Skip to main content

2018 | OriginalPaper | Buchkapitel

An EM Fault Injection Susceptibility Criterion and Its Application to the Localization of Hotspots

verfasst von : Maxime Madau, Michel Agoyan, Philippe Maurine

Erschienen in: Smart Card Research and Advanced Applications

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Electromagnetic (EM) fault injection has been proven efficient in attacking targets such as system-on-chip (SoC) or smartcards. Nonetheless, security characterisations, performed either by certification laboratories or by firms, are time consuming and this impacts on the final result. Indeed complete tests of integrated circuits (ICs) require trying numerous parameters, from pulse polarity to probes geometry and coupling, hence many maps are required to test all surface of Devices Under Test (DUT) and are unfortunately rarely performed.
In this paper we propose a criterion to find zones with a high susceptibility to EM Fault Injection (EMFI). By using preprocessing tools based on both the effects of EMFI on circuits and the analysis of EM emission traces, we are able to speed up the search of zones where faults are more likely to occur hence reducing the time required for security characterisations.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Bar-El, H., Choukri, H., Naccache, D., Tunstall, M., Whelan, C.: The sorcerer’s apprentice guide to fault attacks. IACR Cryptology ePrint Archive, 2004:100 (2004) Bar-El, H., Choukri, H., Naccache, D., Tunstall, M., Whelan, C.: The sorcerer’s apprentice guide to fault attacks. IACR Cryptology ePrint Archive, 2004:100 (2004)
2.
Zurück zum Zitat Bayon, P., Bossuet, L., Aubert, A., Fischer, V., Poucheret, F., Robisson, B., Maurine, P.: Contactless electromagnetic active attack on ring oscillator based true random number generator. In: COSADE, pp. 151–166 (2012) Bayon, P., Bossuet, L., Aubert, A., Fischer, V., Poucheret, F., Robisson, B., Maurine, P.: Contactless electromagnetic active attack on ring oscillator based true random number generator. In: COSADE, pp. 151–166 (2012)
3.
Zurück zum Zitat Dehbaoui, A., Dutertre, J.-M., Robisson, B., Orsatelli, P., Maurine, P., Tria, A.: Injection of transient faults using electromagnetic pulses - practical results on a cryptographic system. IACR Cryptology ePrint Archive, 2012:123 (2012) Dehbaoui, A., Dutertre, J.-M., Robisson, B., Orsatelli, P., Maurine, P., Tria, A.: Injection of transient faults using electromagnetic pulses - practical results on a cryptographic system. IACR Cryptology ePrint Archive, 2012:123 (2012)
4.
Zurück zum Zitat Dehbaoui, A., Dutertre, J.-M., Robisson, B., Tria, A.: Electromagnetic transient faults injection on a hardware and a software implementations of AES. In: FDTC, pp. 7–15 (2012) Dehbaoui, A., Dutertre, J.-M., Robisson, B., Tria, A.: Electromagnetic transient faults injection on a hardware and a software implementations of AES. In: FDTC, pp. 7–15 (2012)
5.
Zurück zum Zitat Dehbaoui, A., Lomné, V., Ordas, T., Torres, L., Robert, M., Maurine, P.: Enhancing electromagnetic analysis using magnitude squared incoherence. IEEE Trans. VLSI Syst. 20(3), 573–577 (2012)CrossRef Dehbaoui, A., Lomné, V., Ordas, T., Torres, L., Robert, M., Maurine, P.: Enhancing electromagnetic analysis using magnitude squared incoherence. IEEE Trans. VLSI Syst. 20(3), 573–577 (2012)CrossRef
6.
Zurück zum Zitat El-Baze, D., Rigaud, J.-B., Maurine, P.: An embedded digital sensor against EM and BB fault injection. In: 2016 Workshop on Fault Diagnosis and Tolerance in Cryptography, FDTC 2016, Santa Barbara, CA, USA, 16 August 2016, pp. 78–86 (2016) El-Baze, D., Rigaud, J.-B., Maurine, P.: An embedded digital sensor against EM and BB fault injection. In: 2016 Workshop on Fault Diagnosis and Tolerance in Cryptography, FDTC 2016, Santa Barbara, CA, USA, 16 August 2016, pp. 78–86 (2016)
7.
Zurück zum Zitat Gruss, D., Maurice, C., Mangard, S.: Rowhammer.js: a remote software-induced fault attack in javascript. In: Detection of Intrusions and Malware, and Vulnerability Assessment - 13th International Conference, DIMVA 2016, Proceedings, San Sebastián, Spain, 7–8 July 2016, pp. 300–321 (2016) Gruss, D., Maurice, C., Mangard, S.: Rowhammer.js: a remote software-induced fault attack in javascript. In: Detection of Intrusions and Malware, and Vulnerability Assessment - 13th International Conference, DIMVA 2016, Proceedings, San Sebastián, Spain, 7–8 July 2016, pp. 300–321 (2016)
8.
Zurück zum Zitat Ordas, S., Guillaume-Sage, L., Maurine, P.: Electromagnetic fault injection: the curse of flip-flops. J. Cryptographic Eng., 1–15 (2016) Ordas, S., Guillaume-Sage, L., Maurine, P.: Electromagnetic fault injection: the curse of flip-flops. J. Cryptographic Eng., 1–15 (2016)
9.
Zurück zum Zitat Ordas, S., Guillaume-Sage, L., Maurine, P.: EM injection: fault model and locality. In: 2015 Workshop on Fault Diagnosis and Tolerance in Cryptography, FDTC 2015, Saint Malo, France, 13 September 2015, pp. 3–13 (2015) Ordas, S., Guillaume-Sage, L., Maurine, P.: EM injection: fault model and locality. In: 2015 Workshop on Fault Diagnosis and Tolerance in Cryptography, FDTC 2015, Saint Malo, France, 13 September 2015, pp. 3–13 (2015)
10.
Zurück zum Zitat Ordas, S., Guillaume-Sage, L., Tobich, K., Dutertre, J.-M., Maurine, P.: Evidence of a larger em-induced fault model. In: Smart Card Research and Advanced Applications - 13th International Conference, CARDIS 2014, Paris, France, 5–7 November 2014, pp. 245–259 (2014). Revised Selected Papers Ordas, S., Guillaume-Sage, L., Tobich, K., Dutertre, J.-M., Maurine, P.: Evidence of a larger em-induced fault model. In: Smart Card Research and Advanced Applications - 13th International Conference, CARDIS 2014, Paris, France, 5–7 November 2014, pp. 245–259 (2014). Revised Selected Papers
11.
Zurück zum Zitat Park, K., Lim, C.S., Yun, D., Baeg, S.: Experiments and root cause analysis for active-precharge hammering fault in DDR3 SDRAM under 3\(\times \) nm technology. Microelectron. Reliab. 57, 39–46 (2016)CrossRef Park, K., Lim, C.S., Yun, D., Baeg, S.: Experiments and root cause analysis for active-precharge hammering fault in DDR3 SDRAM under 3\(\times \) nm technology. Microelectron. Reliab. 57, 39–46 (2016)CrossRef
12.
Zurück zum Zitat Piret, G., Quisquater, J.-J.: A differential fault attack technique against SPN structures, with application to the AES and KHAZAD. In: Cryptographic Hardware and Embedded Systems - CHES 2003, 5th International Workshop, Proceedings, Cologne, Germany, 8–10 September 2003, pp. 77–88 (2003) Piret, G., Quisquater, J.-J.: A differential fault attack technique against SPN structures, with application to the AES and KHAZAD. In: Cryptographic Hardware and Embedded Systems - CHES 2003, 5th International Workshop, Proceedings, Cologne, Germany, 8–10 September 2003, pp. 77–88 (2003)
13.
Zurück zum Zitat Poucheret, F., Tobich, K., Lisart, M., Chusseau, L., Robisson, B., Maurine, P.: Local and direct EM injection of power into CMOS integrated circuits. In: FDTC, pp. 100–104 (2011) Poucheret, F., Tobich, K., Lisart, M., Chusseau, L., Robisson, B., Maurine, P.: Local and direct EM injection of power into CMOS integrated circuits. In: FDTC, pp. 100–104 (2011)
14.
Zurück zum Zitat Quisquater, J.J., Samyde, D.: Eddy current for magnetic analysis with active sensor. In: Proceedings of ESmart 2002, Eurosmart, pp. 185–194 (2002) Quisquater, J.J., Samyde, D.: Eddy current for magnetic analysis with active sensor. In: Proceedings of ESmart 2002, Eurosmart, pp. 185–194 (2002)
15.
Zurück zum Zitat Schmidt, J.-M., Hutter, M: Optical and EM fault-attacks on CRT-based RSA: concrete results. In: Wolkerstorfer, J., Posch, K.C., (eds.) 15th Austrian Workhop on Microelectronics, Austrochip 2007, Proceedings, Graz, Austria, 11 October 2007, pp. 61–67. Verlag der Technischen Universität Graz (2007) Schmidt, J.-M., Hutter, M: Optical and EM fault-attacks on CRT-based RSA: concrete results. In: Wolkerstorfer, J., Posch, K.C., (eds.) 15th Austrian Workhop on Microelectronics, Austrochip 2007, Proceedings, Graz, Austria, 11 October 2007, pp. 61–67. Verlag der Technischen Universität Graz (2007)
16.
Zurück zum Zitat Tobich, K., Maurine, P., Liardet, P.-Y., Lisart, M., Ordas, T.: Voltage spikes on the substrate to obtain timing faults. In: DSD, pp. 483–486 (2013) Tobich, K., Maurine, P., Liardet, P.-Y., Lisart, M., Ordas, T.: Voltage spikes on the substrate to obtain timing faults. In: DSD, pp. 483–486 (2013)
17.
Zurück zum Zitat Zussa, L., Dehbaoui, A., Tobich, K., Dutertre, J.-M., Maurine, P., Guillaume-Sage, L., Clédière, J., Tria, A.: Efficiency of a glitch detector against electromagnetic fault injection. In: DATE, pp. 1–6 (2014) Zussa, L., Dehbaoui, A., Tobich, K., Dutertre, J.-M., Maurine, P., Guillaume-Sage, L., Clédière, J., Tria, A.: Efficiency of a glitch detector against electromagnetic fault injection. In: DATE, pp. 1–6 (2014)
Metadaten
Titel
An EM Fault Injection Susceptibility Criterion and Its Application to the Localization of Hotspots
verfasst von
Maxime Madau
Michel Agoyan
Philippe Maurine
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-319-75208-2_11

Premium Partner