An automatic formal fault analysis method for block ciphers

CN118413354BActive Publication Date: 2026-08-28NORTHWESTERN POLYTECHNICAL UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410440073.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-12
Publication Date
2026-08-28
Estimated Expiration
2044-04-12

AI Technical Summary

Technical Problem

虽然该方法可以提高密码核实现安全性验证的效率,但目前安全属性主要依赖于人工书写,安全属性的质量和完备性难以保障

Benefits of technology

[0035] This invention automates the formal fault propagation model, fault attribute mining, and formal fault analysis of cryptographic kernels, providing an automated analysis method for security verification of cryptographic kernel design in the pre-silicon stage, without requiring testers to have relevant cryptographic knowledge. This invention is applicable to single-byte and multi-byte fault analysis in block cipher systems, with no strict requirements on the location and type of fault injection. Compared with existing fault analysis techniques, this invention has better scalability and universality, avoids complex formula derivations, supports ciphertext-only analysis, and requires only a small amount of ciphertext to recover the key, making it more efficient than existing methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118413354B_ABST
    Figure CN118413354B_ABST
Patent Text Reader

Abstract

The application discloses an automatic formal fault analysis method for block ciphers, which comprises three stages of formal fault propagation model establishment, fault attribute mining and formal fault analysis. The formal fault propagation model of the cipher core measures the propagation process of faults in the cipher iteration. The method can automatically establish a formal fault propagation model for the cipher core design and is suitable for describing the propagation process of different types of faults in the cipher iteration. In the fault attribute mining stage, inherent behavior patterns are extracted from the fault trajectory simulated by the formal fault propagation model as fault attributes, thereby providing mathematical theory support for the formal analysis. In the formal fault analysis stage, the formal verification tool is used to automatically search for correct keys based on the extracted fault attributes. The method has better scalability and universality, does not require complex formula derivation, supports ciphertext-only analysis, and can recover the keys only by using a small amount of ciphertext, and is more effective than the existing method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of security technology, specifically relating to an automatic formal fault analysis method for block ciphers. Background Technology

[0002] Fault injection attacks are a type of active side-channel attack that alters the operating conditions of a cryptographic device, such as clock speed, voltage, or temperature, or uses high-energy rays or malicious logic to induce erroneous outputs. Attackers then exploit the differential or statistical properties of the fault information to recover the key. Compared to passive side-channel attacks, fault injection attacks require fewer side-channel traces to recover the key, making them a more effective method widely used in analyzing the security of cryptographic core designs and implementations.

[0003] Fault injection attacks comprise three parts: fault injection, fault model building, and fault analysis. The purpose of fault injection is to disrupt the normal operation of cryptographic devices. Attackers can choose to inject faults during stages such as cryptographic iteration or key expansion, based on the structural characteristics of the cryptographic algorithm. Fault types can be categorized by the number of faults: single-bit faults, single-byte faults, and multi-byte faults; and by the duration: random faults, persistent faults, and permanent faults. Fault models describe the propagation effect of faults during cryptographic iteration. Currently, most methods require manual fault model building and have strict requirements on the type, number, and location of injected faults. Fault analysis aims to recover the key based on the propagation characteristics of faults during cryptographic iteration. It is mainly divided into fault analysis based on differential properties and fault analysis based on statistical properties. Fault analysis based on differential properties first derives the fault pattern by combining the guessed key and correct / incorrect ciphertext, and then filters the key based on the differential properties satisfied by the fault. This process usually requires complex mathematical derivation. Fault analysis based on statistical properties uses the impact of faults on the statistical distribution of data to search for keys, requiring the analysis of a large number of incorrect ciphertexts. While existing fault analysis methods are effective, most of them are only applicable to specific cryptographic algorithms and lack versatility and scalability.

[0004] Currently, formal verification is a common method for analyzing the security of cryptographic core designs in the pre-silicon phase. The verification process determines the presence of security vulnerabilities in the core design by detecting violations of security properties. Formal verification uses rigorous mathematical methods to prove that the cryptographic core design functions correctly in all states, including methods based on logic verification, model verification, and algebraic verification. While this method can improve the efficiency of cryptographic core security verification, current security properties mainly rely on manual writing, making it difficult to guarantee the quality and completeness of these properties.

[0005] Therefore, existing fault analysis methods generally require manual establishment of fault models, key recovery through complex mathematical derivation or statistical analysis, and have strict requirements on cryptographic algorithms and the location and number of fault injections. Few methods can achieve automatic extraction of security attributes, have no strict restrictions on the types of injected faults, and are applicable to automatic fault analysis of various cryptographic systems. Summary of the Invention

[0006] To overcome the shortcomings of existing technologies, this invention provides an automated formal fault analysis method for block ciphers, comprising three stages: formal fault propagation model establishment, fault attribute mining, and formal fault analysis. The formal fault propagation model of the cipher kernel accurately measures the propagation process of faults during cipher iteration. This method can automatically establish a formal fault propagation model for cipher kernel design, suitable for describing the propagation process of different types of faults during cipher iteration. The fault attribute mining stage extracts inherent behavioral patterns as fault attributes from the fault trajectories simulated by the formal fault propagation model, providing mathematical theoretical support for formal analysis. The formal fault analysis stage uses formal verification tools to automatically search for the correct key based on the extracted fault attributes. This invention's method has better scalability and universality, avoids complex formula derivations, supports ciphertext-only analysis, and requires only a small amount of ciphertext to recover the key, making it more efficient than existing methods.

[0007] The technical solution adopted by this invention to solve its technical problem is as follows:

[0008] Step 1: Establish a formal fault propagation model library for basic logic units;

[0009] A formal fault propagation model for circuit design is established using information flow tracing technology. Fault states are identified by adding fault tags to the input and output signals of the circuit design bit by bit. The propagation of fault information is monitored based on the flow of these fault tags. A fault tag of logic '0' indicates that the signal is not faulty; otherwise, the signal is in a fault state. The propagation of fault tags in the formal fault propagation model of the circuit design satisfies the logical constraints of the circuit design, namely, the fault state corresponding to the input signal can only propagate to the output signal when the input data affects the value of the output data. Boolean expressions can be used to describe the formal propagation model. Based on this method, a formal fault model is built for the fault propagation process of all basic logic units in integrated circuit design, establishing a formal fault propagation model library for basic logic units.

[0010] The formal fault model of the NOT gate has a Boolean expression of O. t =A t A t and O t These are the fault tags corresponding to input signal A and output signal O, respectively.

[0011] The formal fault model Boolean expression for a two-input XOR gate is: Among them B t The fault tag corresponding to input signal B;

[0012] The formal fault model Boolean expression for the two-input AND gate is: Where O is the output signal;

[0013] The formal fault model Boolean expression for a two-input OR gate is:

[0014] Step 2: Establish a formal fault propagation model for the cryptographic kernel;

[0015] By using logic synthesis, the cryptographic core design is transformed into a gate-level netlist. By mapping the basic logic units in the gate-level netlist to the formal propagation model library of basic logic units, the corresponding formal propagation models of basic logic units are logically combined to establish a formal fault propagation model for the cryptographic core.

[0016] Step 3: Formal fault propagation model simulation;

[0017] Using EDA tools, the formal fault propagation model of the cryptographic kernel established in step 2 is stochastically simulated to simulate the fault propagation process of the cryptographic algorithm under any fault state. The fault trajectories simulated by the formal fault propagation model under each fault state are collected to provide data support for mining fault attributes.

[0018] Step 4: Automated discovery of fault attributes;

[0019] Automatic fault attribute mining is achieved using the fault trajectories collected in step 3. These fault attributes are abstract descriptions of the inherent behavioral patterns of the fault propagation process, categorized into fault location attributes and fault-related attributes. Fault location attributes are qualitative, describing which locations in the cryptographic core design are affected by the fault during propagation; this attribute is extracted by observing the distribution of faults in the fault trajectories. Fault-related attributes are quantitative, describing the correlation between fault information from the same fault source. Machine learning techniques are used to mine fault attributes from the fault trajectories, and SVA attribute assertions are employed to formally describe the extracted fault attributes. A fault attribute library is established by mining the fault attributes corresponding to each fault state.

[0020] Step 5: Establish a fault analysis model;

[0021] A fault analysis model is established based on the fault attributes extracted in step 4 and the cryptographic iterative transformation. The fault analysis model describes the correlation between fault attributes and encryption keys. Combining the iterative structure of cryptographic algorithms, fault information that satisfies the extracted fault attributes is derived using key information and erroneous ciphertext. The correlation between encryption keys and fault attributes is established, providing a foundation for formal fault analysis.

[0022] Step 6: Recover the key based on formal fault analysis;

[0023] Combining the fault attribute library from step 4 and the fault analysis model from step 5, formal fault analysis is performed on the erroneous ciphertext. The fault information derived from the fault analysis model is judged to meet the fault attribute filtering key.

[0024] First, we collect correct-incorrect or error-only ciphertext pairs with the same plaintext. Each ciphertext pair is then used as a test case and input into the formal verification tool. Using fault attributes as constraints, the formal verification tool automatically searches for the correct key. When performing a fault injection attack, the attacker injects faults at any round change or key expansion during the execution of the encryption device. The attacker does not need to know the specific location and number of fault injections. Formal fault analysis infers the fault state of the test case based on the fault location attributes and fault-related attributes.

[0025] Furthermore, in step 1, the formal fault propagation model of the basic logic unit is established by adding fault labels to each signal of the basic logic unit to identify the fault state of the corresponding signal, and establishing the formal fault propagation model according to the operation relationship of the basic logic unit to realize the measurement of fault propagation; the formal fault propagation model is described using a standard hardware design language.

[0026] Furthermore, the establishment of the basic unit formal fault model library in step 1 is based on the basic logic gate formal fault model library. According to the combinational laws in circuit design, a formal fault propagation model is further established for the basic logic unit, thereby forming a complete basic logic unit formal fault model library.

[0027] Furthermore, the formal fault propagation model of the cryptographic kernel in step 2 can measure the propagation of different types of faults in the cryptographic iteration process; the formal fault propagation model process of the cryptographic kernel can be automated by mapping the register transfer level code or gate-level netlist of the corresponding cryptographic kernel to the formal fault model library of basic logic units, that is, the formal fault propagation model of the cryptographic kernel can be automatically generated.

[0028] Furthermore, the formal fault propagation model of the cryptographic kernel in step 2 can describe the propagation behavior of any type of fault in the cryptographic iteration process; the arbitrary type of fault includes random faults, persistent faults, and permanent faults.

[0029] Furthermore, in step 3, the fault type, quantity, and injection location of each fault state in the formal fault propagation model simulation are different. The simulation of the propagation process of each fault state is achieved by changing the value of the fault label of the input signal.

[0030] Furthermore, in step 3, the formal fault propagation model simulation can use random plaintext generated by random numbers as simulation stimuli to simulate the propagation process of each fault state and collect the corresponding fault trajectories. The simulation tool used is a standard EDA tool.

[0031] Furthermore, in step 4, the automated fault attribute mining process involves classifying the fault information in the fault trajectory according to the smallest iterative unit in the cryptographic algorithm, using a classification algorithm to extract the logical relationships between each fault information as fault-related attributes, and using logical simplification to transform these relationships into Boolean expressions to describe the fault-related attributes.

[0032] Furthermore, the fault analysis model in step 5 describes the correlation between the correct key and fault attributes, and is described using a standard hardware language or software programming language.

[0033] Furthermore, step 6 recovers erroneous ciphertext in the key based on formal fault analysis. This is achieved by injecting clock glitches or voltage glitches during the encryption process of the cryptographic device, providing a data foundation for formal fault analysis of the cryptographic core. The key is then automatically searched based on fault attribute constraints using standard formal verification tools.

[0034] The beneficial effects of this invention are as follows:

[0035] This invention automates the formal fault propagation model, fault attribute mining, and formal fault analysis of cryptographic kernels, providing an automated analysis method for security verification of cryptographic kernel design in the pre-silicon stage, without requiring testers to have relevant cryptographic knowledge. This invention is applicable to single-byte and multi-byte fault analysis in block cipher systems, with no strict requirements on the location and type of fault injection. Compared with existing fault analysis techniques, this invention has better scalability and universality, avoids complex formula derivations, supports ciphertext-only analysis, and requires only a small amount of ciphertext to recover the key, making it more efficient than existing methods. Attached Figure Description

[0036] Figure 1 This is an overall flowchart of the method of the present invention.

[0037] Figure 2 This is a schematic diagram illustrating the process of establishing the formal fault propagation model library for the basic logic unit of this invention.

[0038] Figure 3 This is a schematic diagram illustrating the process of establishing the formal fault propagation model of the cryptographic kernel in this invention.

[0039] Figure 4 This is a schematic diagram of the automated fault attribute mining process of the present invention.

[0040] Figure 5 This is a schematic diagram of the automatic formal fault analysis process of the present invention.

[0041] Figure 6 This is an embodiment of the AES round-based iterative formal fault propagation model of the present invention.

[0042] Figure 7 This is an example diagram showing the two-round simulation results of the formal fault propagation model of the AES cryptographic kernel with a double-byte fault in an embodiment of the present invention.

[0043] Figure 8 This is a schematic diagram of the fault location attributes under the AES double-byte {S0,S4} fault state in an embodiment of the present invention. Detailed Implementation

[0044] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0045] Existing fault analysis methods typically require manual derivation of complex mathematical theories or analysis of large amounts of ciphertext information. They also have strict requirements on the types of faults injected and most methods only support specific cryptographic algorithms, lacking versatility and scalability. While attribute verification methods can reduce manual analysis, current methods still require manual writing of security attributes. The purpose of this invention is to propose a formal fault analysis method suitable for block ciphers, automating the establishment of a formal fault propagation model for the cryptographic kernel, security attribute mining, and formal fault analysis. By constructing a formal fault propagation model for the cryptographic algorithm, the propagation process of different types of faults in cryptographic iterations can be accurately described. Formal fault analysis uses fault attributes automatically extracted from the fault effect propagation as verification constraints to recover the key. Compared with existing fault analysis methods, the automatic formal fault analysis method proposed in this invention automates fault propagation model establishment, fault attribute extraction, and key analysis. It is applicable to block cipher algorithms with various structures, has no strict requirements on fault types, supports multi-byte fault attacks during key expansion or cipher round transformations, and requires only a small amount of ciphertext to recover the key. In addition, this method does not require testers to have knowledge of cryptographic algorithms and can achieve automatic formal fault analysis of cryptographic core designs.

[0046] This invention proposes an automatic formal fault analysis method applicable to various block cipher algorithms, comprising three stages: formal fault propagation model establishment, fault attribute mining, and formal fault analysis. Figure 1As shown, the formal fault propagation model of the cryptographic kernel accurately measures the propagation process of faults during cryptographic iteration. This method can automatically build a formal fault propagation model for cryptographic kernel design, and is suitable for describing the propagation process of different types of faults during cryptographic iteration. The fault attribute mining stage extracts inherent behavioral patterns as fault attributes from the fault trajectories simulated by the formal fault propagation model, providing mathematical theoretical support for formal analysis. The formal fault analysis stage uses formal verification tools to automatically search for the correct key based on the extracted fault attributes.

[0047] Step 1: Establish a formal fault propagation model library for basic logic units;

[0048] By establishing a formal fault propagation model for circuit design, the propagation process of faults within the circuit design can be accurately measured. Information flow tracing technology is used to study the flow of fault information. Fault tags are added bit-by-bit to the input and output signals in the circuit design to identify the fault state of the signal. A fault tag of logic '0' indicates that the signal is not faulty; otherwise, the signal is in a fault state. The propagation of fault tags in the formal fault propagation model satisfies the logical constraints of the circuit design, meaning that the fault state corresponding to the input signal can only propagate to the output signal if the input data affects the value of the output data. Boolean expressions can be used to accurately describe the formal fault propagation model.

[0049] For a NOT gate (INV), a fault in the input signal A directly affects the output signal O. Therefore, the formal fault model Boolean expression for the NOT gate is O. t =A t A t and O t These are the fault labels corresponding to the input and output signals, respectively. Table 1 shows a partial truth table of the formalized fault propagation model using a two-input XOR gate (XOR-2), where A and B are the input signals and O is the output signal. When fault label A... t =1 or B t When = 1, the fault state flows to output O. However, when both input signals fail simultaneously, fault propagation is blocked. This indicates that the correctness of output signal O is related to the parity of the number of fault signals. Combining the complete truth table, we can obtain the Boolean satisfaction of the XOR-2 formal fault propagation model as follows: Consistent with XOR gate logic, this demonstrates that the fault model can accurately measure fault propagation behavior in XOR-2. Similarly, we can derive the Boolean satisfaction of the two-input AND gate (AND-2) formalized fault propagation model as follows: Since the two-input OR gate (OR-2) and AND-2 satisfy De Morgan's law, the Boolean satisfaction formula corresponding to the OR-2 formal fault propagation model is: These formal fault propagation models of basic logic gates form a library of formal fault propagation models for basic logic gates.

[0050] Table 1. Partial Truth Table of the Formal Fault Propagation Model with Two-Input XOR Gates

[0051]

[0052] For complex basic logic units, their logical structures can be mapped to a formal fault propagation model library for basic logic gates. For example, a two-input selector (MUX-2) can be generated by combining AND, OR, and NOT gates to create a corresponding formal fault model. We can use the same method to build formal fault propagation models for other complex basic logic units, such as NAND and NOR gates. Integrating these formal fault propagation models into the formal fault propagation model library for basic logic gates forms a formal propagation model library for basic logic units in integrated circuit design, such as... Figure 2 As shown.

[0053] Although the derivation of the formal fault propagation model was demonstrated using only a bit-flip fault as an example, we can use a similar approach to construct formal models for other types of faults. In particular, once the injected fault has propagated effectively, the bit-flip fault propagation model can be used to accurately measure the propagation process of the injected fault in cryptographic iterations.

[0054] Step 2: Establish a formal fault propagation model for the cryptographic kernel

[0055] The formal fault propagation model library for basic logical units constructed in Step 1 covers formal fault propagation models for all basic logical units, forming the foundation for establishing a formal fault propagation model for the cryptographic kernel. The process of establishing the formal fault propagation model for the cryptographic kernel is as follows: Figure 3 As shown, logical synthesis is used to transform the cryptographic core design into a gate-level netlist. By mapping the basic logical units in the gate-level netlist to a formal propagation model library of basic logical units, the corresponding formal propagation models of basic logical units are logically combined to establish an accurate formal fault propagation model for the cryptographic core. This method can accurately describe the propagation behavior of any type of fault injected into cryptographic iteration or key expansion.

[0056] Step 3: Formal Fault Propagation Model Simulation

[0057] By using standard EDA tools to perform random simulations on the formal fault propagation model of the cryptographic kernel established in step 2, the fault propagation process of the cryptographic algorithm under any fault state can be simulated. The fault trajectories simulated by the formal fault propagation model under each fault state can be collected to provide data support for mining fault attributes.

[0058] Step 4: Automated Fault Attribute Discovery

[0059] The fault trajectories collected in step 3 are used to automatically mine fault attributes. Fault attributes are abstract descriptions of the inherent behavioral patterns in the fault propagation process, and are divided into fault location attributes and fault correlation attributes. Fault location attributes are qualitative attributes that describe which locations in the cryptographic core design were affected by the fault during propagation, and can be extracted by observing the distribution of faults in the fault trajectory. Fault correlation attributes are quantitative attributes that describe the correlation between fault information from the same fault source. Figure 4 This paper demonstrates the process of automating fault attribute mining. Machine learning techniques are used to extract fault attributes from fault trajectories, and SVA attribute assertions are employed to formally describe the extracted fault attributes. By mining the fault attributes corresponding to each fault state, a fault attribute library is established, providing a theoretical foundation for formal fault analysis.

[0060] Step 5: Establish a fault analysis model

[0061] A fault analysis model is established based on the fault attributes extracted in step 4 and the cryptographic iterative transformation. This model accurately describes the correlation between fault attributes and the encryption key. Combining the iterative structure of the cryptographic algorithm, the model uses key information and erroneous ciphertext to deduce fault information that satisfies the extracted fault attributes, establishing the correlation between the encryption key and the fault attributes, thus providing a foundation for formal fault analysis.

[0062] Step 6: Recover the key based on formal fault analysis

[0063] Combining the fault attribute library from step 4 and the fault analysis model from step 5, formal fault analysis can be performed on the erroneous ciphertext. The key is filtered by judging whether the fault information derived from the fault analysis model satisfies the fault attributes. The specific analysis process is as follows: Figure 5 As shown, firstly, correct-incorrect or error-only ciphertext pairs with the same plaintext are collected. Each ciphertext pair is input as a test case into the formal verification tool. Using fault attributes as constraints, the formal verification tool can automatically search for the correct key. During a fault injection attack, the attacker can inject faults at any round of the encryption device's execution or during key expansion, without needing to know the specific location and number of faults injected. Formal fault analysis can infer the fault state of the test case based on fault location attributes and fault-related attributes. Since only the correct key can make the fault information derived from the fault analysis model satisfy the fault attributes, formal fault analysis can determine a unique key by analyzing multiple test cases.

[0064] Furthermore, in step 1, the formal fault propagation model of the basic logic unit is established by adding fault labels to each signal of the basic logic unit to identify the fault state of the corresponding signal, and establishing the formal fault propagation model according to the operation relationship of the basic logic unit, so as to achieve accurate measurement of fault propagation. The formal fault propagation model can be described using a standard hardware design language.

[0065] Furthermore, the formal fault model library for basic logic units established in step 1 is based on the formal fault model library for basic logic gates. According to the combinational laws in circuit design, a formal fault propagation model is further established for complex basic logic units, thereby forming a complete formal fault model library for basic logic units.

[0066] Furthermore, the formal fault propagation model of the cryptographic kernel in step 2 can accurately measure the propagation of different types of faults in the cryptographic iteration process, without strict requirements on the location, number, or type of fault injection.

[0067] Furthermore, the process of establishing the formal fault propagation model of the cryptographic core in step 2 can be automated. By mapping the register transfer level code or gate-level netlist of the corresponding cryptographic core to the formal fault model library of basic logic units, the formal fault propagation model of the cryptographic core can be automatically generated.

[0068] Furthermore, the formal fault propagation model of the cryptographic kernel in step 2 can accurately describe the behavior of any type of fault in the cryptographic iteration process, such as random faults, persistent faults, and permanent faults.

[0069] Furthermore, in step 3, the fault type, quantity, and injection location of each fault state in the formal fault propagation model simulation are different. The simulation of the propagation process of each fault state can be achieved by changing the value of the fault label of the input signal.

[0070] Furthermore, in step 3, the formal fault propagation model simulation can use random numbers to generate random plaintext as simulation excitation, simulate the propagation process of each fault state and collect the corresponding fault trajectories, and use standard EDA tools for simulation.

[0071] Furthermore, in step 4, the automated fault attribute mining process classifies the fault information in the fault trajectory according to the smallest iterative unit in the cryptographic algorithm, uses a classification algorithm to extract the logical relationships between each fault information as fault-related attributes, and uses logical simplification to transform the relationship into a Boolean expression to achieve an accurate description of the fault-related attributes.

[0072] Furthermore, in step 4, the automatic mining of fault attributes can utilize formal verification tools to verify the completeness and correctness of the attributes, that is, it is necessary to ensure that all fault patterns under a certain fault state satisfy the extracted fault attributes.

[0073] Furthermore, the fault analysis model in step 5 describes the correlation between the correct key and the fault attributes, and can be described using standard hardware languages ​​or software programming languages.

[0074] Furthermore, step 6, which recovers erroneous ciphertext in the key based on formal fault analysis, can be obtained by injecting clock glitches or voltage glitches during the encryption process performed by the cryptographic device, thus providing a data foundation for formal fault analysis of the cryptographic core.

[0075] Furthermore, step 6, which recovers the key based on formal fault analysis, can achieve automated key search by using standard formal verification tools based on fault attribute constraints.

[0076] Furthermore, step 6, which is based on formal fault analysis to recover the key, is applicable to block cipher algorithms with different iterative structures.

[0077] Example:

[0078] Taking the double-byte fault analysis of an AES cryptographic core design as an example, this invention illustrates the automatic formal fault analysis method proposed in this paper. The hardware environment used for implementation included: Intel Core i7, Ubuntu 18.0, Windows 11, a voltage fault injection device, and a Sakura-X development board. We implemented the method proposed in this invention using a GCC compilation environment, the formal verification tool Yosys, and the standard EDA tool Modelsim.

[0079] 1) Automated establishment of formal fault models for AES cryptographic kernels

[0080] The design of the AES cryptographic core implemented using the standard hardware description language Verilog is logically synthesized to generate a gate-level netlist. The basic logic units in the gate-level netlist are then mapped to the constructed formal fault propagation model library of basic logic units, thereby automatically establishing a formal fault propagation model for the AES cryptographic core. Figure 6 This paper presents a formalized fault propagation model corresponding to one round of AES iteration, where rin and rk are the plaintext and key, respectively, and rin_t and rk_t are the corresponding fault labels.

[0081] 2) Simulation of the formal fault propagation model of the AES cryptographic kernel

[0082] Plaintext is generated using a random number generator as input stimulus for the formal fault propagation model. The formal fault propagation model established in step 1) is then simulated using Modelsim. This step requires simulating the propagation process of all fault states and organizing the corresponding fault trajectories according to the fault states. Figure 7 The simulation results show the results of two rounds of modeling with a double-byte fault injected into the state matrix at S0 and S4 in the r-th round of the AES cryptographic kernel, after two iterations. The double-byte fault propagates to all bytes in the state matrix. In each iteration, byte substitution changes the fault value, row shifting changes the fault location, column scrambling spreads the fault to the entire column, and round key addition has no effect on the fault.

[0083] 3) Automated mining of AES fault attributes

[0084] Fault attributes are mined from the fault trajectories collected in step 2) for each fault state. For the fault location attribute corresponding to each fault state, the fault distribution in the ciphertext can be observed to determine the location characteristics of the fault in the ciphertext under different fault locations and numbers. Fault-related attributes require dividing the fault information byte-by-byte, and then using data mining methods to extract the correlations between the fault information. Figure 7 Taking the fault status as an example, its fault location attribute is as follows: Figure 8 As shown, in this fault state, the fault will propagate along the colored paths. Table 2 shows the path taken under these conditions. Figure 7 Under fault conditions, the fault information satisfies the fault-related attributes after two rounds of iteration.

[0085] Table 2 Fault-related attributes under double-byte {S0,S4} fault conditions

[0086]

[0087] 4) Establish an AES fault analysis model

[0088] Establishing an AES fault analysis model to describe the relationship between the fault attributes extracted in step 3) and the AES round keys is the foundation for formal fault analysis. For example, during a fault injection attack in AES round 8, the fault analysis model implements the AES round 10 decryption operation. Using the guessed key and the erroneous ciphertext, the fault information of the round 10 input can be deduced. As shown in step 3), during the AES round 8 attack, the fault information of the round 9 encryption result (round 10 iteration input) satisfies the extracted fault attributes. Therefore, when the fault information deduced by the fault analysis model satisfies the fault attributes, it indicates that the guessed key is a correct key candidate value.

[0089] 5) Perform formal fault analysis on AES.

[0090] In the 8th iteration of AES, a fault injection attack is performed, and erroneous ciphertexts generated under the same plaintext are collected. Two different erroneous ciphertexts form a test case. The erroneous ciphertexts and fault attributes are then input into the Yosys tool. The Yosys tool determines the correctness of the guessed key by checking whether the fault information derived by the fault analysis model using the guessed key satisfies the fault attributes. When there is one and only one key that satisfies the fault attributes in all test cases, that key is the correct key. Usually, only two test cases are needed to uniquely determine the key.

Claims

1. An automatic formal fault analysis method for block ciphers, characterized in that, Includes the following steps: Step 1: Establish a formal fault propagation model library for basic logic units; A formal fault propagation model for circuit design is established using information flow tracing technology. Fault states are identified by adding fault tags to the input and output signals of the circuit design bit by bit. The propagation of fault information is monitored based on the flow of these fault tags. A fault tag of logic '0' indicates that the signal is not faulty; otherwise, the signal is in a fault state. The propagation of fault tags in the formal fault propagation model of the circuit design satisfies the logical constraints of the circuit design, meaning that the fault state corresponding to the input signal can only propagate to the output signal when the input data affects the value of the output data. Boolean expressions can be used to describe the formal propagation model. Based on this method, a formal fault propagation model is built for the fault propagation process of all basic logic units in integrated circuit design, establishing a formal fault propagation model library for basic logic units. The formal fault propagation model of the NOT gate is expressed in Boolean as follows: ,in and These are the fault tags corresponding to input signal A and output signal O, respectively. The formal fault propagation model for a two-input XOR gate is expressed in Boolean form as follows: ,in The fault tag corresponding to input signal B; The formal fault propagation model for the two-input AND gate is expressed in Boolean form as follows: , where O is the output signal; The formal fault propagation model for a two-input OR gate is expressed in Boolean form as follows: ; Step 2: Establish a formal fault propagation model for the cryptographic kernel; The cryptographic core design is transformed into a gate-level netlist using logical synthesis. By mapping the basic logical units in the gate-level netlist to a formal propagation model library of basic logical units, the corresponding formal propagation models of basic logical units are logically combined to establish a formal fault propagation model for the cryptographic core. The formal fault propagation model of the cryptographic core can describe the propagation behavior of any type of fault during the cryptographic iteration process. The arbitrary type of fault includes random faults, persistent faults, and permanent faults. Step 3: Formal fault propagation model simulation; The formal fault propagation model of the cryptographic kernel established in step 2 was stochastically simulated using EDA tools to simulate the fault propagation process of the cryptographic algorithm under any fault state. The fault trajectories simulated by the formal fault propagation model under each fault state were collected to provide data support for mining fault attributes. The fault type, number and injection position of each fault state in the formal fault propagation model simulation are different. The simulation of the propagation process of each fault state is achieved by changing the value of the fault label of the input signal. Step 4: Automated discovery of fault attributes; Automatic fault attribute mining is achieved using the fault trajectories collected in step 3. These fault attributes are abstract descriptions of the inherent behavioral patterns of the fault propagation process, categorized into fault location attributes and fault-related attributes. Fault location attributes are qualitative, describing which locations in the cryptographic core design are affected by the fault during propagation; this attribute is extracted by observing the distribution of faults in the fault trajectories. Fault-related attributes are quantitative, describing the correlation between fault information from the same fault source. Machine learning techniques are used to mine fault attributes from the fault trajectories, and SVA attribute assertions are employed to formally describe the extracted fault attributes. A fault attribute library is established by mining the fault attributes corresponding to each fault state. Step 5: Establish a fault analysis model; A fault analysis model is established based on the fault attributes extracted in step 4 and the cryptographic iterative transformation. The fault analysis model describes the correlation between fault attributes and encryption keys. Combining the iterative structure of cryptographic algorithms, fault information that satisfies the extracted fault attributes is derived using key information and erroneous ciphertext. The correlation between encryption keys and fault attributes is established, providing a foundation for formal fault analysis. Step 6: Recover the key based on formal fault analysis; Combining the fault attribute library from step 4 and the fault analysis model from step 5, formal fault analysis is performed on the erroneous ciphertext. The fault information derived from the fault analysis model is judged to meet the fault attribute filtering key. First, we collect correct-incorrect or error-only ciphertext pairs with the same plaintext. Each ciphertext pair is then used as a test case and input into the formal verification tool. Using fault attributes as constraints, the formal verification tool automatically searches for the correct key. When performing a fault injection attack, the attacker injects faults at any round change or key expansion during the execution of the encryption device. The attacker does not need to know the specific location and number of fault injections. Formal fault analysis infers the fault state of the test case based on the fault location attributes and fault-related attributes.

2. The automatic formal fault analysis method for block ciphers according to claim 1, characterized in that, In step 1, the formal fault propagation model of the basic logic unit is established by adding fault labels to each signal of the basic logic unit to identify the fault state of the corresponding signal, and establishing the formal fault propagation model according to the operation relationship of the basic logic unit to realize the measurement of fault propagation; the formal fault propagation model is described using a standard hardware design language.

3. The automatic formal fault analysis method for block ciphers according to claim 1, characterized in that, The establishment of the basic unit formal fault propagation model library in step 1 is based on the basic logic gate formal fault propagation model library. According to the combinational laws in circuit design, a formal fault propagation model is further established for the basic logic unit, thereby forming a complete basic logic unit formal fault propagation model library.

4. The automatic formal fault analysis method for block ciphers according to claim 1, characterized in that, In step 2, the formal fault propagation model of the cryptographic kernel can measure the propagation of different types of faults in the cryptographic iteration process. The formal fault propagation model process of the cryptographic kernel can be automated by mapping the register transfer level code or gate-level netlist of the corresponding cryptographic kernel to the formal fault propagation model library of basic logic units, that is, the formal fault propagation model of the cryptographic kernel can be automatically generated.

5. The automatic formal fault analysis method for block ciphers according to claim 1, characterized in that, In step 3, the formal fault propagation model simulation can use random plaintext generated by random numbers as simulation stimuli to simulate the propagation process of each fault state and collect the corresponding fault trajectories. The simulation tool used is a standard EDA tool.

6. The automatic formal fault analysis method for block ciphers according to claim 1, characterized in that, In step 4, the automated fault attribute mining process involves classifying the fault information in the fault trajectory according to the smallest iterative unit in the cryptographic algorithm, using a classification algorithm to extract the logical relationships between each fault information as fault-related attributes, and using logical simplification to transform these relationships into Boolean expressions to describe the fault-related attributes.

7. The automatic formal fault analysis method for block ciphers according to claim 1, characterized in that, The fault analysis model in step 5 describes the correlation between the correct key and fault attributes, and is described using a standard hardware language or software programming language.

8. The automatic formal fault analysis method for block ciphers according to claim 1, characterized in that, Step 6 recovers erroneous ciphertext in the key based on formal fault analysis. This is achieved by injecting clock glitches or voltage glitches during the encryption process of the cryptographic device, providing a data foundation for formal fault analysis of the cryptographic core. The key is then automatically searched based on fault attribute constraints using standard formal verification tools.

Citation Information

Patent Citations

  • Attribute-driven persistent fault analysis method

    CN116962025A