SCARE of an unknown hardware Feistel implementation

Real, D.;Dubois, Vincent;Guilloux, A.-M.;Valette, F.;Drissi, M.
(2008) Smart Card Research and Advanced Applications. 8th IFIP WG 8.8/11.2 International Conference, CARDIS 2008 — Location: London, UK (8.September.2008)

Files

pdfdocument.pdf
  • Restricted Access
  • Adobe PDF
  • 596.72 KB

Details

Authors
  • Real, D.
    Author
  • Author
  • Guilloux, A.-M.
    Author
  • Valette, F.
    Author
  • Drissi, M.
    Author
Abstract
Physical attacks based on side channel analysis (SCA) or on fault analysis (FA) target a secret usually manipulated by a public algorithm. SCA can also be used for reverse engineering (SCARE) against the software implementation of a private algorithm. In this paper, we claim that an unknown Feistel scheme with an hardware design can be recovered with a chosen plaintexts SCA attack. First, we show that whatever is the input of the unknown Feistel function, its one-round output can be guessed by SCA. Using this relation, two attacks for recovering the algorithm are proposed: an expensive interpolation attack on a generic Feistel scheme and an improved attack on a specific but commonly used scheme. Then, a countermeasure is proposed.
Affiliations

Citations

Real, D., Dubois, V., Guilloux, A.-M., Valette, F., & Drissi, M. (2008). SCARE of an unknown hardware Feistel implementation. In Grimaud, G.; Standaert, F.-X.; (ed.), Smart Card Research and Advanced Applications. 8th IFIP WG 8.8/11.2 International Conference, CARDIS 2008 (p. p. 218-227). Springer-verlag. https://doi.org/10.1007/978-3-540-85893-5_16