Descending algebraic fault analysis method and device for lightweight block cipher

By decomposing the S-box of the lightweight block cipher into low-order S-boxes and constructing a low-order algebraic equation system, the problem of excessive computing resources and time consumption in the existing technology is solved, and efficient key cracking is achieved.

CN120729499APending Publication Date: 2025-09-30BEIJING INST OF COMP TECH & APPL
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510952468.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

When performing algebraic fault analysis on lightweight block cipher algorithms in the existing technology, the algebraic equation exponent of the S-box substitution operation is high, resulting in high consumption of computing resources and long time, making it difficult to effectively crack the key within the specified time.

Method used

The power-reducing algebraic fault analysis method is used to decompose the S-box into two S-boxes of low algebraic degree, and a low-order S-box algebraic equation group is constructed to reduce the computational complexity. The algebraic equation is constructed by the decomposed S-box and other round function components, and the key is solved using the SAT parser.

Benefits of technology

It effectively reduces the computational complexity of the parser, reduces the number of faults and time required for solving, and improves the efficiency of key cracking.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729499A_ABST
    Figure CN120729499A_ABST
Patent Text Reader

Abstract

The invention relates to a power-down algebraic fault analysis method and device for lightweight block cipher, and belongs to the field of communication and information security. The method comprises the following steps: inputting a plaintext into a target lightweight block cipher to obtain a correct ciphertext, realizing fault injection of the target lightweight block cipher in a last R round, and inputting the same plaintext into the target lightweight block cipher to obtain a fault ciphertext; decomposing the S box of the target lightweight block cipher, and decomposing the original S box into two S boxes with low algebraic times; constructing a correct encryption algebraic equation and a fault encryption algebraic equation of the target lightweight block cipher; assigning the correct ciphertext, the fault ciphertext and the fault information to obtain an assignment algebraic equation; and solving all algebraic equations to obtain an encryption key used for encrypting the target lightweight block cipher. According to the method, the S box substitution operation is subjected to algebraic equation representation by using the equation sets with low algebraic times and small number, and the solving efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of communication and information security, and in particular relates to a method and device for analyzing power-decreasing algebraic faults in lightweight block ciphers. Background Art

[0002] Lightweight block ciphers are cryptographic algorithms designed specifically for resource-constrained environments. They feature a simple design, high computational efficiency, and low resource consumption. They can meet constraints on processing power, storage space, and energy consumption while ensuring security. They are suitable for a variety of applications, including IoT devices and wireless sensor networks, and are a key branch of cryptography. Currently, widely used algorithms such as PRESENT, LED, and SIMON are all lightweight block ciphers.

[0003] Common attack methods against lightweight block ciphers include fault attacks. Fault attacks are specific techniques that alter the correct operation of cryptographic equipment. They can cause errors in the cryptographic algorithm by altering the power supply, generating abnormal radiation, or generating electromagnetic interference. Attackers exploit the fault and its consequences to decrypt sensitive information. Fault attacks can be divided into two phases: fault injection and fault exploitation. Common methods for fault injection include electromagnetic, voltage, laser, and temperature. Fault exploitation builds on fault injection by using techniques such as algebraic analysis to decrypt sensitive information within the cryptographic system.

[0004] Common fault exploitation methods include differential fault analysis, algebraic fault analysis, and algebraic persistent fault analysis. Algebraic fault analysis is a new fault exploitation method developed by Courtois et al. in 2010 by combining algebraic analysis with differential fault analysis. The attacker injects a fault into a normally functioning encryption system, generating the corresponding faulty ciphertext. The attacker then converts the correct encryption process, the faulty encryption process, the ciphertext, the faulty ciphertext, and other information into algebraic equations. This system of equations is then solved using an algebraic solver to ultimately recover the encryption key.

[0005] However, when performing algebraic fault analysis on lightweight block ciphers, the algebraic equations used in S-box substitution operations have high exponentials. Therefore, solving these equations using a general-purpose algebraic solver consumes a lot of computational resources and takes a long time. To crack the key within the specified time, a larger number of faulty ciphertexts or faults may be required. Therefore, a new method is needed to improve the solution efficiency. Summary of the Invention

[0006] (1) Technical issues to be resolved

[0007] The technical problem to be solved by the present invention is how to provide a method and device for power-reducing algebraic fault analysis of lightweight block ciphers, so as to solve the problem that when performing algebraic fault analysis on lightweight block cipher algorithms, the algebraic equations used in the S-box substitution operation have high exponents, resulting in a large amount of computing resources consumed and a long time spent on solving the algebraic equations using a general algebraic parser.

[0008] (2) Technical solution

[0009] In order to solve the above technical problems, the present invention proposes a power-reducing algebraic fault analysis method for lightweight block ciphers, which includes the following steps:

[0010] S101, input plain text into the target lightweight block cipher to obtain the correct cipher text;

[0011] S102: inject a fault into the target lightweight block cipher in the last R rounds, then input the same plaintext to obtain a faulty ciphertext; and form a correct-faulty ciphertext pair with the correct ciphertext and the corresponding faulty ciphertext.

[0012] S103, decomposing the S-box of the target lightweight block cipher into two S-boxes of low algebraic degree;

[0013] S104. Constructing a correct encryption algebraic equation of the target lightweight block cipher based on the two decomposed S-boxes and other round function components of the target lightweight block cipher;

[0014] S105. Constructing a fault encryption algebraic equation of the reciprocal R rounds of the target lightweight block cipher using the two decomposed S-boxes and other round function components of the target lightweight block cipher according to the fault information;

[0015] S106, assigning values ​​to the correct ciphertext, the fault ciphertext, and the fault information to obtain an assignment algebraic equation;

[0016] S107. Solve all algebraic equations to obtain the encryption key used for the target lightweight block cipher encryption.

[0017] The present invention also provides a device for analyzing power-reducing algebraic faults in lightweight block ciphers, the device comprising:

[0018] The encryption module is used to input plaintext into the target lightweight block cipher to obtain the correct ciphertext; implement fault injection into the target lightweight block cipher in the last R rounds, and then input the same plaintext into it to obtain the fault ciphertext;

[0019] Decomposition module, decomposing the S-box of the target lightweight block cipher into two S-boxes of low algebraic degree;

[0020] The analysis module constructs the correct encryption algebraic equation of the target lightweight block cipher based on the two decomposed S-boxes and other round function components of the target lightweight block cipher. Based on the fault information, the analysis module uses the two decomposed S-boxes and other round function components of the target lightweight block cipher to construct the fault encryption algebraic equation of the reciprocal R round of the target lightweight block cipher. The correct ciphertext, the fault ciphertext, and the fault information are assigned to obtain the assigned algebraic equation.

[0021] The solving module solves all algebraic equations to obtain the encryption key.

[0022] The present invention further provides an electronic device, comprising:

[0023] one or more processors;

[0024] a memory for storing one or more programs;

[0025] The processor and the memory communicate with each other via a bus; the memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute the method.

[0026] (3) Beneficial effects

[0027] The present invention proposes a method and device for analyzing power-reducing algebraic faults in lightweight block ciphers. Compared with existing technologies, the present invention has the following advantages: The present invention proposes a power-reducing algebraic fault analysis method for lightweight block ciphers. By introducing S-box decomposition technology, a high-order S-box is decomposed into two low-order S-boxes. This allows the S-box substitution operation to be implemented using a small number of equations with a low algebraic degree to represent algebraic equation, thereby improving solution efficiency. The present method has good universality. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 This is a flowchart of a power-reducing algebraic fault analysis method for lightweight block ciphers proposed by the present invention;

[0029] Figure 2 This is a schematic diagram of the LED encryption algorithm;

[0030] Figure 3 This is a flow chart of a device for analyzing power-reducing algebraic faults for lightweight block ciphers proposed by the present invention;

[0031] Figure 4 This is a schematic structural diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0032] In order to make the purpose, content and advantages of the present invention more clear, the specific implementation methods of the present invention are further described in detail below with reference to the accompanying drawings and examples.

[0033] In view of this, the present invention proposes a method and device for analyzing power-reducing algebraic faults in lightweight block ciphers. To achieve the above-mentioned purpose, the technical solution of the present invention is as follows:

[0034] A first aspect of the present invention provides a method for analyzing power-reducing algebraic faults in lightweight block ciphers, the method comprising:

[0035] S101, input plain text into the target lightweight block cipher to obtain the correct cipher text;

[0036] S102: inject a fault into the target lightweight block cipher in the last R rounds, then input the same plaintext to obtain a faulty ciphertext; and form a correct-faulty ciphertext pair with the correct ciphertext and the corresponding faulty ciphertext.

[0037] S103, decomposing the S-box of the target lightweight block cipher into two S-boxes of low algebraic degree;

[0038] S104. Constructing a correct encryption algebraic equation of the target lightweight block cipher based on the two decomposed S-boxes and other round function components of the target lightweight block cipher;

[0039] S105. Constructing a fault encryption algebraic equation of the reciprocal R rounds of the target lightweight block cipher using the two decomposed S-boxes and other round function components of the target lightweight block cipher according to the fault information;

[0040] S106, assigning values ​​to the correct ciphertext, the fault ciphertext, and the fault information to obtain an assignment algebraic equation;

[0041] S107. Solve all algebraic equations to obtain the encryption key used for the target lightweight block cipher encryption.

[0042] A second aspect of the present invention provides a device for analyzing power-reducing algebraic faults in lightweight block ciphers, comprising:

[0043] The encryption module is used to input plaintext into the target lightweight block cipher to obtain the correct ciphertext; implement fault injection into the target lightweight block cipher in the last R rounds, and then input the same plaintext into it to obtain the fault ciphertext;

[0044] Decomposition module, decomposing the S-box of the target lightweight block cipher into two S-boxes of low algebraic degree;

[0045] The analysis module constructs the correct encryption algebraic equation of the target lightweight block cipher based on the two decomposed S-boxes and other round function components of the target lightweight block cipher. Based on the fault information, the analysis module uses the two decomposed S-boxes and other round function components of the target lightweight block cipher to construct the fault encryption algebraic equation of the reciprocal R round of the target lightweight block cipher. The correct ciphertext, the fault ciphertext, and the fault information are assigned to obtain the assigned algebraic equation.

[0046] The solving module solves all algebraic equations to obtain the encryption key.

[0047] A third aspect of the present invention provides an electronic device, comprising:

[0048] one or more processors;

[0049] a memory for storing one or more programs;

[0050] The processor and the memory communicate with each other via a bus; the memory stores program instructions that can be executed by the processor, and the processor can execute the above method by calling the program instructions.

[0051] A fourth aspect of the present invention provides a non-transitory computer-readable storage medium having a computer program stored thereon, which implements the above method when the computer program is executed by a processor.

[0052] Example 1:

[0053] Figure 1 This is a flowchart illustrating a method for analyzing power-reducing algebraic faults in a lightweight block cipher according to an exemplary embodiment. The method includes the following steps:

[0054] Step S101, input plain text into the target lightweight block cipher to obtain the correct cipher text;

[0055] In the specific implementation of step S101, since the goal is a lightweight block cipher, generally a random plaintext is selected. After the plaintext is input, the correctly encrypted ciphertext is obtained at the output end, and the plaintext and ciphertext are combined into a plaintext-ciphertext pair.

[0056] Step S102: inject a fault into the target lightweight block cipher in the last R rounds, then input the same plaintext to obtain a faulty ciphertext; and form a correct-faulty ciphertext pair with the correct ciphertext and the corresponding faulty ciphertext.

[0057] In the specific implementation of step S102, an appropriate number of fault injection rounds is selected based on the characteristics of the target lightweight block cipher, and an appropriate number of faults is selected based on the key length of the target lightweight block cipher. Using the plaintext selected in step S101, electromagnetic, voltage, or laser interference is applied during the encryption process. This causes a fault with a known location and known or unknown value to be injected over the selected number of fault injection rounds. The fault propagates through R rounds, ultimately yielding a faulty ciphertext. Based on the number of faults, a corresponding correct-faulty ciphertext pair is generated.

[0058] Step S103, decomposing the S-box of the target lightweight block cipher into two S-boxes of low algebraic degree;

[0059] In the specific implementation of step S103, taking the LED_64 algorithm as an example, the S-box is shown in Table 1:

[0060] Table 1 Schematic diagram of S box

[0061] X 0 1 2 3 4 5 6 7 8 9 a b c d e f S[X] c 5 6 b 9 0 a d 3 e f 8 4 7 1 2

[0062] Assume that the input of the S-box is (x0, x1, x2, x3) and the output is (y0, y1, y2, y3), where x0 and y0 are the most significant bits. Then its input and output can be expressed by the following algebraic equations:

[0063] Its algebraic expression is:

[0064]

[0065] From the above, we can see that the algebraic degree of the S-box of the LED_64 cryptographic algorithm is 3. In order to achieve power reduction, the original S-box S(X) is decomposed into two S-boxes of algebraic degree 2: F(X) and G(X), that is, S(X) = F(G(X)), where S, F, G: GF(2) 4 →GF(2) 4 Considering that the input and output of the two S-boxes are both 4-bit variables, assuming X = (x, y, z, w), then G(X) = (g0(X) + g1(X) + g2(X) + g3(X)), where g k (X) is a quadratic Boolean function and can be expressed as an ANF equation using the following formula, where a i and a ij is the coefficient of the quadratic term of the Boolean equation.

[0066] g k (x,y,z,w)=a0+a1x+a2y+a3z+a4w+a 12 xy+a 13 xz+a 14 xw+a 23yz+a 24 yw+a 34 zw

[0067] In order to reduce the search volume, each g k If a0 in the (x, y, z, w) equation is set to 0, then:

[0068] g k (x,y,z,w)=a1x+a2y+a3z+a4w+a 12 xy+a 13 xz+a 14 xw+a 23 yz+a 24 yw+a 34 zw

[0069] For all possible function input combinations g k , calculate the output values ​​of their corresponding ANF equations, and determine whether the function combination meets the balance requirements. If it meets the requirements, it will be added to the set P, otherwise it will be removed;

[0070] For each balanced coefficient contained in the set P, iteratively calculate the corresponding value of G(X) and determine whether the value of G(X) is a quadratic function. If this requirement is met, substitute the value of G(X) into S(G -1 (X)) find the value of F(X);

[0071] Check whether F(X) is a quadratic function. If so, add both G(X) and F(X) to the set of possible decompositions. Finally, select a suitable decomposition scheme by calculating the number of AND gates for each pair of G(X) and F(X) in the set and the Hamming weight of the ANF equation or other methods.

[0072] Taking the LED_64 algorithm as an example, one of the decomposition schemes is shown in Table 2.

[0073] Table 2 Decomposition scheme table

[0074] X 0 1 2 3 4 5 6 7 8 9 a b c d e f F[X] 7 e 9 2 b 0 4 d 5 c a 1 8 3 6 f G[X] 0 8 b 7 a 3 1 c 4 6 f 9 e d 5 2

[0075] The algebraic expression of S-box 1 is:

[0076] The algebraic expression of S-box 2 is:

[0077] The two algebraic equations of the quadratic S-box are used to replace the original algebraic equation of the cubic S-box.

[0078] Step S104, constructing a correct encryption algebraic equation of the target lightweight block cipher based on the two decomposed S-boxes and other round function components of the target lightweight block cipher;

[0079] The specific implementation of step S104 includes:

[0080] Step S1041, analyzing the composition of the target lightweight block cipher round function according to the target lightweight block cipher;

[0081] The round function of lightweight block cipher generally includes: S-box substitution, row transformation, column confusion, round key XOR, etc. Taking the LED_64 encryption algorithm as an example, Figure 2 As shown in Figure 1, the round function includes round key addition, round constant addition, S-box substitution, row shift, and column confusion. After multiple rounds of encryption, the ciphertext is output.

[0082] Step S1042: The encryption process is sequentially converted into the form of algebraic equations according to the structure of the round function. The S-box substitution operation uses two decomposed low-order S-box equations to replace the original equations.

[0083] Step S105 , constructing a fault encryption algebraic equation of the reciprocal R rounds of the target lightweight block cipher using the two decomposed S-boxes and other round function components of the target lightweight block cipher according to the fault information;

[0084] The specific implementation of step S105 includes:

[0085] Step S1051, analyzing the optimal number of fault injection rounds R according to information such as the round function composition and key length of the target lightweight block cipher;

[0086] Step S1052 , using the two decomposed S-boxes and other round function components of the target lightweight block cipher, construct a fault encryption algebraic equation group of the inverse R round of the target lightweight block cipher;

[0087] Step S1053: establishing a corresponding fault encrypted algebraic equation group according to the number of faults.

[0088] Step S106: assigning values ​​to the correct ciphertext and the fault ciphertext, converting the fault information into an algebraic equation, and obtaining an assigned algebraic equation;

[0089] In the specific implementation of step S106, firstly, the correct ciphertext and the fault ciphertext set are assigned values; then the fault information, such as the fault location, fault value, etc., is converted into the form of an algebraic equation; the equations obtained in step S106 are combined to obtain an assigned algebraic equation.

[0090] Step S107, solving all algebraic equations to obtain the encryption key;

[0091] The specific implementation of step S107 includes:

[0092] Step S1071: Input the correct encrypted algebraic equation of S04, the faulty encrypted algebraic equation of S05, and the valued algebraic equation obtained in S06 into an algebraic parser for solving;

[0093] Specifically, in this embodiment, the CryptoMiNiSAT parser based on the SAT problem is used for solution. To adapt to the parser, the algebraic equations are converted into a cnf file. The parser runs on the Ubuntu system and calls the parser installed in the system to crack the key.

[0094] Step S1072: Recover the encryption key used for the target lightweight block cipher encryption based on the solution result of the parser.

[0095] Specifically, when using a SAT parser to solve, fixed variables are used in the algebraic equation group to represent the value of the encryption key, so the corresponding variable values ​​obtained after solving the algebraic equation group are the encryption key.

[0096] In summary, the above embodiments demonstrate that the present invention introduces S-box decomposition technology, decomposing the original high-order S-box into two low-order S-boxes. This reduces the number of high-order variables used when using algebraic equations to represent the algebraic relationships between S-boxes. Furthermore, for certain lightweight block ciphers, this also reduces the number of algebraic equations, effectively reducing the computational complexity of the parser. Compared to traditional algebraic fault analysis methods, the power-reducing algebraic fault analysis method proposed in this application can reduce the number of required faults and effectively shorten the time required to solve them.

[0097] Corresponding to the aforementioned embodiment of a method for analyzing power-reducing algebraic faults of lightweight block ciphers, the present application also provides an embodiment of a device for analyzing power-reducing algebraic faults of lightweight block ciphers.

[0098] The encryption module 301 inputs plaintext into the target lightweight block cipher to obtain the correct ciphertext; implements fault injection into the target lightweight block cipher in the last R rounds, then inputs the same plaintext into the target lightweight block cipher to obtain the faulty ciphertext; and forms a correct-faulty ciphertext pair with the correct ciphertext and its corresponding faulty ciphertext.

[0099] A decomposition module 302 decomposes the S-box of the target lightweight block cipher into two S-boxes of low algebraic degree;

[0100] The analysis module 303 constructs a correct encryption algebraic equation of the target lightweight block cipher based on the two decomposed S-boxes and other round function components of the target lightweight block cipher; constructs a fault encryption algebraic equation of the reciprocal R round of the target lightweight block cipher using the two decomposed S-boxes and other round function components of the target lightweight block cipher based on the fault information; and assigns values ​​to the correct ciphertext, the fault ciphertext, and the fault information to obtain an assigned algebraic equation.

[0101] The solving module 304 solves all algebraic equations to obtain the encryption key. Regarding the apparatus in the above embodiment, the specific process of each module performing the operation has been described in detail in the embodiment of a power-reducing algebraic fault analysis method for lightweight block ciphers, which is omitted here.

[0102] Correspondingly, such as Figure 4 As shown, the present application also provides an electronic device, comprising: one or more processors; a memory for storing one or more programs; the processor and the memory communicate with each other via a bus; the memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute the above-mentioned method for analyzing a power-reducing algebraic fault for a lightweight block cipher. Accordingly, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor, the above-mentioned method for analyzing a power-reducing algebraic fault for a lightweight block cipher is implemented.

[0103] Compared with existing technologies, the present invention has the following advantages: It proposes a method for analyzing power-reducing algebraic faults in lightweight block ciphers. It introduces S-box decomposition technology, decomposing a high-order S-box into two low-order S-boxes. This allows the S-box substitution operation to be implemented using a small number of equations with a low algebraic degree, thus improving the solution efficiency. The method has good universality.

[0104] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A power-reducing algebraic fault analysis method for lightweight block ciphers, characterized in that: The method comprises the following steps: S101, input plain text into the target lightweight block cipher to obtain the correct cipher text; S102, injecting a fault into the target lightweight block cipher in the last R rounds, and then inputting the same plaintext into the cipher to obtain the fault ciphertext; The correct ciphertext and its corresponding faulty ciphertext form a correct-faulty ciphertext pair; S103, decomposing the S-box of the target lightweight block cipher into two S-boxes of low algebraic degree; S104. Constructing a correct encryption algebraic equation of the target lightweight block cipher based on the two decomposed S-boxes and other round function components of the target lightweight block cipher; S105. Constructing a fault encryption algebraic equation of the reciprocal R rounds of the target lightweight block cipher using the two decomposed S-boxes and other round function components of the target lightweight block cipher according to the fault information; S106, assigning values ​​to the correct ciphertext, the fault ciphertext, and the fault information to obtain an assignment algebraic equation; S107. Solve all algebraic equations to obtain the encryption key used for the target lightweight block cipher encryption.

2. The power-reducing algebraic fault analysis method for lightweight block ciphers according to claim 1, wherein: The step S102 includes: selecting an appropriate number of fault injection rounds based on the characteristics of the target lightweight block cipher, and selecting an appropriate number of faults based on the key length of the target lightweight block cipher; using the plaintext in step S1101, applying electromagnetic, voltage, or laser light physical interference during the encryption process, so that faults with known fault locations and known or unknown fault values ​​are injected in the selected number of fault injection rounds, and the faults are propagated through R rounds to ultimately obtain a fault ciphertext; and obtaining a corresponding correct-fault ciphertext pair based on the number of faults.

3. The power-reducing algebraic fault analysis method for lightweight block ciphers according to claim 1, wherein: The step S103 includes: assuming that the input of the S-box is (x0, x1, x2, x3), and the output is (y0, y1, y2, y3), where x0 and y0 are the most significant bits, and the algebraic degree of the S-box is 3, in order to achieve power reduction, the original S-box S(X) is decomposed into two S-boxes of algebraic degree 2: F(X) and G(X), that is, S(X) = F(G(X)), where S, F, G: GF(2) 4 →GF(2) 4 .

4. The power-reducing algebraic fault analysis method for lightweight block ciphers according to claim 3, wherein: Considering that the input and output of the two S-boxes are both 4-bit variables, assuming X = (x, y, z, w), then G(X) = (g0(X) + g1(X) + g2(X) + g3(X)), where g k (X) is a quadratic Boolean function and is expressed as an ANF equation using the following formula, where a i and a ij is the coefficient of the quadratic term of the Boolean equation; g k (x,y,z,w)=a0+a1x+a2y+a3z+a4w+a 12 xy+a 13 xz+a 14 xw+a 23 yz+a 24 yw+a 34 zw In order to reduce the search volume, each g k If a0 in the (x, y, z, w) equation is set to 0, then: g k (x,y,z,w)=a1x+z2y+a3z+a4w+a 12 xy+a 13 xz+a 14 xw+a 23 yz+a 24 yw+a 34 zw For all possible function input combinations g k , calculate the output values ​​of their corresponding ANF equations, and determine whether the function combination meets the balance requirements. If it meets the requirements, it will be added to the set P, otherwise it will be removed; For each balanced coefficient contained in the set P, iteratively calculate the corresponding value of G(X) and determine whether the value of G(X) is a quadratic function. If this requirement is met, substitute the value of G(X) into S(G -1 (X)) find the value of F(X); Check whether F(X) is a quadratic function. If so, add both G(X) and F(X) to the set of possible decompositions. Finally, a suitable decomposition scheme is selected by calculating the number of AND gates of each pair of G(X) and F(X) in the set and the Hamming weight of the ANF equation or other methods.

5. The power-reducing algebraic fault analysis method for lightweight block ciphers according to claim 3 or 4, characterized in that: The S104 includes: Step S1041: Analyze the composition of the target lightweight block cipher's round function based on the target lightweight block cipher; the lightweight block cipher's round function includes: S-box substitution, row transformation, column confusion, and round key exclusive-or. Step S1042: The encryption process is sequentially converted into the form of algebraic equations according to the structure of the round function. The S-box substitution operation uses two decomposed low-order S-box equations to replace the original equations.

6. The power-reducing algebraic fault analysis method for lightweight block ciphers according to claim 5, wherein: The S105 includes: Step S1051, analyzing the optimal number of fault injection rounds R according to the round function composition and key length information of the target lightweight block cipher; Step S1052 , using the two decomposed S-boxes and other round function components of the target lightweight block cipher, construct a fault encryption algebraic equation group of the inverse R round of the target lightweight block cipher; Step S1053: establishing a corresponding fault encrypted algebraic equation group according to the number of faults.

7. The power-reducing algebraic fault analysis method for lightweight block ciphers according to claim 6, wherein: The step S106 includes: first assigning values ​​to the correct ciphertext and the fault ciphertext set; then converting the fault information into the form of an algebraic equation, where the fault information includes: the fault location and the fault value; and combining the equations obtained in step S106 to obtain an assigned algebraic equation.

8. The power-reducing algebraic fault analysis method for lightweight block ciphers according to claim 7, wherein: The S107 includes: Step S1071: Input the correct encrypted algebraic equation of S04, the faulty encrypted algebraic equation of S05, and the valued algebraic equation obtained in S06 into an algebraic parser for solving; use the CryptoMiNiSAT parser based on the SAT problem to solve, and convert the algebraic equation system into a cnf file to adapt to the parser; Step S1072, based on the solution result of the parser, recover the encryption key used for the target lightweight block cipher encryption; when using the parser to solve, fixed variables are used in the algebraic equation group to represent the value of the encryption key, and the corresponding variable value obtained after solving the algebraic equation group is the encryption key.

9. A device for analyzing power-reducing algebraic faults in lightweight block ciphers, characterized in that: The device includes: The encryption module is used to input plaintext into the target lightweight block cipher to obtain the correct ciphertext; implement fault injection into the target lightweight block cipher in the last R rounds, and then input the same plaintext into it to obtain the fault ciphertext; Decomposition module, decomposing the S-box of the target lightweight block cipher into two S-boxes of low algebraic degree; The analysis module constructs the correct encryption algebraic equation of the target lightweight block cipher based on the two decomposed S-boxes and other round function components of the target lightweight block cipher. Based on the fault information, the analysis module uses the two decomposed S-boxes and other round function components of the target lightweight block cipher to construct the fault encryption algebraic equation of the reciprocal R round of the target lightweight block cipher. The correct ciphertext, the fault ciphertext, and the fault information are assigned to obtain the assigned algebraic equation. The solving module solves all algebraic equations to obtain the encryption key.

10. An electronic device, characterized in that: The electronic device includes: one or more processors; a memory for storing one or more programs; The processor and the memory communicate with each other via a bus; the memory stores program instructions that can be executed by the processor, and the processor can execute the method according to any one of claims 1 to 8 by calling the program instructions.

Citation Information

Patent Citations

  • Redundancy enhanced algebraic fault analysis method and device for block cipher

    CN116318612A