Data processing method, device, electronic device and computer storage medium
By collecting and matching the side channel information in the SM9 bilinear pair operation, the problem of difficulty in attacking the private key in the prior art is solved, and the cracking success rate is improved.
Patent Information
- Application Number
- CN202210761094.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-29
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2042-06-29
AI Technical Summary
There is a lack of effective methods in the prior art to side-channel attacks on the private keys in the bilinear SM9 operation, which makes it difficult to guarantee its security.
By collecting the side channel information leaked by the cryptographic device when performing bilinear pairing operations, selecting the target information, and matching it with the preset information templates of multiple candidate keys, the cracked private key is determined.
The success rate of side channel attacks on SM9 bilinear pair operations is improved, and the private key cracking ability is enhanced.
Smart Images

Figure CN115150056B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of security technology, and in particular to a data processing method, device, electronic device, and computer storage medium. Background Art
[0002] The SM9 identity cryptography algorithm is an identity-based cryptography system (IBC) based on bilinear pairings. It is a standard public-key cryptography algorithm in my country's commercial cryptography industry (the standard is called "GM / T 0044-2016SM9 Identity Cryptography Algorithm"). Identity-based cryptography offers significant advantages over the deployment and management of traditional public key infrastructure. The communicating parties can ensure the security of information exchange without the need for public key exchange or third-party authentication services. This means that the cryptographic algorithm is mathematically provable and secure.
[0003] In 1999, Kocher et al. in the United States proposed the idea of side channel attack, which uses side channel information (such as energy, electromagnetic, error, time, etc.) leaked by cryptographic devices during cryptographic operations to obtain sensitive information of the algorithm (such as keys) through cryptographic and statistical calculations.
[0004] The SM9 identification cryptographic algorithm consists of five parts: general principles, digital signature algorithm, key exchange protocol, key encapsulation mechanism, public key encryption algorithm, and parameter definitions. Algorithms involving private keys are particularly vulnerable to side-channel attacks, such as the digital signature algorithm, key exchange protocol, key encapsulation mechanism, and public key encryption algorithm.
[0005] In the existing technology, the side channel attack of SM9 identification cryptographic algorithm mainly focuses on the signature generation algorithm, through the dot multiplication [l]ds A During the calculation process, SPA attacks, template attacks, fault injection attacks, etc. can all be successfully attacked.
[0006] However, the existing technology has not proposed a method for side channel attack on the private key of SM9 bilinear pairing operation. One reason is that the digital signature generation algorithm involves the point multiplication operation of the private key operation [l]ds ASimilar to point multiplication operations on elliptic curves like SM2 and ECC, vulnerabilities are easy to identify and attack, and there's a research foundation. However, bilinear pairing operations are highly complex, involving complex mathematical operations like quadratic, quartic, and dodecaton, significantly reducing the feasibility of attacks. Furthermore, there's no similar research foundation for bilinear pairing operations involving private key operations in key encapsulation mechanisms and public-key encryption algorithms, and the mathematical calculations are even more complex than point multiplication. Existing attack models applicable to point multiplication operations are inappropriate for SM9 bilinear pairing operations, and there's no corresponding attack point.
[0007] Therefore, it is necessary to propose a solution for the SM9 bilinear pairing operation to attack the algorithm instructions involving private keys in the SM9 bilinear pairing operation, thereby improving the protection against side channel attacks on the SM9 bilinear pairing operation. Summary of the Invention
[0008] Embodiments of the present disclosure provide a data processing method, device, electronic device, and computer storage medium.
[0009] In a first aspect, an embodiment of the present disclosure provides a data processing method, which includes:
[0010] Obtaining side channel information collected from a cryptographic device; the side channel information is physical information leaked during a calculation involving a private key to be cracked when the cryptographic device performs a bilinear pairing operation;
[0011] Selecting target information from the side channel information; the target information is the side channel information corresponding to the private key to be cracked during the process of being moved;
[0012] Matching the target information with a plurality of preset information templates corresponding to candidate keys; the preset information templates including reference information corresponding to the candidate keys;
[0013] One of the plurality of candidate keys is determined as the cracked private key based on the matching result.
[0014] Furthermore, side channel information collected from the cryptographic device is obtained, including:
[0015] In response to a start triggering event of a computing process in which the private key to be cracked participates, energy consumption information of the cryptographic device is collected.
[0016] Furthermore, selecting target information from the side channel information includes:
[0017] Get a predetermined target timeframe;
[0018] Part of the side channel information whose collection time is within the target time range is determined as target information.
[0019] Furthermore, the reference information corresponding to the candidate key includes: for the candidate key and a plurality of different plaintext data, when the sample device performs the bilinear pairing operation, multivariate normal distribution information of physical information leaked by the sample device during the process of moving the candidate key.
[0020] Furthermore, matching the target information with preset information templates corresponding to a plurality of candidate keys includes:
[0021] Calculating a matching probability value between the target information and the multivariate normal distribution information corresponding to the candidate key;
[0022] Determining one of the multiple candidate keys as a cracked private key based on the matching result includes:
[0023] The candidate key with the largest matching probability value is determined as the cracked private key.
[0024] Furthermore, the method further comprises:
[0025] determining a plurality of different candidate keys and a plurality of different plaintext data;
[0026] For each candidate key, obtaining side channel information leaked during a bilinear pairing operation performed on the sample device for each of the different plaintext data and the candidate key participating in the operation;
[0027] Selecting, from the side channel information, sample information when the candidate key is moved during the operation in which the candidate key participates;
[0028] For each candidate key, multivariate normal distribution information is obtained based on the sample information corresponding to the different plaintext data, and the multivariate normal distribution information and the candidate key are stored in correspondence as a preset information template of the candidate key.
[0029] Furthermore, the method further comprises:
[0030] Obtain multiple randomly generated random keys;
[0031] For each random key, side channel information is obtained when a bilinear pairing operation is performed on a sample device for preset plaintext data; the side channel information is physical information leaked by the sample device during the operation in which the random key participates;
[0032] A target time range corresponding to the random key migration process is determined based on a correlation between the side channel information and the random key during the random key migration process.
[0033] Furthermore, the method further comprises:
[0034] Obtain multiple randomly generated random keys;
[0035] For each random key, side channel information and intermediate data are obtained when a bilinear pairing operation is performed on a sample device for preset plaintext data; the side channel information is physical information leaked by the sample device during the operation in which the random key participates, and the intermediate data is intermediate data generated based on the random key during the operation in which the random key participates;
[0036] A target time range corresponding to the random key migration process is determined based on the correlation between the side channel information and the intermediate data during the random key migration process.
[0037] Furthermore, determining a target time range corresponding to the random key migration process based on a correlation between the side channel information and the intermediate data during the random key migration process includes:
[0038] extracting a preset attribute value of the intermediate data;
[0039] determining a correlation curve between the preset attribute value and the side channel information;
[0040] The target time range is determined based on the correlation curve.
[0041] Furthermore, determining the target time range based on the correlation curve includes:
[0042] For the same preset plaintext data, determining the relevant feature point corresponding to the maximum absolute value in the correlation curve corresponding to each random key;
[0043] The target time range is obtained based on the statistics of the relevant feature points.
[0044] In a second aspect, an embodiment of the present disclosure provides a data processing device, comprising:
[0045] A first acquisition module is configured to acquire side channel information collected from a cryptographic device; the side channel information is physical information leaked during a calculation process in which a private key to be cracked participates when the cryptographic device performs a bilinear pairing operation;
[0046] A first selection module is configured to select target information from the side channel information; the target information is the side channel information corresponding to the private key to be cracked during the migration process;
[0047] a matching module configured to match the target information with preset information templates corresponding to a plurality of candidate keys; the preset information templates including reference information corresponding to the candidate keys;
[0048] The first determining module is configured to determine one of the multiple candidate keys as a cracked private key based on the matching result.
[0049] Furthermore, the first acquisition module includes:
[0050] The response submodule is configured to collect energy consumption information of the cryptographic device in response to a start triggering event of a calculation process in which the private key to be cracked participates.
[0051] Furthermore, the first selection module includes:
[0052] A first acquisition submodule is configured to acquire a predetermined target time range;
[0053] The first determining submodule is configured to determine part of the side channel information whose collection time is within the target time range as target information.
[0054] Furthermore, the reference information corresponding to the candidate key includes: for the candidate key and a plurality of different plaintext data, when the sample device performs the bilinear pairing operation, multivariate normal distribution information of physical information leaked by the sample device during the process of moving the candidate key.
[0055] Furthermore, the matching module includes:
[0056] a calculation submodule, configured to calculate a matching probability value between the target information and the multivariate normal distribution information corresponding to the candidate key;
[0057] The first determining module includes:
[0058] The second determining submodule is configured to determine the candidate key with the largest matching probability value as the cracked private key.
[0059] Furthermore, the device further comprises:
[0060] a second determining module, configured to determine a plurality of different candidate keys and a plurality of different plaintext data;
[0061] A second acquisition module is configured to acquire, for each candidate key, side channel information leaked during a bilinear pairing operation performed on the sample device on the different plaintext data and in which the candidate key participates;
[0062] A second selection module is configured to select, from the side channel information, sample information when the candidate key is moved during the operation in which the candidate key participates;
[0063] The statistical module is configured to obtain multivariate normal distribution information for each candidate key based on the sample information corresponding to the different plaintext data, and store the multivariate normal distribution information and the candidate key in correspondence as a preset information template of the candidate key.
[0064] Furthermore, the device further comprises:
[0065] A third acquisition module is configured to obtain a plurality of randomly generated random keys;
[0066] a fourth acquisition module configured to, for each random key, acquire side channel information when a bilinear pairing operation is performed on preset plaintext data on a sample device; the side channel information being physical information leaked by the sample device during the operation in which the random key participates;
[0067] The third determining module is configured to determine a target time range corresponding to the random key migration process based on a correlation between the side channel information and the random key during the random key migration process.
[0068] Furthermore, the device further comprises:
[0069] a fifth acquisition module, configured to acquire a plurality of randomly generated random keys;
[0070] a sixth acquisition module configured to, for each random key, acquire side channel information and intermediate data when a bilinear pairing operation is performed on preset plaintext data on a sample device; the side channel information being physical information leaked by the sample device during the operation in which the random key participates, and the intermediate data being intermediate data generated based on the random key during the operation in which the random key participates;
[0071] The fourth determining module is configured to determine a target time range corresponding to the random key migration process based on a correlation between the side channel information and the intermediate data during the random key migration process.
[0072] Furthermore, the fourth determining module includes:
[0073] an extraction submodule, configured to extract a preset attribute value of the intermediate data;
[0074] a third determining submodule, configured to determine a correlation curve between the preset attribute value and the side channel information;
[0075] The fourth determining submodule is configured to determine the target time range based on the correlation curve.
[0076] Furthermore, the fourth determining submodule includes:
[0077] A fifth determining submodule is configured to determine, for the same preset plaintext data, a relevant feature point corresponding to the maximum absolute value in the correlation curve corresponding to each random key;
[0078] The second statistical submodule is configured to obtain the target time range based on the statistics of the relevant feature points.
[0079] The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the functions.
[0080] In one possible design, the apparatus includes a memory and a processor. The memory is configured to store one or more computer instructions that enable the apparatus to perform the corresponding method, and the processor is configured to execute the computer instructions stored in the memory. The apparatus may also include a communication interface for communicating with other devices or a communication network.
[0081] In a third aspect, an embodiment of the present disclosure provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the method described in any one of the above aspects.
[0082] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium for storing computer instructions used by any of the above-mentioned devices, and when the computer instructions are executed by a processor, they are used to implement the method described in any of the above-mentioned aspects.
[0083] In a fifth aspect, an embodiment of the present disclosure provides a computer program product, which includes computer instructions, and when the computer instructions are executed by a processor, they are used to implement the method described in any of the above aspects.
[0084] In a sixth aspect, an embodiment of the present disclosure provides a chip comprising the device described in any of the above aspects.
[0085] The technical solutions provided by the embodiments of the present disclosure may have the following beneficial effects:
[0086] In the embodiment of the present disclosure, when cracking a private key for a bilinear pairing operation, side channel information leaked during the execution of the bilinear pairing operation by the private key is collected from the cryptographic device. The side channel information can be physical information leaked by the cryptographic device. The target information corresponding to the private key to be cracked during the relocation process is selected from the side channel information, and then the target information is matched with a preset information template corresponding to multiple candidate keys. The preset information template includes reference information corresponding to the candidate key. Based on the matching result, one of the multiple candidate keys is selected as the cracked private key. Through the above embodiment, the present disclosure proposes an attack method for bilinear pairing operations with relatively complex operation processes. The attack method cracks the private key based on the characteristic that the operation process in which the private key participates is prone to leaking information when the private key is initially relocated, thereby improving the success rate of the attack.
[0087] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0088] Other features, objectives and advantages of the present disclosure will become more apparent through the following detailed description of non-limiting embodiments in conjunction with the accompanying drawings. In the accompanying drawings:
[0089] Figure 1 A flowchart showing a data processing method according to an embodiment of the present disclosure;
[0090] Figure 2 A structural block diagram of a data processing device according to an embodiment of the present disclosure is shown;
[0091] Figure 3 A structural block diagram of an electronic device according to an embodiment of the present disclosure is shown;
[0092] Figure 4 It is a structural diagram of a computer system suitable for implementing a data processing method according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0093] Hereinafter, exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings so that those skilled in the art can easily implement them. In addition, for the sake of clarity, parts not related to the description of the exemplary embodiments are omitted in the accompanying drawings.
[0094] In the present disclosure, it should be understood that terms such as "including" or "having" are intended to indicate the presence of features, numbers, steps, behaviors, components, parts, or combinations thereof disclosed in the present specification, and do not exclude the possibility that one or more other features, numbers, steps, behaviors, components, parts, or combinations thereof exist or are added.
[0095] It should also be noted that, in the absence of conflict, the embodiments and features of the embodiments of the present disclosure may be combined with each other. The present disclosure will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0096] Template attack is one of the research areas of side-channel attack. Its attack process includes two stages: the first stage is to establish a template, that is, to characterize the energy consumption of all possible key guesses; the second stage is template matching, that is, to calculate the degree of matching between the leaked information to be attacked and the characterized energy consumption characteristics, so as to obtain the key information.
[0097] Bilinear pairing operations such as SM9 involve private key operations, including key exchange protocols, key encapsulation mechanisms, and public key encryption algorithms. The following uses the decryption algorithm process in the public key encryption algorithm as an example to introduce the operation process of SM9 representing the private key participation operation in the cryptographic algorithm; the input includes the ciphertext C, the identification ID B , encrypted private key B The output includes the plaintext M`; mlen is the length in bits of the ciphertext C = C1||C3||C2, K1_len is the length in bits of the key K1 in the block cipher algorithm, and K2_len is the length in bits of the key K2 in the function MAC(K2,Z). To decrypt C, the algorithm flows as follows:
[0098] A1: Extract the bit string C1 from the ciphertext C and verify whether C1 belongs to G1. The ciphertext C consists of C1, C2, and C3. G1 is an additive cyclic group of order N, and its generator P1 is a base point on the elliptic curve.
[0099] A2: Calculate group G T The element w`=e(C1,de B );
[0100] A3: Calculate by encryption method:
[0101] a) If the method for encrypting plaintext is a stream cipher algorithm based on a key derivation function, then
[0102] 1) Calculate the integer klen = mlen + K2_len, then calculate K` = KDF(C1||w`||ID B ,klen). Let K1` be the leftmost mlen bits of K`, and K2` be the remaining K2_len bits. KDF is the key derivation function;
[0103] 2) Calculate M`=C2⊕K1`.
[0104] b) If the method used to encrypt the plaintext is a block cipher algorithm combined with a key derivation function, then
[0105] 1) Calculate the integer klen = K1_len + K2_len, then calculate K` = KDF(C1||w`||ID B ,klen). Let K1` be the leftmost K1_len bits of K`, and K2` be the remaining K2_len bits.
[0106] 2) Calculate M`=Dec(K1`,C2).
[0107] A4: Calculate u = MAC(K2`, C2), extract the bit string C3 from the ciphertext C, and if u ≠ C3, report an error and exit.
[0108] A5: Output plaintext M`.
[0109] The above decryption algorithm uses the R-ate bilinear pairing on the BN curve. The calculation process is as follows:
[0110] Input: P∈E(F q )[r], a=6t+2; / / The input of point P is ciphertext, and point Q is the private key de B ; E is the BN curve equation; r is the curve order; F q is a finite field containing q elements; E′ is a BN curve defined in 6 twist lines on top; F q The quadratic expansion domain of ; a is an integer; t is the curve parameter.
[0111] Output: R a (Q,P); / / R a is the result of R-ate bilinear pairing operation.
[0112] 1. Set a L-1 =1; / / L is the bit length of a
[0113] 2. T←Q, f←1; / / T is the Jacobian coordinate, Q is the affine coordinate; T is assigned Q, f is assigned 1
[0114] 3. for i = L-2 to 0
[0115] 1)f←f 2 ·l T,T (P),T←2T / / l T,T is the line function doubling point operation; l T,Q Point addition operation for line functions
[0116] 2)if a i =1, then f←f·l T,Q (P),T←T+Q
[0117] 4. Calculate Q1 = π q (Q), / / π q It is a Frobenius map
[0118] 5. Calculation T←T+Q1
[0119] 6. Calculation T←T-Q2;
[0120] 7. / / q is the base domain characteristic of the BN curve
[0121] 8. Output f / / The output f is G T The element w in
[0122] The above calculation process corresponds to the implementation process of step A2 in the decryption algorithm process in the public key encryption algorithm.
[0123] From the implementation process of step A2 above, it can be seen that the bilinear pairing operation involving Q-point data is relatively complex. Selecting the Q-point data movement process before the bilinear pairing operation as the attack point makes it easier to locate the operation range of the Q-point data movement operation through the energy consumption curve characteristics of the side channel, and to establish a template for the Q-point data and implement template matching.
[0124] To this end, embodiments of the present disclosure propose a data processing method for exploiting side-channel attacks to crack private key information in bilinear pairing operations. This method selects the initial data movement process, where the private key participates in the bilinear pairing operation, as the attack point. By locating and analyzing the side-channel energy curve at the attack point, the attack success rate can be increased.
[0125] The details of the embodiments of the present disclosure are described in detail below through specific examples.
[0126] Figure 1 Flowchart showing a data processing method according to an embodiment of the present disclosure. Figure 1 As shown, the data processing method includes the following steps:
[0127] In step S101, side channel information collected from a cryptographic device is obtained; the side channel information is physical information leaked during the operation process in which the private key to be cracked participates when the cryptographic device performs a bilinear pairing operation;
[0128] In step S102, target information is selected from the side channel information; the target information is the side channel information corresponding to the private key to be cracked during the migration process;
[0129] In step S103, the target information is matched with preset information templates corresponding to multiple candidate keys; the preset information templates include reference information corresponding to the candidate keys;
[0130] In step S104, one of the multiple candidate keys is determined as the cracked private key based on the matching result.
[0131] In this embodiment, the data processing method can be executed on a cryptographic device or any device capable of communicating with the cryptographic device. The cryptographic device can perform bilinear pairing operations, such as the bilinear pairing operations in the SM9 identification cryptographic algorithm. In the bilinear pairing operations, the operations involved in the private key include key exchange operations, key decapsulation operations, and decryption operations of the public key encryption algorithm.
[0132] The idea of side channel attack is to use the side channel information leaked by cryptographic devices during the execution of cryptographic operations, such as energy, electromagnetic, error, time and other physical information, and then calculate the side channel information through cryptography and statistics to obtain sensitive information of the algorithm (such as private keys).
[0133] In the embodiment of the present disclosure, a side channel attack concept is adopted for the bilinear pairing operation. When the cryptographic device performs the bilinear pairing operation, the side channel information leaked by the cryptographic device is collected during the operation in which the private key participates, such as energy, electromagnetic, error, time and other physical information, and then the private key is calculated based on the physical information.
[0134] In the existing technology, there are side channel attack methods for the SM9 digital signature algorithm, such as the point multiplication operation S=[l]ds in the SM9 digital signature algorithm. A Conduct template attacks or horizontal attacks. However, the existing technologies are all aimed at side channel attacks on the point multiplication operation of the SM9 digital signature algorithm, and no side channel attacks on the bilinear pairing operation of other algorithms of SM9 (such as the key encapsulation mechanism and the public key encryption algorithm) are proposed. On the one hand, the reason is that the point multiplication operation involving the private key operation in the digital signature generation algorithm [l]ds A Similar to the point multiplication operation of elliptic curves such as SM2 and ECC, it is easy to find vulnerabilities and implement attacks, and there is a research basis; on the other hand, the key encapsulation mechanism and the bilinear pairing operation e(C1, de B ), there is no similar research basis, and the mathematical calculation is more complicated than the dot multiplication operation, making the attack difficult.
[0135] In the data processing method proposed in the embodiment of the present disclosure, for bilinear pairing operations, side channel information leaked during the operation in which the private key is involved is collected by the cryptographic device, and then target information is selected from the side channel information. The target information is the side channel information when the private key is moved from the external interface to the storage area, and then an attack is performed on the side channel information generated when the private key is moved. That is, the embodiment of the present disclosure selects the private key moving process at the initial stage of the bilinear operation as the attack point, which can avoid the complex calculation process of the bilinear pairing operation and improve the success rate of the attack.
[0136] In some embodiments, after obtaining the side channel information collected from the cryptographic device, the target information corresponding to the process of the private key being moved in the initial stage of the operation is selected from the side channel information. The process of the private key being moved can be understood as the process of transferring the private key from the external interface of the cryptographic device or a storage area inside the cryptographic device to another storage area, so the process of the private key being moved can also be understood as the process of the private key being transferred. It is understandable that for security reasons, the private key will be stored on a secure medium. In the process of executing the cryptographic identification algorithm based on the bilinear pairing operation, when the private key is needed, the private key will be moved from the secure medium to an internal storage device such as the memory of the cryptographic device. Therefore, the embodiment of the present disclosure attacks the process of the private key being moved, that is, cracking the private key based on the side channel information corresponding to the process of being moved.
[0137] In some embodiments, preset information templates corresponding to different candidate keys can be pre-established. These preset information templates can include reference information corresponding to the candidate key. This reference information can be side-channel information collected during the migration of the candidate key when performing a bilinear pairing operation on the current candidate key and different plaintexts. In other words, the reference information corresponds to the target information and is both side-channel information corresponding to the candidate key and the private key to be cracked during the migration process when performing the bilinear pairing operation.
[0138] In some embodiments, when constructing a preset information template for a candidate key, the cryptographic device used may have the same hardware environment as the cryptographic device used to crack the current private key, for example, may be a cryptographic device of the same type.
[0139] In some embodiments, a preset information template corresponding to all possible candidate keys can be established, and all possible candidate keys can be enumerated based on bytes. For example, when the cryptographic device writes the key in units of 8 bits, or 1 byte, 256 candidate keys can be enumerated.
[0140] In some embodiments, for each candidate key, all plaintexts can be exhaustively enumerated, and the plaintexts are also exhaustively enumerated in bytes. For example, when a cryptographic device stores plaintext data in units of 8 bits, or 1 byte, 256 types of plaintexts can be exhaustively enumerated. It can be seen in this example that for the same candidate key, reference information can be obtained by statistically calculating the side channel information corresponding to the 256 types of plaintexts; for example, the reference information can be the mean and / or covariance data representation of the side channel information corresponding to the 256 types of plaintexts. It should be noted that, considering the influence of the side channel information collection environment, collecting side channel information for the same plaintext data only once may result in inaccuracy or incomplete information. Therefore, in actual applications, multiple side channel information corresponding to the same plaintext data can be repeatedly used for the same candidate key. That is, for the same candidate key, the final reference information obtained can be far more than 256 types.
[0141] After obtaining target information for the current private key to be cracked, the target information can be matched with reference information of multiple candidate keys, and the most matching candidate key can be determined as the cracked private key based on the matching result.
[0142] In the embodiment of the present disclosure, when cracking a private key for a bilinear pairing operation, side channel information leaked during the execution of the bilinear pairing operation by the private key is collected from the cryptographic device. The side channel information can be physical information leaked by the cryptographic device. The target information corresponding to the private key to be cracked during the relocation process is selected from the side channel information, and then the target information is matched with a preset information template corresponding to multiple candidate keys. The preset information template includes reference information corresponding to the candidate key. Based on the matching result, one of the multiple candidate keys is selected as the cracked private key. Through the above embodiment, the present disclosure proposes an attack method for bilinear pairing operations with relatively complex operation processes. The attack method cracks the private key based on the characteristic that the operation process in which the private key participates is prone to leaking information when the private key is initially relocated, thereby improving the success rate of the attack.
[0143] It should be noted that the embodiment of the present disclosure uses the above-mentioned data processing method to attack the bilinear pairing operation to find the weaknesses of the identification cryptographic algorithm, and further improves the bilinear pairing operation based on the found weaknesses, thereby improving the security of the identification cryptographic algorithm.
[0144] In an optional implementation of this embodiment, step S101, i.e., the step of obtaining side channel information collected from the cryptographic device, further includes the following steps:
[0145] In response to a start triggering event of a computing process in which the private key to be cracked participates, energy consumption information of the cryptographic device is collected.
[0146] In this optional implementation, when a bilinear pairing operation is performed on a cryptographic device, the energy consumption information leaked by the cryptographic device during the operation in which the private key to be cracked participates can be detected. Considering that the embodiment of the present disclosure uses the target information of the private key to be cracked during the process of being moved at the beginning of the operation, a period of time can be set in advance to collect the energy consumption information within the set time period, and the energy consumption information is determined as the side channel information collected from the cryptographic device. It should be noted that the embodiment of the present disclosure collects the side channel information during the process in which the private key participates in the operation. As described above, in the bilinear pairing operation, the process in which the private key participates in the operation may include but is not limited to a password exchange operation, a password decapsulation operation, and a public key encrypted decryption operation. Therefore, the start triggering event of the operation process in which the private key to be cracked participates may include but is not limited to the start execution event of the password exchange operation, the password decapsulation operation, and the public key encrypted decryption operation.
[0147] In an optional implementation of this embodiment, step S102, i.e., the step of selecting target information from the side channel information, further includes the following steps:
[0148] Get a predetermined target timeframe;
[0149] Part of the side channel information whose collection time is within the target time range is determined as target information.
[0150] In this optional implementation, the target time range corresponds to the period during which the private key is moved when performing operations involving the private key in bilinear pairing operations. Typically, the target time range can be pre-predicted through model training or other methods, and the target time range is greater than or equal to the actual period during which the private key to be cracked was moved, meaning that the actual period falls within the target time range.
[0151] The collected side channel information may include, but is not limited to, physical information leaked by the cryptographic device corresponding to the collection time, such as energy consumption information. The collection time can be relative. For example, the start time of the computation process involving the private key to be cracked can be determined as time 0 of the collection time, and the collection time corresponding to the side channel information is relative to this time 0. The target time range is also a time range relative to the start time of the collection. By matching the collection time of the side channel information corresponding to the private key to be cracked with the target time range, the portion of the side channel information whose collection time falls within the target time range is determined as the target information.
[0152] In an optional implementation of this embodiment, the reference information corresponding to the candidate key includes: for the candidate key and multiple different plaintext data, when the sample device performs the bilinear pairing operation, the multivariate normal distribution information of the physical information leaked by the sample device during the movement of the candidate key.
[0153] In this optional implementation, the sample device can be a device of the same type or with the same hardware environment as the cryptographic device. A variety of plaintext data can be pre-determined, and a bilinear pairing operation can be performed on the sample device for the current candidate key and plaintext data. Physical information leaked by the sample device during the operation involving the candidate key is collected, and some information during the candidate key's transfer is selected for statistical analysis to obtain multivariate normal distribution information of multiple physical information corresponding to the same candidate key and a variety of plaintext data. This multivariate normal distribution information can indicate the distribution of physical information leaked by the key device during the transfer of the candidate key during the bilinear pairing operation involving the candidate key. When the target information corresponding to the current private key to be cracked closely matches the physical information corresponding to one of the candidate keys, it can be determined that the private key to be cracked is most likely the candidate key corresponding to the closely matching physical information.
[0154] In an optional implementation of this embodiment, step S103, i.e., the step of matching the target information with preset information templates corresponding to multiple candidate keys, further includes the following steps:
[0155] Calculating a matching probability value between the target information and the multivariate normal distribution information corresponding to the candidate key;
[0156] Step S104, i.e., determining one of the multiple candidate keys as the cracked private key based on the matching result, further includes the following steps:
[0157] The candidate key with the largest matching probability value is determined as the cracked private key.
[0158] In this optional implementation, the matching probability value between the target information and the multivariate normal distribution information can be calculated to select the most matching candidate key from multiple candidate keys as the cracked private key.
[0159] In some embodiments, multivariate normal distribution information can be represented by a mean and covariance. The mean and covariance can be calculated using the physical information corresponding to the same candidate key and multiple different plaintext data. Specifically, for the same candidate key and multiple different plaintext data, the physical information leaked from sample devices is collected, and the mean and covariance are calculated after selecting some physical information during the candidate key migration process.
[0160] In some embodiments, the following formula may be used to calculate the matching probability between the target information and the multivariate normal distribution information:
[0161]
[0162] Among them, p is the matching probability value, t is the target information, m is the mean, C is the covariance, d i represents the i-th plaintext data, k j represents the jth candidate key.
[0163] In an optional implementation of this embodiment, the method further includes the following steps:
[0164] determining a plurality of different candidate keys and a plurality of different plaintext data;
[0165] For each candidate key, obtaining side channel information leaked during a bilinear pairing operation performed on the sample device for each of the different plaintext data and the candidate key participating in the operation;
[0166] Selecting, from the side channel information, sample information when the candidate key is moved during the operation in which the candidate key participates;
[0167] For each candidate key, multivariate normal distribution information is obtained based on the sample information corresponding to the different plaintext data, and the multivariate normal distribution information and the candidate key are stored in correspondence as a preset information template of the candidate key.
[0168] In this optional implementation, all or part of the possible candidate keys and possible plaintext data may be determined in advance based on the number of binary bits of the data on the cryptographic device.
[0169] For example, when the number of bits used for data storage and processing in a cryptographic device is 1 byte, it can exhaustively enumerate the 256 data that can be represented by 1 byte of binary data, identify each of these 256 data as candidate keys, and for each candidate key, randomly generate n types of plaintext data. Then, an identification cryptographic algorithm based on linear pairing operations is executed on each candidate key. Side channel information is collected for each pair of candidate key and plaintext data, and sample information is selected from each side channel information when the candidate key is moved during the operation. A total of 256 × n types of sample information can be obtained. For each candidate key, the multivariate normal distribution information of the n types of sample information corresponding to the n types of plaintext data can be statistically analyzed to obtain a preset information template corresponding to each candidate key. This multivariate normal distribution information can be obtained by calculating the mean m and covariance matrix C of the n types of sample information.
[0170] In an optional implementation of this embodiment, the method further includes the following steps:
[0171] Obtain multiple randomly generated random keys;
[0172] For each random key, side channel information is obtained when a bilinear pairing operation is performed on a sample device for preset plaintext data; the side channel information is physical information leaked by the sample device during the operation in which the random key participates;
[0173] A target time range corresponding to the random key migration process is determined based on a correlation between the side channel information and the random key during the random key migration process.
[0174] In this optional implementation, the preset plaintext data may be one or more types. For each type of preset plaintext data, multiple random keys may be randomly generated, and bilinear pairing operations may be performed on sample devices respectively. Side channel information leaked by the sample devices during the operations involving the random keys may be collected, and a type of side channel information may be obtained for each pair of random keys and preset plaintext data.
[0175] It is understandable that the random key has a certain correlation with the collected side channel information. Based on this correlation, the characteristics of the side channel information during the process of random key movement can be analyzed. Therefore, by statistically analyzing the above characteristics in the side channel information corresponding to multiple random keys for the same or multiple preset plaintext data, the target time range corresponding to the private key movement process during the operation process when the private key is unknown can be predicted.
[0176] In an optional implementation of this embodiment, the method further includes the following steps:
[0177] Obtaining a plurality of randomly generated random keys and at least one or more types of plaintext data;
[0178] For each random key, side channel information and intermediate data generated by performing a bilinear pairing operation on the sample device for the preset plaintext data are obtained; the side channel information is physical information leaked by the sample device during the operation in which the random key participates, and the intermediate data is intermediate data generated based on the random key during the operation in which the random key participates;
[0179] A target time range corresponding to the random key migration process is determined based on the correlation between the side channel information and the intermediate data.
[0180] In this optional implementation, the preset plaintext data may be one or more types. For each type of preset plaintext data, multiple random keys may be randomly generated, and bilinear pairing operations may be performed on sample devices respectively. Side channel information leaked by the sample devices during the operations involving the random keys may be collected, and a type of side channel information may be obtained for each pair of random keys and preset plaintext data.
[0181] In addition, during the bilinear pairing operations performed on the sample devices, intermediate data generated by using the random key during the operations in which the random key participates is also obtained.
[0182] Since the generation of the intermediate data has a certain correlation with the relocation of the random key, the correlation between the intermediate data of multiple random keys and the side channel information for the same preset plaintext data can be statistically analyzed, and then the target time range corresponding to the relocation of the random key can be determined based on the correlation.
[0183] In an optional implementation of this embodiment, the step of determining a target time range corresponding to the random key migration process based on the correlation between the side channel information and the intermediate data further includes the following steps:
[0184] extracting a preset attribute value of the intermediate data;
[0185] determining a correlation curve between the preset attribute value and the side channel information;
[0186] The target time range is determined based on the correlation curve.
[0187] In this optional implementation, for the intermediate data obtained during the operation process involving a random key in an identification cryptographic algorithm based on linear pair operations, a preset attribute value can be obtained using a preset model. For example, the Hamming distance and / or Hamming weight in the intermediate data can be obtained based on a Hamming distance and Hamming weight model, and then a correlation curve between the Hamming distance and Hamming weight and the side channel information can be determined.
[0188] The following uses the energy consumption curve of the side channel information as an example to illustrate the calculation formula of the correlation curve, as shown below:
[0189]
[0190] Wherein, cov() represents covariance, Var(·) represents variance, t represents power consumption curve, and h represents random variable after intermediate data modeling, that is, preset attribute of intermediate data.
[0191] In an optional implementation of this embodiment, the step of determining the target time range based on the correlation curve further includes the following steps:
[0192] For the same preset plaintext data, determining the relevant feature point corresponding to the maximum absolute value in the correlation curve corresponding to each random key;
[0193] The target time range is obtained based on the statistics of the relevant feature points.
[0194] In this optional implementation method, for the same preset plaintext data, the relevant feature point corresponding to the maximum absolute value in the correlation curve corresponding to each random key is determined, and the time range of these relevant feature points corresponding to all random keys for the same preset plaintext data is counted to determine the target time range.
[0195] It should be noted that if there are multiple types of plaintext data, the time ranges corresponding to the multiple types of plaintext data may be further counted to obtain the target time range.
[0196] The following are embodiments of the apparatus disclosed herein, which can be used to execute embodiments of the method disclosed herein.
[0197] Figure 2 The structure block diagram of the data processing device according to one embodiment of the present disclosure is shown. The device can be implemented as part or all of an electronic device through software, hardware or a combination of both. Figure 2 As shown, the data processing device includes:
[0198] The first acquisition module 201 is configured to acquire side channel information collected from a cryptographic device; the side channel information is physical information leaked during the operation of the private key to be cracked when the cryptographic device performs a bilinear pairing operation;
[0199] A first selection module 202 is configured to select target information from the side channel information; the target information is the side channel information corresponding to the private key to be cracked during the migration process;
[0200] A matching module 203 is configured to match the target information with a preset information template corresponding to a plurality of candidate keys; the preset information template includes reference information corresponding to the candidate keys;
[0201] The first determining module 204 is configured to determine one of the multiple candidate keys as the cracked private key based on the matching result.
[0202] In this embodiment, the data processing device can be run on a cryptographic device or any device capable of communicating with the cryptographic device. The cryptographic device can perform bilinear pairing operations, such as the bilinear pairing operations in the SM9 identification cipher algorithm. In the bilinear pairing operations, the operations involving the private key include key exchange operations, key decapsulation operations, and decryption operations of the public key encryption algorithm.
[0203] The idea of side channel attack is to use the side channel information leaked by cryptographic devices during the execution of cryptographic operations, such as energy, electromagnetic, error, time and other physical information, and then calculate the side channel information through cryptography and statistics to obtain sensitive information of the algorithm (such as private keys).
[0204] In the embodiment of the present disclosure, a side channel attack concept is adopted for the bilinear pairing operation. When the cryptographic device performs the bilinear pairing operation, the side channel information leaked by the cryptographic device is collected during the operation in which the private key participates, such as energy, electromagnetic, error, time and other physical information, and then the private key is calculated based on the physical information.
[0205] In the prior art, there are side channel attack devices for the SM9 digital signature algorithm, such as the point multiplication operation S=[l]ds in the SM9 digital signature algorithm. A Conduct template attacks or horizontal attacks. However, the existing technologies are all aimed at side channel attacks on the point multiplication operation of the SM9 digital signature algorithm, and no side channel attacks on the bilinear pairing operation of other algorithms of SM9 (such as the key encapsulation mechanism and the public key encryption algorithm) are proposed. On the one hand, the reason is that the point multiplication operation involving the private key operation in the digital signature generation algorithm [l]ds A Similar to the point multiplication operation of elliptic curves such as SM2 and ECC, it is easy to find vulnerabilities and implement attacks, and there is a research basis; on the other hand, the key encapsulation mechanism and the bilinear pairing operation e(C1, de B )C1,deB, there is no similar research basis, and the mathematical calculation is more complicated than the dot multiplication operation, which makes the attack difficult.
[0206] In the data processing device proposed in the embodiment of the present disclosure, for bilinear pairing operations, side channel information leaked during the operation in which the private key is involved is collected by the cryptographic device, and then target information is selected from the side channel information. The target information is the side channel information when the private key is moved from the external interface to the storage area, and then an attack is performed on the side channel information generated when the private key is moved. That is, the embodiment of the present disclosure selects the private key moving process at the initial stage of the bilinear operation as the attack point, which can avoid the complex calculation process of the bilinear pairing operation and improve the success rate of the attack.
[0207] In some embodiments, after obtaining the side channel information collected from the cryptographic device, the target information corresponding to the process of the private key being moved in the initial stage of the operation is selected from the side channel information. The process of the private key being moved can be understood as the process of transferring the private key from the external interface of the cryptographic device or a storage area inside the cryptographic device to another storage area, so the process of the private key being moved can also be understood as the process of the private key being transferred. It is understandable that for security reasons, the private key will be stored on a secure medium. In the process of executing the cryptographic identification algorithm based on the bilinear pairing operation, when the private key is needed, the private key will be moved from the secure medium to an internal storage device such as the memory of the cryptographic device. Therefore, the embodiment of the present disclosure attacks the process of the private key being moved, that is, cracking the private key based on the side channel information corresponding to the process of being moved.
[0208] In some embodiments, preset information templates corresponding to different candidate keys can be pre-established. These preset information templates can include reference information corresponding to the candidate key. This reference information can be side-channel information collected during the migration of the candidate key when performing a bilinear pairing operation on the current candidate key and different plaintexts. In other words, the reference information corresponds to the target information and is both side-channel information corresponding to the candidate key and the private key to be cracked during the migration process when performing the bilinear pairing operation.
[0209] In some embodiments, when constructing a preset information template for a candidate key, the cryptographic device used may have the same hardware environment as the cryptographic device used to crack the current private key, for example, may be a cryptographic device of the same type.
[0210] In some embodiments, a preset information template corresponding to all possible candidate keys can be established, and all possible candidate keys can be enumerated based on bytes. For example, when the cryptographic device writes the key in units of 8 bits, or 1 byte, 256 candidate keys can be enumerated.
[0211] In some embodiments, for each candidate key, all plaintexts can be exhaustively enumerated, and the plaintexts are also exhaustively enumerated in bytes. For example, when a cryptographic device stores plaintext data in units of 8 bits, or 1 byte, 256 types of plaintexts can be exhaustively enumerated. It can be seen in this example that for the same candidate key, reference information can be obtained by statistically calculating the side channel information corresponding to the 256 types of plaintexts; for example, the reference information can be the mean and / or covariance data representation of the side channel information corresponding to the 256 types of plaintexts. However, considering the impact of the side channel information collection environment, collecting side channel information only once for the same plaintext data may result in inaccuracy or incomplete information. Therefore, in actual applications, multiple side channel information corresponding to the same plaintext data can be repeatedly used for the same candidate key. In other words, for the same candidate key, the final reference information obtained can be far more than 256 types.
[0212] After obtaining target information for the current private key to be cracked, the target information can be matched with reference information of multiple candidate keys, and the most matching candidate key can be determined as the cracked private key based on the matching result.
[0213] In the embodiment of the present disclosure, when cracking a private key for a bilinear pairing operation, side channel information leaked during the execution of the bilinear pairing operation by the private key is collected from the cryptographic device. The side channel information can be physical information leaked by the cryptographic device. The target information corresponding to the private key to be cracked during the relocation process is selected from the side channel information, and then the target information is matched with a preset information template corresponding to multiple candidate keys. The preset information template includes reference information corresponding to the candidate key. Based on the matching result, one of the multiple candidate keys is selected as the cracked private key. Through the above embodiment, the present disclosure proposes an attack method for bilinear pairing operations with relatively complex operation processes. The attack method cracks the private key based on the characteristic that the operation process in which the private key participates is prone to leaking information when the private key is initially relocated, thereby improving the success rate of the attack.
[0214] It should be noted that the embodiment of the present disclosure uses the above-mentioned data processing device to attack the bilinear pairing operation to find the weaknesses of the identification cryptographic algorithm, and further improves the bilinear pairing operation based on the found weaknesses, thereby improving the security of the identification cryptographic algorithm.
[0215] In an optional implementation of this embodiment, the first acquisition module includes:
[0216] The response submodule is configured to collect energy consumption information of the cryptographic device in response to a start triggering event of a calculation process in which the private key to be cracked participates.
[0217] In this optional implementation, when a bilinear pairing operation is performed on a cryptographic device, the energy consumption information leaked by the cryptographic device during the operation in which the private key to be cracked participates can be detected. Considering that the embodiment of the present disclosure uses the target information of the private key to be cracked during the process of being moved at the beginning of the operation, a period of time can be set in advance to collect the energy consumption information within the set time period, and the energy consumption information is determined as the side channel information collected from the cryptographic device. It should be noted that the embodiment of the present disclosure collects the side channel information during the process in which the private key participates in the operation. As described above, in the bilinear pairing operation, the process in which the private key participates in the operation may include but is not limited to a password exchange operation, a password decapsulation operation, and a public key encrypted decryption operation. Therefore, the start triggering event of the operation process in which the private key to be cracked participates may include but is not limited to the start execution event of the password exchange operation, the password decapsulation operation, and the public key encrypted decryption operation.
[0218] In an optional implementation of this embodiment, the first selection module includes:
[0219] A first acquisition submodule is configured to acquire a predetermined target time range;
[0220] The first determining submodule is configured to determine part of the side channel information whose collection time is within the target time range as target information.
[0221] In this optional implementation, the target time range corresponds to the period during which the private key is moved when performing operations involving the private key in bilinear pairing operations. Typically, the target time range can be pre-predicted through model training or other methods, and the target time range is greater than or equal to the actual period during which the private key to be cracked was moved, meaning that the actual period falls within the target time range.
[0222] The collected side channel information may include, but is not limited to, physical information leaked by the cryptographic device corresponding to the collection time, such as energy consumption information. The collection time can be relative. For example, the start time of the computation process involving the private key to be cracked can be determined as time 0 of the collection time, and the collection time corresponding to the side channel information is relative to this time 0. The target time range is also a time range relative to the start time of the collection. By matching the collection time of the side channel information corresponding to the private key to be cracked with the target time range, the portion of the side channel information whose collection time falls within the target time range is determined as the target information.
[0223] In an optional implementation of this embodiment, the reference information corresponding to the candidate key includes: for the candidate key and multiple different plaintext data, when the sample device performs the bilinear pairing operation, the multivariate normal distribution information of the physical information leaked by the sample device during the movement of the candidate key.
[0224] In this optional implementation, the sample device can be a device of the same type or with the same hardware environment as the cryptographic device. A variety of plaintext data can be pre-determined, and a bilinear pairing operation can be performed on the sample device for the current candidate key and plaintext data. Physical information leaked by the sample device during the operation involving the candidate key is collected, and some information during the candidate key's transfer is selected for statistical analysis to obtain multivariate normal distribution information of multiple physical information corresponding to the same candidate key and a variety of plaintext data. This multivariate normal distribution information can indicate the distribution of physical information leaked by the key device during the transfer of the candidate key during the bilinear pairing operation involving the candidate key. When the target information corresponding to the current private key to be cracked closely matches the physical information corresponding to one of the candidate keys, it can be determined that the private key to be cracked is most likely the candidate key corresponding to the closely matching physical information.
[0225] In an optional implementation of this embodiment, the matching module includes:
[0226] a calculation submodule, configured to calculate a matching probability value between the target information and the multivariate normal distribution information corresponding to the candidate key;
[0227] The first determining module includes:
[0228] The second determining submodule is configured to determine the candidate key with the largest matching probability value as the cracked private key.
[0229] In this optional implementation, the matching probability value between the target information and the multivariate normal distribution information can be calculated to select the most matching candidate key from multiple candidate keys as the cracked private key.
[0230] In some embodiments, multivariate normal distribution information can be represented by a mean and covariance. The mean and covariance can be calculated using the physical information corresponding to the same candidate key and multiple different plaintext data. Specifically, for the same candidate key and multiple different plaintext data, the physical information leaked from sample devices is collected, and the mean and covariance are calculated after selecting some physical information during the candidate key migration process.
[0231] In some embodiments, the following formula may be used to calculate the matching probability between the target information and the multivariate normal distribution information:
[0232]
[0233] Among them, p is the matching probability value, t is the target information, m is the mean, C is the covariance, d i represents the i-th plaintext data, k j represents the jth candidate key.
[0234] In an optional implementation of this embodiment, the apparatus further includes:
[0235] a second determining module, configured to determine a plurality of different candidate keys and a plurality of different plaintext data;
[0236] A second acquisition module is configured to acquire, for each candidate key, side channel information leaked during a bilinear pairing operation performed on the sample device on the different plaintext data and in which the candidate key participates;
[0237] A second selection module is configured to select, from the side channel information, sample information when the candidate key is moved during the operation in which the candidate key participates;
[0238] The statistical module is configured to obtain multivariate normal distribution information for each candidate key based on the sample information corresponding to the different plaintext data, and store the multivariate normal distribution information and the candidate key in correspondence as a preset information template of the candidate key.
[0239] In this optional implementation, all or part of the possible candidate keys and possible plaintext data may be determined in advance based on the number of binary bits of the data on the cryptographic device.
[0240] When the number of bits used for data storage and processing is 1 byte, a cryptographic device can exhaustively enumerate the 256 data points that can be represented by 1 byte of binary data. These 256 data points are then identified as candidate keys. For each candidate key, n types of plaintext data are randomly generated, and then an identification cryptographic algorithm based on linear pairing operations is executed on each pair. Side channel information is collected for each pair of candidate key and plaintext data. Sample information is then selected from each side channel information when the candidate key is moved during the operation, resulting in a total of 256 × n types of sample information. For each candidate key, the multivariate normal distribution information of the n types of sample information corresponding to the n types of plaintext data can be statistically analyzed to obtain a preset information template corresponding to each candidate key. This multivariate normal distribution information can be obtained by calculating the mean m and covariance matrix C of the n types of sample information.
[0241] In an optional implementation of this embodiment, the apparatus further includes:
[0242] A third acquisition module is configured to obtain a plurality of randomly generated random keys;
[0243] a fourth acquisition module configured to, for each random key, acquire side channel information when a bilinear pairing operation is performed on preset plaintext data on a sample device; the side channel information being physical information leaked by the sample device during the operation in which the random key participates;
[0244] The third determining module is configured to determine a target time range corresponding to the random key migration process based on a correlation between the side channel information and the random key during the random key migration process.
[0245] In this optional implementation, the preset plaintext data may be one or more types. For each type of preset plaintext data, multiple random keys may be randomly generated, and bilinear pairing operations may be performed on sample devices respectively. Side channel information leaked by the sample devices during the operations involving the random keys may be collected, and a type of side channel information may be obtained for each pair of random keys and preset plaintext data.
[0246] It is understandable that the random key has a certain correlation with the collected side channel information. Based on this correlation, the characteristics of the side channel information during the process of random key movement can be analyzed. Therefore, by statistically analyzing the above characteristics in the side channel information corresponding to multiple random keys for the same or multiple preset plaintext data, the target time range corresponding to the private key movement process during the operation process when the private key is unknown can be predicted.
[0247] In an optional implementation of this embodiment, the apparatus further includes:
[0248] a fifth acquisition module, configured to acquire a plurality of randomly generated random keys;
[0249] a sixth acquisition module configured to, for each random key, acquire side channel information and intermediate data when a bilinear pairing operation is performed on preset plaintext data on a sample device; the side channel information being physical information leaked by the sample device during the operation in which the random key participates, and the intermediate data being intermediate data generated based on the random key during the operation in which the random key participates;
[0250] The fourth determining module is configured to determine a target time range corresponding to the random key migration process based on a correlation between the side channel information and the intermediate data during the random key migration process.
[0251] In this optional implementation, the preset plaintext data may be one or more types. For each type of preset plaintext data, multiple random keys may be randomly generated, and bilinear pairing operations may be performed on sample devices respectively. Side channel information leaked by the sample devices during the operations involving the random keys may be collected, and a type of side channel information may be obtained for each pair of random keys and preset plaintext data.
[0252] In addition, during the bilinear pairing operations performed on the sample devices, intermediate data generated by using the random key during the operations in which the random key participates is also obtained.
[0253] Since the generation of the intermediate data has a certain correlation with the relocation of the random key, the correlation between the intermediate data of multiple random keys and the side channel information for the same preset plaintext data can be statistically analyzed, and then the target time range corresponding to the relocation of the random key can be determined based on the correlation.
[0254] In an optional implementation of this embodiment, the fourth determining module includes:
[0255] an extraction submodule, configured to extract a preset attribute value of the intermediate data;
[0256] a third determining submodule, configured to determine a correlation curve between the preset attribute value and the side channel information;
[0257] The fourth determining submodule is configured to determine the target time range based on the correlation curve.
[0258] In this optional implementation, for the intermediate data obtained during the operation process involving a random key in an identification cryptographic algorithm based on linear pair operations, a preset attribute value can be obtained using a preset model. For example, the Hamming distance and / or Hamming weight in the intermediate data can be obtained based on a Hamming distance and Hamming weight model, and then a correlation curve between the Hamming distance and Hamming weight and the side channel information can be determined.
[0259] The following uses the energy consumption curve of the side channel information as an example to illustrate the calculation formula of the correlation curve, as shown below:
[0260]
[0261] Wherein, cov() represents covariance, Var(·) represents variance, t represents power consumption curve, and h represents random variable after intermediate data modeling, that is, preset attribute of intermediate data.
[0262] In an optional implementation of this embodiment, the fourth determining submodule includes:
[0263] A fifth determining submodule is configured to determine, for the same preset plaintext data, a relevant feature point corresponding to the maximum absolute value in the correlation curve corresponding to each random key;
[0264] The second statistical submodule is configured to obtain the target time range based on the statistics of the relevant feature points.
[0265] In this optional implementation method, for the same preset plaintext data, the relevant feature point corresponding to the maximum absolute value in the correlation curve corresponding to each random key is determined, and the time range of these relevant feature points corresponding to all random keys for the same preset plaintext data is counted to determine the target time range.
[0266] It should be noted that if there are multiple types of plaintext data, the time ranges corresponding to the multiple types of plaintext data may be further counted to obtain the target time range.
[0267] The present disclosure also provides a chip including the aforementioned data processing device. The chip may be any chip capable of implementing the data processing process described above. The device may be implemented as part or all of the chip using software, hardware, or a combination of both. The data processing process is described in the above description of the data processing method and will not be further elaborated here.
[0268] The present disclosure also discloses an electronic device, Figure 3 A structural block diagram of an electronic device according to an embodiment of the present disclosure is shown. Figure 3 As shown, the electronic device 300 includes a memory 301 and a processor 302; wherein,
[0269] The memory 301 is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor 302 to implement the above method steps.
[0270] Figure 4 It is a structural diagram of a computer system suitable for implementing a data processing method according to an embodiment of the present disclosure.
[0271] like Figure 4 As shown, the computer system 400 includes a processing unit 401, which can execute various processes in the above-mentioned embodiments according to a program stored in a read-only memory (ROM) 402 or a program loaded from a storage unit 408 into a random access memory (RAM) 403. Various programs and data required for the operation of the computer system 400 are also stored in the RAM 403. The processing unit 401, the ROM 402, and the RAM 403 are connected to each other via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.
[0272] The following components are connected to the I / O interface 405: an input section 406 including a keyboard, a mouse, etc.; an output section 407 including a cathode ray tube (CRT), a liquid crystal display (LCD), a speaker, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN card, a modem, etc. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the I / O interface 405 as needed. A removable medium 411, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 410 as needed so that a computer program read therefrom can be installed into the storage section 408 as needed. Among them, the processing unit 401 can be implemented as a processing unit such as a CPU, a GPU, a TPU, an FPGA, an NPU, etc.
[0273] In particular, according to embodiments of the present disclosure, the methods described above can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product comprising a computer program tangibly embodied on a computer-readable medium, the computer program comprising program code for executing the methods described. In such embodiments, the computer program can be downloaded and installed from a network via the communication portion 409 and / or installed from the removable medium 411.
[0274] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the diagram or block diagram can represent a module, program segment or part of the code, and the module, program segment or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, as well as the combination of boxes in the block diagram and / or flow chart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or can be implemented using a combination of dedicated hardware and computer instructions.
[0275] The units or modules involved in the embodiments described in this disclosure may be implemented in software or hardware. The units or modules described may also be provided in a processor, and the names of these units or modules do not, in certain circumstances, constitute limitations on the units or modules themselves.
[0276] As another aspect, the present disclosure further provides a computer-readable storage medium. This computer-readable storage medium may be included in the apparatus described in the above embodiments, or may be a standalone computer-readable storage medium not incorporated into the apparatus. The computer-readable storage medium stores one or more programs, which are used by one or more processors to execute the methods described in the present disclosure.
[0277] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of the invention herein is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also encompasses other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the inventive concept. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.
Claims
1. A data processing method, wherein: The method is used to find out the weaknesses of the identification cryptographic algorithm by attacking the bilinear pairing operation, and further improve the bilinear pairing operation according to the weaknesses found, so as to improve the security of the identification cryptographic algorithm; The method comprises: Obtaining side channel information collected from a cryptographic device; the side channel information is physical information leaked during a calculation involving a private key to be cracked when the cryptographic device performs a bilinear pairing operation; Selecting target information from the side channel information; the target information is the side channel information corresponding to the private key to be cracked during the process of being moved; Matching the target information with a plurality of preset information templates corresponding to candidate keys; the preset information templates including reference information corresponding to the candidate keys; determining one of the plurality of candidate keys as a cracked private key based on the matching result; The step of selecting target information from the side channel information includes: Get a predetermined target timeframe; Determining part of the side channel information whose collection time falls within the target time range as target information; The method further comprises: Obtain multiple randomly generated random keys; For each random key, side channel information is obtained when a bilinear pairing operation is performed on preset plaintext data on a sample device, or the side channel information and intermediate data are obtained simultaneously; the side channel information is physical information leaked by the sample device during the operation in which the random key participates, and the intermediate data is intermediate data generated based on the random key during the operation in which the random key participates; Based on the correlation between the side channel information and the random key during the random key being moved, the target time range corresponding to the random key being moved is determined; or, based on the correlation between the side channel information and the intermediate data during the random key being moved, the target time range corresponding to the random key being moved is determined.
2. The method according to claim 1, wherein Obtain side-channel information collected from cryptographic devices, including: In response to a start triggering event of a computing process in which the private key to be cracked participates, energy consumption information of the cryptographic device is collected.
3. The method according to claim 1 or 2, wherein: The reference information corresponding to the candidate key includes: for the candidate key and multiple different plaintext data, when the sample device performs the bilinear pairing operation, multivariate normal distribution information of physical information leaked by the sample device during the process of moving the candidate key.
4. The method according to claim 3, wherein: Matching the target information with preset information templates corresponding to multiple candidate keys includes: Calculating a matching probability value between the target information and the multivariate normal distribution information corresponding to the candidate key; Determining one of the multiple candidate keys as a cracked private key based on the matching result includes: The candidate key with the largest matching probability value is determined as the cracked private key.
5. The method according to claim 1 or 2, wherein: The method further comprises: determining a plurality of different candidate keys and a plurality of different plaintext data; For each candidate key, obtaining side channel information leaked during a bilinear pairing operation performed on the sample device for each of the different plaintext data and the candidate key participating in the operation; Selecting, from the side channel information, sample information when the candidate key is moved during the operation in which the candidate key participates; For each candidate key, multivariate normal distribution information is obtained based on the sample information corresponding to the different plaintext data, and the multivariate normal distribution information and the candidate key are stored in correspondence as a preset information template of the candidate key.
6. The method according to claim 1, wherein Determining a target time range corresponding to the random key migration process based on a correlation between the side channel information and the intermediate data during the random key migration process includes: extracting a preset attribute value of the intermediate data; determining a correlation curve between the preset attribute value and the side channel information; The target time range is determined based on the correlation curve.
7. The method according to claim 6, wherein: Determining the target time range based on the correlation curve includes: For the same preset plaintext data, determining the relevant feature point corresponding to the maximum absolute value in the correlation curve corresponding to each random key; The target time range is obtained based on the statistics of the relevant feature points.
8. A data processing device, wherein: The device is used to find out the weaknesses of the identification cryptographic algorithm by attacking the bilinear pairing operation, and further improve the bilinear pairing operation according to the weaknesses found, so as to improve the security of the identification cryptographic algorithm; The device comprises: A first acquisition module is configured to acquire side channel information collected from a cryptographic device; the side channel information is physical information leaked during a calculation process in which a private key to be cracked participates when the cryptographic device performs a bilinear pairing operation; A first selection module is configured to select target information from the side channel information; the target information is the side channel information corresponding to the private key to be cracked during the migration process; a matching module configured to match the target information with preset information templates corresponding to a plurality of candidate keys; the preset information templates including reference information corresponding to the candidate keys; a first determining module configured to determine one of the plurality of candidate keys as a cracked private key based on a matching result; The first selection module includes: A first acquisition submodule is configured to acquire a predetermined target time range; A first determining submodule is configured to determine part of the side channel information whose collection time falls within the target time range as target information; The device further comprises: A third acquisition module is configured to obtain a plurality of randomly generated random keys; a fourth acquisition module configured to, for each random key, acquire side channel information when a bilinear pairing operation is performed on preset plaintext data on a sample device; the side channel information being physical information leaked by the sample device during the operation in which the random key participates; A third determining module is configured to determine a target time range corresponding to the random key migration process based on a correlation between the side channel information and the random key during the random key migration process; or The device further comprises: a fifth acquisition module, configured to acquire a plurality of randomly generated random keys; a sixth acquisition module configured to, for each random key, acquire side channel information and intermediate data when a bilinear pairing operation is performed on preset plaintext data on a sample device; the side channel information being physical information leaked by the sample device during the operation in which the random key participates, and the intermediate data being intermediate data generated based on the random key during the operation in which the random key participates; The fourth determining module is configured to determine a target time range corresponding to the random key migration process based on a correlation between the side channel information and the intermediate data during the random key migration process.
9. The device according to claim 8, wherein The first acquisition module includes: The response submodule is configured to collect energy consumption information of the cryptographic device in response to a start triggering event of a calculation process in which the private key to be cracked participates.
10. The device according to claim 8 or 9, wherein The reference information corresponding to the candidate key includes: for the candidate key and multiple different plaintext data, when the sample device performs the bilinear pairing operation, multivariate normal distribution information of physical information leaked by the sample device during the process of moving the candidate key.
11. The device according to claim 10, wherein The matching module includes: a calculation submodule, configured to calculate a matching probability value between the target information and the multivariate normal distribution information corresponding to the candidate key; The first determining module includes: The second determining submodule is configured to determine the candidate key with the largest matching probability value as the cracked private key.
12. The device according to claim 8 or 9, wherein The device further comprises: a second determining module, configured to determine a plurality of different candidate keys and a plurality of different plaintext data; A second acquisition module is configured to acquire, for each candidate key, side channel information leaked during a bilinear pairing operation performed on the sample device on the different plaintext data and in which the candidate key participates; A second selection module is configured to select, from the side channel information, sample information when the candidate key is moved during the operation in which the candidate key participates; The statistical module is configured to obtain multivariate normal distribution information for each candidate key based on the sample information corresponding to the different plaintext data, and store the multivariate normal distribution information and the candidate key in correspondence as a preset information template of the candidate key.
13. The device according to claim 8, wherein The fourth determining module includes: an extraction submodule, configured to extract a preset attribute value of the intermediate data; a third determining submodule, configured to determine a correlation curve between the preset attribute value and the side channel information; The fourth determining submodule is configured to determine the target time range based on the correlation curve.
14. The device according to claim 13, wherein The fourth determining submodule includes: A fifth determining submodule is configured to determine, for the same preset plaintext data, a relevant feature point corresponding to the maximum absolute value in the correlation curve corresponding to each random key; The second statistical submodule is configured to obtain the target time range based on the statistics of the relevant feature points.
15. An electronic device, wherein: The method comprises a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the method according to any one of claims 1 to 7.
16. A computer-readable storage medium having computer instructions stored thereon, wherein: When the computer instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.
17. A chip comprising the device according to any one of claims 8 to 14.
Citation Information
Patent Citations
Side channel analysis method and device of attack SM9 signature algorithm, medium and equipment
CN112332970A
Private key recovery method and system for realizing modular reduction attack based on RSA-CRT of template
CN113965324A