[1]Boneh D, DeMillo, R A, Lipton R J. On the importance of checking cryptographic protocols for faults[C] Proc of Int Conf on the Theory and Applications of Cryptographic Techniques. Berlin: Springer, 1997: 3751[2]Biham E, Shamir A. Differential fault analysis of secret key cryptosystems[C] Proc of Annual Int Cryptology Conf. Berlin: Springer, 1997: 513525[3]Hemme L. A differential fault attack against early rounds of (Triple) DES[C] Proc of Int Workshop on Cryptographic Hardware and Embedded Systems. Berlin: Springer, 2004: 254267[4]Fuhr T, Jaulmes E, Lomné V, et al. Fault attacks on AES with faulty ciphertexts only[C] Proc of 2013 Workshop on Fault Diagnosis and Tolerance in Cryptography. Piscataway, NJ: IEEE, 2013: 108118[5]Li Y, Sakiyama K, Gomisawa S, et al. Fault sensitivity analysis[C] Proc of Int Workshop on Cryptographic Hardware and Embedded Systems. Berlin: Springer, 2010: 320334[6]Ghalaty N F, Yuce B, Taha M, et al. Differential fault intensity analysis[C] Proc of 2014 Workshop on Fault Diagnosis and Tolerance in Cryptography. Piscataway, NJ: IEEE, 2014: 4958[7]BarEl H, Choukri H, Naccache D, et al. The sorcerer’s apprentice guide to fault attacks [J]. Proceedings of the IEEE, 2006, 94(3): 370382[8]Gierlichs B, Schmidt J M, Tunstall M. Infective computation and dummy rounds: Fault protection for block ciphers without checkbeforeoutput[C] Proc of Int conf on cryptology and information security in Latin America. Berlin: Springer, 2012: 305321[9]Clavier C. Secret external encodings do not prevent transient fault analysis[C] Proc of Cryptographic Hardware and Embedded Systems. Berlin: Springer, 2007: 181194[10]Dobraunig C, Eichlseder M, Korak T, et al. SIFA: Exploiting ineffective fault inductions on symmetric cryptography [J]. IACR Trans on Cryptographic Hardware Embedded System, 2018, 2018(3): 547572[11]吕述望, 苏波展, 王鹏, 等. SM4分组密码算法综述[J]. 信息安全研究, 2016, 2(11): 9951007[12]Zhang L, Wu W L. Differential fault analysis on SMS4 [J]. Chinese Journal of Computers, 2006, 29(9): 1596[13]Li R, Sun B, Li C, et al. Differential fault analysis on SMS4 using a single fault [J]. Information Processing Letters, 2011, 111(4): 156163[14]朱仁杰. 扩大故障注入范围的SM4差分故障攻击研究[J]. 计算机科学, 2019, 46(S2): 493506[15]金雨璇, 杨宏志, 王相宾, 等. 对SM4算法的改进差分故障攻击[J]. 密码学报, 2020, 7(4): 453464