{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,4,24]],"date-time":"2024-04-24T00:27:40Z","timestamp":1713918460564},"reference-count":24,"publisher":"Oxford University Press (OUP)","issue":"4","license":[{"start":{"date-parts":[[2023,7,4]],"date-time":"2023-07-04T00:00:00Z","timestamp":1688428800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,4,21]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>It had always been believed that there was an inherent barrier to Differential Fault Attack (DFA) on the nonce-based authenticated encryption algorithm. At CHES 2016, Saha et al. proposed an Internal Differential Fault Attack on a parallelizable counter-mode algorithm. They induce the attack to classical DFA at the expense of one more fault injection in every encryption process. In this paper, we propose the DFA on HYENA, which is a nonce-based authenticated encryption mode for GIFT-128. Our work is the first pure classical DFA on a nonce-based authenticated encryption algorithm with only one fault injected in every decryption process. Firstly, we give the DFA on GIFT-128 with a fault injected into the 39th-round input. Based on this work, we inject a fault in the underlying GIFT-128 of a HYENA decryption process and make this decryption process still generate the correct tag and output plaintext. This makes the necessary conditions of DFA satisfied. Experiments show that at most 56 key bits of HYENA can be recovered with only a few faulty ciphertexts. In addition, our fault injection is easier to achieve than most other work about fault attack, because the injection location is relatively random and the fault type can be arbitrary. It should be noted that the left 72 key bits cannot be recovered in this way.<\/jats:p>","DOI":"10.1093\/comjnl\/bxad066","type":"journal-article","created":{"date-parts":[[2023,7,5]],"date-time":"2023-07-05T03:02:15Z","timestamp":1688526135000},"page":"1370-1380","source":"Crossref","is-referenced-by-count":0,"title":["A Break Of Barrier To Classical Differential Fault Attack On The Nonce-Based Authenticated Encryption Algorithm"],"prefix":"10.1093","volume":"67","author":[{"given":"Shuai","family":"Liu","sequence":"first","affiliation":[{"name":"PLA SSF Information Engineering University , Zhengzhou 450000 , China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jizhou","family":"Ren","sequence":"additional","affiliation":[{"name":"Australian National University college of Engineering, Computing and Cybernetics , Canberra 2601 , Australian"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jie","family":"Guan","sequence":"additional","affiliation":[{"name":"PLA SSF Information Engineering University , Zhengzhou 450000 , China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bin","family":"Hu","sequence":"additional","affiliation":[{"name":"PLA SSF Information Engineering University , Zhengzhou 450000 , China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sudong","family":"Ma","sequence":"additional","affiliation":[{"name":"PLA SSF Information Engineering University , Zhengzhou 450000 , China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hao","family":"Bai","sequence":"additional","affiliation":[{"name":"National University of Defense Technology , Changsha 410000 , China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2023,7,4]]},"reference":[{"key":"2024042316182329300_ref1","first-page":"2","article-title":"Optical Fault Induction Attacks. Proceedings of CHES 2002, Redwood Shores","author":"Skorobogatov","year":"2002"},{"key":"2024042316182329300_ref2","first-page":"110","article-title":"Power supply glitch induced faults on FPGA: An in-depth analysis of the injection mechanism","volume-title":"Proceedings of IOLTS 2013","author":"Zussa","year":"2013"},{"key":"2024042316182329300_ref3","first-page":"105","article-title":"An in-depth and black-box characterization of the e _ ects of clock glitches on 8-bit MCUs","volume-title":"Proceedings of FDTC 2011","author":"Balasch","year":"2011"},{"key":"2024042316182329300_ref4","first-page":"2020","article-title":"Fault attacks in symmetric key cryptosystems","volume":"2020","author":"Baksi","year":"2022","journal-title":"Cryptology ePrint Archive"},{"key":"2024042316182329300_ref5","first-page":"37","article-title":"On the Importance of Checking Cryptographic Protocols for Faults (Extended Abstract)","volume-title":"Proceedings of EUROCRYPT 1997","author":"Boneh","year":"1997"},{"key":"2024042316182329300_ref6","first-page":"513","article-title":"Differential Fault Analysis of Secret Key Cryptosystems","volume-title":"Proceedings of CRYPTO 1997","author":"Biham","year":"1997"},{"key":"2024042316182329300_ref7","doi-asserted-by":"crossref","first-page":"967","DOI":"10.1109\/12.869328","article-title":"Checking before output may not be enough against fault-based cryptanalysis","volume":"49","author":"Yen","year":"2000","journal-title":"IEEE Trans. Comput."},{"key":"2024042316182329300_ref8","first-page":"106","article-title":"Fault Based Collision Attacks on AES","volume-title":"Proceedings of FDTC 2006","author":"Bl\u00f6mer","year":"2006"},{"key":"2024042316182329300_ref9","first-page":"108","article-title":"Fault Attacks on AES with Faulty Ciphertexts Only","volume-title":"Proceedings of FDTC 2013","author":"Fuhr","year":"2013"},{"key":"2024042316182329300_ref10","first-page":"612","article-title":"Fault Template Attacks on Block Ciphers Exploiting Fault Propagation","volume-title":"Proceedings of EUROCRYPT 2020","author":"Saha","year":"2020"},{"key":"2024042316182329300_ref11","first-page":"315","article-title":"Statistical Ineffective Fault Attacks on Masked AES with Fault Countermeasures","volume-title":"Proceedings of ASIACRYPT 2018","author":"Dobraunig","year":"2018"},{"key":"2024042316182329300_ref12","doi-asserted-by":"crossref","first-page":"1166","DOI":"10.1093\/comjnl\/bxy044","article-title":"Fault attack on ACORN v3","volume":"61","author":"Zhang","year":"2018","journal-title":"Comput. J."},{"key":"2024042316182329300_ref13","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1049\/iet-ifs.2012.0319","article-title":"Review of gate-level differential power analysis and fault analysis countermeasures","volume":"8","author":"Marzouqi","year":"2012","journal-title":"IET Inf. Sec."},{"key":"2024042316182329300_ref14","first-page":"581","article-title":"Friet: An Authenticated Encryption Scheme with Built-in Fault Detection","volume-title":"Proceedings of EUROCRYPT 2020","author":"Simon","year":"2020"},{"key":"2024042316182329300_ref15","first-page":"168","article-title":"Information-Combining Differential Fault Attacks on DEFAULT","volume-title":"Proceedings of EUROCRYPT 2022","author":"Nageler","year":"2022"},{"key":"2024042316182329300_ref16","first-page":"417","article-title":"Scope: On the side channel vulnerability of releasing unveried plaintexts","volume-title":"Proceedings of SAC 2015","author":"Saha","year":"2015"},{"key":"2024042316182329300_ref17","doi-asserted-by":"crossref","first-page":"197","DOI":"10.1007\/978-3-319-13039-2_12","article-title":"EscApe: Diagonal Fault Analysis of APE","volume-title":"Proceedings of INDOCRYPT 2014","author":"Saha","year":"2014"},{"key":"2024042316182329300_ref18","first-page":"369","article-title":"Statistical Fault Attacks on Nonce-Based Authenticated Encryption Schemes","volume-title":"Proceedings of ASIACRYPT 2016","author":"Dobraunig","year":"2016"},{"key":"2024042316182329300_ref19","first-page":"581","article-title":"EnCounter: On Breaking the Nonce Barrier in Differential Fault Analysis with a Case-Study on PAEQ","volume-title":"Proceedings of CHES 2016","author":"Saha","year":"2016"},{"key":"2024042316182329300_ref20","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1007\/s13389-017-0179-0","article-title":"Internal differential fault analysis of parallelizable ciphers in the counter-mode","volume":"9","author":"Saha","year":"2019","journal-title":"J. Cryptogr. Eng."},{"key":"2024042316182329300_ref21","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1049\/ise2.12041","article-title":"Fault attacks on authenticated encryption modes for GIFT","volume":"16","author":"Liu","year":"2022","journal-title":"IET Inf. Sec."},{"key":"2024042316182329300_ref22","article-title":"Hyena","author":"Chakraborti"},{"key":"2024042316182329300_ref23","doi-asserted-by":"crossref","first-page":"669","DOI":"10.1049\/cje.2021.05.008","article-title":"Differential fault attack on GIFT","volume":"30","author":"Xie","year":"2021","journal-title":"Chin. J. Electron."},{"key":"2024042316182329300_ref24","first-page":"321","article-title":"GIFT: A Small Present - Towards Reaching the Limit of Lightweight Encryption","volume-title":"Proceedings of CHES 2017","author":"Banik","year":"2017"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/4\/1370\/57295707\/bxad066.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/4\/1370\/57295707\/bxad066.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,23]],"date-time":"2024-04-23T16:45:50Z","timestamp":1713890750000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/67\/4\/1370\/7217095"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,4]]},"references-count":24,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2023,7,4]]},"published-print":{"date-parts":[[2024,4,21]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxad066","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2024,4]]},"published":{"date-parts":[[2023,7,4]]}}}