A method and device for analyzing chosen plaintext persistence faults of block ciphers
By introducing select plaintext assisted analysis in PFA, the problem of PFA requiring a large number of fault ciphertexts and fault injection locations and value identification difficulty is solved, and more efficient key recovery and fault locations and value recovery are achieved, improving the practicality of packet password persistent fault attacks.
Patent Information
- Application Number
- CN202210728749.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-24
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-06-24
AI Technical Summary
PFA requires a large number of fault ciphertexts in packet cipher fault analysis, and it is difficult to identify fault injection locations and values, and it is difficult to recover keys in multiple fault situations.
Selected plaintext is used for auxiliary analysis. By constructing a selected plaintext with the same size as the S box of the packet cipher, all possible failure situations are analyzed, and the S box cannot output value set is obtained, and the number of ciphertexts is reduced by adding random plaintext, and the key cannot be excluded to restore the master key.
Improves the practicality of persistent fault attacks, reduces the number of ciphertexts required, and can recover keys, fault locations and fault values in multiple fault situations. It is suitable for packet password persistent fault attacks in various scenarios.
Smart Images

Figure CN115001656B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of communication and information security technology, and in particular relates to a method and device for analyzing selected plaintext persistence faults of block ciphers. Background Art
[0002] Block ciphers are an important part of modern cryptography and are also the most widely used and influential cryptographic system. Their main task is to provide data confidentiality, and they are also commonly used in the construction of random numbers, sequence ciphers, hash functions, etc. Currently, the widely used common cryptographic algorithms such as Advanced Encryption Standard (AES) and PRESENT have extremely high theoretical security performance, and traditional cryptographic analysis methods are unlikely to pose a substantial threat to these algorithms.
[0003] For block ciphers, fault attack is an effective attack method. Fault attack is an implementation-based attack method, which includes two stages: fault injection and fault analysis. When the execution of the cryptographic algorithm is accidentally or maliciously interfered with and deviates from its normal process, attackers and analysts can obtain secret information hidden inside the device based on the resulting fault information. In the fault injection stage, the attacker needs to interfere with the operation of the cryptographic device and make it go wrong. Common fault injection methods include electromagnetic, laser, voltage, and clock glitches. In the fault analysis stage, the attacker analyzes the output of the faulty cryptographic device to infer sensitive information in the cryptographic system.
[0004] Common fault analysis methods include DFA (Differential Fault Analysis), AFA (Algebraic Fault Analysis), SFA (Statistical Fault Analysis), etc. When the fault existence time is classified, it can be divided into transient faults, permanent faults, and persistent faults, etc. Among them, most traditional fault attack methods are aimed at transient faults.
[0005] At CHES 2018, Zhang Fan et al. proposed PFA (Persistent Fault Analysis), which applies persistent faults to fault analysis methods. A persistent fault is a fault that is injected into a cryptographic device and persists unless the device is restarted. PFA injects a persistent fault into the S-box of the block cipher, causing an element in the S-box to change, resulting in the S-box output distribution becoming uneven. v and u represent the original value and the changed value of the faulty S-box position, respectively, and they are related Where f represents the fault differential value. Assume that the last round of the cryptographic algorithm is the output of the S-box and the key K R After XOR, we get the faulty ciphertext C.
[0006] Since the S-box is injected with a fault, an output v of the S-box output S[x] will no longer appear, that is, S[x]≠v. When the key K remains unchanged, when enough ciphertexts C are collected, The size of the key search space is reduced to one, which is the actual key value.
[0007] In the process of implementing the present invention, the inventors found that PFA, as a new method for fault analysis of block ciphers, still has the following disadvantages:
[0008] PFA requires a large number of faulty ciphertexts, which is less practical in actual attack scenarios; it is difficult to identify the PFA fault injection location and fault value; when the number of injected faults is greater than one, it is difficult to find the value that no longer appears in the S-box, and it is impossible to use PFA to solve the key. Summary of the invention
[0009] The purpose of the embodiments of the present application is to provide a method and device for selected plaintext persistent fault analysis of block ciphers, so as to solve the technical problems existing in the related art that PFA requires a large number of fault ciphertexts, it is difficult to identify the PFA fault injection position and fault value, and it is difficult to recover the key when the number of injected faults is greater than one.
[0010] According to a first aspect of an embodiment of the present application, a method for analyzing a persistent fault of a selected plaintext of a block cipher is provided, comprising:
[0011] Perform fault injection on the block cipher to obtain the target cipher containing the fault;
[0012] Constructing a number of selected plaintexts equal to the size of the S-box of the block cipher, and inputting the selected plaintexts into the target cipher to obtain a first faulty ciphertext;
[0013] Analyze all possible fault conditions according to the first fault ciphertext and the selected plaintext and obtain a corresponding set of impossible output values of the S-box;
[0014] According to the number of faults corresponding to all possible fault conditions and the target password, a specific number of random plaintexts are added, and the random plaintexts are input into the target password to obtain a second fault ciphertext;
[0015] For each possible fault condition and the corresponding impossible output value set of the S-box, impossible key values are eliminated according to the first fault ciphertext and the second fault ciphertext to obtain an encrypted master key.
[0016] Furthermore, faults are injected into the block cipher to obtain a target cipher containing faults, including:
[0017] Choose a block cipher as a target;
[0018] The fault injection technology is used to inject faults into the block cipher to obtain a target cipher containing faults.
[0019] Further, constructing a number of selected plaintexts that is the same as the size of the S-box of the block cipher, inputting the selected plaintexts into the target cipher, and obtaining a first faulty ciphertext, including:
[0020] According to the size of the S-box of the block cipher, the same number of selected plaintexts are constructed, wherein the selected plaintexts have the same elements except for the different values of the θth elements;
[0021] The selected plaintext is input into the target password, and the selected plaintext is encrypted by the target password when a fault is contained, so as to obtain a first fault ciphertext.
[0022] Further, according to the first fault ciphertext and the selected plaintext, all possible fault conditions are analyzed and a corresponding set of impossible output values of the S-box is obtained, including:
[0023] Find ciphertexts with equal values in the first fault ciphertexts, and construct several θ-element sets according to the θ-th elements in the selected plaintexts corresponding to the ciphertexts with equal values;
[0024] Calculating a set of fault locations according to the set of θ elements, wherein the number of the sets of fault locations is equal to the number of the sets of θ elements;
[0025] According to the fault location set, the same number of S-box original value sets are calculated;
[0026] For each of the S-box original value sets, one element is excluded and the remaining elements are placed in the S-box impossible output value set, thereby obtaining several S-box impossible output value sets according to the value of the θth element of the master key.
[0027] Further, according to the number of faults corresponding to all possible fault conditions and the target password, a specific number of random plaintexts are added, and the random plaintexts are input into the target password to obtain a second fault ciphertext, including:
[0028] Calculate the number of random plaintexts that need to be added based on the number of failures corresponding to all possible failure situations and the target password;
[0029] Constructing random plaintexts of the random plaintext quantity, inputting the random plaintexts into the target password, and obtaining a second fault ciphertext;
[0030] The formula for calculating the number of random plaintexts that need to be added is as follows:
[0031]
[0032] Where n f represents the number of faults, represents the bit length of the elements in the faulty ciphertext C, and r is the iteration variable.
[0033] Furthermore, for each possible fault condition and the corresponding impossible output value set of the S-box, impossible key values are eliminated according to the first fault ciphertext and the second fault ciphertext to obtain the encryption master key, including:
[0034] For each candidate value k θ ,have The candidate S-box cannot output the set of values For each set The last round key K is calculated using the following formula: R Eliminate impossible values to obtain the last round key, and then perform inverse key expansion to obtain the final encryption master key:
[0035]
[0036] Among them, n f Represents the number of faults, and the fault ciphertext C has a total of m elements.
[0037] According to a second aspect of an embodiment of the present application, a device for analyzing selected plaintext persistence faults of a block cipher is provided, comprising:
[0038] A fault injection module is used to inject faults into the block cipher to obtain a target cipher containing faults;
[0039] A construction module, configured to construct a number of selected plaintexts that is the same as the size of the S-box of the block cipher, and input the selected plaintexts into the target cipher to obtain a first faulty ciphertext;
[0040] An analysis module, configured to analyze all possible fault conditions and obtain a corresponding set of impossible output values of the S-box according to the first fault ciphertext and the selected plaintext;
[0041] An adding module, configured to add a specific number of random plaintexts according to the number of faults corresponding to all possible fault conditions and the target password, and input the random plaintexts into the target password to obtain a second fault ciphertext;
[0042] The exclusion module is used to exclude impossible key values according to the first fault ciphertext and the second fault ciphertext for each possible fault situation and the corresponding impossible output value set of the S box, so as to obtain the encryption master key.
[0043] According to a third aspect of an embodiment of the present application, there is provided an electronic device, including:
[0044] one or more processors;
[0045] A memory for storing one or more programs;
[0046] When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in the first aspect.
[0047] According to a fourth aspect of an embodiment of the present application, a computer-readable storage medium is provided, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method described in the first aspect are implemented.
[0048] The technical solution provided by the embodiments of the present application may have the following beneficial effects:
[0049] As can be seen from the above embodiments, the present application introduces selected plaintext for auxiliary analysis. Compared with the traditional PFA, the introduction of selected plaintext can use the fault ciphertext and the selected plaintext to directly obtain the number of injected faults and the location of fault injection, which solves the problem that the original PFA is difficult to identify specific faults in practice, thereby improving the practicality of persistent fault attacks; in the case of multiple faults, each fault ciphertext can exclude n f The impossible value of the key can greatly reduce the number of ciphertexts required compared to traditional PFA; while recovering the master key, it also recovers the fault location and fault value. This application uses a method that combines PFA with chosen plaintext, has no restrictions on the platform and target algorithm, and is suitable for persistent fault attacks on block ciphers in various scenarios.
[0050] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0052] Figure 1 The invention is a flowchart showing a method for analyzing chosen plaintext persistence faults of a block cipher according to an exemplary embodiment.
[0053] Figure 2 is a flowchart of step S11 according to an exemplary embodiment.
[0054] Figure 3 is a flowchart of step S12 according to an exemplary embodiment.
[0055] Figure 4 is a flowchart of step S13 according to an exemplary embodiment.
[0056] Figure 5 is a flowchart of step S14 according to an exemplary embodiment.
[0057] Figure 6 The invention is a block diagram showing a device for analyzing chosen plaintext persistence faults of a block cipher according to an exemplary embodiment. DETAILED DESCRIPTION
[0058] Here, exemplary embodiments are described in detail, and examples thereof are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application.
[0059] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms of "a", "said" and "the" used in this application and the appended claims are also intended to include plural forms unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0060] It should be understood that although the terms first, second, third, etc. may be used in the present application to describe various information, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0061] Figure 1 is a flow chart of a method for analyzing a persistent fault of a block cipher using chosen plaintext according to an exemplary embodiment. Figure 1 As shown, the method may include the following steps:
[0062] Step S11: inject faults into the block cipher to obtain a target cipher containing faults;
[0063] Step S12: constructing selected plaintexts of the same number as the size of the S-box of the block cipher, inputting the selected plaintexts into the target cipher to obtain a first faulty ciphertext;
[0064] Step S13: Analyze all possible fault conditions according to the first fault ciphertext and the selected plaintext and obtain a corresponding set of impossible output values of the S-box;
[0065] Step S14: according to the number of faults corresponding to all possible fault conditions and the target password, a specific number of random plaintexts are added, and the random plaintexts are input into the target password to obtain a second fault ciphertext;
[0066] Step S15: For each possible fault condition and the corresponding impossible output value set of the S-box, impossible key values are eliminated according to the first fault ciphertext and the second fault ciphertext to obtain the encryption master key.
[0067] As can be seen from the above embodiments, the present application introduces selected plaintext for auxiliary analysis. Compared with the traditional PFA, the introduction of selected plaintext can use the fault ciphertext and the selected plaintext to directly obtain the number of injected faults and the location of fault injection, which solves the problem that the original PFA is difficult to identify specific faults in practice, thereby improving the practicality of persistent fault attacks; in the case of multiple faults, each fault ciphertext can exclude n f The impossible value of the key can greatly reduce the number of ciphertexts required compared to traditional PFA; while recovering the master key, it also recovers the fault location and fault value. This application uses a method that combines PFA with chosen plaintext, has no restrictions on the platform and target algorithm, and is suitable for persistent fault attacks on block ciphers in various scenarios.
[0068] Specifically, the method can use the selected plaintext and the first fault ciphertext to calculate the number of faults, candidate values of the fault positions and candidate values of the fault values when the number of faults, the fault positions and the fault values are unknown. When the number of faults is known, the total number of ciphertexts required to obtain the key for the number of faults is calculated, and the number of second fault ciphertexts can be calculated by subtracting the total number of ciphertexts from the number of first fault ciphertexts. For each candidate value of the fault position and fault value, the total fault ciphertext is used to eliminate impossible key values. If the remaining space of the key is reduced to 0, it proves that the candidate value is wrong. When the key space is reduced to 1, it proves that the key is the correct key, and the corresponding fault position and fault value are also the correct fault conditions.
[0069] In the specific implementation of step S11, a fault is injected into the block cipher to obtain a target cipher containing a fault;
[0070] Specifically, Figure 2 As shown, this step may include the following sub-steps:
[0071] Step S21: Select a block cipher as a target;
[0072] Step S22: Use the fault injection technology to perform fault injection on the block cipher to obtain a target cipher containing faults.
[0073] In the specific implementation of step S21-step S22, the fault includes the fault number n f , fault location l and fault value f, we can select a software or hardware containing the target block cipher and use RowHammer or other fault injection techniques to inject random faults into the target cipher, where the number of faults is n f . So that the n of S box f An element fails, assuming the original value of the i-th failure is v i , the fault value after the fault is injected is u i ,in
[0074] In the specific implementation of step S12, a number of selected plaintexts equal to the size of the S-box of the block cipher is constructed, and the selected plaintexts are input into the target cipher to obtain a first faulty ciphertext;
[0075] Specifically, Figure 3 As shown, this step may include the following sub-steps:
[0076] Step S31: constructing the same number of selected plaintexts according to the size of the S-box of the block cipher, wherein the selected plaintexts are identical in elements except for the different values of the θth elements;
[0077] Specifically, assuming that the size of the S-box of the target cipher is n×n, construct n×n special selected plaintexts, which are the same except for the θth element, and the θth elements are: 0, 1, ..., 2 w -1(2 w =n×n). Since the first round key K remains unchanged during the encryption process, the θth element of the selected plaintext after XOR with the first round round key can also be n×n mutually unequal values (0, 1, ..., 2 w -1). In this way, when accessing the faulty S-box, every position of the faulty S-box can be accessed.
[0078] Step S32: input the selected plaintext into the target password, and encrypt the selected plaintext by using the target password when a fault is present, to obtain a first fault ciphertext.
[0079] Specifically, the selected plaintext is input into the target cipher containing the fault, the target cipher encrypts the selected plaintext under a fixed key, and outputs the same number of first fault ciphertexts C. The first fault ciphertext C is collected, and the first fault ciphertext C contains m elements, each element contains w bits (2 w =n×n).
[0080] In the specific implementation of step S13, according to the first fault ciphertext and the selected plaintext, all possible fault conditions are analyzed and a corresponding set of impossible output values of the S-box is obtained;
[0081] Specifically, Figure 4 As shown, this step may include the following sub-steps:
[0082] Step S41: Find ciphertexts with equal values in the first fault ciphertexts, and construct several θ-element sets according to the θ-th elements in the selected plaintexts corresponding to the ciphertexts with equal values;
[0083] Specifically, using the first faulty ciphertext C1, find the ciphertext with the same value in the faulty ciphertext, and put the θth element in the selected plaintext corresponding to the equal ciphertext into the set In this embodiment, it is assumed that there are n s ciphertext sets, the faulty ciphertexts in each set are equal, and the number of equal ciphertexts in a set is λ i (0≤i<n s ),Right now
[0084] Step S42: Calculating a set of fault locations according to the set of θ elements, wherein the number of the sets of fault locations is equal to the number of the sets of θ elements;
[0085] Specifically, n is obtained according to the first fault ciphertext and the plaintext. s Collections After that, the number of faults can be obtained. and n s The set of fault locations k θ The θth element of the master key. Because the constructed selected plaintext has the same value except for the θth element. Then the θth elements of multiple plaintexts are equal after the first round of faulty S-box transformation, and all subsequent intermediate states and the final ciphertext are also equal. Since there is no such thing as different inputs having the same output in a correct S-box, this situation is caused by a fault, so the location of the fault injection can be inferred by using the θth element of the plaintext corresponding to these equal ciphertexts.
[0086] Step S43: Calculate and obtain the same number of S-box original value sets according to the fault location set;
[0087] Specifically, for each set of fault locations The original value set of the S-box before the failure is The values after the failure are Maybe a collection Any one of them. Since each set The elements in are equal after passing through the faulty S-box, but the set There is also an element that is not affected by the fault. You can choose any one of these positions. Assuming it is a correct S-box element that is not affected by the fault, and the rest are faulty S-box elements, then their outputs after the fault is injected must be the element value of the correct S-box output.
[0088] Step S44: For each of the S-box original value sets, one element is excluded and the remaining elements are placed in the S-box impossible output value set, thereby obtaining several S-box impossible output value sets according to the value of the θth element of the master key.
[0089] Specifically, assuming k θ In the case of known (in fact k θ is unknown), use the above method to obtain the original value set of S box After that, for each set Exclude one of the elements and put the rest into the collection In all sets After completing the same operation, the resulting set It is a candidate for the impossible value output value set of the S-box. θ is unknown, k θ Possible values are 2 w Species (0~2 w -1), each k θ correspond A set of candidate So we can get There is no possible set of output values for a candidate S-box.
[0090] In the specific implementation of step S14, according to the number of faults corresponding to all possible fault conditions and the target password, a specific number of random plaintexts are added, and the random plaintexts are input into the target password to obtain a second fault ciphertext;
[0091] Specifically, Figure 5 As shown, this step may include the following sub-steps:
[0092] Step S51: Calculate the number of random plaintexts that need to be added according to the number of faults corresponding to all possible fault conditions and the target password;
[0093] The formula for calculating the number of random plaintexts that need to be added is as follows:
[0094]
[0095] Where n f represents the number of faults, represents the bit length of the elements in the faulty ciphertext C, and r is the iteration variable. The left side of the minus sign in this formula indicates that when there are n f In the case of a failure, the key space is reduced to the number of required faulty ciphertexts. The part to the right of the minus sign indicates that there are already 2 w The faulty ciphertext is constructed by w Subtracting them is the number of additional faulty ciphertexts that need to be added.
[0096] Step S52: constructing random plaintexts of the random plaintext quantity, inputting the random plaintexts into the target password, and obtaining a second fault ciphertext;
[0097] Specifically, the specific implementation of step S52 is the same as the specific implementation of step S12, which will not be described in detail here.
[0098] In the specific implementation of step S15, for each possible fault condition and the corresponding impossible output value set of the S-box, impossible key values are eliminated according to the first fault ciphertext and the second fault ciphertext to obtain the encrypted master key.
[0099] Specifically, the first faulty ciphertext and the second faulty ciphertext have the same status and use in this step, so they are collectively referred to as faulty ciphertext C. For each candidate value k θ ,have The candidate S-box cannot output the set of values For each set The last round key K is calculated using the following formula: R Eliminate impossible values to obtain the last round key, and then perform inverse key expansion to obtain the final encryption master key:
[0100]
[0101] Among them, n f represents the number of faults, and the faulty ciphertext C has a total of m elements. Because the ciphertext C is the output of the last round of S-boxes XORed with the last round of round key K R However, the S-box will not output the set Then for the ciphertext C the i-th element C i , After transformation, we can get the formula for excluding impossible values of the key
[0102] Corresponding to the aforementioned embodiment of the method for analyzing chosen-plaintext persistent faults of block ciphers, the present application also provides an embodiment of an apparatus for analyzing chosen-plaintext persistent faults of block ciphers.
[0103] Figure 6 1 is a block diagram of a device for analyzing selected plaintext persistence faults of block ciphers according to an exemplary embodiment. Figure 6 , the device may include:
[0104] A fault injection module 21 is used to inject faults into the block cipher to obtain a target cipher containing faults;
[0105] A construction module 22, configured to construct selected plaintexts of the same number as the size of the S-box of the block cipher, and input the selected plaintexts into the target cipher to obtain a first faulty ciphertext;
[0106] An analysis module 23, configured to analyze all possible fault conditions and obtain a corresponding set of impossible output values of the S-box according to the first fault ciphertext and the selected plaintext;
[0107] An adding module 24 is used to add a specific number of random plaintexts according to the number of faults corresponding to all possible fault situations and the target password, and input the random plaintexts into the target password to obtain a second fault ciphertext;
[0108] The elimination module 25 is used to eliminate impossible key values according to the first fault ciphertext and the second fault ciphertext for each possible fault situation and the corresponding impossible output value set of the S box, so as to obtain the encryption master key.
[0109] Regarding the device in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0110] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The device embodiment described above is only schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present application scheme. A person of ordinary skill in the art can understand and implement it without paying any creative work.
[0111] Correspondingly, the present application also provides an electronic device, comprising: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the above-mentioned selected plaintext persistent fault analysis method for block ciphers.
[0112] Accordingly, the present application also provides a computer-readable storage medium on which computer instructions are stored. When the instructions are executed by a processor, the above-mentioned method for analyzing the selected plaintext persistence fault of a block cipher is implemented.
[0113] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the contents disclosed herein. The present application is intended to cover any variations, uses or adaptations of the present application, which follow the general principles of the present application and include common knowledge or customary technical means in the art that are not disclosed in the present application.
[0114] It will be appreciated that the present application is not limited to the exact construction that has been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof.
Claims
1. A method for analyzing chosen plaintext persistence faults of block ciphers, characterized in that: include: Perform fault injection on the block cipher to obtain the target cipher containing the fault; Constructing a number of selected plaintexts equal to the size of the S-box of the block cipher, and inputting the selected plaintexts into the target cipher to obtain a first faulty ciphertext; Analyze all possible fault conditions according to the first fault ciphertext and the selected plaintext and obtain a corresponding set of impossible output values of the S-box; According to the number of faults corresponding to all possible fault conditions and the target password, a specific number of random plaintexts are added, and the random plaintexts are input into the target password to obtain a second fault ciphertext; For each possible fault condition and the corresponding impossible output value set of the S-box, impossible key values are eliminated according to the first fault ciphertext and the second fault ciphertext to obtain an encrypted master key.
2. The method according to claim 1, characterized in that Perform fault injection on the block cipher to obtain the target cipher with faults, including: Choose a block cipher as a target; The fault injection technology is used to inject faults into the block cipher to obtain a target cipher containing faults.
3. The method according to claim 1, characterized in that Constructing selected plaintexts of the same number as the size of the S-box of the block cipher, inputting the selected plaintexts into the target cipher, and obtaining a first faulty ciphertext, comprising: According to the size of the S-box of the block cipher, the same number of selected plaintexts are constructed, wherein the selected plaintexts have the same elements except for the different values of the θth elements; The selected plaintext is input into the target password, and the selected plaintext is encrypted by the target password when a fault is contained, so as to obtain a first fault ciphertext.
4. The method according to claim 1, characterized in that: According to the first fault ciphertext and the selected plaintext, all possible fault conditions are analyzed and a corresponding set of impossible output values of the S-box is obtained, including: Find ciphertexts with equal values in the first fault ciphertexts, and construct several θ-element sets according to the θ-th elements in the selected plaintexts corresponding to the ciphertexts with equal values; Calculating a set of fault locations according to the set of θ elements, wherein the number of the sets of fault locations is equal to the number of the sets of θ elements; According to the fault location set, the same number of S-box original value sets are calculated; For each of the S-box original value sets, one element is excluded and the remaining elements are put into the S-box impossible output value set, thereby obtaining several S-box impossible output value sets according to the value of the θth element of the master key.
5. The method according to claim 4, characterized in that According to the number of faults corresponding to all possible fault conditions and the target password, a specific number of random plaintexts are added, and the random plaintexts are input into the target password to obtain a second fault ciphertext, including: Calculate the number of random plaintexts that need to be added based on the number of failures corresponding to all possible failure situations and the target password; Constructing random plaintexts of the random plaintext quantity, inputting the random plaintexts into the target password, and obtaining a second fault ciphertext; The formula for calculating the number of random plaintexts that need to be added is as follows: where n f represents the number of faults, w represents the bit length of the element in the first faulty ciphertext C, and r is the iteration variable.
6. The method according to claim 4, characterized in that For each possible fault condition and the corresponding impossible output value set of the S-box, impossible key values are eliminated according to the first fault ciphertext and the second fault ciphertext to obtain an encrypted master key, including: For each candidate value k θ ,have The candidate S-box cannot output the set of values For each set The last round key K is calculated using the following formula: R Eliminate impossible values to obtain the last round key, and then perform inverse key expansion to obtain the final encryption master key: Among them, n f Indicates the number of faults. The first fault ciphertext C has a total of m elements, n s is the number of fault location sets.
7. A device for analyzing the persistence of chosen plaintext faults of block ciphers, characterized in that: include: A fault injection module is used to inject faults into the block cipher to obtain a target cipher containing faults; A construction module, configured to construct a number of selected plaintexts that is the same as the size of the S-box of the block cipher, and input the selected plaintexts into the target cipher to obtain a first faulty ciphertext; An analysis module, configured to analyze all possible fault conditions and obtain a corresponding set of impossible output values of the S-box according to the first fault ciphertext and the selected plaintext; An adding module, configured to add a specific number of random plaintexts according to the number of faults corresponding to all possible fault conditions and the target password, and input the random plaintexts into the target password to obtain a second fault ciphertext; The exclusion module is used to exclude impossible key values according to the first fault ciphertext and the second fault ciphertext for each possible fault situation and the corresponding impossible output value set of the S box, so as to obtain the encryption master key.
8. An electronic device, characterized in that: include: one or more processors; A memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the instruction is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Plaintext or ciphertext selection based side channel power analysis attack method on round function output of SM4 cipher algorithm
CN104202145A
Detection and error correction method for persistent fault attack based on SPN structure
CN113886810A