SCARE of an unknown hardware Feistel implementation
Real, D.;Dubois, Vincent;Guilloux, A.-M.;Valette, F.;Drissi, M.
(2008) Smart Card Research and Advanced Applications. 8th IFIP WG 8.8/11.2 International Conference, CARDIS 2008 — Location: London, UK (8.September.2008)
Physical attacks based on side channel analysis (SCA) or on fault analysis (FA) target a secret usually manipulated by a public algorithm. SCA can also be used for reverse engineering (SCARE) against the software implementation of a private algorithm. In this paper, we claim that an unknown Feistel scheme with an hardware design can be recovered with a chosen plaintexts SCA attack. First, we show that whatever is the input of the unknown Feistel function, its one-round output can be guessed by SCA. Using this relation, two attacks for recovering the algorithm are proposed: an expensive interpolation attack on a generic Feistel scheme and an improved attack on a specific but commonly used scheme. Then, a countermeasure is proposed.
Real, D., Dubois, V., Guilloux, A.-M., Valette, F., & Drissi, M. (2008). SCARE of an unknown hardware Feistel implementation. In Grimaud, G.; Standaert, F.-X.; (ed.), Smart Card Research and Advanced Applications. 8th IFIP WG 8.8/11.2 International Conference, CARDIS 2008 (p. p. 218-227). Springer-verlag. https://doi.org/10.1007/978-3-540-85893-5_16