{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:04:07Z","timestamp":1777806247275,"version":"3.51.4"},"reference-count":27,"publisher":"SAGE Publications","issue":"2","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2024,4,9]]},"abstract":"<jats:p>Cache attacks pose a serious security threat to cryptographic implementations in processor architectures. In this paper, we first propose cache attacks against Blowfish, which can break the protection of key-dependent S-box. This attack targets at the subkey calculation of Blowfish, and fully exploits features of the subkey calculation to construct a leakage equation group about the key. Without any knowledge of plaintext and ciphertext, the attacker only needs to obtain the cache leakage once to recover a variable-length key in minute-level time. More than that, we establish a leakage model for cache attack situations to evaluate the exhausting space of the intermediate value of block ciphers, and estimate the time complexity of cache attacks. In our experiments, we perform Flush + Reload and Prime + Probe attacks and recover the random key of Blowfish in OpenSSL 1.1.1h in 4 minutes. Furthermore, we have applied our attacks to existing systems, such as JavaScript-blowfish and Bcrypt. Our attack on JavaScript-blowfish can recover any plaintext input by the user. As for Bcrypt, our attack can recover the hash values stored in the database, thereby allowing attackers to impersonate the user\u2019s identity.<\/jats:p>","DOI":"10.3233\/jcs-230052","type":"journal-article","created":{"date-parts":[[2023,11,17]],"date-time":"2023-11-17T11:31:45Z","timestamp":1700220705000},"page":"165-191","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":1,"title":["Cache attacks on subkey calculation of\u00a0Blowfish"],"prefix":"10.1177","volume":"32","author":[{"given":"Haopeng","family":"Fan","sequence":"first","affiliation":[{"name":"Henan Key Laboratory of Network Cryptography Technology, Zhengzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenhao","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yongjuan","family":"Wang","sequence":"additional","affiliation":[{"name":"Henan Key Laboratory of Network Cryptography Technology, Zhengzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiangbin","family":"Wang","sequence":"additional","affiliation":[{"name":"Henan Key Laboratory of Network Cryptography Technology, Zhengzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang","family":"Gao","sequence":"additional","affiliation":[{"name":"Henan Key Laboratory of Network Cryptography Technology, Zhengzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2023,11,15]]},"reference":[{"key":"ref001","first-page":"1","volume":"11","author":"Adomnicai A.","year":"2020","journal-title":"Cryptology ePrint Archive"},{"key":"ref002","first-page":"1207","volume":"6","author":"Bae D.","year":"2020","journal-title":"J Korea Inst Inf Secur Cryptol"},{"key":"ref003","doi-asserted-by":"publisher","DOI":"10.1007\/11894063_16"},{"key":"ref004","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00022"},{"key":"ref005","first-page":"1","volume":"4","author":"Domnitser L.","year":"2012","journal-title":"ACM Transactions on Architecture and Code Optimization (TACO)"},{"key":"ref006","first-page":"1","volume":"1","author":"Doychev G.","year":"2015","journal-title":"Transactions on information and system security (TISSEC)"},{"key":"ref007","doi-asserted-by":"publisher","DOI":"10.1109\/IAEAC54830.2022.9929896"},{"key":"ref008","doi-asserted-by":"publisher","DOI":"10.3758\/BF03209464"},{"key":"ref009","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2020.i1.231-255"},{"key":"ref010","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.22"},{"key":"ref011","first-page":"1","volume":"1","author":"Hasan M.K.","year":"2021","journal-title":"Complexity"},{"key":"ref012","doi-asserted-by":"publisher","DOI":"10.1145\/3123939.3124546"},{"key":"ref013","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.42"},{"key":"ref014","first-page":"5","volume":"10","author":"Jang S.W.","year":"2017","journal-title":"Anal Appl Math"},{"key":"ref015","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2000-82-304"},{"key":"ref016","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"ref017","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-42921-8_29"},{"key":"ref018","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-021-00099-1"},{"key":"ref019","doi-asserted-by":"crossref","unstructured":"M.\u00a0Neve and J.P.\u00a0Seifert, Advances on Access-Driven Cache Attacks on AES. Selected Areas in Cryptography, Springer, Berlin, 2007, pp.\u00a0147\u2013162.","DOI":"10.1007\/978-3-540-74462-7_11"},{"key":"ref020","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24586-2_13"},{"key":"ref021","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2018.00068"},{"key":"ref022","doi-asserted-by":"publisher","DOI":"10.1145\/3307650.3322246"},{"key":"ref023","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-58108-1_24"},{"key":"ref024","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00050"},{"key":"ref025","doi-asserted-by":"crossref","unstructured":"Y.\u00a0Tsunoo, T.\u00a0Saito, T.\u00a0Suzaki, M.\u00a0Shigeri and H.\u00a0Miyauchi, Cryptanalysis of DES Implemented on Computers with Cache. International Workshop on Cryptographic Hardware and Embedded Systems (CHES 2003), Springer, Berlin, 2003, pp.\u00a062\u201376.","DOI":"10.1007\/978-3-540-45238-6_6"},{"key":"ref026","unstructured":"M.\u00a0Werner, T.\u00a0Unterluggauer, L.\u00a0Giner, M.\u00a0Schwarz, D.\u00a0Gruss and S.\u00a0Mangard, in: Proceedings of 28th USENIX Conference on Security Symposium (SEC\u201919), Santa Clara, 14\u201316 Aug, USENIX Association, 2019, pp.\u00a0675\u2013692."},{"key":"ref027","unstructured":"Y.\u00a0Yarom and K.\u00a0Falkner, FLUSH + RELOAD: A high resolution, low noise, L3 cache side-channel attack, in: 23th USENIX Conference on Security Symposium (SEC\u201914), San Diego, 20\u201322 Aug, USENIX Association, 2014, pp.\u00a0719\u2013732."}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-230052","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-230052","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-230052","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:48Z","timestamp":1777495548000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-230052"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":27,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,4,9]]}},"alternative-id":["10.3233\/JCS-230052"],"URL":"https:\/\/doi.org\/10.3233\/jcs-230052","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,15]]}}}