Encryption Method, Device, Equipment and Storage Medium for Resisting Error Injection Attacks
By introducing two encryption paths and backtrack verification mechanisms into the encryption method, the verification problem of existing encryption methods under error injection attacks is solved, and the self-checksum security is improved to ensure the accuracy of encryption results and the ability to resist attacks.
Patent Information
- Application Number
- CN202210954818.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-10
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-08-10
AI Technical Summary
When facing error injection attacks, existing encryption methods cannot effectively verify the correctness of the encryption method, and cannot confirm the correct path in the verification scheme, and are easily parsed by attackers using judgment bit data.
Two encryption paths are used to encrypt the encrypted data, and the encryption results are processed through the backtracking verification mechanism and the random infection model, and the error injection attack is detected and the correct encryption results are output.
It realizes self-checking of the encryption method in the case of error injection attacks, improves the security and accuracy of the encryption method, and prevents attackers from cracking ciphertext data and their round keys.
Smart Images

Figure CN115333824B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular, to an encryption method, apparatus, device, and storage medium for resisting error injection attacks. Background Art
[0002] In existing encryption methods, the redundancy and comparison verification scheme for encrypted data designs redundancy rounds through the encryption method and verifies by comparing the results of the original algorithm and the redundancy round algorithm. The existing verification scheme usually generates one-bit data as a judgment bit after the comparison operation. When an error injection attack occurs, if the attacker obtains the judgment bit data by some means, the original encrypted data is more vulnerable to attack at this time.
[0003] Based on the redundancy and comparison verification scheme, the existing infection algorithm destroys the fault propagation pattern, so that even if the attacker obtains the faulty ciphertext, they cannot parse the information in it. By introducing the random principle, the error is spread to a wider range to achieve the purpose of resisting error attacks. However, this scheme cannot verify the correctness of the encryption method and cannot confirm the correct path in the verification scheme.
[0004] Therefore, there is an urgent need for an encryption scheme that can perform self-verification and resist error injection attacks. Summary of the Invention
[0005] To solve the above technical problems, embodiments of the present application provide an encryption method, apparatus, electronic device, and computer-readable storage medium for resisting error injection attacks. The specific solutions are as follows:
[0006] In a first aspect, embodiments of the present application provide an encryption method for resisting error injection attacks, where the encryption method includes:
[0007] Obtain data to be encrypted;
[0008] Perform encryption operations on the data to be encrypted using a first encryption path and a second encryption path respectively to obtain a first encryption result;
[0009] Perform backtracking verification on the first encryption result according to the encryption operation periods of the first encryption path and the second encryption path;
[0010] If the result of the backtracking verification includes an error injection attack, output a second encryption result, where the second encryption result includes ciphertext data obtained by processing the first encryption result according to a random infection model;
[0011] If the result of the backtracking verification does not include an error injection attack, output the first encryption result.
[0012] According to a specific implementation manner of an embodiment of the present application, the operation processes of the first encryption path and the second encryption path both include corresponding random redundancy cycles;
[0013] The step of performing backtracking verification on the first encryption result according to the encryption operation cycles of the first encryption path and the second encryption path includes:
[0014] Comparing whether the first encryption operation cycle of the first encryption path is the same as the second encryption operation cycle of the second encryption path;
[0015] If the first encryption operation cycle is different from the second encryption operation cycle, perform backtracking verification on the first encryption result;
[0016] If the first encryption operation cycle is the same as the second encryption operation cycle, perform a preset scrambling process on the random redundancy cycle of any one of the encryption paths, and perform encryption according to the processed random redundancy cycle until the first encryption operation cycle and the second encryption operation cycle are different.
[0017] According to a specific implementation manner of an embodiment of the present application, the first encryption path includes a first random mask, the second encryption path includes a second random mask, and the first random mask is different from the second random mask;
[0018] The steps of respectively encrypting the data to be encrypted by using the first encryption path and the second encryption path to obtain a first encryption result include:
[0019] Performing encryption processing on the data to be encrypted for a preset number of rounds according to the first random mask and the first random redundancy cycle to obtain a first output;
[0020] Performing encryption processing on the data to be encrypted for a preset number of rounds according to the second random mask and the second random redundancy cycle to obtain a second output;
[0021] Saving the first output and the second output to obtain the first encryption result.
[0022] According to a specific implementation manner of an embodiment of the present application, both the first output and the second output include round keys, intermediate ciphertext data, and target ciphertext data. The steps of performing backtracking verification on the first encryption result include:
[0023] Performing decryption processing on the ciphertext data in the first output and the second output for a preset number of rounds according to the corresponding round keys to obtain verification data for the corresponding encryption path;
[0024] If the verification data is the same as the corresponding intermediate ciphertext data, the corresponding encryption path does not include an error injection attack;
[0025] If the verification data is different from the corresponding intermediate ciphertext data, the corresponding encryption path includes an error injection attack.
[0026] According to a specific implementation manner of an embodiment of the present application, the step of processing the first encryption result according to the random infection model includes:
[0027] Detect whether the first encryption path and the second encryption path include an error injection attack;
[0028] When the detection result is that at least one of the first encryption path and the second encryption path includes an error injection attack, send the first encryption result to the random infection model.
[0029] According to a specific implementation manner of an embodiment of the present application, the step of processing the first encryption result according to the random infection model further includes:
[0030] Perform a random byte permutation process on the first encryption result to obtain a permutation encryption result;
[0031] Perform a preset random process on the permutation encryption result to obtain the second encryption result.
[0032] According to a specific implementation manner of an embodiment of the present application, the step of performing a preset random process on the permutation encryption result to obtain the second encryption result includes:
[0033] After performing a preset logical process on the permutation encryption result and a third random mask, obtain the second encryption result.
[0034] In a second aspect, an embodiment of the present application provides an encryption device for resisting error injection attacks, and the encryption device includes:
[0035] An acquisition module, configured to acquire data to be encrypted;
[0036] An encryption module, configured to perform encryption operations on the data to be encrypted by using a first encryption path and a second encryption path respectively to obtain a first encryption result;
[0037] A verification module, configured to perform a retrospective verification on the first encryption result according to the encryption operation periods of the first encryption path and the second encryption path;
[0038] A first execution module, configured to output a second encryption result if the result of the retrospective verification includes an error injection attack, and the second encryption result includes ciphertext data obtained by processing the first encryption result according to the random infection model;
[0039] A second execution module, configured to output the first encryption result if the result of the backtracking verification does not include an error injection attack.
[0040] In a third aspect, an embodiment of the present application provides an electronic device, including a processor and a memory. The memory stores a computer program, and when the computer program runs on the processor, it executes the encryption method for resisting error injection attacks described in the foregoing first aspect and any implementation manner of the first aspect.
[0041] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and when the computer program runs on a processor, it executes the encryption method for resisting error injection attacks described in the foregoing first aspect and any implementation manner of the first aspect.
[0042] An embodiment of the present application provides an encryption method, device, equipment, and storage medium for resisting error injection attacks. The encryption method includes: obtaining data to be encrypted; respectively performing encryption operations on the data to be encrypted by using a first encryption path and a second encryption path to obtain a first encryption result; performing backtracking verification on the first encryption result according to the encryption operation periods of the first encryption path and the second encryption path; if the result of the backtracking verification includes an error injection attack, output a second encryption result, where the second encryption result includes ciphertext data obtained by processing the first encryption result according to a random infection model; if the result of the backtracking verification does not include an error injection attack, output the first encryption result. The present invention adds a backtracking verification mechanism and a random diffusion mechanism after detecting an error, and can improve the security of the encryption method while verifying the correctness of the encryption method. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] To more clearly illustrate the technical solutions of the present invention, the accompanying drawings required for the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the protection scope of the present invention. In each drawing, similar components are numbered similarly.
[0044] Figure 1 It shows a schematic flowchart of an encryption method for resisting error injection attacks provided by an embodiment of the present application;
[0045] Figure 2 It shows a schematic diagram of an interaction process of an encryption method for resisting error injection attacks provided by an embodiment of the present application;
[0046] Figure 3 It shows a schematic diagram of an interaction process of an encryption method for resisting error injection attacks provided by an embodiment of the present application;
[0047] Figure 4 The figure shows a schematic diagram of the device modules of an encryption device for resisting error injection attacks provided by an embodiment of the present application. Detailed implementation manners
[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.
[0049] Generally, the components of the embodiments of the present invention described and shown herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0050] Hereinafter, the terms "including", "having" and their cognates that can be used in various embodiments of the present invention are only intended to represent specific features, numbers, steps, operations, elements, components or combinations of the foregoing items, and should not be construed as first excluding the existence of one or more other features, numbers, steps, operations, elements, components or combinations of the foregoing items or increasing the possibility of one or more features, numbers, steps, operations, elements, components or combinations of the foregoing items.
[0051] In addition, the terms "first", "second", "third", etc. are only used for descriptive distinction and cannot be construed as indicating or implying relative importance.
[0052] Unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as commonly understood by those of ordinary skill in the art to which various embodiments of the present invention belong. The terms (such as those defined in a general-use dictionary) will be construed to have the same meaning as the contextual meaning in the relevant technical field and will not be construed to have an idealized meaning or an overly formal meaning unless clearly defined in various embodiments of the present invention.
[0053] Reference Figure 1 , which is a schematic diagram of the method flow of an encryption method for resisting error injection attacks provided by an embodiment of the present application. The encryption method for resisting error injection attacks provided by the embodiment of the present application, as Figure 1 shown, the encryption method for resisting error injection attacks includes:
[0054] Step S101, obtain the data to be encrypted;
[0055] Specifically, the data to be encrypted is the plaintext data that needs to be encrypted, and its data type can be any type of data. The data to be encrypted can be stored in bit form or byte form, and this embodiment does not limit this.
[0056] In a specific embodiment, the data to be encrypted can be the plaintext parameters input by the user in the front-end system. After encrypting the plaintext parameters based on the encryption method provided by this embodiment, ciphertext data is obtained and output.
[0057] The encryption method provided by this embodiment is an encryption method implemented based on the block encryption method. The block encryption method can be the SM4 encryption method, the AES encryption method, the DES encryption method, etc., and this is not limited here.
[0058] Step S102, respectively use the first encryption path and the second encryption path to perform encryption operations on the data to be encrypted, and obtain a first encryption result;
[0059] Specifically, the second encryption path serves as a redundant encryption path for the first encryption path, which is used to improve the error resistance ability of the encryption method and avoid the influence of the data to be encrypted being attacked by error injection during the data encryption process. The fault injection attack is a way of attacking that introduces errors in the encryption operation through the cryptographic chip device, resulting in an incorrect result of the cryptographic device, and analyzing the incorrect result to obtain the round key. The error can be an error type such as a numerical error or a clock error, and the error is not specifically limited here.
[0060] The first encryption path and the second encryption path can perform encryption operations on the data to be encrypted for a preset number of rounds according to the set parameters. The encryption method in this embodiment includes at least one second encryption path, that is, the encryption method includes at least one redundant encryption path.
[0061] Taking the SM4 encryption algorithm as an example, the encryption method provided by this embodiment uses the first encryption path and the second encryption path to encrypt the data to be encrypted simultaneously.
[0062] Specifically, as Figure 2 shown, when this embodiment uses the SM4 encryption algorithm to process the data to be encrypted, both the first encryption path and the second encryption path need to perform 32 rounds of encryption operations on the data to be encrypted.
[0063] The encryption operation steps of the regular rounds of the first encryption path and the second encryption path are the same to ensure the redundancy relationship between the first encryption path and the second encryption path.
[0064] The first encryption path performs a complete encryption operation on the data to be encrypted and obtains a first output Out1, and the second encryption path performs a complete encryption operation on the data to be encrypted and obtains a second output Out2.
[0065] Step S103, perform a retrospective check on the first encryption result according to the encryption operation cycles of the first encryption path and the second encryption path;
[0066] Specifically, in this embodiment, after completing the encryption operation steps of the first encryption path and the second encryption path, a self-check process is immediately performed on the first encryption result, and subsequent different encryption processes are performed according to the self-check result of the first encryption result.
[0067] Through the self-check mechanism in this embodiment, the correctness of the encryption result can be verified by the encryption method itself, thereby providing security guarantee for the data encryption process.
[0068] According to a specific implementation manner of an embodiment of the present application, the operation processes of the first encryption path and the second encryption path both include corresponding random redundancy cycles;
[0069] The step of performing a retrospective check on the first encryption result according to the encryption operation cycles of the first encryption path and the second encryption path includes:
[0070] Compare whether the first encryption operation cycle of the first encryption path is the same as the second encryption operation cycle of the second encryption path;
[0071] If the first encryption operation cycle is different from the second encryption operation cycle, perform a retrospective check on the first encryption result;
[0072] If the first encryption operation cycle is the same as the second encryption operation cycle, perform a preset scrambling process on the random redundancy cycle of any encryption path, and perform encryption according to the processed random redundancy cycle until the first encryption operation cycle and the second encryption operation cycle are different.
[0073] In a specific embodiment, random redundancy cycles are added to both the first encryption path and the second encryption path to ensure that the encryption operation cycles of the first encryption path and the second encryption path are different, thereby avoiding injecting errors into the same positions in the two encryption paths when an error injection attack injects an error clock.
[0074] Specifically, within the redundancy cycle, the encryption path continues to perform the encryption operation step, and the power consumption generated by performing the encryption operation within the redundancy cycle has no obvious difference from the power consumption generated by performing the encryption operation in other cycles.
[0075] During the encryption operation step within the redundant period, some random variable data is used as intermediate variables to participate in the operation. When the random redundant period of the encryption path ends, the intermediate variables participating in the encryption operation in this process will continue to participate in the valid operation of the encryption path.
[0076] Specifically, before the step of performing the backtracking verification, the encryption method proposed in this embodiment also needs to determine whether the encryption operation periods of the first encryption path and the second encryption path are the same.
[0077] If the encryption operation periods of the first encryption path and the second encryption path are exactly the same, it means that the redundant periods in the first encryption path and the second encryption path are the same, and the two encryption paths will output the encryption results at the same time. When the encryption operation periods of the first encryption path and the second encryption path are the same, it is easier to inject the same error synchronously in the two encryption paths during the error injection attack, and the probability of the encryption method being attacked is significantly increased.
[0078] In this embodiment, a preset disorder processing is performed on the random redundant period of any one of the first encryption path and the second encryption path with the same encryption operation period, and then the encryption operation is performed using the preset disordered redundant period to ensure that the output times of the two encryption paths are different. Thereby effectively reducing the probability of injecting the same error synchronously in the two encryption paths and further enhancing the anti-attack ability of the encryption method.
[0079] It should be noted that the preset disorder processing can be an inversion processing or other processing methods for scrambling the order. The preset disorder processing is used to make the encryption operation periods of the first encryption path and the second encryption path different.
[0080] When the encryption operation periods of the first encryption path and the second encryption path are different, the backtracking verification step is continued.
[0081] According to a specific implementation manner of an embodiment of the present application, the first encryption path includes a first random mask, the second encryption path includes a second random mask, and the first random mask and the second random mask are different;
[0082] The steps of respectively using the first encryption path and the second encryption path to perform an encryption operation on the data to be encrypted to obtain a first encryption result include:
[0083] Performing a preset number of rounds of encryption processing on the data to be encrypted according to the first random mask and the first random redundant period to obtain a first output;
[0084] Performing a preset number of rounds of encryption processing on the data to be encrypted according to the second random mask and the second random redundant period to obtain a second output;
[0085] Save the first output and the second output to obtain the first encryption result.
[0086] In a specific embodiment, the first random mask and the second random mask can be random numbers or other random elements, and are adaptively replaced according to the actual application scenario.
[0087] As Figure 2 shown, the first random mask is the random number 1, and the second random mask is the random number 2.
[0088] When performing the first-round encryption operation in the encryption path, different random masks are introduced on two encryption paths respectively. The first random mask is encrypted along with the complete encryption path of the first encryption path, and a first output Out1 with the random number 1 is obtained.
[0089] The second random mask is encrypted along with the complete encryption path of the second encryption path, and a second output Out2 with the random number 2 is obtained.
[0090] Specifically, the encrypted random number 1' can be obtained after the random number 1 is processed by encryption operation, the encrypted random number 2' can be obtained after the random number 2 is processed by encryption operation, and the random number 1' and the random number 2' can be used for subsequent error diffusion steps.
[0091] By introducing different random masks in the encryption processes of the first encryption path and the second encryption path, it is possible to effectively avoid injecting the same error synchronously on the first encryption path and the second encryption path, thereby ensuring the accuracy of the backtracking verification.
[0092] According to a specific implementation manner of an embodiment of the present application, both the first output and the second output include round keys, intermediate ciphertext data, and target ciphertext data. The steps for performing backtracking verification on the first encryption result include:
[0093] Decrypt the ciphertext data in the first output and the second output for a preset number of rounds according to the corresponding round keys to obtain the verification data for the corresponding encryption path;
[0094] If the verification data is the same as the corresponding intermediate ciphertext data, the corresponding encryption path does not include an error injection attack;
[0095] If the verification data is different from the corresponding intermediate ciphertext data, the corresponding encryption path includes an error injection attack.
[0096] In a specific embodiment, the backtracking verification step is a decryption operation step.
[0097] In this embodiment, the backtracking verification steps for the first encryption path and the second encryption path are the same.
[0098] The number of operation rounds of the decryption operation step is the same as that of the encryption step to obtain the decrypted plaintext data.
[0099] As Figure 2 shown, both the first encryption path and the second encryption path perform 32 rounds of decryption operation steps to implement the encryption verification of the first encryption result.
[0100] Specifically, the backtracking verification step can obtain the first round key, the first intermediate ciphertext data, and the first target ciphertext data based on the first output Out1 sent by the first encryption path. After decrypting the first target ciphertext data based on the first round key, the corresponding first decrypted plaintext is obtained as the verification data. Compare the first intermediate ciphertext data and the first decrypted plaintext. If the first intermediate ciphertext data and the first decrypted plaintext are the same, it means that there is no error injection attack in the first encryption path.
[0101] Based on the second output sent by the second encryption path, obtain the second round key, the second intermediate ciphertext data, and the second target ciphertext data. After decrypting the second target ciphertext data based on the second round key, the corresponding second decrypted plaintext is obtained as the verification data. Compare the second intermediate ciphertext data and the second decrypted plaintext. If the second intermediate ciphertext data and the second decrypted plaintext are the same, it means that there is no error injection attack in the second encryption path.
[0102] Specifically, the intermediate ciphertext data is the intermediate data generated during the encryption operation according to the round function.
[0103] If there is a difference between the verification data and the original data in the encryption path, it means that there is an error injection attack in the encryption path at this time. At this time, set an error flag bit Error in the first encryption result so that the subsequent error diffusion step can identify the attack according to the error flag bit Error.
[0104] Specifically, the error flag bit is a high-level signal, that is, when Error = 1, it means that there is at least one error injection attack in the first encryption path and the second encryption path.
[0105] In a specific embodiment, for the encryption situation without error injection attack, the first encryption result can be directly used as the output of the encryption method in this embodiment.
[0106] For the encryption situation including error injection attack, it is also necessary to further perform error diffusion processing on the first encryption result.
[0107] According to a specific implementation manner of an embodiment of the present application, the step of processing the first encryption result according to the random infection model includes:
[0108] Detect whether the first encryption path and the second encryption path include an error injection attack;
[0109] If the detection result is that at least one of the first encryption path and the second encryption path includes an error injection attack, send the first encryption result to the random infection model.
[0110] In a specific embodiment, after obtaining the first output Out1 and the second output Out2, an exclusive OR operation is performed on the first output Out1 and the second output Out2, and the same error injection judgment parameter Δ can be obtained.
[0111] In a specific embodiment, when the error injection judgment parameter Δ is 0, it means that no error is injected in both encryption paths or the same error is synchronously injected at the same position in both encryption paths; when the error injection judgment parameter Δ is not 0, it means that an error is injected in at least one of the two encryption paths.
[0112] In the encryption method proposed in this embodiment, when it is detected that there is at least one injection error in the first encryption path or the second encryption path, the first output and the second output are directly sent to the random infection model, so that the random infection model can perform diffusion processing on the error.
[0113] It should be noted that as Figure 3 shown, when the error injection judgment parameter Δ is 0, this embodiment needs to further determine the specific value of the error flag bit Error in the first encryption result. If the error flag bit Error = 0, it means that both encryption paths pass the backtracking check, that is, no error injection is included in both encryption paths, and the next encryption operation can be performed.
[0114] If the error flag bit Error = 1, it means that the same error is synchronously injected at the same position in both paths. At this time, Δ is respectively exclusive ORed with the random number 1' and the random number 2' to obtain the intermediate parameter M1 and the intermediate parameter M2, and then M1 and M2 are exclusive ORed to obtain the random infection model startup parameter Δ1, where the random number 1' is the parameter obtained after the random number 1 undergoes an encryption operation, and the random number 2' is the parameter obtained after the random number 2 undergoes an encryption operation. The random number 1' and the random number 2' are different parameters.
[0115] In summary, when the error injection judgment parameter Δ is not 0, or when the error injection judgment parameter Δ is 0 and the random infection model startup parameter Δ1 is not 0, it is necessary to use the random infection model to process the first encryption result to obtain a second encryption result with error diffusion.
[0116] Step S104, if the result of the backtracking verification includes an error injection attack, output the second encryption result, where the second encryption result includes ciphertext data obtained by processing the first encryption result according to the random infection model.
[0117] In a specific embodiment, after using the random infection model to perform error diffusion on the first encryption result, a corresponding second encryption result can be obtained. The errors in the second encryption result are scattered in random bytes of the ciphertext data, making it impossible for an attacker to perform a round key attack on the ciphertext data.
[0118] According to a specific implementation manner of an embodiment of the present application, the step of processing the first encryption result according to the random infection model further includes:
[0119] Perform a random byte permutation process on the first encryption result to obtain a permutation encryption result;
[0120] Perform a preset random process on the permutation encryption result to obtain the second encryption result.
[0121] In a specific embodiment, a random byte permutation algorithm is set in the random infection model. The data in the first encryption result can be regarded as an n×n byte matrix, where n is a positive integer.
[0122] For example, when processing a 4×4 byte matrix, the specific execution manner of the random byte permutation algorithm can be to replace the byte at the [x, y] position with the byte at the [(x + random) mod 4, (y + random) mod 4] position, where x, y ∈ {0, 1, 2, 3}; random ∈ {0, 1, 2, 3}.
[0123] After the random byte permutation process, it is difficult to determine which byte in the first encryption result is replaced by which byte in the matrix, so as to disperse the error to other bytes at different positions to complete the error diffusion process.
[0124] According to a specific implementation manner of an embodiment of the present application, the step of performing a preset random process on the permutation encryption result to obtain the second encryption result includes:
[0125] Perform a preset random process on the permutation encryption result and a third random mask to obtain the second encryption result.
[0126] In a specific embodiment, as Figure 3 shown, in the random infection model, the error diffusion of the first encryption result can be further enhanced by further introducing a third random mask.
[0127] Specifically, the third random mask is the random number 3.
[0128] Perform an exclusive OR operation on the random number 3 and the permutation encryption result to complete the random infection of the first encryption result, obtaining the error diffusion result F(Δ1) or F(Δ).
[0129] After adding the random number 3, even if the first encryption path or the second encryption path repeats the encryption operation, and the positions and values of the errors injected by the repeated encryption operation are the same, the error diffusion results output by the random infection model will not be the same.
[0130] Perform an exclusive OR operation on the error diffusion result and the first output Out1 and the second output Out2 respectively to obtain the corresponding second encryption result.
[0131] The ciphertext and round key in the second encryption result include randomly scattered errors, so that an attacker cannot obtain the encrypted information and its round key by injecting errors.
[0132] Step S105, if the result of the backtracking check does not include an error injection attack, output the first encryption result.
[0133] In a specific embodiment, if the encryption results output by the first encryption path and the second encryption path both pass the backtracking check, that is, there is no error injection attack in both encryption paths, directly output the first encryption result as ciphertext data, and the first encryption result includes encrypted ciphertext and a key.
[0134] The encryption method for resisting error injection attacks proposed in this embodiment encrypts the data to be encrypted by setting two identical paths respectively, and adds random redundancy periods to the two encryption paths respectively, and uses the randomness of the redundancy periods to confuse the cryptographic algorithm, so as to effectively resist the injection of faulty clock errors.
[0135] By introducing different random mask values in the encryption path and redundant rounds, it is possible to effectively resist the attacker from synchronously injecting the same error at the same position in the encryption path. After the two encryption paths complete the encryption operation steps, they both go through a backtracking check, and the decrypted output result and the encrypted input plaintext are verified for consistency, which can achieve self-checking of the encryption method to improve the accuracy of the encryption method. By introducing a random diffusion function, the errors injected by the attacker are dispersed to other bytes, so that the error injection points in the ciphertext data cannot be confirmed. Even if the attacker obtains the ciphertext data with injected errors, they cannot crack the ciphertext information and its round keys of the ciphertext data.
[0136] Reference Figure 4 , which is a schematic diagram of the device modules of an encryption device 400 for resisting error injection attacks provided by an embodiment of the present application. The encryption device 400 for resisting error injection attacks provided by an embodiment of the present application is as Figure 4 shown, and the encryption device 400 for resisting error injection attacks includes:
[0137] An acquisition module 401, configured to acquire data to be encrypted;
[0138] An encryption module 402, configured to perform encryption operations on the data to be encrypted respectively using a first encryption path and a second encryption path to obtain a first encryption result;
[0139] A verification module 403, configured to perform backtracking verification on the first encryption result according to the encryption operation cycles of the first encryption path and the second encryption path;
[0140] A first execution module 404, configured to, if the result of the backtracking verification includes an error injection attack, output a second encryption result, where the second encryption result includes ciphertext data obtained by processing the first encryption result according to a random infection model;
[0141] A second execution module 405, configured to, if the result of the backtracking verification does not include an error injection attack, output the first encryption result.
[0142] In addition, an embodiment of the present application also provides an electronic device, which includes a processor and a memory. The memory stores a computer program, and when the computer program runs on the processor, it executes the encryption method for resisting error injection attacks in the foregoing embodiments.
[0143] An embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored, and when the computer program runs on a processor, it executes the encryption method for resisting error injection attacks in the foregoing embodiments.
[0144] For the specific implementation processes of the encryption device, electronic device, and computer-readable storage medium for resisting error injection attacks mentioned in the above embodiments, reference may be made to the specific implementation processes of the above method embodiments, which will not be elaborated herein one by one.
[0145] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and structure diagrams in the accompanying drawings show the possible architectures, functions, and operations of the devices, methods, and computer program products according to multiple embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, program segment, or part of the code, and the module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the structure diagram and / or flowchart, as well as the combination of blocks in the structure diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0146] In addition, in each embodiment of the present invention, the various functional modules or units can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part.
[0147] If the described functions are implemented in the form of software functional modules and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a smart phone, personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs, etc., which can store program codes.
[0148] The above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily conceive of changes or substitutions, which should all be covered within the protection scope of the present invention.
Claims
1. An encryption method for resisting error injection attacks, characterized in that, The encryption method includes: Obtain data to be encrypted; Perform encryption operations on the data to be encrypted using a first encryption path and a second encryption path respectively to obtain a first encryption result; wherein, the second encryption path serves as a redundant encryption path for the first encryption path; Perform retrospective verification on the first encryption result according to the encryption operation periods of the first encryption path and the second encryption path; If the result of the retrospective verification includes an error injection attack, output a second encryption result, where the second encryption result includes ciphertext data obtained by processing the first encryption result according to a random infection model; the random infection model is used to perform diffusion processing on errors; If the result of the retrospective verification does not include an error injection attack, output the first encryption result; The step of performing encryption operations on the data to be encrypted using a first encryption path and a second encryption path respectively to obtain a first encryption result includes: Perform encryption operations on the data to be encrypted for a preset number of rounds using the first encryption path and a first random redundancy period to obtain a first output, and perform encryption operations on the data to be encrypted for a preset number of rounds using the second encryption path and a second random redundancy period to obtain a second output; Save the first output and the second output to obtain the first encryption result; The operation processes of the first encryption path and the second encryption path both include corresponding random redundancy periods; The step of performing retrospective verification on the first encryption result according to the encryption operation periods of the first encryption path and the second encryption path includes: Compare whether the first encryption operation period of the first encryption path is the same as the second encryption operation period of the second encryption path; If the first encryption operation period is different from the second encryption operation period, perform retrospective verification on the first encryption result; If the first encryption operation period is the same as the second encryption operation period, perform a preset scrambling process on the random redundancy period of any encryption path, and perform encryption according to the processed random redundancy period until the first encryption operation period and the second encryption operation period are different; Both the first output and the second output include round keys, intermediate ciphertext data, and target ciphertext data. The step of performing retrospective verification on the first encryption result includes: Perform decryption operations on the target ciphertext data in the first output and the second output for a preset number of rounds according to the corresponding round keys to obtain verification data for the corresponding encryption path; If the verification data is the same as the corresponding intermediate ciphertext data, the corresponding encryption path does not include an error injection attack; If the verification data is different from the corresponding intermediate ciphertext data, the corresponding encryption path includes an error injection attack.
2. The encryption method according to claim 1, wherein The first encryption path includes a first random mask, and the second encryption path includes a second random mask, and the first random mask and the second random mask are different; The step of performing encryption operations on the data to be encrypted for a preset number of rounds using the first encryption path and a first random redundancy period to obtain a first output includes: Performing encryption processing on the data to be encrypted for a preset number of rounds according to the first random mask and the first random redundancy period to obtain a first output; The step of performing encryption operations on the data to be encrypted for a preset number of rounds by using the second encryption path and the second random redundancy period to obtain a second output includes: Performing encryption processing on the data to be encrypted for a preset number of rounds according to the second random mask and the second random redundancy period to obtain a second output.
3. The encryption method according to claim 1, wherein The step of processing the first encryption result according to the random infection model includes: Detecting whether the first encryption path and the second encryption path include error injection attacks; When the detection result is that at least one of the first encryption path and the second encryption path includes an error injection attack, sending the first encryption result to the random infection model.
4. The encryption method according to claim 3, characterized in that, The step of processing the first encryption result according to the random infection model further includes: Performing random byte permutation processing on the first encryption result to obtain a permutation encryption result; Performing preset random processing on the permutation encryption result to obtain the second encryption result.
5. The encryption method according to claim 4, characterized in that, The step of performing preset random processing on the permutation encryption result to obtain the second encryption result includes: Performing preset logical processing on the permutation encryption result and a third random mask to obtain the second encryption result.
6. An encryption device for resisting error injection attacks, characterized in that, An encryption device for performing the encryption method for resisting error injection attacks according to claim 1, the encryption device includes: An acquisition module, configured to acquire data to be encrypted; An encryption module, configured to perform encryption operations on the data to be encrypted by using a first encryption path and a second encryption path respectively to obtain a first encryption result; wherein, the second encryption path serves as a redundant encryption path of the first encryption path; A verification module, configured to perform backtracking verification on the first encryption result according to the encryption operation periods of the first encryption path and the second encryption path; A first execution module, configured to output a second encryption result if the result of the backtracking verification includes an error injection attack, and the second encryption result includes ciphertext data obtained by processing the first encryption result according to the random infection model; the random infection model is used for diffusing errors; A second execution module, configured to output the first encryption result if the result of the backtracking verification does not include an error injection attack; The encryption module is further configured to perform encryption operations on the data to be encrypted by using the first encryption path to obtain a first output, and perform encryption operations on the data to be encrypted by using the second encryption path to obtain a second output; saving the first output and the second output to obtain the first encryption result.
7. An electronic device, characterized in that, The electronic device includes a processor and a memory, and the memory stores a computer program, and when the computer program runs on the processor, it executes the encryption method for resisting error injection attacks according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, A computer-readable storage medium stores a computer program, and when the computer program runs on a processor, it executes the encryption method for resisting error injection attacks according to any one of claims 1 to 5.
Citation Information
Patent Citations
AES encryption method for resisting differential power attacks
CN101729241A
Random infection fault attack prevention method based on INS network
CN106130712A