{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:35:41Z","timestamp":1750307741791,"version":"3.41.0"},"reference-count":20,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2008,4,1]],"date-time":"2008-04-01T00:00:00Z","timestamp":1207008000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2008,4]]},"abstract":"<jats:p>Implementation cryptanalysis has emerged as a realistic threat for cryptographic systems. It consists of two classes of attacks: fault-injection and side-channel attacks. In this work, we examine the resistance of the Fiat--Shamir scheme to fault-injection attacks, since Fiat--Shamir is a popular scheme for \u201clight\u201d consumer devices, such as smartcards, in a wide range of consumer services. We prove that an existing attack, known as the Bellcore attack, is incomplete. We propose an extension to the protocol that proactively secures Fiat--Shamir systems from the Bellcore attack and we prove its strength. Finally, we introduce a new attack model, which, under stronger assumptions, can derive the secret keys from both the original Fiat--Shamir scheme as well as its proposed extension. Our approach demonstrates that countermeasures for implementation cryptanalysis must be carefully designed and that deployed systems must include appropriate protection mechanisms for all known attacks and be flexible enough to incorporate countermeasures for new ones.<\/jats:p>","DOI":"10.1145\/1347375.1347384","type":"journal-article","created":{"date-parts":[[2008,5,15]],"date-time":"2008-05-15T18:28:05Z","timestamp":1210876085000},"page":"1-13","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["The security of the Fiat--Shamir scheme in the presence of transient hardware faults"],"prefix":"10.1145","volume":"7","author":[{"given":"Artemios G.","family":"Voyiatzis","sequence":"first","affiliation":[{"name":"University of Patras, Patras, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dimitrios N.","family":"Serpanos","sequence":"additional","affiliation":[{"name":"University of Patras, Patras, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,5,8]]},"reference":[{"volume-title":"Security Engineering\u2014A Guide to Building Dependable Distributed Systems","author":"Anderson R.","unstructured":"Anderson , R. 2001. Security Engineering\u2014A Guide to Building Dependable Distributed Systems . Wiley , New York . 317--318. Anderson, R. 2001. Security Engineering\u2014A Guide to Building Dependable Distributed Systems. Wiley, New York. 317--318.","key":"e_1_2_1_1_1"},{"volume-title":"Proceedings of the 2nd USENIX Workshop on Electronic Commerce","author":"Anderson R.","unstructured":"Anderson , R. and Kuhn , M . 1996. Tamper-resistance -- a cautionary note . In Proceedings of the 2nd USENIX Workshop on Electronic Commerce , Oakland, CA. USENIX Association. 1--11. Anderson, R. and Kuhn, M. 1996. Tamper-resistance -- a cautionary note. In Proceedings of the 2nd USENIX Workshop on Electronic Commerce, Oakland, CA. USENIX Association. 1--11.","key":"e_1_2_1_2_1"},{"key":"e_1_2_1_3_1","volume-title":"Security Protocols: Proceedings of the 5thInternational Workshop Paris, France, April 7--9, B. Christianson, B. Crispo, M. Lomas, and M. Roe, Eds. Springer-Verlag Lecture Notes in Computer Science","volume":"1361","author":"Anderson R.","unstructured":"Anderson , R. and Kuhn , M . 1997. Low cost attacks on tamper resistance devices . In Security Protocols: Proceedings of the 5thInternational Workshop Paris, France, April 7--9, B. Christianson, B. Crispo, M. Lomas, and M. Roe, Eds. Springer-Verlag Lecture Notes in Computer Science , Vol. 1361 . 125--136. Anderson, R. and Kuhn, M. 1997. Low cost attacks on tamper resistance devices. In Security Protocols: Proceedings of the 5thInternational Workshop Paris, France, April 7--9, B. Christianson, B. Crispo, M. Lomas, and M. Roe, Eds. Springer-Verlag Lecture Notes in Computer Science, Vol. 1361. 125--136."},{"key":"e_1_2_1_4_1","volume-title":"-P","author":"Aum\u00fcller C.","year":"2002","unstructured":"Aum\u00fcller , C. , Bier , P. , Fischer , W. , Hofreiter , P. , and Seifert , J . -P . 2002 . Fault attacks on RSA with CRT: concrete results and practical countermeasures. In Cryptographic Hardware and Embedded Systems\u2014CHES 2002, 4th International Workshop, Redwood Shores, CA, 13--15 August, Revised Papers. B. S. Kaliski Jr., \u00c7. K. Ko\u00e7, and C. Paar, Eds. Springer-Verlag Lecture Notes in Computer Science, Vol. 2523 . 260--275. Aum\u00fcller, C., Bier, P., Fischer, W., Hofreiter, P., and Seifert, J.-P. 2002. Fault attacks on RSA with CRT: concrete results and practical countermeasures. In Cryptographic Hardware and Embedded Systems\u2014CHES 2002, 4th International Workshop, Redwood Shores, CA, 13--15 August, Revised Papers. B. S. Kaliski Jr., \u00c7. K. Ko\u00e7, and C. Paar, Eds. Springer-Verlag Lecture Notes in Computer Science, Vol. 2523. 260--275."},{"doi-asserted-by":"publisher","key":"e_1_2_1_5_1","DOI":"10.1109\/JPROC.2005.862424"},{"key":"e_1_2_1_6_1","volume-title":"Cryptology: Proceedings of Crypto '97, B. S. Kaliski Jr., Ed","author":"Biham E.","year":"1997","unstructured":"Biham , E. and Shamir , A . 1997 . Differential fault analysis of secret key cryptosystems. In Advances in Cryptology: Proceedings of Crypto '97, B. S. Kaliski Jr., Ed . Springer-Verlag Lecture Notes in Computer Science, Vol. 1294 . Springer-Verlag , New York. 513--525. Biham, E. and Shamir, A. 1997. Differential fault analysis of secret key cryptosystems. In Advances in Cryptology: Proceedings of Crypto '97, B. S. Kaliski Jr., Ed. Springer-Verlag Lecture Notes in Computer Science, Vol. 1294. Springer-Verlag, New York. 513--525."},{"key":"e_1_2_1_7_1","volume-title":"-P","author":"Bl\u00f6mmer J.","year":"2003","unstructured":"Bl\u00f6mmer , J. and Seifert , J . -P . 2003 . Fault based cryptanalysis of the Advanced Encryption Standard (AES). In Financial Cryptography, FC '03 Proceedings. Lecture Notes in Computer Science, Vol. 2742 , Springer-Verlag , New York. 162--181. Bl\u00f6mmer, J. and Seifert, J.-P. 2003. Fault based cryptanalysis of the Advanced Encryption Standard (AES). In Financial Cryptography, FC '03 Proceedings. Lecture Notes in Computer Science, Vol. 2742, Springer-Verlag, New York. 162--181."},{"key":"e_1_2_1_8_1","series-title":"Lecture Notes in Computer Science","volume-title":"Cryptology: Proceedings of Eurocrypt '97","author":"Boneh D.","year":"1997","unstructured":"Boneh , D. , Demillo , R. A. , and Lipton , R. J . 1997 . On the importance of checking cryptographic protocols for faults. In Advances in Cryptology: Proceedings of Eurocrypt '97 . Lecture Notes in Computer Science , Vol. 1233 , Springer-Verlag , New York. 37--51. Boneh, D., Demillo, R. A., and Lipton, R. J. 1997. On the importance of checking cryptographic protocols for faults. In Advances in Cryptology: Proceedings of Eurocrypt '97. Lecture Notes in Computer Science, Vol. 1233, Springer-Verlag, New York. 37--51."},{"doi-asserted-by":"publisher","key":"e_1_2_1_9_1","DOI":"10.1007\/s001450010016"},{"volume-title":"Proceedings of the 12th USENIX Security Symposium. 1--14","author":"Brumley D.","unstructured":"Brumley , D. , and Boneh , D . 2003. Remote timing attacks are practical . In Proceedings of the 12th USENIX Security Symposium. 1--14 . Brumley, D., and Boneh, D. 2003. Remote timing attacks are practical. In Proceedings of the 12th USENIX Security Symposium. 1--14.","key":"e_1_2_1_10_1"},{"key":"e_1_2_1_11_1","series-title":"Lecture Notes in Computer Science","volume-title":"Cryptology: Proceedings of Crypto '86","author":"Fiat A.","year":"1987","unstructured":"Fiat , A. and Shamir , A . 1987 . How to prove yourself: practical solution to identification and signature problems. In Advances in Cryptology: Proceedings of Crypto '86 . Lecture Notes in Computer Science , Vol. 263 , Springer-Verlag , New York. 186--199. Fiat, A. and Shamir, A. 1987. How to prove yourself: practical solution to identification and signature problems. In Advances in Cryptology: Proceedings of Crypto '86. Lecture Notes in Computer Science, Vol. 263, Springer-Verlag, New York. 186--199."},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"Govindavajhala S.","year":"2003","unstructured":"Govindavajhala , S. and Appel , A. W . 2003. Using memory errors to attack a virtual machine . In Proceedings of IEEE Symposium on Security and Privacy 2003 . 154--165. Govindavajhala, S. and Appel, A. W. 2003. Using memory errors to attack a virtual machine. In Proceedings of IEEE Symposium on Security and Privacy 2003. 154--165."},{"key":"e_1_2_1_13_1","series-title":"Lecture Notes in Computer Science","volume-title":"RSA, DSS, and other systems. In Advances in Cryptology: Proceedings of Crypto '96","author":"Kocher P.","unstructured":"Kocher , P. 1996. Timing attacks on implementations of Diffie-Hellman , RSA, DSS, and other systems. In Advances in Cryptology: Proceedings of Crypto '96 . Lecture Notes in Computer Science , Vol. 1109 , Springer-Verlag , New York . 104--113. Kocher, P. 1996. Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In Advances in Cryptology: Proceedings of Crypto '96. Lecture Notes in Computer Science, Vol. 1109, Springer-Verlag, New York. 104--113."},{"key":"e_1_2_1_14_1","series-title":"Lecture Notes in Computer Science","volume-title":"Cryptology: Proceedings of Crypto '99","author":"Kocher P.","year":"1999","unstructured":"Kocher , P. , Jaffe , J. , and Benjamin , J . 1999 . Differential power analysis. In Advances in Cryptology: Proceedings of Crypto '99 . Lecture Notes in Computer Science , Vol. 1666 , Springer-Verlag , New York. 388--397. Kocher, P., Jaffe, J., and Benjamin, J. 1999. Differential power analysis. In Advances in Cryptology: Proceedings of Crypto '99. Lecture Notes in Computer Science, Vol. 1666, Springer-Verlag, New York. 388--397."},{"key":"e_1_2_1_15_1","series-title":"Lecture Notes in Computer Science","volume-title":"Financial Cryptography, FC '97 Proceedings","author":"Macher D. P.","unstructured":"Macher , D. P. 1997. Fault induction attacks, tamper resistance, and hostile reverse engineering in perspective . In Financial Cryptography, FC '97 Proceedings . Lecture Notes in Computer Science , Vol. 1318 , Springer-Verlag , New York . 109--121. Macher, D. P. 1997. Fault induction attacks, tamper resistance, and hostile reverse engineering in perspective. In Financial Cryptography, FC '97 Proceedings. Lecture Notes in Computer Science, Vol. 1318, Springer-Verlag, New York. 109--121."},{"key":"e_1_2_1_16_1","volume-title":"Lecture Notes in Computer Science","volume":"2140","author":"Quisquater J.-J.","unstructured":"Quisquater , J.-J. and Samyne , D . 2001. ElectoMagnetic analysis (EMA): measures and countermeasures. In Smart Card Programming and Security --E-smart 2001 . Lecture Notes in Computer Science , Vol. 2140 . Springer-Verlag, New York. 200--210. Quisquater, J.-J. and Samyne, D. 2001. ElectoMagnetic analysis (EMA): measures and countermeasures. In Smart Card Programming and Security --E-smart 2001. Lecture Notes in Computer Science, Vol. 2140. Springer-Verlag, New York. 200--210."},{"unstructured":"Rao J. R. and Rahatgi P. 2001. EMpowering side-channel attacks. Cryptography ePrint archive 2001\/037. Available in http:\/\/eprint.iacr.org\/2001\/037.  Rao J. R. and Rahatgi P. 2001. EMpowering side-channel attacks. Cryptography ePrint archive 2001\/037. Available in http:\/\/eprint.iacr.org\/2001\/037.","key":"e_1_2_1_17_1"},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the Workshop on Cryptographic Hardware and Embedded Systems -- CHES","volume":"2523","author":"Skorobogatov S.","year":"2002","unstructured":"Skorobogatov , S. and Anderson , R . 2002. Optical fault injection attacks . In Proceedings of the Workshop on Cryptographic Hardware and Embedded Systems -- CHES 2002 . Lecture Notes in Computer Science , Vol. 2523 , Springer-Verlag, New York. 2--19. Skorobogatov, S. and Anderson, R. 2002. Optical fault injection attacks. In Proceedings of the Workshop on Cryptographic Hardware and Embedded Systems -- CHES 2002. Lecture Notes in Computer Science, Vol. 2523, Springer-Verlag, New York. 2--19."},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the 7th IEEE Symposium on Computers and Communications (ISCC 2002","author":"Voyiatzis A. G.","year":"2002","unstructured":"Voyiatzis , A. G. and Serpanos , D. N . 2002. Active Hardware Attacks and Proactive Countermeasures . In Proceedings of the 7th IEEE Symposium on Computers and Communications (ISCC 2002 ), Taormina, Italy, July 2--4 2002 . IEEE Press, Los Alamitos, CA. 361--366. Voyiatzis, A. G. and Serpanos, D. N. 2002. Active Hardware Attacks and Proactive Countermeasures. In Proceedings of the 7th IEEE Symposium on Computers and Communications (ISCC 2002), Taormina, Italy, July 2--4 2002. IEEE Press, Los Alamitos, CA. 361--366."},{"key":"e_1_2_1_20_1","volume-title":"Proceedings of the 24th International Conference on Distributed Systems Workshops (IEEE ICDCS 2004 Workshop ADSN 2004)","author":"Voyiatzis A. G.","year":"2004","unstructured":"Voyiatzis , A. G. and Serpanos , D. N . 2004. A Fault-Injection Attack on Fiat-Shamir Cryptosystems . In Proceedings of the 24th International Conference on Distributed Systems Workshops (IEEE ICDCS 2004 Workshop ADSN 2004) , Tokyo, Japan , March 2004 , IEEE Press, Los Alamitos, CA. 618--621. Voyiatzis, A. G. and Serpanos, D. N. 2004. A Fault-Injection Attack on Fiat-Shamir Cryptosystems. In Proceedings of the 24th International Conference on Distributed Systems Workshops (IEEE ICDCS 2004 Workshop ADSN 2004), Tokyo, Japan, March 2004, IEEE Press, Los Alamitos, CA. 618--621."}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1347375.1347384","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1347375.1347384","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:38:58Z","timestamp":1750253938000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1347375.1347384"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,4]]},"references-count":20,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2008,4]]}},"alternative-id":["10.1145\/1347375.1347384"],"URL":"https:\/\/doi.org\/10.1145\/1347375.1347384","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"type":"print","value":"1539-9087"},{"type":"electronic","value":"1558-3465"}],"subject":[],"published":{"date-parts":[[2008,4]]},"assertion":[{"value":"2004-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2007-03-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2008-05-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}