CKKS embedded implementation-oriented side channel analysis method and system
By constructing the template to locate the leaked location and using the interconnected convolutional neural network and factor graph to optimize the classification results, the leakage problem caused by the implementation of median splicing by CKKS is solved, and the accuracy and security of side channel analysis are improved.
Patent Information
- Application Number
- CN202510827704.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-20
AI Technical Summary
The existing side channel analysis technology cannot effectively target the leakage characteristics in CKKS embedded implementation, especially the leakage caused by bit splicing operations, resulting in insufficient security.
A side channel analysis method for CKKS embedded implementation is designed. By constructing a template to locate the leakage location, use an interconnected convolutional neural network to analyze the leakage characteristics of electromagnetic traces, and integrate multiple leakage information through a factor graph to optimize the classification results.
It improves the accuracy of side channel analysis, enables more precise identification and evaluation of the risk of leakage of CKKS embedded devices, and is suitable for resource-constrained embedded devices.
Smart Images

Figure CN120342520A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cyberspace security, and in particular, to a side-channel analysis method and system for CKKS embedded implementation. Background Art
[0002] The statements in this part merely provide background technical information related to the present invention and do not necessarily constitute prior art.
[0003] Fully homomorphic encryption (FHE) is an encryption technology that supports performing calculations on encrypted data, thereby ensuring the security of the calculation process. This ability makes FHE of great value in applications such as secure data analysis and processing, such as cloud computing and privacy-preserving machine learning.
[0004] CKKS (Cheon-Kim-Kim-Song encryption scheme) is a lattice-based fully homomorphic encryption scheme that uses approximate homomorphic encryption and allows operations on floating-point values. Based on the characteristics of small resource overhead and high execution efficiency of CKKS, it has broad application prospects on embedded devices.
[0005] To accelerate the implementation and provide convenient and fast deployment, the prior art has developed a Simple Encrypted Arithmetic-Embedded (SEAL-Embedded) library. The "bit-splicing" technology is introduced in the SEAL-Embedded library to optimize the implementation of CKKS symmetric and asymmetric encryption, which is used to reduce the memory overhead during encryption on embedded devices, thereby providing an efficient CKKS implementation for resource-constrained embedded devices.
[0006] Although CKKS is secure at the mathematical analysis level, side-channel leakage still occurs in its implementation on embedded devices. Currently, there are various side-channel analysis techniques for lattice cryptography, and their analysis targets mostly focus on NTT transformation, polynomial multiplication, Gaussian sampling, and message encoding / decoding, etc. However, these attacks mainly target the vulnerabilities in the encryption implementation of lattice cryptography. The homomorphic encryption characteristics and floating-point calculations of CKKS make its data flow and operation mode in implementation significantly different from traditional lattice cryptography. Therefore, these techniques are not directly applicable to the CKKS embedded implementation. Summary of the Invention
[0007] To solve the above problems, the present invention proposes a side-channel analysis method and system for CKKS embedded implementation. The target execution algorithm is the polynomial sampling module in the SEAL-Embedded library. A deep neural network is designed considering the leakage characteristics of bit concatenation. The leakage intensity of electromagnetic traces is quantitatively analyzed through the deep neural network, and a factor graph is used to construct the relationship between leakage information to obtain the final side-channel analysis result.
[0008] In some embodiments, the following technical solutions are adopted: A side-channel analysis method for CKKS embedded implementation, including: Obtain electromagnetic traces when a CKKS embedded device executes a target algorithm; For the obtained electromagnetic traces, construct a template based on the operation being executed, locate the leakage position, and identify the leakage position; Input the electromagnetic traces with the identified leakage position into a trained interconnected convolutional neural network to obtain the predicted probability distribution for each category, and further obtain the predicted leakage category; wherein, each time the interconnected convolutional neural network takes four trace segments as input, and the features of the four trace segments respectively correspond to the four coefficients in a bit-concatenated byte; Construct a factor graph of the target algorithm, integrate the relationship between various leakage information through the belief propagation algorithm, optimize the predicted classification result, and obtain the optimized leakage category.
[0009] As a further solution, for the obtained electromagnetic traces, construct a template based on the operation being executed to locate the leakage position. The specific process is as follows: Take the operation being executed at the leakage position as the target operation, obtain the energy consumption trace of the target operation, calculate the mean and covariance matrix of the energy consumption trace, and obtain the template corresponding to the target operation; Use a sliding window to perform template matching in segments on the entire obtained electromagnetic trace, and indicate the leakage position by calculating the matching probability under the multivariate Gaussian normal distribution.
[0010] As a further solution, the interconnected convolutional neural network includes: an input layer, a first convolutional layer, a second convolutional layer, a first fully connected layer, a second fully connected layer, an activation function layer, and an output layer; after each convolutional layer, a batch normalization layer and a max pooling layer are sequentially added; Among them, the input of the input layer is four trace segments, corresponding to the four coefficients in a bit-concatenated byte; the leakage features of each trace segment are extracted through the first convolutional layer and the second convolutional layer; the leakage features are sequentially mapped through the first fully connected layer and the second fully connected layer to obtain features with label categories; the features are input into the activation function to obtain the predicted probability distribution for each category.
[0011] As a further solution, the leakage features are mapped through the first fully connected layer and the second fully connected layer in sequence. The specific process is as follows: Leakage features are respectively mapped to features through the first fully connected layer ; Features are respectively mapped to features through the second fully connected layer ; Among them, the features contain both their own coefficient features and the features of the first coefficient , the features contain both their own coefficient features and the features of the second coefficient , contain both their own coefficient features and the features of the third coefficient .
[0012] As a further solution, the target algorithm is the polynomial sampling module in the SEAL-Embedded library. The vulnerabilities of the sampling coefficients include: value leakage before modulo-3 reduction, 2-bit value leakage, and Hamming weight leakage of bytes.
[0013] Among them, for the 2-bit value leakage and the Hamming weight leakage of bytes, a trained interconnected convolutional neural network is respectively used to classify the input traces; For the value leakage before modulo-3 reduction, a trained convolutional neural network is used to classify the traces.
[0014] As a further solution, the factor graph of the target algorithm is specifically: Taking the four coefficients of the 2-bit value leakage, the Hamming weight of the byte, and the value before modulo-3 reduction as variable nodes, and taking the posterior distribution corresponding to each variable node as a factor node. When the factor node depends on the variable node, they are connected by an edge.
[0015] In some other embodiments, the following technical solutions are adopted: A side-channel analysis system for CKKS embedded implementation, comprising: A trace acquisition module, configured to acquire electromagnetic traces when a CKKS embedded device executes a target algorithm; A leakage position identification module, configured to, for the acquired electromagnetic traces, construct a template based on the operation being performed at the leakage position, locate the leakage position, and identify the leakage position; The category prediction module is configured to input the electromagnetic traces identifying the leakage locations into a trained interconnected convolutional neural network to obtain the predicted probability distribution for each category, and further obtain the predicted leakage category. Among them, the interconnected convolutional neural network takes four trace segments as input each time, and the features of the four trace segments respectively correspond to the four coefficients in the bit-concatenated byte. The category optimization module is configured to construct a factor graph of the target algorithm, integrate the relationships between various leakage information through the belief propagation algorithm, and optimize the predicted classification result to obtain the optimized leakage category.
[0016] In some other embodiments, the following technical solutions are adopted: A terminal device includes a processor and a memory. The processor is used to implement instructions; the memory is used to store multiple instructions, and the instructions are adapted to be loaded and executed by the processor to perform the above-mentioned high-precision battery model parameter identification method based on output response reconstruction.
[0017] In some other embodiments, the following technical solutions are adopted: A computer-readable storage medium stores multiple instructions, and the instructions are adapted to be loaded and executed by the processor of the terminal device to perform the above-mentioned high-precision battery model parameter identification method based on output response reconstruction.
[0018] Compared with the prior art, the beneficial effects of the present invention are: (1) The present invention locates the leakage location based on the operation construction template, differentiates specific operations, and can perform pattern matching in the entire trace, so as to identify all leakage locations corresponding to the target operation.
[0019] (2) The present invention designs an interconnected convolutional neural network for the leakage characteristics of bit concatenation. There is a connection between the leakage characteristics of the four coefficients in each byte during bit concatenation, and each coefficient always depends on the previous coefficient for concatenation. The input of the interconnected convolutional neural network of the present invention is the energy consumption traces corresponding to the four coefficients in each byte, and the features of the previous traces are concatenated in the fully connected layer. This operation simulates bit concatenation, enabling the model to pay attention to the leakage characteristics of the previous traces during classification, thereby improving the classification accuracy.
[0020] (3) Due to the characteristics of rejection sampling and bit concatenation, leakage occurs not only during the sampling process of 2-bit coefficients in each round. The present invention constructs a factor graph of the target algorithm, establishes the relationships between various leakage information through the factor graph, and can comprehensively characterize the leakage of the polynomial sampling module of the SEAL-Embedded library from multiple perspectives, thereby making the side-channel analysis have higher accuracy.
[0021] Other features and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of this aspect. Description of the Drawings
[0022] Figure 1 It is a flowchart of the side-channel analysis method for CKKS embedded implementation in the embodiment of the present invention; Figure 2 It is a schematic diagram of leakage localization based on operations in the embodiment of the present invention; Figure 3 It is a schematic diagram of the interconnected convolutional neural network structure in the embodiment of the present invention; Figure 4 It is a factor graph constructed based on the leakage in rejection sampling in the embodiment of the present invention; Figure 5 It is a comparison chart of the accuracy and loss of ICNN and CNN in the embodiment of the present invention; among them, (a) is the accuracy comparison, and (b) is the loss comparison; Figure 6 It is a change chart of the information entropy during the belief propagation process in the embodiment of the present invention. Detailed Implementation Manner
[0023] It should be noted that the following detailed description is illustrative and is intended to provide further description of the present invention. Unless otherwise specified, all technical and scientific terms used in the present invention have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.
[0024] It should be noted that the terms used herein are only for describing the specific implementation manner and are not intended to limit the exemplary implementation manner according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0025] Embodiment 1 In this embodiment, the polynomial sampling module in the SEAL-Embedded library is used as the target algorithm to be executed.
[0026] Specifically, the SEAL-Embedded library provides a polynomial sampling module to obtain random values. During the symmetric and asymmetric encryption processes, the private key sk and the encrypted sample u are uniformly sampled from R 3({−1, 0, 1}), and this polynomial sampling module is implemented through rejection sampling and modulo 3 reduction.
[0027] The polynomial sampling module is implemented as the sample_small_poly_ternary_prng_96 function. This function first generates a random byte through rejection sampling. If the sampled value is not within the valid range, it will perform sampling again in a loop. If the sampled value is valid, it will be mapped to R 3({−1, 0, 1}) through modulo-3 reduction, that is, mapped to a value in {−1, 0, 1}. Then, it stores the triple in the array through the set_small_poly_idx function.
[0028] In the SEAL-Embedded library, to reduce storage overhead, the sampling results are bit-concatenated. Specifically, when the polynomial sampling module samples the secret key, it generates 2-bit secret key coefficients each time, and every four secret key coefficients are bit-concatenated into an 8-bit number, that is, a byte. Therefore, the bit-concatenation technique can store the sampling results in a more compact form and reduce storage overhead.
[0029] There are two potential vulnerabilities that can be exploited in this implementation: The first vulnerability is that rand_val stores the byte after rejection sampling, and this vulnerability provides information about the coefficient value before modulo-3 reduction.
[0030] The second vulnerability is the bit-concatenation operation on the sampled 2-bit coefficients, which may not only leak the value information of the 2-bit coefficients but also leak the Hamming weight information after concatenating multiple coefficients.
[0031] Therefore, in this embodiment, the polynomial sampling module in the SEAL-Embedded library is used as the target algorithm for side-channel analysis.
[0032] Based on this, in one or more embodiments, a side-channel analysis method for CKKS embedded implementation is disclosed. Combining Figure 1 , the specific process includes: S101: Obtain the electromagnetic traces when the CKKS embedded device executes the target algorithm.
[0033] As a specific implementation, in this embodiment, the STM32F407G-DISC1 development board is used to run the CKKS algorithm in the SEAL-Embedded library. This development board contains a 32-bit ARM Cortex-M4 STM32F407G microcontroller, which is widely used in Internet of Things devices. In addition, a digital oscilloscope DSOX3024T and a Langer RF2 near-field probe are used to record the electromagnetic traces of the microcontroller, and a PA303 amplifier is used for signal preprocessing, and measurements are carried out under a sampling rate of 500MSa / s and a bandwidth limit of 200MHz.
[0034] S102: For the obtained electromagnetic traces, locate the leakage positions based on the operations being executed, and identify the leakage positions.
[0035] Since rejection sampling only filters the sampled values within the valid range, the results of each sampling are not stored every time, which leads to uneven sampling time intervals for each coefficient.
[0036] To analyze the vulnerabilities in rejection sampling, it is necessary to identify the leakage positions of each coefficient in the traces. In this embodiment, the operations being executed at the leakage positions are used as the target operations, and a template is constructed based on the target operations to locate the leakage positions for identifying the leakage positions. The specific process is as follows: First, analyze the leakage characteristics of the target operations, obtain the energy consumption traces corresponding to each operation value of the target operations, and then calculate the mean and covariance matrix for these energy consumption traces to obtain the template of the leakage positions.
[0037] Among them, the calculation formulas for the mean and covariance matrix are as follows: ; ; Among them, is the mean, is the covariance matrix, represents the number of traces, represents the i th trace.
[0038] Then, use this template to match in the complete traces. When similar trace segments are found, mark them, and the marked traces are the leakage positions.
[0039] Specifically, use a sliding window to perform template matching in segments on the entire trace, and indicate the leakage positions through the matching probability under the multivariate Gaussian normal distribution.
[0040] The matching probability formula under the multivariate Gaussian normal distribution is as follows: ; Among them, is the target position, represents ; indicates the matching probability between the template and the trace in the sliding window. In this embodiment, a threshold is set. When the matching probability is greater than this threshold, it indicates a successful match, and the size of the threshold can be adjusted according to the actual situation. represents the dimension of the target position, that is, the number of points included. In addition, in the formula, the dimension of is also , The dimension of .
[0041] As a specific example, if the leakage location of a 2-bit coefficient is where the modulo-3 calculation of rand_val is being performed, it is necessary to identify the location of the modulo-3 calculation. Specifically, a template for the modulo-3 calculation is constructed, which is the energy consumption trace of the modulo-3 calculation. Subsequently, this template is used to match in the complete trace. When a similar trace segment is found, it is marked, and the marked trace is the leakage location of the 2-bit coefficient.
[0042] Traditional templates all distinguish leakage locations based on data. However, rejection sampling is adopted in the polynomial sampling module. Rejection sampling will evaluate the sampling result after random sampling. If the result does not meet the requirements, it will be discarded and resampled. Therefore, not every sampling result will be output, and there is a large error in the method of distinguishing leakage locations based on data.
[0043] In this embodiment, in order to find the truly output result, a model is built for the target operation, enabling pattern matching in the entire trace, thereby identifying all leakage locations corresponding to the target operation. For example: when the modulo-3 operation occurs, it indicates that the sampling module has output a result of a 2-bit coefficient, which will not lead to locating sampling results that do not meet the requirements.
[0044] Figure 2 An example of the method for locating leakage locations based on operations is given, specifically for locating the leakage of the Hamming weight of the coefficient. Figure 2 There are four correlation peak positions in the lower half of , and those four positions represent the occurrence of the target operation; the leakage locations are delimited near the target operation. Figure 2 Four intervals are marked by the red dashed lines in the upper half of , and these four intervals are the leakage locations.
[0045] S103: Input the electromagnetic trace for identifying the leakage location into the trained interconnected convolutional neural network to obtain the predicted probability distribution for each category, and the index corresponding to the maximum probability is the category of the leakage information predicted by the model.
[0046] When targeting different classification objectives, the categories of leakage information included are also different. In this embodiment, the vulnerabilities of the sampling coefficients include 3 types (i.e., there are three classification objectives): leakage of the value before modulo-3 reduction (denoted as rand_val), leakage of 2-bit values (denoted as 2-bits), and leakage of the Hamming weight of bytes (denoted as HW).
[0047] For the rand_val leakage, it is the result of random sampling within the range of 0 to 255, so it has 256 possible categories: {0, 1, ..., 255}. For the 2-bits leakage, each value corresponds to a coefficient in the secret polynomial, and due to the ternary nature of each coefficient, it has three possible categories: {00, 01, 10}. For the HW leakage, it represents the Hamming weight of an 8-bit value after bit concatenation, and the HW label is formed by concatenating four ternary values, so the result has five possible categories: {0, 1, 2, 3, 4}.
[0048] During the sampling process, bit concatenation stores every four coefficients in one byte. For 2-bits and HW, the leakage characteristics of the four coefficients in each byte are different, while the coefficients at the same position in different bytes have similar leakage characteristics. Therefore, all coefficients can be divided into four types: type 1, type 2, type 3, and type 4, representing the 1st, 2nd, 3rd, and 4th 2-bit coefficients in each byte respectively.
[0049] To analyze the leakage characteristics caused by bit concatenation, this embodiment designs an Interconnected Convolutional Neural Network (ICNN) to learn the leakage characteristics of consecutive intervals among the four coefficients. Combining Figure 3 , the ICNN consists of two convolutional layers and three fully connected layers, and finally performs classification through the SoftMax function. After each convolutional layer, a BatchNorm layer and a MaxPooling layer are added in sequence. In addition, the SeLU activation function is applied after each layer to avoid the problems of gradient vanishing and explosion.
[0050] Specifically, the ICNN accepts four trace segments as input each time. They correspond to the four coefficients in one byte and extract their features through two convolutional layers. The leakage characteristics of these trace segments are represented as , where represents the feature dimension.
[0051] Then, these features are input into the first fully connected layer and mapped to , where represents the new feature dimension.
[0052] Subsequently, it is mapped to through the second fully connected layer; The feature is concatenated with the feature to obtain the concatenated feature . The concatenated feature is mapped to through the second fully connected layer; The feature is concatenated with the feature Concatenate to obtain the concatenated feature , and the concatenated feature is mapped through the second fully connected layer to ; Feature is concatenated with feature to obtain the concatenated feature , and the concatenated feature is mapped through the second fully connected layer to ; After being fused through two fully connected layers, and both contain their own features and the features of the previous coefficient. Finally, the obtained are all mapped to the label category dimension and input into the SoftMax function to obtain the predicted probability distribution for each category.
[0053] To perform the 2-bits and HW classification tasks, the categorical cross-entropy function is used as the loss function. For traces of type , the one-hot encoding of the correct label is denoted as , the predicted probability of the model for the sample belonging to each category is denoted as , and the number of categories is denoted as . The loss function is defined as: ; where represents the probability that the correct sample belongs to the th category, while is the probability that the model predicts the sample belongs to the th category. The number of traces in each batch is denoted as , represents the th trace in the batch. The overall loss function is expressed as: .
[0054] For rand_val, since it does not require bit concatenation, in this embodiment, a common convolutional neural network CNN is used to classify its electromagnetic traces. This model is also composed of two convolutional layers and three fully connected layers. After each convolutional layer, a BatchNorm layer and an AveragePooling layer are added in sequence. Finally, classification is performed through the SoftMax function, and the categorical cross-entropy function is used as the loss function.
[0055] Compared with ordinary CNNs, the ICNN proposed in this embodiment takes four traces as input, and these four traces correspond to the four coefficients in bit concatenation. At the same time, the ICNN performs concatenation in the fully connected layer, concatenating the features of the previous traces in each trace, simulating bit concatenation, enabling the model to focus on the leakage features of the previous traces during classification.
[0056] S104: Construct a factor graph of the target algorithm, integrate the relationships between various leakage information through the belief propagation algorithm, optimize the predicted classification results, and obtain the optimized leakage categories.
[0057] Since the 2-bit coefficient is the key coefficient, and its classification accuracy directly reflects the intensity of the leakage, therefore, the main goal of this step is to optimize the classification results of the leakage categories of the 2-bit coefficient.
[0058] In this embodiment, the probability distribution output by the interconnected convolutional neural network in step S103 is input to the factor graph as the initial probability distribution in the factor graph, and then is further updated by belief propagation.
[0059] The goal of using the belief propagation algorithm in this embodiment is to further optimize the probability distribution of the 2-bit coefficient by utilizing the relationships between the three types of leakage. Therefore, the final analysis result is still a probability distribution, and the final classification category can be obtained by selecting the index corresponding to the maximum probability, that is, obtaining one of {00, 01, 10}. Compared with the probability distribution output by the ICNN, the belief propagation algorithm has a higher classification accuracy.
[0060] To jointly utilize the leakage information of the three vulnerabilities of 2-bits, HW, and rand_val, this embodiment constructs a factor graph corresponding to rejection sampling. When analyzing side-channel leakage, it is often possible to construct a factor graph of the target encryption algorithm to model the relationships between intermediate variables. The factor graph consists of variable nodes for each variable and factor nodes for each function, and connects them when the variable nodes are parameters of the factor nodes.
[0061] Based on these rules, arithmetic relationships between leakages can be constructed using the factor graph. When a factor node (represented by a rectangle) depends on a variable node (represented by a circle), they are connected by an edge. The factor graph corresponding to rejection sampling is as Figure 4 shown; where f hw , f mod3 represents the relationship between the two connected variables. f hw connects the 2-bit value and HW, indicating that HW can be calculated from the Hamming weight of four 2-bit values. f mod3Connects a 2-bit value with the value before modulo-3 reduction, indicating that the value before modulo-3 reduction can obtain the 2-bit value after modulo-3 calculation.
[0062] HW variable (The Hamming weight of new_val) can be derived from the four coefficients of 2-bits (the value of val_in).
[0063] In addition, the rand_val variable (the value of rand_val) is connected to the 2-bit variable through modulo operation. The posterior distributions of these variables provided by the aforementioned neural network analysis are added as function nodes. For example, corresponding to the posterior distribution.
[0064] The factor graph is input into belief propagation, and the information is propagated to determine the marginal probability distribution of the coefficients. Message passing includes from variables to factors and from factors to variables, following the calculation rules; the specific process is as follows: Before belief propagation, first initialize the probability distribution for each variable node in the factor graph, and then the belief propagation calculation can begin. During the belief propagation process, it is divided into two propagation directions: from variables to factors and from factors to variables: (1) From variables to factors: Each variable node combines the information of adjacent nodes to calculate the message, and then sends the message to the connected factor nodes. The message here is composed of the current probability distribution of the variable and the messages from other factor nodes.
[0065] (2) From factors to variables: Each factor node receives the messages from all adjacent variable nodes and calculates the messages to be sent to each variable node. These messages are usually based on the product of the factor potential function and the received variable messages.
[0066] Repeat the above message passing and update steps until the messages converge.
[0067] Finally, by iteratively performing the message propagation calculation, the marginal probability of the coefficient is determined.
[0068] The coefficient 's marginal probability is the final probability distribution. At this time, each trace will obtain a probability distribution, and the final category of each coefficient can be obtained by selecting the index corresponding to the maximum probability, that is, one of {00, 01, 10} is obtained through classification.
[0069] At this time, the classification accuracy can be observed. If the classification accuracy is very high, it indicates that the side-channel leakage of this part is obvious.
[0070] To prove the effectiveness of the ICNN in this embodiment, it is compared with the CNN model widely used for deep learning-based side-channel analysis. The same parameter settings are used for CNN and ICNN during evaluation. The validation accuracy and loss comparison after each epoch during the training process are shown in Figure 5 as (a) and (b) in Figure 5 where (a) in Figure 5 is the accuracy comparison graph, and
[0071] after obtaining the 2-bits, HW, and rand_val probability distributions of the SoftMax output, the Figure 4 designed factor graph is used to integrate their probability distributions, and the belief propagation is used to update these probability distributions. 10 rounds of belief propagation iterations are performed, and the information entropy is used to represent the uncertainty of the probability distribution. Figure 6 shows the change in the information entropy of the 2-bits probability distribution after each belief propagation iteration. The darker area represents a higher entropy value, indicating greater uncertainty, while the lighter area represents a lower entropy value, indicating less uncertainty. It can be observed that in the initial probability distribution, the information entropy of the target coefficient is higher, resulting in a lower attack success rate. As the number of belief propagation iterations increases, the information entropy of the probability distribution gradually decreases. Finally, the entropy values of the four probability distributions approach 0.
[0072] Table 1 gives the comparison data of the analysis accuracy of different types using a single trace.
[0073] Table 1 Comparison of Analysis Accuracy Using a Single Trace
[0074] Finally, Table 1 shows the analysis accuracy rates when different methods use a single trace. The average accuracy rate using CNN is 85.6%, and the average accuracy rate using ICNN is 91.8%. Compared with CNN, ICNN captures the leakage features of bit concatenation, thus significantly improving the analysis accuracy rates of the latter three types of traces. After integrating these three types of leakage information using belief propagation, the average accuracy rate further rises to 99.2%. Therefore, the method proposed in this solution can analyze the leakage in the SEAL-Embedded library with higher accuracy and evaluate the threat level of its leakage to security with higher standards. In addition, since the analysis object in this embodiment is the bit concatenation technique, the proposed method can be applied to various implementations that use bit concatenation for memory compression under resource-constrained conditions, not limited to the SEAL-Embedded library.
[0075] Embodiment 2 In one or more embodiments, a side-channel analysis system for CKKS embedded implementation is disclosed, specifically including: A trace acquisition module, configured to acquire electromagnetic traces when a CKKS embedded device executes a target algorithm; A leakage position identification module, configured to, for the acquired electromagnetic traces, construct a template based on the operations being executed at the leakage position, locate the leakage position, and identify the leakage position; A category prediction module, configured to input the electromagnetic traces with the identified leakage position into a trained interconnected convolutional neural network to obtain the predicted probability distribution of each category, and further obtain the predicted leakage category; wherein, the interconnected convolutional neural network takes four trace segments as input each time, and the features of the four trace segments respectively correspond to the four coefficients in the bit concatenated byte; A category optimization module, configured to construct a factor graph of the target algorithm, integrate the relationships between various leakage information through the belief propagation algorithm, and optimize the predicted classification result to obtain the optimized leakage category.
[0076] It should be noted that the specific implementation manners of the above modules are exactly the same as those in Embodiment 1 and will not be elaborated further.
[0077] Embodiment 3 In one or more embodiments, a terminal device is disclosed, which includes a processor and a memory. The processor is used to implement instructions; the memory is used to store multiple instructions, and the instructions are adapted to be loaded and executed by the processor to perform the side-channel analysis method for CKKS embedded implementation described in Embodiment 1.
[0078] It should be understood that in this embodiment, the processor may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0079] The memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. A part of the memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.
[0080] In the implementation process, each step of the above method may be completed by the integrated logic circuit in the hardware of the processor or the instructions in the form of software.
[0081] Embodiment 4 In one or more embodiments, a computer-readable storage medium is disclosed, in which multiple instructions are stored, and the instructions are suitable for being loaded and executed by the processor of the terminal device to perform the side-channel analysis method for CKKS embedded implementation described in Embodiment 1.
[0082] Although the specific implementation manners of the present invention are described above in conjunction with the accompanying drawings, it is not a limitation on the protection scope of the present invention. Those skilled in the art should understand that based on the technical solutions of the present invention, various modifications or deformations that can be made by those skilled in the art without creative efforts are still within the protection scope of the present invention.
Claims
1. A side-channel analysis method for CKKS embedded implementation, characterized in that, Including: Obtain the electromagnetic traces when the CKKS embedded device executes the target algorithm; For the obtained electromagnetic traces, construct a template based on the operation being executed, locate the leakage position, and identify the leakage position; Input the electromagnetic traces identifying the leakage position into the trained interconnected convolutional neural network to obtain the predicted probability distribution for each category, and then obtain the predicted leakage category; wherein, the interconnected convolutional neural network takes four trace segments as input each time, and the features of the four trace segments respectively correspond to the four coefficients in the bit-concatenated byte; Construct a factor graph of the target algorithm, integrate the relationships between various leakage information through the belief propagation algorithm, optimize the predicted classification result, and obtain the optimized leakage category.
2. The side-channel analysis method for CKKS embedded implementation according to claim 1, characterized in that For the obtained electromagnetic traces, construct a template based on the operation being executed to locate the leakage position. The specific process is as follows: Take the operation being executed at the leakage position as the target operation, obtain the energy consumption traces of the target operation, calculate the mean and covariance matrix of the energy consumption traces, and obtain the template corresponding to the target operation; Use a sliding window to perform template matching in segments on the entire obtained electromagnetic trace, and indicate the leakage position by calculating the matching probability under the multivariate Gaussian normal distribution.
3. The side-channel analysis method for CKKS embedded implementation according to claim 1, characterized in that The interconnected convolutional neural network includes: an input layer, a first convolutional layer, a second convolutional layer, a first fully connected layer, a second fully connected layer, an activation function layer, and an output layer; after each convolutional layer, a batch normalization layer and a max pooling layer are sequentially added; Among them, the input of the input layer is four trace segments, corresponding to the four coefficients in a bit-concatenated byte; extract the leakage features of each trace segment through the first convolutional layer and the second convolutional layer; the leakage features are sequentially mapped through the first fully connected layer and the second fully connected layer to obtain features with label categories; the features are input into the activation function to obtain the predicted probability distribution for each category.
4. A side-channel analysis method for CKKS embedded implementation according to claim 1, characterized in that, The specific process of the leakage features being sequentially mapped through the first fully connected layer and the second fully connected layer is as follows: Leakage feature Are respectively mapped to features through the first fully connected layer ; Feature are respectively mapped to features through the second fully connected layer ; Among them, the feature contains both its own coefficient feature and the feature of the first coefficient , the feature contains its own coefficient feature and the feature of the second coefficient , contains its own coefficient feature and the feature of the third coefficient .
5. A side-channel analysis method for CKKS embedded implementation according to claim 1, characterized in that, The target algorithm is the polynomial sampling module in the SEAL-Embedded library, and the vulnerabilities of the sampling coefficients include: value leakage before modulo-3 reduction, 2-bit value leakage, and Hamming weight leakage of the byte.
6. The side-channel analysis method for CKKS embedded implementation according to claim 5, characterized in that, For the 2-bit value leakage and the Hamming weight leakage of the byte, use the trained interconnected convolutional neural network to classify the input traces respectively; For the value leakage before modulo-3 reduction, use the trained convolutional neural network to classify the traces.
7. The side-channel analysis method for CKKS embedded implementation according to the claim, characterized in that, The factor graph of the target algorithm is specifically: Take the four coefficients of the 2-bit value leakage, the Hamming weight of the byte, and the value before modulo-3 reduction as variable nodes, and take the posterior distribution corresponding to each variable node as a factor node. When the factor node depends on the variable node, connect them through an edge.
8. A side-channel analysis system for CKKS embedded implementation, characterized in that, Including: A trace acquisition module configured to obtain the electromagnetic traces when the CKKS embedded device executes the target algorithm; A leakage position identification module configured to, for the obtained electromagnetic traces, construct a template based on the operation being executed at the leakage position, locate the leakage position, and identify the leakage position; The category prediction module is configured to input the electromagnetic trace identifying the leakage location into a trained interconnected convolutional neural network to obtain the predicted probability distribution for each category, and further obtain the predicted leakage category; wherein, the interconnected convolutional neural network takes four trace segments as input each time, and the features of the four trace segments respectively correspond to four coefficients in the bit-concatenated byte. The category optimization module is configured to construct a factor graph of the target algorithm, integrate the relationships between various leakage information through the belief propagation algorithm, and optimize the predicted classification result to obtain the optimized leakage category.
9. A terminal device, comprising a processor and a memory, the processor being configured to implement instructions; the memory being configured to store a plurality of instructions, characterized in that, The instruction is adapted to be loaded and executed by a processor for the high-precision battery model parameter identification method based on output response reconstruction according to any one of claims 1-7.
10. A computer-readable storage medium storing multiple instructions, characterized in that, The instruction is adapted to be loaded and executed by a processor of a terminal device for the high-precision battery model parameter identification method based on output response reconstruction according to any one of claims 1-7.
Citation Information
Patent Citations
Safety chip side channel leakage detection method and system based on neural network
CN112600659A
Side channel leakage position positioning method and device, storage medium and terminal
CN112883385A
Side channel attack method and system based on deep learning
CN117093984A
Modeling type side channel attack method based on tetrad network
CN118018176A
Deep learning side channel analysis method for efficiently recovering secret key
CN119276461A