[Home ] [Archive]   [ فارسی ]  
:: Main :: About :: Current Issue :: Archive :: Search :: Submit :: Contact ::
Main Menu
Home::
Journal Information::
Articles archive::
For Authors::
For Reviewers::
Registration::
Site Facilities::
Indexing::
Contact us::
::
Search in website

Advanced Search
..
Receive site information
Enter your Email in the following box to receive the site news and information.
..
Print ISSN
Print ISSN: 2476-3047
..
:: Volume 14, Issue 1 (9-2025) ::
منادی 2025, 14(1): 120-135 Back to browse issues page
An Overview of Transient Fault Attacks on Block Ciphers
Mehdi Farzanegan1
1- Cyberspace Research Institute, Shahid Beheshti University, Tehran, Iran
Abstract:   (1234 Views)
Fault injection attacks constitute a powerful class of active adversarial techniques within the gray-box threat model, where the attacker is assumed to have partial knowledge of the target system and physical access to the cryptographic device. Over the past decades, these attacks have evolved from theoretical constructs into highly practical and efficient tools capable of compromising even well-engineered cryptographic implementations. By deliberately inducing faults during the execution of cryptographic algorithms, an adversary can manipulate intermediate computations and exploit discrepancies between correct and faulty outputs to extract sensitive information, most notably secret keys.

This paper presents a comprehensive survey of transient fault injection attacks targeting block ciphers, focusing on both theoretical foundations and practical considerations. It begins by formalizing fault models, which serve as the critical link between physical fault injection techniques and algorithmic cryptanalysis. Fault models are characterized by several dimensions, including the fault resolution (bit-level, byte-level, or word-level), fault type (e.g., random, stuck-at, or bit-flip), and the number of affected variables. Additionally, spatial and temporal precision play a crucial role: while some attacks require precise targeting of specific operations at exact clock cycles, others operate under more relaxed assumptions. The classification also distinguishes between transient, persistent, and permanent faults, each with different implications for attack feasibility and complexity. A more precise fault model typically enables stronger attacks but increases the difficulty of practical realization.

The paper further explores various fault injection techniques, highlighting their operational principles and trade-offs. Clock glitching and voltage glitching are widely used due to their relatively low cost and ease of implementation, though they offer limited spatial precision. Environmental manipulations, such as temperature variations, can also induce faults but with lower controllability. Electromagnetic fault injection (EMFI) provides improved spatial targeting without requiring invasive access, while laser-based fault injection offers the highest precision, enabling attackers to target specific transistors or memory cells. However, such precision comes at the cost of expensive equipment and invasive chip preparation. These techniques are compared based on criteria such as spatial locality (local vs. global faults), required physical access (invasive vs. non-invasive), cost, and technical expertise.

A central contribution of the work is the systematic classification of fault analysis techniques into three main categories: differential, collision-based, and statistical methods. Differential Fault Analysis (DFA), one of the most influential approaches, leverages the propagation of injected faults through the cryptographic algorithm. By comparing correct and faulty ciphertexts, the attacker can infer information about intermediate states and gradually recover the secret key. The paper illustrates this concept through a detailed analysis of DFA applied to AES, where a single-byte fault injected in an intermediate round can affect multiple output bytes, significantly reducing the key search space. Variants such as Impossible Differential Fault Analysis (IDFA) further refine this approach by exploiting impossible differential patterns to eliminate incorrect key candidates.

Collision-based methods, including CFA and IFA, exploit conditions such as output collisions or unchanged outputs rather than differences. In CFA, the attacker finds inputs that yield identical outputs in both faulty and fault-free executions, revealing constraints on internal states. In contrast, IFA identifies faults that do not alter the output, indicating specific properties of intermediate values. SEA further extends this idea by considering faults that affect unused internal data, leaving the output unchanged. These approaches are particularly useful when differential methods are limited by countermeasures.

Statistical fault analysis techniques form an advanced class of attacks that exploit biases in faulty output distributions, with methods such as SFA, SIFA, and SEFA often relying solely on faulty data, unlike DFA. SIFA is particularly effective against implementations with fault detection, as it leverages ineffective faults—those that do not alter the output—to extract key information even when outputs are suppressed or randomized, challenging the assumption that such faults are harmless. SEFA extends this approach by focusing on effective faults, offering improved robustness in noisy environments and requiring fewer samples for key recovery. In addition, advanced models such as Linked Fault Analysis (LFA) and Fault Template Attacks (FTA) exploit structural properties of implementations and fault propagation patterns, demonstrating that fault attacks can adapt to increasingly sophisticated scenarios, even with only partial system information available.

In the final part, the paper reviews countermeasures against fault injection attacks at three levels: physical, protocol, and algorithmic implementation. Physical-level defenses include shielding, sensors, and tamper-resistant packaging to prevent or detect external interference. Protocol-level approaches, such as periodic key refreshing, aim to limit the usefulness of extracted information. At the implementation level, techniques such as redundancy, concurrent error detection, output randomization, and error correction codes are widely employed. However, each of these methods introduces trade-offs in terms of performance, area overhead, or energy consumption. Moreover, many countermeasures can be bypassed by advanced attacks such as SIFA, which exploit the very mechanisms designed to detect faults.

In conclusion, fault injection attacks remain a critical challenge in the secure implementation of cryptographic systems. Their effectiveness stems from the interplay between physical fault mechanisms and algorithmic vulnerabilities. As the field advances, emerging research directions include combined fault and side-channel attacks, automated fault analysis using machine learning techniques, and the study of fault attacks on post-quantum cryptographic algorithms. Addressing these challenges requires a holistic, multi-layered approach that integrates robust design principles across all levels of the system.
Keywords: Fault attack, Fault injection, Active attack, Fault countermeasures
Full-Text [PDF 2067 kb]   (664 Downloads)    
Type of Study: Review Article | Subject: Cryptology and Information Security
Received: 2024/11/11 | Accepted: 2025/07/20 | Published: 2026/02/3
Add your comments about this article
Your username or Email:

CAPTCHA


XML   Persian Abstract   Print


Download citation:
BibTeX | RIS | EndNote | Medlars | ProCite | Reference Manager | RefWorks
Send citation to:

Farzanegan M. An Overview of Transient Fault Attacks on Block Ciphers. منادی 2025; 14 (1) :120-135
URL: http://monadi.isc.org.ir/article-1-289-en.html


Rights and permissions
Creative Commons License This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Volume 14, Issue 1 (9-2025) Back to browse issues page
دوفصل نامه علمی  منادی امنیت فضای تولید و تبادل اطلاعات( افتا) Biannual Journal Monadi for Cyberspace Security (AFTA)
Persian site map - English site map - Created in 0.15 seconds with 39 queries by YEKTAWEB 4774