This paper describes a DFA attack on the AES key schedule. This fault model assumes that the attacker can induce a single
byte fault on the round key. It efficiently finds the key of AES-128 with feasible computation and less than thirty pairs
of correct and faulty ciphertexts. Several countermeasures are also proposed. This weakness can be resolved without modifying
the structure of the AES algorithm and without decreasing the efficiency.
Keywords AES - Differential fault analysis (DFA) - Physical cryptanalysis - Rijndael - Smart cards
Supported in part by the National Science Council of the Republic of China under contract NSC 91-2213-E-008-032.