Side channel energy analysis method, apparatus, storage medium, and electronic device

By introducing the Gini impurity index analysis method, the dependence of existing side-channel energy analysis techniques on equipment and models is solved, achieving greater universality and lower computational overhead, thus improving attack effectiveness.

CN112966290BActive Publication Date: 2026-01-23TSINGHUA UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110356614.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-04-01
Publication Date
2026-01-23
Estimated Expiration
2041-04-01

AI Technical Summary

Technical Problem

Existing side-channel energy analysis techniques are highly dependent on attack devices and energy models, and have high computational overhead, which limits their application.

Method used

The Gini impurity index analysis method is adopted. By encrypting randomly selected plaintext, the encryption energy trace is collected, and the Gini impurity index is calculated based on multiple key assumptions and energy trace sets, so as to select a suitable key value.

Benefits of technology

It reduces reliance on attack equipment and energy models, improves the universality of side-channel energy analysis, and reduces computational overhead, resulting in better attack effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112966290B_ABST
    Figure CN112966290B_ABST
Patent Text Reader

Abstract

The application provides a side channel energy method, device, storage medium and electronic equipment, and relates to the technical field of information security, and the method comprises the following steps: performing a preset encryption operation on a plurality of randomly selected plaintexts respectively; collecting encryption energy traces generated in the encryption operation process; and cyclically executing the following steps to obtain an overall key of the encryption operation: generating a plurality of key hypothesis values of a certain byte in the overall key; selecting a part of the energy traces corresponding to a certain sampling point of each encryption energy trace to obtain an energy trace set of the sampling point; calculating a Gini impurity index corresponding to each key hypothesis value based on the plurality of key hypothesis values and the energy trace set of the sampling point; and determining the key value of the certain byte in the overall key based on the Gini impurity index. The technical scheme provided by the application can reduce the dependence on attack equipment and energy models, and has high universality and small calculation cost.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security, in particular to a side channel energy analysis method and device, a storage medium and an electronic device. BACKGROUND

[0002] Modern cryptography algorithms provide important protection for information security in the information age. Cryptography algorithms have sufficient theoretical security through careful design and extensive rigorous argument. However, in the information society, cryptography algorithms need to be physically implemented in various devices to play their role. Special cryptographic chips and single-chip devices provide the main carrier for the implementation of cryptography algorithms. The implementation scheme of cryptography algorithms determines the security of the implementation.

[0003] Since the energy analysis technology was first proposed and applied in 1996, side channel energy attack technology has been increasingly studied. This technology analyzes and processes the energy information generated by the operation of a cryptographic device to obtain the secret information of the cryptographic algorithm. The existing simple energy attack, differential energy attack, correlation energy attack, template attack and other energy analysis technologies have shown strong attack ability, but have certain limitations, such as high requirements for attackers, the need to have a similar device to the attacked device and a good energy model, the need for a corresponding relationship between the energy model and the real energy leakage, and insufficient information utilization, which limits the use of energy analysis technology. SUMMARY

[0004] To solve the above problems in the prior art, the present application provides a side channel energy analysis method, device, storage medium and electronic device, which can reduce the dependence on attack devices and energy models, and has high universality and small computational overhead.

[0005] To achieve the above object, the technical scheme of the present application is as follows:

[0006] In a first aspect, the embodiments of the present application provide a side channel energy analysis method, which comprises:

[0007] performing a preset encryption operation on a plurality of randomly selected plaintexts respectively;

[0008] collecting an encryption energy trace corresponding to each plaintext generated in the encryption operation process; wherein each encryption energy trace has T sampling points;

[0009] cyclically performing the following steps until the overall key of the encryption operation is obtained, wherein the overall key has a bytes:

[0010] generating a plurality of key hypothesis values of the fth byte in the overall key; wherein 1≤f≤a;

[0011] selecting a partial energy trace corresponding to an oth sampling point of each of the encrypted energy traces to obtain an energy trace set of the oth sampling point, wherein 1≤o≤T;

[0012] calculating a Gini impurity index corresponding to each of the key hypothesis values based on the plurality of key hypothesis values and the energy trace set of the oth sampling point;

[0013] selecting a key hypothesis value from the plurality of key hypothesis values as a key value of an fth byte in the overall key based on the Gini impurity index.

[0014] Preferably, the calculating a Gini impurity index corresponding to each of the key hypothesis values based on the plurality of key hypothesis values and the energy trace set of the oth sampling point comprises:

[0015] adopting an unsupervised clustering algorithm to cluster the energy trace set of the oth sampling point into X types, wherein X is preset;

[0016] for each of the key hypothesis values, the following steps are performed:

[0017] dividing the energy trace set of the oth sampling point in the X types into V subsets based on the key hypothesis value and the obtained plaintext value set, wherein X=V;

[0018] calculating a Gini impurity index corresponding to the key hypothesis value based on the V subsets and the X types.

[0019] Preferably, the dividing the energy trace set of the oth sampling point in the X types into V subsets based on the key hypothesis value and the obtained plaintext value set comprises:

[0020] selecting a partial plaintext corresponding to a position of a byte position of the key hypothesis value in the overall key from each of the plaintexts to obtain the plaintext value set;

[0021] obtaining an output value of an objective function based on the key hypothesis value and the plaintext value set, wherein the objective function is a pre-set non-injective function;

[0022] dividing the energy trace set of the oth sampling point in the X types into V subsets based on the output value of the objective function.

[0023] Preferably, when the encryption operation adopts a block cipher algorithm for encryption, the objective function is an output of an S-box.

[0024] Preferably, the step of calculating the Gini impurity index corresponding to the key hypothesis value based on the V subsets and the X types includes:

[0025] The Gini value for each subset is calculated based on the probability that the energy trace in each subset originates from each type;

[0026] Based on the Gini value of each subset, calculate the Gini impurity index corresponding to the key hypothesis value.

[0027] Preferably, the Gini value for each subset is calculated using the following expression:

[0028]

[0029] Among them, D i Gini(D) is the i-th subset of the V subsets. i ) represents the Gini value of the i-th subset; m represents the type index of the X types; Type m represents the energy trace set of the m-th type among the X types; p m Let be the probability that the energy trace in the i-th subset comes from Type m; D(o) be the set of energy traces at the o-th sampling point; and N be the number of plaintexts.

[0030] The Gini impurity index corresponding to the key hypothesis value is calculated using the following expression:

[0031]

[0032] Wherein, Gini_index(D(o),k j ) is related to the key hypothesis value k j The corresponding Gini impurity index; j is the index of the plurality of key hypothesis values; |D i | represents the number of energy traces in the i-th subset; |D(o)| represents the number of energy trace sampling points in D(o).

[0033] Preferably, the step of selecting a key hypothesis value from the plurality of key hypothesis values ​​as the key value of the f-th byte in the overall key based on the Gini impurity index includes:

[0034] The following expression is used to select one key hypothesis value from the plurality of key hypothesis values ​​as the key value of the f-th byte in the overall key:

[0035]

[0036] Where, k f * k is the key value of the f-th byte; j ,o represents the key hypothesis value kj and obtaining the Gini impurity index at the oth sampling point.

[0037] In a second aspect, an embodiment of the present application provides a side channel energy analysis device, the device comprising:

[0038] an encryption unit configured to perform a preset encryption operation on each of a plurality of randomly selected plaintexts;

[0039] a collection unit configured to collect an encryption energy trace corresponding to each of the plaintexts generated in the encryption operation process; wherein each of the encryption energy traces has T sampling points;

[0040] a key acquisition unit configured to cyclically perform the following steps until the overall key of the encryption operation is obtained, wherein the overall key has a number of bytes a:

[0041] generating a plurality of key hypothesis values of an fth byte in the overall key; wherein 1≤f≤a;

[0042] selecting a partial energy trace corresponding to an oth sampling point of each of the encryption energy traces to obtain an energy trace set of the oth sampling point; wherein 1≤o≤T;

[0043] calculating a Gini impurity index corresponding to each of the key hypothesis values based on the plurality of key hypothesis values and the energy trace set of the oth sampling point;

[0044] selecting a key hypothesis value from the plurality of key hypothesis values as a key value of the fth byte in the overall key based on the Gini impurity index.

[0045] In a third aspect, an embodiment of the present application provides a storage medium having program code stored thereon, wherein the program code, when executed by a processor, implements the side channel energy analysis method according to any one of the above embodiments.

[0046] In a fourth aspect, an embodiment of the present application provides an electronic device comprising a memory and a processor, wherein the memory has program code stored thereon and executable on the processor, and the program code, when executed by the processor, implements the side channel energy analysis method according to any one of the above embodiments.

[0047] The side channel energy analysis method, device, storage medium and electronic equipment provided by the embodiment of the present application can perform a preset encryption operation on a plurality of randomly selected plaintexts, and collect an encryption energy trace corresponding to each plaintext generated in the encryption operation process; based on a plurality of key hypothesis values and an energy trace set of an oth sampling point in each encryption energy trace, a Gini impurity index corresponding to each key hypothesis value is calculated, and based on the Gini impurity index, a key hypothesis value is selected from the plurality of key hypothesis values as a key value of a certain byte in the overall key of the encryption operation. It can be seen that the Gini impurity index in the decision classification is introduced into the side channel energy analysis, and the appropriate key hypothesis value is selected based on the Gini impurity index. Compared with the prior art, the present application only needs to obtain the encryption energy trace, and there is no strict restriction and requirement on the attacker, that is, the dependence on the attack device and the energy model can be reduced, thereby having higher universality and smaller calculation overhead. Practice shows that the present application has good attack effect under different assumed leakage models in any simple or complex energy leakage situation. BRIEF DESCRIPTION OF DRAWINGS

[0048] The scope of the present disclosure can be better understood by reading the following detailed description of exemplary embodiments in conjunction with the accompanying drawings, in which:

[0049] Figure 1 The method flowchart of the embodiment of the present application is shown in the figure;

[0050] Figure 2 The calculation flowchart of the Gini impurity index of a certain key hypothesis value and a certain sampling point in the embodiment of the present application is shown in the figure;

[0051] Figure 3 The device structure diagram of the embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0052] In order to make the purpose, technical scheme and advantages of the present application more clear, the implementation method of the present application will be described in detail below in conjunction with the drawings and embodiments, so that the implementation process of the present application can be fully understood and implemented by applying technical means to solve technical problems and achieve technical effects.

[0053] In the following description, many specific details are set forth in order to provide a thorough understanding of the present application, however, the present application can also be implemented in other ways different from those described herein, therefore, the protection scope of the present application is not limited by the specific embodiments disclosed below.

[0054] Example One

[0055] According to an embodiment of the present application, a side channel energy analysis method is provided, which is a new side channel energy analysis technique based on Gini impurity index classifier, namely Gini impurity index analysis. Algorithm 1 shown in Table 1 demonstrates the whole process of the Gini impurity index analysis algorithm. Generally, side channel analysis techniques all adopt a divide-and-conquer strategy to reduce the computational complexity, i.e. only part of the key values are obtained each time, and the whole key values are obtained by repeating multiple times. Therefore, the output result of Algorithm 1 each time is also part of the key values, such as 1 byte of key values.

[0056] Table 1

[0057]

[0058]

[0059] In Table 1, the first step of the algorithm is to randomly select N pieces of plaintext (P n |n=1,2,3,…,N} to represent the set of N random plaintexts, and the value of N can be selected according to actual conditions.

[0060] The second step of the algorithm is to perform N times of encryption operation on the N random plaintexts, and N pieces of encrypted energy traces can be obtained by using an oscilloscope or other devices. According to the set sampling frequency, each encrypted energy trace will contain T sampling points (o to represent the set of N encrypted energy traces, where o (1≤o≤T) represents the oth sampling point, and n (1≤n≤N) represents the nth encrypted energy trace.

[0061] The third step of the algorithm is to generate multiple key hypothesis values, which are represented by k={k 1 ,k 2 ,k 3 ,…,k M}, where M represents the size of the vector space. If 1 byte of part of the key values is selected, then M=2 8 =256, and there are 256 hypothesis key values in total.

[0062] The fourth step of the algorithm is to select part of the plaintext values at the corresponding byte position according to the byte position of the selected part of the attack key values. For example, if 1 byte of the part of the attack key values is selected, then the corresponding part of the plaintext values should also be the value of the 1th byte of the whole random plaintext. That is, p={p 1 ,p 2 ,p 3 ,…,p n}, where p n is the part of P n (1≤n≤N). When 1 byte of the key is selected, then p nrepresents a value of 1 byte.

[0063] Step 5 of the algorithm is to calculate the objective function value of the intermediate value For a block cipher algorithm, the output of the S-box is generally selected as the objective function of the algorithm. The objective function is any function in the attacked cipher algorithm, which is determined by the attacker. The intermediate value of the objective function is represented as the output value of the objective function according to different plaintexts and keys.

[0064] Step 6 of the algorithm is the Gini impurity index discriminator, which is used to calculate the Gini impurity index values corresponding to different energy trace sampling points under different key hypothesis values. This is also the core step of the algorithm. The final output will select the most likely correct key hypothesis value according to the Gini impurity index calculated under different key hypothesis values and energy trace sampling points, that is

[0065] Based on the above algorithm, as shown in Table 1, the method described in the embodiment includes: Figure 1

[0066] Step S101, a plurality of plaintexts are randomly selected and subjected to a predetermined encryption operation;

[0067] In the embodiment, the plurality of plaintexts are randomly selected, for example, N plaintexts are randomly selected, {P n |n=1,2,3,…,N} is used to represent a set of N random plaintexts, as shown in step 1 of the algorithm in Table 1, wherein the value of N can be selected according to actual conditions.

[0068] As shown in step 2 of the algorithm in Table 1, the N random plaintexts are subjected to N times of predetermined encryption operation, and the predetermined encryption operation refers to the encryption operation performed by using a predetermined key and a predetermined encryption algorithm. During the execution of the encryption operation, the corresponding encryption energy is generated, and therefore, the information of the encryption operation, such as the key used in the encryption operation, can be analyzed by collecting the encryption energy.

[0069] Step S102, collecting the encryption energy traces corresponding to each of the plaintexts generated during the encryption operation; wherein each of the encryption energy traces has T sampling points;

[0070] In the embodiment, the encryption energy in step S101 can be collected by an oscilloscope or the like, and the encryption energy reflected in the oscilloscope is N encryption energy traces, each of which corresponds to a plaintext. According to the actual sampling frequency set by the oscilloscope, each encryption energy trace has T sampling points.

[0071] As shown in step 2 of the algorithm in Table 1,​​ to represent the set of N encrypted energy traces, where o (1≤o≤T) represents the oth sampling point, and n (1≤n≤N) represents the nth energy trace.

[0072] Step S103, the steps S1031-S1034 are executed in a loop until the overall key of the encryption operation is obtained, wherein the overall key has a bytes:

[0073] Step S1031, a plurality of key hypothesis values of the fth byte in the overall key are generated; wherein 1≤f≤a;

[0074] In this embodiment, only 1 byte of key value is obtained each time, so only 1 byte of key value is generated each time, that is, all possible key hypothesis values of a certain byte are generated in an exhaustive manner.

[0075] For example, for the fth byte in the overall key, since 1 byte is 8 bits, the key hypothesis values generated by exhaustive generation include: 0, 1, 2, …, 255, a total of 256 key hypothesis values.

[0076] As shown in step 3 of the algorithm in Table 1, the plurality of key hypothesis values of a certain byte can be represented by a vector k={k 1 , k 2 , k 3 ,…,k M}, where M represents the size of the vector space. In this embodiment, M=2 8 =256, k={0,1,2,…,255}.

[0077] Step S1032, the part of the energy trace corresponding to the oth sampling point of each of the encrypted energy traces is selected to obtain the energy trace set of the oth sampling point; wherein 1≤o≤T;

[0078] In this embodiment, based on the actual set sampling frequency, the corresponding part of the energy trace is selected at the same sampling point of each encrypted energy trace, so that the energy trace set at the sampling point can be obtained, as shown in Figure 2 . The energy trace set of the oth sampling point is represented by D(o) or .

[0079] That is, any oth sampling point in the N energy traces is selected to obtain the energy trace set D(o) of the oth sampling point.

[0080] Step S1033, based on the plurality of key hypothesis values and the energy trace set of the oth sampling point, the Gini impurity index corresponding to each of the key hypothesis values is calculated;

[0081] In this embodiment, the Gini impurity index corresponding to each key hypothesis value is calculated based on the plurality of key hypothesis values and the energy trace set of the oth sampling point, comprising:

[0082] Step one, using an unsupervised clustering algorithm to cluster the energy trace set of the oth sampling point into X types; wherein X is pre-set;

[0083] Specifically, as shown in Figure 2 The energy trace set D(o) of the oth sampling point is clustered into X types (Type 1-Type X) using the unsupervised clustering k-means method, wherein X is pre-set by the attacker. In this embodiment, the value of X is equal to the number of values V of the intermediate value of the objective function (i.e. the output value of the objective function) in the above-mentioned step 5 of the algorithm. The number of values V of the intermediate value of the objective function is determined by the encryption algorithm. If the output of the selected objective function is 1 byte, i.e. 256 possible values, then V=256. Through this step, the N values in the set D(o) are clustered into X types, and different types can be represented by different colored solid circles.

[0084] Step two, for each key hypothesis value, the following steps are performed:

[0085] Based on the key hypothesis value and the obtained plaintext value set, the energy trace set of the oth sampling point in the X types is divided into V subsets; wherein X=V; based on the V subsets and the X types, the Gini impurity index corresponding to the key hypothesis value is calculated.

[0086] In this embodiment, the above-mentioned dividing the energy trace set of the oth sampling point in the X types into V subsets based on the key hypothesis value and the obtained plaintext value set, comprising:

[0087] Based on the byte position of the key hypothesis value in the overall key, the part of the plaintext at the position corresponding to the byte position in each plaintext is selected to obtain the plaintext value set; based on the key hypothesis value and the plaintext value set, the output value of the objective function is obtained; wherein the objective function is a pre-set non-injective function; based on the output value of the objective function, the energy trace set of the oth sampling point in the X types is divided into V subsets. Wherein, when the encryption operation uses a block cipher algorithm for encryption, the objective function is the output of the S-box.

[0088] Specifically, as shown in step 4 of the algorithm in Table 1, based on the byte position of the current key assumption value within the overall key used in the encryption operation, a portion of the plaintext at the position corresponding to the aforementioned byte position is selected from each plaintext. That is, if the current key assumption value is the f-th byte of the overall key, then the corresponding portion of the plaintext should also be the value of the f-th byte of each random plaintext. The set of plaintext values ​​obtained through selection can be represented as p = {p 1 ,p 2 ,p 3 ,…,p N Let} represent the number of random plaintexts.

[0089] Based on the current key assumption value k j With the above plaintext value p = {p 1 ,p 2 ,p 3 ,…,p N By employing the selected encryption algorithm, the output value v of the objective function can be obtained. i,j (1≤i≤N), as shown in step 5 of the algorithm in Table 1. Based on this objective function, the output value v is... i,j The energy trace set D(o) at the o-th sampling point can be divided into V subsets. For example, the output value v of the objective function can be... i,j Values ​​equal to 0 are grouped into one category, v i,j Those equal to 1 are classified into one category, v i,j Those equal to 2 are grouped into one category, and so on.

[0090] Here, V represents the number of intermediate values ​​of the objective function, i.e., the number of subsets in the above partition, and X = V. For example... Figure 2 As shown in the diagram, each circle in the third step represents a subset D. g (1≤g≤V), the energy trace sampling points contained in each subset come from different clustering types in the second step. Generally, if the current key assumption is the correct key value, then each subset D... g The energy trace samples in the data mostly come from the same cluster type; conversely, the sample types in each subset are more chaotic.

[0091] Finally, based on the subset partitioning and clustering type, the Gini impurity index value Gini_Index(D(o),k) corresponding to the current key assumption and current sampling point is calculated. j Iterate through all key hypothesis values ​​k. j After sampling point o, according to the criteria Obtain the correct key assumption value.

[0092] Specifically, the calculation of the Gini impurity index corresponding to the key hypothesis value based on the V subsets and the X types includes:

[0093] Based on the probability that the energy traces in each of the subsets come from each of the types, a Gini value of each of the subsets is calculated; based on the Gini value of each of the subsets, a Gini impurity index corresponding to the key hypothesis value is calculated.

[0094] In this embodiment, the following expression is used to calculate the Gini value of each of the subsets:

[0095]

[0096] wherein D i is the i-th subset of the V subsets; Gini(D i ) is the Gini value of the i-th subset; m is the type serial number of the X types; Type m is the set of energy traces of the m-th type of the X types; p m is the probability that the energy traces in the i-th subset come from Type m; D(o) is the set of energy traces of the o-th sampling point; and N is the number of the plaintexts.

[0097] In this embodiment, the following expression is used to calculate the Gini impurity index corresponding to the key hypothesis value:

[0098]

[0099] wherein Gini_index(D(o), k j ) is the Gini impurity index corresponding to the key hypothesis value k j ; j is the serial number of the plurality of key hypothesis values; |D i | is the number of energy traces in the i-th subset; and |D(o)| is the number of energy trace sampling points in D(o).

[0100] In step S1034, based on the Gini impurity index, one key hypothesis value is selected from the plurality of key hypothesis values as the key value of the f-th byte of the overall key.

[0101] In this embodiment, the following expression is used to select one key hypothesis value from the plurality of key hypothesis values as the key value of the f-th byte of the overall key:

[0102]

[0103] wherein k f * is the key value of the f-th byte; and k j ,o represents that the Gini impurity index is obtained under the key hypothesis value k j and the o-th sampling point.

[0104] It should be noted that k in the above calculation process j and D(o) is certain, that is, a certain key assumption value currently selected and the energy trace set under a certain sampling point currently selected. In the calculation process, all key assumption values and all sampling points need to be traversed to obtain all Gini impurity indexes, and then the smallest Gini impurity index is found from all Gini impurity indexes. The key assumption value corresponding to the smallest Gini impurity index is the correct key assumption value on the byte.

[0105] It should be noted that only a part of the key used in the encryption operation, that is, a byte of the key value, is obtained through the above steps S1031 to S1034. The above steps are executed in a loop to obtain the overall key of the encryption operation.

[0106] The calculation principle of using the Gini impurity index to obtain the key value is described in detail below:

[0107] First, the definition and formula of the Gini value and the Gini impurity index are given. The Gini value of a data set D reflects the probability that two samples randomly selected from the data set D come from different categories, that is:

[0108]

[0109] Where n represents the number of categories of samples in the data set D, p i represents the probability of occurrence of samples of category i in the data set D. It can be seen that the smaller the Gini value of the data set D, the higher the purity of the samples in the data set D.

[0110] The Gini impurity index is used to judge the quality of classification. For a data set D, if a certain attribute k is used to divide it, and the Gini impurity index of the data set D under the attribute k can be obtained:

[0111]

[0112] Where D v represents a certain subset of the data set D divided according to the attribute k, V represents the total number of subsets divided, |D v | and |D| represent the total number of samples in the data subset and the data set, respectively. Considering that the number of samples in different subsets is different, the Gini value of each subset is given a weight This means that the data subset with more samples has a greater impact on the division effect. The attribute that can produce the smallest Gini impurity index is the optimal division attribute of the data set D, that is:

[0113]

[0114] For example Figure 2As shown, each subset has samples from different types, and to obtain the final Gini impurity index value, the Gini value of each subset D i (1≤i≤V) is calculated, that is:

[0115]

[0116] where p m represents the probability that the sample in the subset D i comes from the type Type m. The value of p m can be estimated as: where, D(o) can also be represented. After calculating the Gini value of all subsets, the Gini impurity index under a certain key hypothesis and energy trace sampling point can be obtained:

[0117]

[0118] The smallest Gini impurity index corresponds to the optimal partition attribute, which can also be converted to the largest 1-Gini_index, which corresponds to the optimal partition attribute, that is:

[0119]

[0120] Thus, the optimal key hypothesis value and the optimal sampling point position can be obtained.

[0121] It should be noted that the selection of the objective function in the embodiment must be a non-injective function, otherwise all key hypothesis values will produce the same partition result, that is, the same Gini impurity index value.

[0122] The side channel energy analysis method provided by the embodiment of the application performs a preset encryption operation on a plurality of randomly selected plaintexts, and collects an encryption energy trace corresponding to each plaintext generated in the encryption operation process; based on a plurality of key hypothesis values and an energy trace set of an oth sampling point in each encryption energy trace, a Gini impurity index corresponding to each key hypothesis value is calculated, and based on the Gini impurity index, a key hypothesis value is selected from the plurality of key hypothesis values as a key value of a certain byte in an overall key of the encryption operation. It can be seen that the Gini impurity index in decision classification is introduced into the side channel energy analysis, and a suitable key hypothesis value is selected based on the Gini impurity index. Compared with the prior art, the application only needs to obtain the encryption energy trace, and there is no strict restriction and requirement on the attacker, that is, the dependence on the attack device and the energy model can be reduced, so that the attacker does not need to master a device similar to the attacked device and does not need to have a perfect estimation and requirement on the power consumption leakage model. The method increases the universality of the side channel energy analysis while producing smaller additional calculation overhead.

[0123] In addition, the embodiment introduces an unsupervised learning method into the side channel energy analysis technology, and energy information can be more fully utilized. Practice shows that the application has good attack effect in any simple or complex energy leakage situation and under different assumed leakage models.

[0124] Example Two

[0125] Corresponding to the method embodiments, the application also provides a side channel energy analysis device, as shown in the accompanying drawings, the device comprises: Figure 3

[0126] An encryption unit 201 is configured to perform a preset encryption operation on a plurality of plaintexts selected randomly;

[0127] An acquisition unit 202 is configured to acquire an encryption energy trace corresponding to each plaintext generated in the encryption operation process; wherein each encryption energy trace has T sampling points;

[0128] A key acquisition unit 203 is configured to perform the following steps in a loop until the overall key of the encryption operation is acquired, wherein the overall key has a bytes:

[0129] A plurality of key hypothesis values of the fth byte in the overall key are generated; wherein 1≤f≤a;

[0130] A part of the energy trace corresponding to the oth sampling point of each encryption energy trace is selected to obtain an energy trace set of the oth sampling point; wherein 1≤o≤T;

[0131] Based on the plurality of key hypothesis values and the energy trace set of the oth sampling point, a Gini impurity index corresponding to each key hypothesis value is calculated;

[0132] Based on the Gini impurity index, one key hypothesis value is selected from the plurality of key hypothesis values as the key value of the fth byte in the overall key.

[0133] In the embodiment, based on the plurality of key hypothesis values and the energy trace set of the oth sampling point, a Gini impurity index corresponding to each key hypothesis value is calculated, which comprises:

[0134] The energy trace set of the oth sampling point is clustered into X types by using an unsupervised clustering algorithm; wherein X is pre-set;

[0135] For each key hypothesis value, the following steps are performed:

[0136] ​Based on the key hypothesis value and the obtained plaintext value set, the energy trace set of the oth sampling point in the X types is divided into V subsets; wherein, X=V;

[0137] Based on the V subsets and the X types, the Gini impurity index corresponding to the key hypothesis value is calculated.

[0138] In the embodiment, based on the key hypothesis value and the obtained plaintext value set, the energy trace set of the oth sampling point in the X types is divided into V subsets, comprising:

[0139] Based on the byte position of the key hypothesis value in the whole key, the part of plaintext in each plaintext corresponding to the position of the byte position is selected to obtain the plaintext value set;

[0140] Based on the key hypothesis value and the plaintext value set, the output value of the objective function is obtained; wherein, the objective function is a pre-set non-injective function;

[0141] Based on the output value of the objective function, the energy trace set of the oth sampling point in the X types is divided into V subsets.

[0142] In the embodiment, when the encryption operation adopts a block cipher algorithm for encryption, the objective function is the output of the S-box.

[0143] In the embodiment, based on the V subsets and the X types, the Gini impurity index corresponding to the key hypothesis value is calculated, comprising:

[0144] Based on the probability that the energy trace in each subset comes from each type, the Gini value of each subset is calculated;

[0145] Based on the Gini value of each subset, the Gini impurity index corresponding to the key hypothesis value is calculated.

[0146] In the embodiment, the Gini value of each subset is calculated by using the following expression:

[0147]

[0148] Wherein, D i is the ith subset in the V subsets; Gini(D i ) is the Gini value of the ith subset; m is the type serial number of the X types; Type m is the energy trace set of the mth type in the X types; p m is the probability that the energy trace in the ith subset comes from Type m; D(o) is the energy trace set of the oth sampling point; N is the number of plaintexts;

[0149] In this embodiment, the Gini impurity index corresponding to the key hypothesis value is calculated by using the following expression:

[0150]

[0151] Gini_index(D(o),k j ) is the Gini impurity index corresponding to the key hypothesis value k j ; j is the serial number of the plurality of key hypothesis values; |D i | is the number of energy traces in the i-th subset; |D(o)| is the number of energy trace sampling points in D(o).

[0152] In this embodiment, the Gini impurity index is used to select a key hypothesis value from the plurality of key hypothesis values as the key value of the f-th byte of the overall key, including:

[0153] The following expression is used to select a key hypothesis value from the plurality of key hypothesis values as the key value of the f-th byte of the overall key:

[0154]

[0155] Gini_index(D(o),k f * f is the key value of the f-th byte; k j ,o represents the Gini impurity index obtained under the key hypothesis value k j and the o-th sampling point.

[0156] The working principle, working process, and other contents related to the specific embodiments of the above device can be referred to the specific embodiments of the side channel energy analysis method provided by the present application, and the same technical content will not be described in detail here.

[0157] Example Three

[0158] According to the embodiments of the present application, a storage medium is also provided, and the storage medium stores program codes. When the program codes are executed by a processor, the side channel energy analysis method according to any one of the above embodiments is implemented.

[0159] The specific content of the method can be referred to the specific embodiments of the side channel energy analysis method provided by the present application, and the same technical content will not be described in detail here.

[0160] Example Four

[0161] According to an embodiment of the present application, an electronic device is also provided, which includes a memory and a processor, wherein the memory stores program codes executable on the processor, and the program codes, when executed by the processor, implement the side channel energy analysis method according to any one of the above embodiments.

[0162] The specific content of the method can be referred to the specific embodiments of the side channel energy analysis method provided by the present application, and the same technical content will not be described in detail here.

[0163] The side channel energy analysis method, device, storage medium and electronic device provided by the embodiments of the present application can perform a preset encryption operation on a plurality of randomly selected plaintexts, and collect an encryption energy trace corresponding to each plaintext generated in the encryption operation process; based on a plurality of key hypothesis values and an energy trace set of an oth sampling point in each encryption energy trace, a Gini impurity index corresponding to each key hypothesis value is calculated, and based on the Gini impurity index, a key hypothesis value is selected from the plurality of key hypothesis values as a key value of a certain byte in an overall key of the encryption operation. It can be seen that the Gini impurity index in decision classification is introduced into the side channel energy analysis, and the appropriate key hypothesis value is selected based on the Gini impurity index. Compared with the prior art, the present application only needs to obtain the encryption energy trace, and there is no strict restriction and requirement on the attacker, that is, the dependence on the attack device and the energy model can be reduced, thereby having high universality and small calculation overhead. Practice shows that the present application has good attack effect under different assumed leakage models in any simple or complex energy leakage situation.

[0164] The embodiments of the present application can be used to analyze and evaluate the security of the implementation of the cryptographic algorithm. The Gini impurity index is used in the decision tree classification in the prior art, and is used to judge the quality of classification. The Gini impurity index in decision classification is used in the side channel energy analysis for the first time, and the Gini impurity index is used as a discriminator of energy analysis. The technical solution provided by the present application can make full use of the available energy information (i.e. energy trace), improve the information utilization degree in the side channel energy analysis, and has no strict restriction and requirement on the attacker.

[0165] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed.

[0166] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e., may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment of the present application.

[0167] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0168] If the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for making an electronic device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.

[0169] Although the disclosed embodiments of the present application are as above, the content described is only for the purpose of facilitating understanding of the embodiments adopted by the present application, and is not intended to limit the present application. Any person skilled in the art of the present application can make any modification and change in the form and details without departing from the spirit and scope of the present application, but the protection scope of the present application shall be subject to the scope defined by the appended claims.

Claims

1. A side-channel energy analysis method, characterized in that, The method includes: Perform preset encryption operations on multiple randomly selected plaintext messages; Collect the encrypted energy traces corresponding to each plaintext generated during the encryption operation; wherein each encrypted energy trace has T sampling points; The following steps are repeated until the overall key for the encryption operation is obtained, wherein the overall key has a bytes: Generate multiple key assumption values ​​for the f-th byte in the overall key; where 1 ≤ f ≤ a; Select a portion of the energy trace corresponding to the o-th sampling point of each encrypted energy trace to obtain the energy trace set of the o-th sampling point; where 1≤o≤T; Based on the multiple key hypothesis values ​​and the energy trace set of the o-th sampling point, the Gini impurity index corresponding to each key hypothesis value is calculated; Based on the Gini impurity index, one key hypothesis value is selected from the plurality of key hypothesis values ​​as the key value of the f-th byte in the overall key; The calculation of the Gini impurity index corresponding to each key hypothesis value based on the plurality of key hypothesis values ​​and the energy trace set of the o-th sampling point includes: An unsupervised clustering algorithm is used to cluster the energy trace set of the o-th sampling point into X types; where X is predetermined. For each of the stated key assumption values, perform the following steps: Based on the key hypothesis and the obtained set of plaintext values, the energy trace set of the o-th sampling point in the X types is divided into V subsets; where X = V; Based on the V subsets and the X types, calculate the Gini impurity index corresponding to the key hypothesis value; The calculation of the Gini impurity index corresponding to the key hypothesis value based on the V subsets and the X types includes: The Gini value for each subset is calculated based on the probability that the energy trace in each subset originates from each type; Based on the Gini value of each subset, calculate the Gini impurity index corresponding to the key hypothesis value; the Gini value of each subset is calculated using the following expression: Among them, D i Gini(D) is the i-th subset of the V subsets. i ) represents the Gini value of the i-th subset; m represents the type index of the X types; Type m represents the energy trace set of the m-th type among the X types; p m Let be the probability that the energy trace in the i-th subset comes from Type m; D(o) be the set of energy traces at the o-th sampling point; and N be the number of plaintexts. The Gini impurity index corresponding to the key hypothesis value is calculated using the following expression: Wherein, Gini_index(D(o),k j ) is related to the key hypothesis value k j The corresponding Gini impurity index; j is the index of the plurality of key hypothesis values; |D i | represents the number of energy traces in the i-th subset; |D(o)| represents the number of energy trace sampling points in D(o); The step of selecting a key hypothesis value from the plurality of key hypothesis values ​​as the key value of the f-th byte in the overall key based on the Gini impurity index includes: The following expression is used to select one key hypothesis value from the plurality of key hypothesis values ​​as the key value of the f-th byte in the overall key: Where, k f * k is the key value of the f-th byte; j ,o represents the key hypothesis value k j The Gini impurity index is obtained at the o-th sampling point.

2. The side-channel energy analysis method according to claim 1, characterized in that, Based on the key hypothesis and the obtained set of plaintext values, the energy trace set of the o-th sampling point in the X types is divided into V subsets, including: Based on the byte position of the assumed key value in the overall key, a portion of the plaintext at the position corresponding to the byte position in each plaintext is selected to obtain the set of plaintext values; Based on the key hypothesis and the set of plaintext values, the output value of the target function is obtained; wherein, the target function is a pre-set non-injective function, and the target function is any function in the attacking cryptographic algorithm, determined by the attacker; Based on the output value of the objective function, the energy trace set of the o-th sampling point in the X types is divided into V subsets.

3. The side-channel energy analysis method according to claim 2, characterized in that, When the encryption operation uses a block cipher algorithm, the objective function is the output of the S-box.

4. A side-channel energy analysis device, characterized in that, The device includes: The encryption unit is used to perform preset encryption operations on multiple randomly selected plaintexts respectively; The acquisition unit is used to acquire the encrypted energy traces corresponding to each plaintext generated during the encryption operation; wherein each encrypted energy trace has T sampling points; A key acquisition unit is configured to repeatedly execute the following steps until the overall key for the encryption operation is obtained, wherein the overall key has a bytes: Generate multiple key assumption values ​​for the f-th byte in the overall key; where 1 ≤ f ≤ a; Select a portion of the energy trace corresponding to the o-th sampling point of each encrypted energy trace to obtain the energy trace set of the o-th sampling point; where 1≤o≤T; Based on the multiple key hypothesis values ​​and the energy trace set of the o-th sampling point, the Gini impurity index corresponding to each key hypothesis value is calculated; Based on the Gini impurity index, one key hypothesis value is selected from the plurality of key hypothesis values ​​as the key value of the f-th byte in the overall key; The key acquisition unit is used for: An unsupervised clustering algorithm is used to cluster the energy trace set of the o-th sampling point into X types; where X is predetermined. For each of the stated key assumption values, perform the following steps: Based on the key hypothesis and the obtained set of plaintext values, the energy trace set of the o-th sampling point in the X types is divided into V subsets; where X = V; Based on the V subsets and the X types, calculate the Gini impurity index corresponding to the key hypothesis value; The key acquisition unit is also used for: The Gini value for each subset is calculated based on the probability that the energy trace in each subset originates from each type; Based on the Gini value of each subset, calculate the Gini impurity index corresponding to the key hypothesis value; the Gini value of each subset is calculated using the following expression: Among them, D i Gini(D) is the i-th subset of the V subsets. i ) represents the Gini value of the i-th subset; m represents the type index of the X types; Type m represents the energy trace set of the m-th type among the X types; p m Let be the probability that the energy trace in the i-th subset comes from Type m; D(o) be the set of energy traces at the o-th sampling point; and N be the number of plaintexts. The Gini impurity index corresponding to the key hypothesis value is calculated using the following expression: Wherein, Gini_index(D(o),k j ) is related to the key hypothesis value k j The corresponding Gini impurity index; j is the index of the plurality of key hypothesis values; |D i | represents the number of energy traces in the i-th subset; |D(o)| represents the number of energy trace sampling points in D(o); The key acquisition unit is also used for: The following expression is used to select one key hypothesis value from the plurality of key hypothesis values ​​as the key value of the f-th byte in the overall key: Where, k f * k is the key value of the f-th byte; j ,o represents the key hypothesis value k j The Gini impurity index is obtained at the o-th sampling point.

5. A storage medium storing program code, characterized in that, When the program code is executed by the processor, it implements the side-channel energy analysis method as described in any one of claims 1 to 3.

6. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores program code that can run on the processor. When the program code is executed by the processor, it implements the side-channel energy analysis method as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Second order side channel energy analysis method for SM4 cipher algorithm

    CN103825722A

  • A side channel template attack method based on decision tree

    CN109257160A