Differential Fault Attack on Camellia
-
Abstract
Camellia is the final winner of 128-bit blockcipher in NESSIE project, and is also certified as the international IETF standard cipher for SSL/TLS cipher suites.In this study, we present an effcient differential fault attack on Camellia. Ideally, by using our techniques, on average, the complete key of Camellia-128 is recovered with64 faulty ciphertexts while the full keys of Camellia-192and Camellia-256 are retrieved with 96 faulty ciphertexts.Our attack is applicable to generic block ciphers with overall Fiestel structure using a SPN round function.All theseattacks have been successfully put into experimental simulations on a personal computer.
-
-