Fault injection attacks are a serious concern for cryptographic hardware.Adversaries may extract sensitive information from the faulty output that is producedby a cryptographic circuit after actively disturbing its computation. Alternatively,the information whether an output would have been faulty, even if it is withheld frombeing released, may be exploited. The former class of attacks, which requires thecollection of faulty outputs, such as Differential Fault Analysis (DFA), then eitherexploits some knowledge about the position of the injected fault or about its value.The latter class of attacks, which can be applied without ever obtaining faulty outputs,such as Statistical Ineffective Fault Attacks (SIFA), then either exploits a dependencybetween the effectiveness of the fault injection and the value to be faulted (e.g., anLSB stuck-at-0 only affecting odd numbers), denoted as SIFA-1, or a conditionalpropagation of a faulted value based on a sensitive intermediate (e.g., multiplicationof a faulted value by 0 prevents propagation), denoted as SIFA-2. The aptitude ofadditive masking schemes, which were designed to prevent side-channel analysis, toalso thwart fault attacks is typically assumed to be limited. Common fault models,such as toggle/bit-flip, stuck-at-0 or stuck-at-1 survive the recombination of Booleanshares well enough for generic attacks to succeed. More precisely, injecting a fault intoone or multiple Boolean shares often results in the same, or at least a predictable, errorappearing in the sensitive variable after recombination. In this work, we show thatadditive masking in prime-order fields breaks such relationships, causing frequentlyexploited biases to decrease exponentially in the number of shares. As a result,prime masking offers surprisingly strong protection against generic statistical attacks,which require a dependency between the effectiveness of an injected fault and thesecret variable that is manipulated, such as SIFA-1. Operation-dependent statisticalattacks, such as SIFA-2 and Fault Template Attacks (FTA), may still be performedagainst certain prime-field structures, even if they are masked with many shares. Yet,we analyze the corresponding cases and are able to provide specific guidelines onhow to avoid vulnerabilities either at the cipher design or implementation level bymaking informed decisions about the primes, non-linear mappings and masked gadgetsused. Since prime-field masking appears to be one of the rare instances of affordablecountermeasures that naturally provide sound protection against side-channel analysisand certain fault injection attacks, we believe there is a strong incentive for developingnew ciphers to leverage these advantages.
Moos, T., Saha, S., & Standaert, F.-X. (2024). Prime Masking vs. Faults - Exponential Security Amplification against Selected Classes of Attacks. IACR Transactions on Cryptography Hardware and Embedded Systems, 2024(4), 690-736. https://doi.org/10.46586/tches.v2024.i4.690-736 (Original work published 2024)