Building a Side-Channel Attack Scheme on SipHash FPGA Implementation
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F68407700%3A21240%2F25%3A00386088" target="_blank" >RIV/68407700:21240/25:00386088 - isvavai.cz</a>
Výsledek na webu
<a href="https://doi.org/10.1109/DSD67783.2025.00033" target="_blank" >https://doi.org/10.1109/DSD67783.2025.00033</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/DSD67783.2025.00033" target="_blank" >10.1109/DSD67783.2025.00033</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
Building a Side-Channel Attack Scheme on SipHash FPGA Implementation
Popis výsledku v původním jazyce
This paper introduces a novel side-channel attack scheme targeting FPGA implementations of the SipHash cipher, a cryptographic hash function commonly used for message authentication. At the time of writing, we were unaware of any side-channel attack on hardware implementation of the SipHash. A leakage function was built that is able to compute part of the internal state after 1 round based on just a few bits of the key. Our approach is based on progressively eliminating incorrect subkeys in iterations, while adding new bits of the key we attack, rather than trying to extract the subkey directly. The total amount of key hypothesizes does not exceed a limit when it becomes unfeasible to compute. In the end, all 128 bits of the SipHash key are obtained.
Název v anglickém jazyce
Building a Side-Channel Attack Scheme on SipHash FPGA Implementation
Popis výsledku anglicky
This paper introduces a novel side-channel attack scheme targeting FPGA implementations of the SipHash cipher, a cryptographic hash function commonly used for message authentication. At the time of writing, we were unaware of any side-channel attack on hardware implementation of the SipHash. A leakage function was built that is able to compute part of the internal state after 1 round based on just a few bits of the key. Our approach is based on progressively eliminating incorrect subkeys in iterations, while adding new bits of the key we attack, rather than trying to extract the subkey directly. The total amount of key hypothesizes does not exceed a limit when it becomes unfeasible to compute. In the end, all 128 bits of the SipHash key are obtained.
Klasifikace
Druh
D - Stať ve sborníku
CEP obor
—
OECD FORD obor
20206 - Computer hardware and architecture
Návaznosti výsledku
Projekt
<a href="/cs/project/VJ02010010" target="_blank" >VJ02010010: Nástroje pro verifikaci bezpečnosti kryptografických zařízení s využitím AI</a><br>
Návaznosti
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název statě ve sborníku
Proceedings of the 2025 28th Euromicro Conference on Digital System Design
ISBN
979-8-3315-8499-3
ISSN
2639-3859
e-ISSN
2771-2508
Počet stran výsledku
5
Strana od-do
160-164
Název nakladatele
IEEE Computer Society
Místo vydání
Los Alamitos
Místo konání akce
Salerno
Datum konání akce
10. 9. 2025
Typ akce podle státní příslušnosti
WRD - Celosvětová akce
Kód UT WoS článku
001717790400021