Key-Recovery Attack Against Ascon Using 1-Bit Random Fault Model
摘要
NIST-selected lightweight cryptography Ascon is becoming increasingly important in IoT devices with limited computational resources. Without countermeasures, Ascon is vulnerable to secret key recovery through fault attacks, which can pose a serious threat to the security of IoT systems. In this study, we focus on Differential Fault Analysis and investigate the physical attack security of Ascon authentication encryption in the context of fault attacks. We propose the DFA attack using a one-bit random fault model, where an attacker bit-flips one random bit of the S-box input to reduce the 128-bit key space. According to theoretical considerations based on the coupon collector problem and practical simulations, the key space can be reduced less than 10 bits by 640 fault injections.