comparator configured to compare the control output with an expected control output, and to generate a fault status signal if the control output is different from the expected control output. The second layer includes a second data processing element identical to the first data processing element, configured to receive a first operational input and to execute the same predetermined operation on the first operational input to generate a first operational output. The data processing component may include a computer processor.
Owner:NAGRAVISION SRL

Detection of fault attacks

A method is provided for detecting a fault attack when performing a process including a plurality of operations. The method comprises identifying a group of operations selected from the plurality of
Owner:PQSHIELD LTD

Detection of fault attacks

A method is provided for detecting a fault attack when performing a process including a plurality of operations. The method comprises identifying a group of operations selected from the plurality of operations and performing operations from the group of operations in a random order such that each operation is repeated n times where n is less than or equal to a security parameter corresponding to a maximum number of potential fault attacks. The results of the n repetitions of each operation are compared to determine whether the output value of each repetition of the operation is the same. In a case that the output value of each repetition is not the same an action to record or mitigate a fault attack is performed.
Owner:PQSHIELD LTD

A security protection method based on SM9 decryption algorithm

The present invention discloses a security protection method based on the SM9 decryption algorithm. The method masks a private key with a random number and performs a random operation on the operands of the point multiplication. The private key is not leaked during the entire decryption algorithm process. At the same time, the intermediate processes are fully masked, so that power consumption, electromagnetic and key information are unrelated, thereby being able to resist energy consumption and electromagnetic attacks. Since the operation time is determined according to the value of the random number, when the NAF point multiplication operation is adopted, the point multiplication operation time of the random window is also random, thereby being able to resist timing attacks. When the KDF function is used for operation, a CT randomization method is adopted to avoid leaking sensitive information. By comparing the previous and next SM3 hash operation values, it is effectively detected whether the parameter variables have been tampered with or whether there is error injection. The decrypted plaintext is encrypted again, and it is possible to detect whether all parameter variables and intermediate variables in the full-process operation have been tampered with or whether there is error injection, thereby being able to resist fault attacks.
Owner:SOUTHEAST UNIV

A fault attack method against RIPEMD-160 hash algorithm

The present application relates to a kind of fault attack methods for RIPEMD-160 hash algorithm, first randomly generates to be handled message, and to be handled message is as the input of RIPEMD-160 algorithm, using random single byte fault model, in the fifth round of import random 8 bits fault, obtains error output.Based on error output, deduce intermediate state value, then using statistical method, calculate the hamming weight of intermediate state value, according to the minimum value of hamming weight, the correct value of corresponding message is obtained.Repeat the process of importing fault and analysis, finally the complete message to be handled can be deduced.The method provided by the present application is easy to implement, fast and high accuracy, and provides important analysis basis for the security research of RIPEMD-160 hash algorithm.
Owner:DONGHUA UNIV

Vulnerability handling device, vulnerability handling method, and vulnerability handling program

The detection unit (101) detects vulnerabilities to fault attacks contained in the program code (210). The correction unit (103) corrects the program code (210) to address the vulnerabilities detected by the detection unit (101). The determination unit (102) determines whether or not the corrected program code (130) corrected by the correction unit (103) has vulnerabilities to fault attacks.
Owner:MITSUBISHI ELECTRIC CORP

A method for detecting that an ascon algorithm is resistant to impossible statistical fault analysis

The application relates to a method for detecting that an Ascon algorithm resists impossible statistical fault analysis, first, a plaintext to be processed is randomly generated, an Ascon authentication encryption algorithm is used to process the plaintext message, in this stage, the processing process is interfered with to induce faults, error output is obtained to obtain an error label; then, through a decryption algorithm and a statistical method, an intermediate state value is calculated, the probability of occurrence of each value is counted, key candidate values leading to intermediate state values which are theoretically impossible to obtain are excluded, key candidate values making the probability of occurrence of the intermediate state values most conform to ideal conditions are selected, the fault introduction and analysis process are repeated for multiple times, and then, a complete key is recovered. The application is easy to implement, fast and high in accuracy, and provides a good analysis basis for the security research of the Ascon authentication encryption algorithm resisting impossible statistical fault attacks.
Owner:DONGHUA UNIV +1

Vulnerability addressing device, vulnerability addressing method, and vulnerability addressing program

A detection unit (101) detects vulnerability to fault attacks contained in program code (210). A correction unit (103) makes a correction to the program code (210) to address the vulnerability detected by the detection unit (101). A determination unit (102) determines whether or not vulnerability to fault attacks is present in corrected program code (130) after the correction has been made by the correction unit (103).
Owner:MITSUBISHI ELECTRIC CORP

A Differential Fault Attack Method for Lightweight Authentication Encryption Algorithms

This invention discloses a lightweight authentication encryption algorithm differential fault attack method, relating to the fields of cryptography and information security technology; it initializes the AEGIS encryption algorithm and injects a random single-bit fault, with plaintext P as input. i The method involves encrypting the AEGIS encryption algorithm after initialization to generate correct and incorrect ciphertexts and obtaining their output difference. The output difference between the correct and incorrect ciphertexts is then XORed, and the location of the fault is determined using the XOR result. Byte state recovery is then performed based on the XOR result, and the word state recovery process is repeated. Finally, the inverse round function formula and encryption formula are applied to restore the complete internal state. This invention employs a lightweight authentication encryption algorithm differential fault attack method, which can efficiently extract key features from complex high-dimensional time-series data and accurately identify potential fault modes.
Owner:HENAN UNIV OF SCI & TECH

Capability Testing Method and System for Fault Attack Based on Hamming Weight

The present invention relates to the technical field of device testing, and particularly to a method and system for testing the ability of fault attacks based on Hamming weight, including fault response classification, establishment of a fault leakage function, selection of an effective time attack window, and selection of voltage glitches for fault injection attacks; selection of an effective fault injection parameter interval, and injecting a large number of faults within the above time window; according to the response distribution of each slice within the time window, selecting any appropriate combination of fault parameters, and reducing the entropy of the unknown key of the target device by analyzing the fault information. The present invention grasps the essence of the fault based on the fault probability of Hamming weight, accurately establishes a leakage model, has low requirements for data, strong fault tolerance, greatly reduces the data volume compared with the existing model, has good practicability, and solves the problem that most of the existing leakage models have certain limitations and cannot simultaneously take into account the requirements for data, data volume, fault tolerance, and attack efficiency.
Owner:NAVAL UNIV OF ENG PLA

Encryption methods and devices

This application discloses an encryption method and apparatus. The method includes: obtaining data to be encrypted and a first key; wherein the first key is obtained through a primitive key arrangement algorithm; if the final key of the first key is obtained through a differential fault attack, and the initial key of the first key is obtained through the final key and a constructed impossible differential path, then the primitive key arrangement algorithm is updated; based on the initial key and the updated primitive key arrangement algorithm, a second key is determined; and the data to be encrypted is encrypted using the second key.
Owner:LENOVO (BEIJING) LTD

A security protection method based on SM9 signature algorithm

The present invention discloses a security protection method based on the SM9 signature algorithm. The method determines the operation time according to the value of a random number. The operation time is random. In addition, the point multiplication operation time is also random, which can resist timing attacks. A key mask operation is performed on the user's private key. At the same time, the point multiplication operands are randomized in the point multiplication operation. The NAF point multiplication algorithm is used. The private key is not leaked during the signature algorithm. At the same time, the intermediate process is fully masked, so that power consumption, electromagnetic and key information are unrelated, and the method can resist energy consumption and electromagnetic attacks. By comparing the hash operation at the beginning of the algorithm and before the point multiplication operation, it can detect whether the relevant parameter variables have been tampered with or whether there is error injection. In addition, after the signature is completed, a verification operation is performed on the signature value. It can detect whether all parameter variables and intermediate variables in the full process operation have been tampered with or whether there is error injection, which can resist fault attacks.
Owner:SOUTHEAST UNIV

Methods, apparatus, computer equipment, and storage media for detecting latent fault attacks in SILC-certified encryption algorithms.

This application provides a method for detecting latent fault attacks in the SILC authentication encryption algorithm, comprising: acquiring multiple authentication tags output by the target encryption device to obtain a tag set; setting multiple sets of subkey candidate sets; wherein each set of subkey candidate sets corresponds to a fault import position, and the subkey candidate set exhaustively lists all subkey candidate values ​​affected by the fault after the fault is imported at the corresponding fault import position; determining whether the master key can be recovered based on the tag set and each set of subkey candidate sets; if so, determining that the target encryption device has suffered a latent fault attack within a preset period. This scheme helps to detect and respond to latent fault attacks that may lead to master key leakage or encryption system failure as early as possible, effectively ensuring the encryption security of the target encryption device and the confidentiality and integrity of related information.
Owner:E-SURFING DIGITAL LIFE TECH CO LTD

A combined threshold mask protection method of Ascon authentication encryption algorithm

The application discloses a combined threshold mask protection method of Ascon authentication encryption algorithm, which combines threshold implementation with exchange-based infection technology, and comprises the following steps: constructing a second-order threshold implementation of the Ascon algorithm; copying a complete copy of the constructed second-order threshold mask as a redundant mask; and reducing the number of additional random numbers used by the exchange technology based on the copy through the exchange bit sharing selection algorithm provided by the application, and exchanging part of the sharing selected. The method has the advantages that the Ascon algorithm can effectively resist second-order power consumption attacks and first-order differential fault attacks, only a small amount of additional random numbers and a small circuit implementation area are needed, and the hardware implementation cost can be significantly reduced.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Method for protecting against fault attacks an execution of a generation of a crystals-dilithium signature

The invention relates to methods, and associated devices, for protecting the execution of the generation of a Crystals-Dilithium digital signature σ of a message M with a secret key sk against attacks exploiting invalid signatures content by fault attacks. In order to prevent an attacker bypassing by fault injection attacks tests on a second test vector (I) from obtaining invalid signatures as outputs of the signature generation algorithm, the invention modifies the norm check performed on the second test vector (I) in such a way that if this check is skipped, the candidate signature is rejected by the subsequent test performed on a fourth vector of polynomials h.
Owner:THALES DIS FRANCE SA

Method for protecting performance of verification of post-CRYSTALS-DIITHIUM quantum signatures from fault attacks

The invention relates to a method for protecting the performance of a verification of a post-Crystal-Diithium quantum digital signature [sigma] of a message M, comprising a challenge seed, a test vector z and a polynomial hint vector h, generated using a secret key sk = ([rho], K, tr, s1, s2, t0), said digital signature verification verifying said digital signature [sigma], said message M and a public key pk = ([rho], K, tr, s1, s2, t0), said digital signature verification verifying said digital signature [sigma], said message M and said public key pk = ([rho], K, tr, s1, s2, t0). The invention relates to a method for verifying one of conditions P1, P2 and P3 (t1, t1) as input and comprising the following steps: ensuring that a fault attack intended to verify one of the conditions P1, P2 and P3 does not result in a signature accepting forgery, where: P1: ct1.2 d = 0, and.
Owner:THALES DIS FRANCE SA

Fault attack method for RIPEMD-160 hash algorithm

The invention relates to a fault attack method for an RIPEMD-160 hash algorithm, and the method comprises the steps: firstly, randomly generating a to-be-processed message, taking the to-be-processed message as the input of the RIPEMD-160 algorithm, employing a random single-byte fault model, importing a random 8-bit fault in the last fifth round, and obtaining an error output; and reversely deducing an intermediate state value based on the error output, calculating the Hamming weight of the intermediate state value by using a statistical method, and solving a correct value of the corresponding message according to the minimum Hamming weight. The fault import and analysis process is repeated, and finally a complete to-be-processed message can be deduced. The method provided by the invention is easy to implement, high in speed and high in accuracy, and provides an important analysis basis for the safety research of the RIPEMD-160 hash algorithm.
Owner:DONGHUA UNIV

Method for detecting resistance of saturnin cryptographic algorithm to impossible differential fault attack

This invention relates to a method for detecting the SATURNIN cryptographic algorithm's resistance to impossible differential fault attacks, comprising the following steps: randomly generating a plaintext message M to be processed; processing the plaintext message M using the SATURNIN cryptographic algorithm to obtain the correct output ciphertext Y; processing the plaintext message M using the SATURNIN cryptographic algorithm, and introducing a fault at a designated position in the fourth-to-last super-round to obtain an incorrect output ciphertext; deriving the intermediate state values ​​of the penultimate super-round based on the obtained correct output ciphertext Y and the incorrect output ciphertext, and further deriving the intermediate state values ​​of the penultimate super-round based on the intermediate state values ​​of the penultimate super-round, and calculating the difference value of the sum of the intermediate state values; using a set of impossible differential relation equations to further compress the key search space; repeating the fault introduction and analysis process; and finally deriving the correct key K. This invention can evaluate the security of products encapsulated using the SATURNIN cryptographic algorithm.
Owner:DONGHUA UNIV +1

Fault attack inversion based on triplication

Systems and techniques for secure processing are provided. For example, a process may include providing an input value to generate a first output value; obtaining a plurality of first intermediate output values based on a function of the first output value and a trim value; embedding the plurality of first intermediate output values into a mathematical structure; obtaining a plurality of second intermediate output values, wherein the plurality of second intermediate output values are a function of an inverse element of the fine tuning value, the plurality of first intermediate output values, and a random number; determining a most general value in the plurality of second intermediate output values; obtaining a third intermediate value, the third intermediate value being based on an inverse of the random number and a function of the most general value; the third intermediate value is projected from the mathematical structure to obtain a second output value for output.
Owner:QUALCOMM INC

Chip real-time detection method and device, chip and storage medium

The application discloses a kind of real-time detection method, device and chip of chip, storage medium, the method includes: when receiving any detection circuit sends alarm signal, first check algorithm and second check algorithm are used respectively to check signal and obtain first check signal and second check signal, the detection circuit is correspondingly set with each module of the chip;When the first check signal and the second check signal fail to compare, the chip is triggered to reset operation or self-destruction operation;By using first check algorithm and second check algorithm to check signal and carry out check operation, and the state of different check signals is compared, when state is inconsistent, it is determined that alarm signal is attacked, and alarm signal is fed back to application, with the effect of resisting multi-point fault attack.
Owner:BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD +2

Differential fault attack method for lightweight cipher gift based on byte model

The application discloses a differential fault attack method of a lightweight cipher GIFT based on a byte model, and comprises the following steps: obtaining correct cipher texts generated by using the GIFT algorithm to encrypt plaintexts without injecting byte faults and error cipher texts generated by encrypting the plaintexts after injecting byte faults, wherein the GIFT algorithm is encrypted through a plurality of S boxes; performing an exclusive or operation on the correct cipher texts and the error cipher texts to obtain output differentials of each corresponding S box in the encryption process of target plaintexts, and determining a target S box injected with a byte fault in the plurality of S boxes according to the output differentials of each S box and input differentials of each S box obtained in advance; determining an input value of the target S box in the encryption process of plaintexts without injecting byte faults as a correct input value of the target S box according to the input differentials and the output differentials of the target S box; and recovering an encryption key used by the plaintexts without injecting byte faults and the plaintexts with injecting byte faults through the correct input value of the target S box.
Owner:HENAN UNIV OF SCI & TECH

Fault attack countermeasures using unified mask logic

Systems and techniques for security processing are provided. For example, a process for security processing may include obtaining a cryptographic input at a cryptographic algorithm execution component; obtaining a first mask and a second mask at the cryptographic algorithm execution component; executing a first logic circuit using the first mask and the password input to obtain a first output; executing a second logic circuit using the second mask and the password input to obtain a second output; and performing a comparison of the first output and the second output to determine whether the comparison is a successful comparison.
Owner:QUALCOMM INC

Method for protecting against fault attacks an execution of a generation of a crystals-dilithium signature

The invention relates to methods, and associated devices, for protecting the execution of the generation of a Crystals-Dilithium digital signature δ of a message M with a secret key sk against attacks exploiting invalid signatures content by fault attacks. In order to prevent an attacker bypassing by fault injection attacks any of first rejections tests on a second test vector r0 / ro~ or on a first test vector z or of second rejection tests on a fourth vector of polynomials h or on the value c*to from obtaining invalid signatures as outputs of the signature generation algorithm, the present invention, before outputting a candidate signature verifies that the value of the second vector of polynomials w1' computed when generating the candidate signature truly corresponds to the value w1' that will later be computed when verifying the candidate signature. To this end, an additional rejection test is added to the signature generation algorithm, after the second rejection tests.
Owner:THALES DIS FRANCE SA