A Novel Lattice-Based Fault Injection Attack Targeting the Nonce in the SM2 Digital Signature Algorithm


연구 분야: Cryptography



학회: ACM Transactions on Embedded Computing Systems, Volume 24, Issue 4


초록

In embedded systems, particularly resource-constrained Internet of Things (IoT) devices, the SM2 Digital Signature Algorithm (SM2-DSA) standard is widely deployed for cryptographic security. While fault injection attacks can compromise digital signatures and extract private keys without physical damage, traditional approaches require precise temporal or spatial control, resulting in limited success rates and revealing insufficient research into the potential vulnerabilities of SM2-DSA. To address this issue, this article introduces a novel and efficient lattice-based fault attack method targeting SM2-DSA. The method involves injecting faults into the nonce before the fourth step of the signature operation. By leveraging both the correct and erroneous intermediate values of Q obtained from the signature and verification processes, we can deduce partial bits of the nonce. Following this, we construct a lattice attack to recover the private key. Additionally, we establish the theoretical security boundary for lattice attack against SM2-DSA. Building upon the boundary, we propose an efficient implementation scheme for the attack. Experimental results demonstrate a 100% success rate over 1,000 trials, using 61 signatures with six known bits of nonces for 256-bit SM2-DSA, with each recovery process completed in under three seconds. Finally, we propose countermeasures against this attack. Our proposed attack reveals potential security vulnerabilities in SM2-DSA implementations, providing constructive guidance for enhancing algorithmic security measures and defensive countermeasures.


Author Profile
Cuiping Shao

Shenzhen University of Advanced Technology Shenzhen China and Guangdong Provincial Key Laboratory of Computility Microelectronics Shenzhen China

Andorra
Author Profile
Wenzhe Li

Shenzhen Institutes of Advanced Technology Chinese Academy of Sciences Shenzhen China and University of the Chinese Academy of Sciences Beijing China

Andorra
Author Profile
Huiyun Li

Shenzhen University of Advanced Technology Shenzhen China and Guangdong Provincial Key Laboratory of Computility Microelectronics Shenzhen China

Andorra

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Andorra, China
사이트 ACM
좋아요 수 0

연관 논문 목록 (494건)