{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:24:37Z","timestamp":1750220677031,"version":"3.41.0"},"reference-count":54,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2020,9,1]],"date-time":"2020-09-01T00:00:00Z","timestamp":1598918400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Des. Autom. Electron. Syst."],"published-print":{"date-parts":[[2021,1,31]]},"abstract":"<jats:p>Fault attacks belong to a potent class of implementation-based attacks that can compromise a crypto-device within a few milliseconds. Out of the large numbers of faults that can occur in the device, only a very few are exploitable in terms of leaking the secret key. Ignorance of this fact has resulted in countermeasures that have either significant overhead or inadequate protection. This article presents a framework, referred to as FaultDroid, for automated vulnerability analysis of fault attacks. It explores the entire fault attack space, identifies the single\/multiple fault scenarios that can be exploited by a differential fault attack, rank-orders them in terms of criticality, and provides design guidance to mitigate the vulnerabilities at low cost. The framework enables a designer to automatically evaluate the fault attack vulnerabilities of a block cipher implementation and then incorporate efficient countermeasures. FaultDroid uses a formal model of fault attacks on a high-level specification of a block cipher and hence is equally applicable to both software and hardware implementation of the cipher. As case studies, we employ FaultDroid to comprehensively evaluate the fault scenarios in several common ciphers\u2014AES, CLEFIA, CAMELLIA, SMS4, SIMON, PRESENT, and GIFT\u2014and assess their vulnerability.<\/jats:p>","DOI":"10.1145\/3410336","type":"journal-article","created":{"date-parts":[[2020,9,2]],"date-time":"2020-09-02T04:04:02Z","timestamp":1599019442000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["FaultDroid"],"prefix":"10.1145","volume":"26","author":[{"given":"Indrani","family":"Roy","sequence":"first","affiliation":[{"name":"Indian Institute of Technology Madras, Chennai, TamilNadu, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chester","family":"Rebeiro","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Madras, Chennai, TamilNadu, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aritra","family":"Hazra","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, Paschim Medinipur, West Bengal, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Swarup","family":"Bhunia","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, FL"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,9]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2659651.2659709"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/IOLTS.2010.5560194"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-012-0046-y"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/DATE.2011.5763307"},{"volume-title":"Proceedings of the 7th Annual International Workshop on Selected Areas in Cryptography (SAC\u201900)","year":"2000","author":"Aoki Kazumaro","key":"e_1_2_1_5_1"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66787-4_16"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2013.12"},{"key":"e_1_2_1_8_1","first-page":"585","article-title":"SIMON and SPECK: Block ciphers for the Internet of Things","volume":"2015","author":"Beaulieu Ray","year":"2015","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2744769.2747946"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2003.1190590"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44598-6_8"},{"volume-title":"Proceedings of the 9th International Workshop on Cryptographic Hardware and Embedded Systems (CHES\u201907)","author":"Bogdanov Andrey","key":"e_1_2_1_12_1"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/s001450010016"},{"key":"e_1_2_1_14_1","unstructured":"Jakub Breier and Xiaolu Hou. 2017. Automated Fault Analysis of Assembly Code With a Case Study on PRESENT Implementation.  Jakub Breier and Xiaolu Hou. 2017. Automated Fault Analysis of Assembly Code With a Case Study on PRESENT Implementation."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2018.i2.96-122"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-013-0049-3"},{"volume-title":"Proceedings of the 11th USENIX Workshop on Offensive Technologies (WOOT\u201917)","year":"2017","author":"Cui Ang","key":"e_1_2_1_17_1"},{"volume-title":"The Design of Rijndael: AES\u2014The Advanced Encryption Standard","author":"Daemen Joan","key":"e_1_2_1_18_1"},{"key":"e_1_2_1_19_1","first-page":"329","article-title":"SMS4 encryption algorithm for wireless networks","volume":"2008","author":"Diffie Whitfield","year":"2008","journal-title":"IACR Cryptology ePrint Archive"},{"volume":"1294","volume-title":"Lecture Notes in Computer Science","author":"Biham E.","key":"e_1_2_1_20_1"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2014.15"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33481-8_17"},{"volume-title":"Smart Card Research and Advanced Applications","series-title":"Lecture Notes in Computer Science","author":"Goubet Lucien","key":"e_1_2_1_23_1"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2228360.2228463"},{"key":"e_1_2_1_25_1","first-page":"272","article-title":"FEDS: Comprehensive fault attack exploitability detection for software implementations of block ciphers","volume":"2020","author":"Keerthi","year":"2020","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded Systems"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2008.20"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2012.2231707"},{"volume-title":"Differential fault analysis attack resistant architectures for the advanced encryption standard","author":"Karpovsky Mark G.","key":"e_1_2_1_28_1","doi-asserted-by":"crossref","DOI":"10.1007\/1-4020-8147-2_12"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2004.1311880"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45238-6_10"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3061639.3062340"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15031-9_22"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2012.19"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2008.149"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-014-0077-7"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02384-2_26"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-013-0065-3"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2019.2897629"},{"key":"e_1_2_1_40_1","first-page":"581","article-title":"A diagonal fault attack on the advanced encryption standard","volume":"2009","author":"Saha D.","year":"2009","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_41_1","first-page":"1008","article-title":"Automatic characterization of exploitable faults: A machine learning approach","volume":"2017","author":"Saha Sayandeep","year":"2017","journal-title":"IACR Cryptology ePrint Archive"},{"volume-title":"Proceedings of the 6th International Workshop on Security Proofs for Embedded Systems (PROOFS@CHES\u201917)","year":"2017","author":"Saha Sayandeep","key":"e_1_2_1_42_1"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2018.i2.242-276"},{"volume-title":"The Blowfish encryption algorithm. Dr. Dobb\u2019s Journal\u2014Software Tools for the Professional Programmer 19, 4","year":"1994","author":"Schneier Bruce","key":"e_1_2_1_44_1"},{"key":"e_1_2_1_45_1","first-page":"23","article-title":"Twofish: A 128-bit block cipher","volume":"15","author":"Schneier Bruce","year":"1998","journal-title":"NIST AES Proposal"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/EDCC-7.2008.11"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74619-5_12"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.23919\/DATE48585.2020.9116380"},{"volume-title":"Proceedings of the 26th USENIX Security Symposium (USENIX Security\u201917)","author":"Tang Adrian","key":"e_1_2_1_49_1"},{"volume-title":"Proceedings of the 13th WISTP International Conference on Information Security Theory and Practice(WISTP\u201911)","author":"Tunstall M.","key":"e_1_2_1_50_1"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-011-0018-7"},{"volume-title":"Proceedings of the 16th International Workshop on Cryptographic Hardware and Embedded Systems (CHES\u201914)","year":"2014","author":"Tupsamudre Harshal","key":"e_1_2_1_52_1"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2017.18"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TEST.2004.1387397"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2016.2516905"}],"container-title":["ACM Transactions on Design Automation of Electronic Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3410336","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3410336","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:03:15Z","timestamp":1750197795000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3410336"}},"subtitle":["An Algorithmic Approach for Fault-Induced Information Leakage Analysis"],"short-title":[],"issued":{"date-parts":[[2020,9]]},"references-count":54,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,1,31]]}},"alternative-id":["10.1145\/3410336"],"URL":"https:\/\/doi.org\/10.1145\/3410336","relation":{},"ISSN":["1084-4309","1557-7309"],"issn-type":[{"type":"print","value":"1084-4309"},{"type":"electronic","value":"1557-7309"}],"subject":[],"published":{"date-parts":[[2020,9]]},"assertion":[{"value":"2020-01-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-06-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-09-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}