Supporting Material to "SIFA: Exploiting Ineffective Fault Inductions on Symmetric Cryptography"

Primas, Robert; Korak, Thomas

Dobraunig, Christoph; Eichlseder, Maria; Korak, Thomas; Mangard, Stefan; Mendel, Florian; Primas, Robert

Supplementary material to the paper "SIFA: Exploiting Ineffective Fault Inductions on Symmetric Cryptography" by Christoph Dobraunig, Maria Eichlseder, Thomas Korak, Stefan Mangard, Florian Mendel, and Robert Primas (CHES 2018,


Ineffectively faulted AES Ciphertexts for different platforms and with different fault countermeasures in place (including infection-based configurations). Files:

  • */ct_correct.txt: AES ciphertexts where a fault was induced during the encryption, but did not change the ciphertext (decimal, CSV, 1 row per ciphertext)
  • */round_keys.txt: 11 expanded AES round keys used for all ciphertexts (decimal, CSV, 1 row per round key)
  • */sei_hardware.dat: Results of the statistical key-recovery evaluation. Row i lists the SEI of the right key, the SEI of the best wrong key, and the rank of the correct key after using 4*i of the ciphertexts in ct_correct.txt.

Target platforms and setups are described in more detail in the paper.

