Analysis Method, Device and Electronic Device for Encryption Program

By reversely analyzing the output results of the encryption program, combining the running trajectory and selection function, the correct key of the encryption program is determined, which solves the problem of low analysis efficiency of encryption program in the prior art and achieves more efficient key acquisition.

CN115361206BActive Publication Date: 2025-05-30HILLSTONE NETWORKS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210995129.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-18
Publication Date
2025-05-30
Estimated Expiration
2042-08-18

AI Technical Summary

Technical Problem

The prior art is inefficient in analyzing encryption programs, especially after the encryption program performs external input encoding or adds redundant wheels in the first round, the binary instrumentation tool cannot accurately obtain the key.

Method used

By obtaining the N running trajectories of the encryption program and N output results, the K keys of the Mth byte in the output are exhaustively output, and the output results are reversely analyzed based on the pre-constructed selection function and key, the correlation between the simulated value and the intermediate value is determined, and the correct key of the Mth byte is finally determined.

Benefits of technology

This method can avoid the influence of external input encoding and redundant wheel obfuscation components, improve the efficiency of obtaining correct keys, and improve the efficiency of encryption program analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115361206B_ABST
    Figure CN115361206B_ABST
Patent Text Reader

Abstract

The present application discloses an analysis method, device, and electronic device for an encryption program. Among them, the method includes: obtaining N running trajectories and N output results of the encryption program, where the output result is the file encrypted by the encryption program, each output result corresponds to a running trajectory, the output result includes at least one byte, and the running trajectory at least contains J intermediate values generated during the operation of the encryption program; exhaustively enumerating K keys corresponding to the Mth byte in the output result; performing reverse analysis on the output result according to a pre-constructed selection function and the key to obtain a simulated value, where the simulated value is the predicted intermediate value predicted by the selection function according to the output result and the key; determining the correlation between the simulated value and the intermediate value; and determining the correct key for the Mth byte according to the correlation. The present application solves the technical problem of low analysis efficiency of the encryption program in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security, and in particular, to a method, an apparatus, and an electronic device for analyzing an encryption program. Background Art

[0002] Currently, the main method for analyzing an encryption program at the software level is to use binary instrumentation tools such as DBI (Dynamic Binary Instrumentation) to obtain the memory read and write traces of the encryption program during operation, and perform a byte-by-byte key exhaustion analysis on the first round of the cryptographic algorithm, and then extract the key.

[0003] However, during the process of obtaining the key through the binary instrumentation tool, the input of the encryption program needs to be unprotected. In other words, it is necessary to ensure that the encryption program is not encoded by an external input encoding component, and the first round of the cryptographic algorithm in the encryption program is not affected by confusion (redundant rounds, confusion rounds), etc. Otherwise, the binary instrumentation tool cannot obtain the correct password.

[0004] However, in recent years, with the increasing protection of the first round of cryptographic algorithms, coding techniques and anti-debugging techniques have been applied to protect encryption programs. For example: by performing external input encoding on the encryption program to hide the real input of the encryption program, resulting in the binary instrumentation tool being unable to perform side-channel attacks, or adding redundant rounds and other confusion components in the first round of the cryptographic algorithm, which will also cause the binary instrumentation tool to be unable to extract the key or the extracted key to be a false key.

[0005] For the above problems, no effective solution has been proposed yet. Summary of the Invention

[0006] Embodiments of the present application provide a method, an apparatus, and an electronic device for analyzing an encryption program, so as to at least solve the technical problem of low analysis efficiency of the encryption program in the prior art.

[0007] According to one aspect of the embodiments of the present application, a method for analyzing an encryption program is provided, including: obtaining N running traces and N output results of the encryption program, where the output result is a file encrypted by the encryption program, each output result corresponds to one running trace, the output result includes at least one byte, and the running trace at least includes J intermediate values generated during the operation of the encryption program; exhausting K keys corresponding to the Mth byte in the output result; performing reverse analysis on the output result according to a pre-constructed selection function and the key to obtain a simulated value, where the simulated value is a predicted intermediate value predicted by the selection function according to the output result and the key, the K keys correspond to K simulated values, and each key corresponds to one simulated value; determining the correlation degree between the simulated value and the intermediate value; and determining the correct key of the Mth byte according to the correlation degree.

[0008] Furthermore, the analysis method of the encryption program further includes: Step 1, obtaining an unencrypted file; Step 2, running the encryption program according to the emulator and encrypting the unencrypted file according to the encryption program to obtain a running track and an output result, where the emulator is an application program that calls the encryption program to perform a simulated encryption operation; Step 3, repeatedly executing Step 1 and Step 2 N times to obtain N running tracks and N output results.

[0009] Furthermore, the analysis method of the encryption program further includes: determining that the simulated value is the first bit sequence and the intermediate value is the second bit sequence, where both the first bit sequence and the second bit sequence are sequences composed of the numerical value 1 and / or the numerical value 0; when the value at the C position of the first bit sequence is the numerical value 0, determining that the value at the C position of the second bit sequence is the value in the first set; when the value at the C position of the first bit sequence is the numerical value 1, determining that the value at the C position of the second bit sequence is the value in the second set; determining the correlation degree according to the first set and the second set.

[0010] Furthermore, the analysis method of the encryption program further includes: determining that the number of numerical values 1 in the first set is the first quantity, and the number of numerical values 1 in the second set is the second quantity; determining that the total number of all numerical values in the first set is the third quantity, and the number of all numerical values in the second set is the fourth quantity; calculating the ratio of the first quantity to the third quantity to obtain the first ratio; calculating the ratio of the second quantity to the fourth quantity to obtain the second ratio; determining the correlation degree according to the first ratio and the second ratio.

[0011] Furthermore, the analysis method of the encryption program further includes: calculating the absolute value of the first ratio and the second ratio; determining the absolute value of the difference to obtain the correlation degree, where J intermediate values correspond to J correlation degrees, and each intermediate value corresponds to a correlation degree.

[0012] Furthermore, the analysis method of the encryption program further includes: detecting whether there is at least one correlation degree greater than a preset threshold among the J correlation degrees corresponding to the simulated value; in the case where there is at least one correlation degree greater than the preset threshold among the J correlation degrees corresponding to the simulated value, determining that the key corresponding to the simulated value is the candidate key for the Mth byte; determining the correct key for the Mth byte according to the candidate key.

[0013] Furthermore, the analysis method of the encryption program further includes: determining all candidate keys from N*K keys, where the N*K keys are all the keys corresponding to the Mth byte in the N output results; sorting all the candidate keys according to the correlation degree of each candidate key to obtain a sorting result; determining the candidate key with the highest correlation degree as the correct key for the Mth byte according to the sorting result.

[0014] According to another aspect of the embodiments of the present application, there is also provided an analysis device for an encryption program, including: an acquisition module, configured to acquire N running trajectories and N output results of the encryption program, where the output result is a file encrypted by the encryption program, each output result corresponds to a running trajectory, the output result includes at least one byte, and the running trajectory at least includes J intermediate values generated by the encryption program during the operation process; an exhaustive module, configured to exhaust K keys corresponding to the M-th byte in the output result; an analysis module, configured to perform reverse analysis on the output result according to a pre-constructed selection function and the key to obtain a simulated value, where the simulated value is a predicted intermediate value predicted by the selection function according to the output result and the key, the K keys correspond to K simulated values, and each key corresponds to a simulated value; a first determination module, configured to determine the correlation between the simulated value and the intermediate value; a second determination module, configured to determine the correct key of the M-th byte according to the correlation.

[0015] According to another aspect of the embodiments of the present application, there is also provided a computer-readable storage medium, in which a computer program is stored, where the computer program is configured to execute the above-mentioned analysis method of the encryption program when running.

[0016] According to another aspect of the embodiments of the present application, there is also provided an electronic device, the electronic device includes one or more processors; a storage device, configured to store one or more programs, when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement a program for running, where the program is configured to execute the above-mentioned analysis method of the encryption program when running.

[0017] In the technical solution of the present application, by adopting the method of performing reverse analysis on the output result of the encryption program according to the selection function and the key, first, N running trajectories and N output results of the encryption program are acquired, then the K keys corresponding to the M-th byte in the output result are exhausted, then the output result is reversely analyzed according to the pre-constructed selection function and the key to obtain a simulated value, and the correlation between the simulated value and the intermediate value is determined, and finally the correct key of the M-th byte is determined according to the correlation. Wherein, the output result is a file encrypted by the encryption program, each output result corresponds to a running trajectory, the output result includes at least one byte, and the running trajectory at least includes J intermediate values generated by the encryption program during the operation process; the simulated value is a predicted intermediate value predicted by the selection function according to the output result and the key, the K keys correspond to K simulated values, and each key corresponds to a simulated value.

[0018] As can be seen from the above, the present application performs reverse analysis on the output result according to the pre-constructed selection function and the key pairs obtained by exhaustive search, so as to reversely simulate the intermediate value generated by the password algorithm of the encryption program when encrypting a file. Since the present application uses the reverse analysis method, it can avoid the problem of being unable to accurately obtain the correct key due to the external input encoding of the encryption program. At the same time, since the last round of the encryption process is analyzed during the reverse analysis, it can also avoid the problem of being unable to extract the correct key due to the addition of confusion components such as redundant rounds in the first round of the password algorithm, thereby improving the acquisition efficiency of the correct key and further enhancing the analysis efficiency of the encryption program.

[0019] Thus, through the technical solution of the present application, the purpose of ensuring the acquisition of the correct key of the encryption program is achieved, the effect of improving the acquisition efficiency of the correct key is realized, and the technical problem of low analysis efficiency of the encryption program in the prior art is solved. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0021] Figure 1 is a flowchart of an optional encryption program analysis method according to an embodiment of the present application;

[0022] Figure 2 is a schematic diagram of an optional encryption program analysis method according to an embodiment of the present application;

[0023] Figure 3 is a flowchart of an optional method for obtaining a running track according to an embodiment of the present application;

[0024] Figure 4 is a flowchart of an optional method for generating a simulation value according to an embodiment of the present application;

[0025] Figure 5 is a flowchart of another optional method for generating a simulation value according to an embodiment of the present application;

[0026] Figure 6 is a flowchart of an optional method for classifying a running track according to an embodiment of the present application;

[0027] Figure 7 is a schematic structural diagram of an optional encryption program analysis system according to an embodiment of the present application;

[0028] Figure 8 is a schematic diagram of an optional encryption program analysis device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of this application.

[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data used in appropriate cases can be interchanged so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0031] In addition, it should also be noted that the relevant information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set between this system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and after receiving the consent information feedback from the aforementioned users or institutions, the relevant information can be obtained.

[0032] Embodiment 1

[0033] According to the embodiments of this application, an embodiment of a method for analyzing an encryption program is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.

[0034] Optionally, an encryption program analysis system can be used as the execution subject of the encryption program analysis method in the embodiments of this application.

[0035] Figure 1 is a flowchart of an optional encryption program analysis method according to the embodiments of this application. As Figure 1 shown, the method includes the following steps:

[0036] Step S101: Obtain N running trajectories and N output results of the encryption program.

[0037] In step S101, the output result is the file encrypted by the encryption program. Each output result corresponds to a running trajectory. The output result includes at least one byte, and the running trajectory contains at least J intermediate values generated during the operation of the encryption program.

[0038] Optionally, the above encryption program is a binary program. The above running trajectory is used to characterize the encryption process when the encryption program encrypts a file. In other words, the running trajectory can be understood as a record of the encryption process, where the encryption trajectory contains at least J intermediate values generated during the operation of the encryption program. It should be noted that the above N and J can be understood as at least one. The value of N and the value of J can be the same or different, and are specifically set according to the actual situation. This application does not make too many limitations here.

[0039] In addition, the above intermediate value can be understood as the intermediate state of the encryption process. For example, when the encryption program encrypts plaintext A into ciphertext A, it may go through multiple conversions. For example, plaintext A is successively converted into ciphertext 1, ciphertext 2, ciphertext 3, and ciphertext A. Among them, ciphertext 1, ciphertext 2, and ciphertext 3 in the intermediate process are intermediate states.

[0040] Step S102: Exhaustively list K keys corresponding to the Mth byte in the output result.

[0041] Optionally, the output result includes at least one byte, where the Mth byte can be any one of the at least one byte. The encryption program analysis system can obtain the K passwords corresponding to the Mth byte by exhaustive means. Since the key space is 256 choices from 0 to 255, the value of K in this application can be determined to be at most 256. For the convenience of description, the Mth byte can be represented by k h which means that k h represents the single-byte key obtained by exhaustive listing.

[0042] Step S103: Perform reverse analysis on the output result according to the pre-constructed selection function and the key to obtain a simulated value.

[0043] In step S103, the simulated value is the predicted intermediate value predicted by the selection function according to the output result and the key. The K keys correspond to K simulated values, and each key corresponds to one simulated value.

[0044] Specifically, from the perspective of the result, the function of the selection function is to divide the running trajectory into two different sets for later analysis of the running trajectory. From the perspective of the motivation, it is to be able to mathematically simulate the key intermediate values generated during the running of the binary program. Different from the DBI analysis technology in the prior art, the selection function of the present application does not depend on the input, but depends on the output result of the binary program, and then performs reverse analysis on the encryption program according to the output result.

[0045] Among them, the selection function is as follows:

[0046]

[0047] Among them, o e represents the output result of the binary program, and this output result can be obtained together when the encryption program analysis system obtains the running trajectory. inv S Box is the inverse operation of the S-box of the cryptographic algorithm. k h represents the brute-force single-byte key, and the key space is 256 choices from 0 to 255. j represents the j-th bit of the generated intermediate value, so the value range is 0 or 1.

[0048] In addition, the meaning represented by this selection function is: according to the output result o e and by brute-forcing the key k h to predict the input information of the last S-box of the binary program (encryption program) (that is, the intermediate value of the last round). It should be noted that assuming k h is the correct key, then the output result of the selection function is the input information of the last S-box of the binary program. Assuming k h is the wrong key, then the output result of the selection function has no association with the input of the last S-box of the binary cryptographic program.

[0049] Step S104, determine the correlation degree between the simulated value and the intermediate value.

[0050] In step S104, the above-mentioned correlation degree is used to characterize the correlation between the simulated value and the intermediate value. The greater the correlation degree, the stronger the correlation between the two. In other words, if the correlation degree between a simulated value and an intermediate value is greater, it means that the simulated value is closer to the intermediate value and the similarity between the two is higher.

[0051] Step S105, determine the correct key of the M-th byte according to the correlation degree.

[0052] In step S105, since a total of N running trajectories and N output results are obtained, and the M-th byte of each output result corresponds to K keys, therefore, for the M-th byte, the N output results correspond to a total of N*K keys. On this basis, the encryption program analysis system can determine the correct key from the N*K keys according to the relevance. For example, the key with the highest relevance is taken as the correct key.

[0053] Based on the content of the above steps S101 to S105, it can be seen that in the technical solution of this application, by using the method of reverse analysis of the output result of the encryption program according to the selection function and the key, first, N running trajectories and N output results of the encryption program are obtained, then the K keys corresponding to the M-th byte in the output result are enumerated, and then the output result is reversely analyzed according to the pre-constructed selection function and the key to obtain a simulated value, and the relevance between the simulated value and the intermediate value is determined. Finally, the correct key of the M-th byte is determined according to the relevance. Among them, the output result is the file encrypted by the encryption program, each output result corresponds to a running trajectory, the output result includes at least one byte, and the running trajectory contains at least J intermediate values generated by the encryption program during the operation process; the simulated value is the predicted intermediate value predicted by the selection function according to the output result and the key, the K keys correspond to K simulated values, and each key corresponds to a simulated value.

[0054] From the above content, it can be seen that this application reversely analyzes the output result according to the pre-constructed selection function and the keys obtained by exhaustive search, and can reversely simulate the intermediate value generated by the encryption algorithm of the encryption program when encrypting the file. Since this application is a reverse analysis method, it can avoid the problem that the correct key cannot be accurately obtained due to the external input encoding of the encryption program. At the same time, since the last round of the encryption process is analyzed during the reverse analysis, it can also avoid the problem that the correct key cannot be extracted due to the addition of confusing components such as redundant rounds in the first round of the encryption algorithm, thereby improving the acquisition efficiency of the correct key, and further improving the analysis efficiency of the encryption program.

[0055] Thus, through the technical solution of this application, the purpose of ensuring the acquisition of the correct key of the encryption program is achieved, the effect of improving the acquisition efficiency of the correct key is realized, and further the technical problem of low analysis efficiency of the encryption program in the prior art is solved.

[0056] In an alternative embodiment, Figure 2 shows a schematic diagram of an analysis method for an encryption program according to an embodiment of this application, as Figure 2 shown, the analysis method of the encryption program is mainly divided into four parts, namely collecting the running trajectory of the encryption program, constructing a selection function, analyzing the running trajectory, and determining the correct key.

[0057] Optionally, when collecting the running trace of the encryption program, the encryption program analysis system mainly performs the following steps: Step 1, obtain the unencrypted file; Step 2, run the encryption program according to the emulator and encrypt the unencrypted file according to the encryption program to obtain the running trace and the output result, where the emulator is an application program that calls the encryption program to perform simulated encryption operations; Step 3, loop and execute Step 1 and Step 2 N times to obtain N running traces and N output results.

[0058] Specifically, the above emulator is an automated password program simulation device constructed based on the Qiling framework. This device mainly consists of an input-output adapter, an anti-debugging bypass component, a password program simulation component, and an energy trace acquisition component. Through simple configuration, it can automatically simulate the password program and collect the running trace. Among them, the anti-debugging bypass component in this device is used to avoid anti-debugging detection.

[0059] It should be noted that the Qiling framework is a cross-platform, lightweight emulator that supports multiple CPU architectures. This lightweight emulator can use hook functions for any instruction. Through the hook functions, it can implement the functions of bypassing the anti-debugging component and the random number component, and can also obtain the memory read and write traces during the running process of the encryption program.

[0060] It should be noted that traditional DBI analysis tools achieve monitoring of the running trace by instrumenting the binary programs executed in the operating system. However, this traditional method is easily interfered by anti-debugging.

[0061] In this application, using the CPU simulation framework (i.e., the Qiling framework), the emulator can directly extract instructions from the binary program and collect the running trace after simulated operation. Since it runs on a lightweight virtual machine, the collection of the running trace will no longer be in the monitoring mode, but directly collect the running trace in an active manner. This active collection method can collect the complete running trace.

[0062] In addition, the recorded running trace s e is a bit sequence, and the length of the sequence is related to the specific algorithm and filtering rule. Let the length of the sequence be X bits. When used, s e [i] represents the i-th bit of the bit sequence, where i < X.

[0063] Optionally, as Figure 3 shown, the process of the encryption program analysis system collecting the running trace by calling the emulator can be referred to as follows:

[0064] Step 1: Initialize the emulator. Among them, the initialization work of the emulator is mainly to start the emulator according to the configuration file.

[0065] Step 2: Initialize e and N, where e = 0 and N represents the number of running trajectories to be collected. Generally, 100 < N < 256. On the one hand, if N is too small, it may lead to inaccurate final key analysis. If N is too large, it will cause the space occupied by the running trajectories to be too large.

[0066] Step 3: Randomly select an input (i.e., an unencrypted file) and run the encryption program. Obtain the running trajectory through the corresponding interface of the simulator and record it as s e and record the output result of the simulator as o e .

[0067] Step 4: Increment e by 1.

[0068] Step 5: Repeat Step 3 and Step 4 until e > n, then stop and exit the virtual machine.

[0069] In an alternative embodiment, each running trajectory contains all intermediate values during the operation of the encryption program. There is a certain correlation between these real intermediate values and the simulated values generated by the selection function. When k h is the correct key, the simulated values generated by the selection function will have a strong correlation with the intermediate values hidden in the running trajectory. Conversely, if k h is not the correct key, the correlation is relatively low. This application combines the measurement method of Pearson correlation coefficient in statistics and uses the differential median method to calculate the Pearson correlation coefficient between the running trajectory and the selection function, that is, the correlation.

[0070] Specifically, the encryption program analysis system first determines that the simulated value is the first bit sequence and the intermediate value is the second bit sequence, where both the first bit sequence and the second bit sequence are sequences composed of the numerical value 1 or the numerical value 0. Then when the value at position C in the first bit sequence is 0, the encryption program analysis system determines that the value at position C in the second bit sequence is the value in the first set; when the value at position C in the first bit sequence is 1, the encryption program analysis system determines that the value at position C in the second bit sequence is the value in the second set. Finally, the encryption program analysis system determines the correlation according to the first set and the second set.

[0071] Optionally, the encryption program analysis system first determines that the number of 1s in the first set is the first quantity, and the number of 1s in the second set is the second quantity; determines that the total number of all numerical values in the first set is the third quantity, and the number of all numerical values in the second set is the fourth quantity. Then the encryption program analysis system calculates the ratio of the first quantity to the third quantity to obtain the first ratio; calculates the ratio of the second quantity to the fourth quantity to obtain the second ratio. Finally, the encryption program analysis system determines the correlation according to the first ratio and the second ratio.

[0072] Optionally, the encryption program analysis system calculates the difference between the first ratio and the second ratio, and determines the absolute value of the difference to obtain the relevance. Among them, the J intermediate values correspond to J relevances, and each intermediate value corresponds to one relevance.

[0073] Among them, Figure 4 shows a flowchart of generating a simulated value according to an embodiment of the present application. As Figure 4 shown, for the Mth byte of the output result, the encryption program analysis system first exhaustively guesses the key k h , and then for each k h calculates the simulated value according to the selection function Sel and the output result o e . Since k h ranges from 0 to 255, a total of 256 keys, so for each k h , the simulated value corresponding to each o e needs to be recorded.

[0074] As Figure 4 shown, Figure 4 the i in it is used to count the keys, representing the current i-th key. Starting from i = 0, the simulated value corresponding to each key k h is calculated respectively until after i is greater than 255, the calculation of the simulated value exits.

[0075] In addition, the encryption program analysis system will record the obtained simulated values in the three-dimensional table Sim

[256] [n][8]. Specifically, as Figure 5 shown, since the simulated value is in the format of 8-bit binary, therefore, the value of each bit is stored in the corresponding position according to the position. For example, Figure 5 the Sel(o e , k h , 0) represents the value of the first bit (the first bit among 8 bits) of the simulated value corresponding to the key k h , and Sel(o e , k h , 0) will be correspondingly stored in Sim[k h [e][0]. After all the simulated values corresponding to one output result are stored, the encryption program analysis system will continue to store the simulated values corresponding to the next output result until all the simulated values corresponding to N output results are stored in the three-dimensional table.

[0076] Optionally, after obtaining the simulated value, the encryption program analysis system will next classify the motion trajectory. First, the encryption program analysis system initializes two empty sets, namely the first set A 0 and the second set A 1, and then the encryption program analysis system fills the two sets with data according to the data in the Sim three-dimensional table. The specific method is as Figure 6 shown. For each k h , the running trajectory s e of each bit s e [i] is classified. When flag = Sim[k h [e][j] = 1, the value of v = s e [i] enters the second set A 1 . When flag = Sim[k h [e][j] = 0, the value of s e [i] enters the first set A 0 . After all the running trajectories of the i-th bit are classified, the averages of sets A 0 , A 1 are calculated respectively calculate their differences and save the results into the three-dimensional table M[k h [j][i].

[0077] Among them, Table 1 shows a schematic table for classifying motion trajectories.

[0078] Table 1

[0079] Analog value Intermediate value A Intermediate value B 0 0 1 1 1 0 0 0 1 1 1 1 0 0 0 0 0 0 0 0 0

[0080] As shown in Table 1, according to the principle that in the intermediate values, which set each value is placed in depends on whether the simulated value at the corresponding position is 0 or 1, the value (0, 0, 0, 0, 0) in the intermediate value A is placed in the first set A 0 , and the value (1, 1) is placed in the second set A 1 . Therefore, for the intermediate value A, the average value of the first set A 0 is 0 (corresponding to the first ratio), and the average value of the second set A 1 is 1 (corresponding to the second ratio). The correlation degree is equal to the absolute value of the difference between the first ratio and the second ratio. Therefore, the correlation degree between the intermediate value A and the simulated value in Table 1 is 1.

[0081] Similarly, the value (1, 1, 0, 1, 0) in the intermediate value B is placed in the first set A 0 , and the value (0, 1) is placed in the second set A 1 . Therefore, for the intermediate value B, the average value of the first set A 0 is 3 / 5, and the average value of the second set A 1 is 1 / 2. The correlation degree is equal to the absolute value of the difference between 3 / 5 and 1 / 2. Therefore, the correlation degree between the intermediate value B and the simulated value in Table 1 is 0.1.

[0082] In an alternative embodiment, the encryption program analysis system detects whether there is at least one relevance greater than a preset threshold among the J relevances corresponding to the analog value. In the case where there is at least one relevance greater than the preset threshold among the J relevances corresponding to the analog value, the key corresponding to the analog value is determined as the candidate key for the M-th byte, and the correct key for the M-th byte is determined according to the candidate key.

[0083] Optionally, the above preset threshold can be set customarily. Generally speaking, if the relevance is between 0.7 and 1, it indicates a strong correlation between the analog value and the intermediate value; if the relevance is below 0.3, it indicates that there is no correlation between the analog value and the intermediate value. Therefore, the preset threshold can be set to 0.7.

[0084] In an alternative embodiment, the encryption program analysis system determines all candidate keys from N*K keys, where the N*K keys are all the keys corresponding to the M-th byte in the N output results. Then, the encryption program analysis system sorts all the candidate keys according to the relevance of each candidate key to obtain a sorting result, and determines the candidate key with the highest relevance as the correct key for the M-th byte according to the sorting result.

[0085] Optionally, after the encryption program analysis system calculates the relevance between all the analog values corresponding to k h and the running track, the encryption program analysis system will obtain a complete three-dimensional array M

[256] [8][m]. On this basis, the encryption program analysis system expands the two-dimensional array represented by M[k h , counts the number of keys with a relevance greater than the preset threshold of 0.7, and stores these keys in the array Corr[k h . Finally, the encryption program analysis system checks the key with the highest relevance in the array Corr[k h as the correct key for the M-th byte. It is easy to note that after the correct keys for all bytes are determined, the encryption program analysis system can obtain the round keys of the encryption program. h In an alternative embodiment,

[0086] shows a schematic structural diagram of an encryption program analysis system. As shown in Figure 7 wherein, the encryption program analysis system includes: an initialization module, a program simulation running module, a running track receiving module, and a running track analysis module. Figure 7 As shown in

[0087] Specifically, the initialization module is the first module of the encryption program analysis system. Its main functions are to generate the Qiling simulator through configuration information, import the encryption program to be simulated and run, and adapt the input and output of the encryption program to be run. The configuration information mainly includes the following basic information:

[0088] Table 2

[0089]

[0090]

[0091] Optionally, the program simulation and running module runs the password program on the CPU simulator by randomly constructing an unencrypted file each time. After the running is completed, the output o e content is saved, and this is executed N times.

[0092] Optionally, the running track receiving module is used to collect the read and write details of the memory based on the filter in the configuration by using the hook function of the Qiling framework during each program simulation and running. The collected read and write values are stored in s e in the form of a bit sequence in chronological order, and finally s e .

[0093] Optionally, the running track analysis module is used to analyze the running track and finally output the correct key.

[0094] It should be noted that in the prior art, binary instrumentation tools such as DBI are used to obtain the key of the encryption program. The main reasons for its success are as follows: On the one hand, the password program (i.e., the encryption program) is compiled based on a specific operating system and architecture, and the running environment of this password program supports debugging, so it is very easy to use binary instrumentation tools such as DBI to successfully obtain the memory read and write tracks during the running process. On the other hand, the input of the password program is not protected, that is, it is not encoded by an external input encoding component, and the first round of the password algorithm in the password program is not affected by confusion (redundant rounds, confusion rounds, etc.), so an analysis program can be constructed to exhaustively search for the key and then extract the key.

[0095] However, in recent years, due to the increased protection for the first round of cryptographic algorithms, coding techniques and anti-debugging techniques have been applied to protect cryptographic programs. For example, external input coding will hide the real input of the cryptographic program, resulting in the inability to perform side-channel attacks through binary instrumentation tools such as DBI. Adding obfuscation components such as redundant rounds in the first round of the cryptographic algorithm will also cause the inability to extract the key or the extracted key to be a false key through binary instrumentation tools such as DBI. The application of anti-debugging techniques at the operating system level will prevent binary instrumentation tools such as DBI from obtaining the running trace, and will also result in the inability to perform further key extraction. Moreover, in order to meet the application requirements, cryptographic programs are generally used across platforms and exist on platforms such as Linux, Windows, macOS, and Android. However, traditional DBI frameworks need to reconstruct the environment for different operating systems and CPU architectures, resulting in a very high upfront cost, which is not conducive to the development of the security evaluation of cryptographic programs.

[0096] In this application, the encryption program analysis method based on output reverse can reverse-analyze the intermediate process during the execution of the last round of the cryptographic program through the output of the cryptographic program, and extract the key in combination with the running trace. It can not only avoid the problem of being unable to accurately obtain the correct key due to external input coding of the encryption program or adding obfuscation components such as redundant rounds in the first round, but also bypass the anti-debugging components, thus improving the efficiency of obtaining the correct key. Secondly, the automated encryption program analysis system uses the QilingCPU simulation program across architectures and operating systems to simulate the operation of the cryptographic program, and then obtains the running trace of the cryptographic program, which can solve the problem in the prior art that it is necessary to reconstruct the environment for different operating systems and CPU architectures, resulting in a very high upfront cost, and thus achieves the effect of reducing the R & D cost.

[0097] Embodiment 2

[0098] According to an embodiment of the present application, there is also provided an embodiment of an analysis device for an encryption program, wherein, Figure 8 is a schematic diagram of an optional analysis device for an encryption program according to an embodiment of the present application, as Figure 8 shown. The device includes: an acquisition module 801, an exhaustive module 802, an analysis module 803, a first determination module 804, and a second determination module 805.

[0099] Among them, the acquisition module 801 is used to acquire N running traces and N output results of the encryption program, where the output result is the file encrypted by the encryption program, each output result corresponds to a running trace, the output result includes at least one byte, and the running trace contains at least J intermediate values generated during the operation of the encryption program.

[0100] Optionally, the above encryption program is a binary program. The above running track is used to characterize the encryption process when the encryption program encrypts a file. In other words, the running track can be understood as a record of the encryption process. Among them, the encryption track at least includes J intermediate values generated by the encryption program during the operation process. It should be noted that the above N and J can be understood as at least one. The value of N and the value of J can be the same or different, and are specifically set according to the actual situation. This application does not make too many limitations here.

[0101] In addition, the above intermediate value can be understood as the intermediate state of the encryption process. For example, when the encryption program encrypts plaintext A into ciphertext A, it may go through multiple conversions. For example, plaintext A is successively converted into ciphertext 1, ciphertext 2, ciphertext 3, and ciphertext A. Among them, ciphertext 1, ciphertext 2, and ciphertext 3 in the intermediate process are the intermediate states.

[0102] The exhaustive module 802 is used to exhaustively find the K keys corresponding to the Mth byte in the output result.

[0103] Optionally, the output result includes at least one byte. Among them, the Mth byte can be any byte among the at least one byte. The analysis device can obtain the K passwords corresponding to the Mth byte by exhaustive method. Since the key space is 256 choices from 0 to 255, the value of K in this application can be determined to be at most 256. For the convenience of description, the Mth byte can be represented by k h That is, k h represents the single-byte key obtained by exhaustive search.

[0104] The analysis module 803 is used to perform reverse analysis on the output result according to the pre-constructed selection function and the key to obtain a simulated value. The simulated value is the predicted intermediate value predicted by the selection function according to the output result and the key. The K keys correspond to K simulated values, and each key corresponds to a simulated value.

[0105] Optionally, the simulated value is the predicted intermediate value predicted by the selection function according to the output result and the key. The K keys correspond to K simulated values, and each key corresponds to a simulated value.

[0106] Specifically, from the perspective of the result, the role of the selection function is to divide the running track into two different sets for later analysis of the running track. From the perspective of the motivation, it is to be able to mathematically simulate the key intermediate values generated when the binary program runs. Different from the DBI analysis technology in the prior art, the selection function in this application does not depend on the input, but depends on the output result of the binary program, and then performs reverse analysis on the encryption program according to the output result.

[0107] Among them, the selection function is as follows:

[0108]

[0109] Among them, o e represents the output result of the binary program, and this output result can be obtained together when the analysis device acquires the running trajectory. inv S Box is the inverse operation of the S-box of the cryptographic algorithm. k h represents the brute-force single-byte key, and the key space has 256 choices from 0 to 255. j represents the j-th bit of the generated intermediate value, so the value range is 0 or 1.

[0110] In addition, the meaning represented by this selection function is: according to the output result o e and by brute-forcing the key k h in a way to predict the input information of the last S-box of the binary program (encryption program) (i.e., the intermediate value of the last round). It should be noted that assuming k h is the correct key, then the output result of the selection function is the input information of the last S-box of the binary program. Assuming k h is the wrong key, then the output result of the selection function has no relation to the input of the last S-box of the binary cryptographic program.

[0111] The first determination module 804 is used to determine the correlation degree between the simulated value and the intermediate value.

[0112] Optionally, the above-mentioned correlation degree is used to characterize the correlation between the simulated value and the intermediate value. The greater the correlation degree, the stronger the correlation between the two. In other words, if the correlation degree between a simulated value and an intermediate value is greater, it means that the simulated value is closer to the intermediate value and the similarity between the two is higher.

[0113] The second determination module 805 is used to determine the correct key of the M-th byte according to the correlation degree.

[0114] Optionally, since a total of N running trajectories and N output results are acquired, and the M-th byte of each output result corresponds to K keys, therefore, for the M-th byte. The N output results correspond to a total of N*K keys. On this basis, the analysis device can determine the correct key from the N*K keys according to the correlation degree. For example, the key with the largest correlation degree is used as the correct key.

[0115] In this application, a method is adopted to perform reverse analysis on the output result of the encryption program according to a selection function and a secret key. First, N running traces and N output results of the encryption program are obtained. Then, K secret keys corresponding to the Mth byte in the output result are exhaustively enumerated. Subsequently, reverse analysis is performed on the output result according to the pre-constructed selection function and the secret key to obtain a simulated value, and the correlation between the simulated value and the intermediate value is determined. Finally, the correct secret key for the Mth byte is determined according to the correlation. Among them, the output result is the file encrypted by the encryption program, each output result corresponds to a running trace, the output result includes at least one byte, and the running trace contains at least J intermediate values generated by the encryption program during the operation process; the simulated value is the predicted intermediate value predicted by the selection function according to the output result and the secret key, K secret keys correspond to K simulated values, and each secret key corresponds to a simulated value.

[0116] As can be seen from the above, this application performs reverse analysis on the output result according to the pre-constructed selection function and the secret key obtained by exhaustive enumeration, and can reversely simulate the intermediate values generated by the encryption algorithm of the encryption program when encrypting the file. Since this application is a reverse analysis method, it can avoid the problem of being unable to accurately obtain the correct secret key due to the external input encoding of the encryption program. At the same time, since the last round of the encryption process is analyzed during reverse analysis, it can also avoid the problem of being unable to extract the correct secret key due to the addition of confusing components such as redundant rounds in the first round of the encryption algorithm, thereby improving the acquisition efficiency of the correct secret key and further enhancing the analysis efficiency of the encryption program.

[0117] Thus, through the technical solution of this application, the purpose of ensuring the acquisition of the correct secret key of the encryption program is achieved, the effect of improving the acquisition efficiency of the correct secret key is realized, and further the technical problem of low analysis efficiency of the encryption program in the prior art is solved.

[0118] Optionally, the above acquisition module further includes: a first execution unit, a second execution unit, and a third execution unit. Among them, the first execution unit is used to execute step 1 to obtain an unencrypted file; the second execution unit is used to execute step 2 to run the encryption program according to the emulator and encrypt the unencrypted file according to the encryption program to obtain a running trace and an output result, where the emulator is an application program that calls the encryption program to perform a simulated encryption operation; the third execution unit is used to execute step 3 and loop through steps 1 and 2 N times to obtain N running traces and N output results.

[0119] Specifically, the above-mentioned simulator is an automated password program simulation device constructed based on the Qiling framework. This device mainly consists of an input / output adapter, an anti-debugging bypass component, a password program simulation component, and an energy trace acquisition component. Through simple configuration, it can automatically simulate password programs and collect running traces. Among them, the anti-debugging bypass component in this device is used to avoid anti-debugging detection.

[0120] It should be noted that the Qiling framework is a cross-platform, lightweight simulator that supports multiple CPU architectures. This lightweight simulator can use hook functions for any instruction, and through hook functions, it can achieve the functions of bypassing anti-debugging components and random number components, and can also obtain the memory read and write traces of the encryption program during operation.

[0121] It should be noted that traditional DBI analysis tools achieve monitoring of running traces by instrumenting binary programs executed in the operating system. However, this traditional method is easily interfered by anti-debugging.

[0122] In this application, using the CPU simulation framework (i.e., the Qiling framework), the simulator can directly extract instructions from binary programs and collect running traces after simulated operation. Since it runs on a lightweight virtual machine, the collection of running traces will no longer be in the monitoring mode, but directly collect running traces in an active manner. This active collection method can collect complete running traces.

[0123] In addition, the recorded running trace s e is a bit sequence, and the length of the sequence is related to the specific algorithm and filtering rules. Let the length of the sequence be X bits. When used, s e [i] represents the i-th bit of the bit sequence, where i < X.

[0124] Optionally, as Figure 3 shown, the process of the analysis device collecting running traces by calling the simulator can be referred to as follows:

[0125] Step 1: Initialize the simulator. Among them, the initialization work of the simulator is mainly to start the simulator according to the configuration file.

[0126] Step 2: Initialize e and N. Among them, e = 0, and N represents the number of running traces to be collected. Generally speaking, 100 < N < 256. On the one hand, if N is too small, it may lead to inaccurate final key analysis. And if N is too large, it will cause the space occupied by the running traces to be too large.

[0127] Step 3: Randomly select an input (i.e., an unencrypted file) and run the encryption program, and obtain the running trace recorded as s through the corresponding interface of the simulator e, and record the output result of the simulator as o e .

[0128] Step 4: Accumulate e once.

[0129] Step 5: Repeat Step 3 and Step 4 until e > n, then stop and exit the virtual machine.

[0130] Optionally, the above first determination module further includes: a first determination unit, a second determination unit, a third determination unit, and a fourth determination unit. Among them, the first determination unit is used to determine that the analog value is the first bit sequence and the intermediate value is the second bit sequence, where both the first bit sequence and the second bit sequence are sequences composed of numerical value 1 and / or numerical value 0; the second determination unit is used to determine that when the C position in the first bit sequence is numerical value 0, the value at the C position in the second bit sequence is the value in the first set; the third determination unit is used to determine that when the C position in the first bit sequence is numerical value 1, the value at the C position in the second bit sequence is the value in the second set; the fourth determination unit is used to determine the correlation degree according to the first set and the second set.

[0131] Optionally, the above fourth determination unit further includes: a first determination sub-module, a second determination sub-module, a first calculation sub-module, a second calculation sub-module, and a third determination sub-module. Among them, the first determination sub-module is used to determine that the number of numerical value 1 in the first set is the first quantity, and the number of numerical value 1 in the second set is the second quantity; the second determination sub-module is used to determine that the total number of all numerical values in the first set is the third quantity, and the number of all numerical values in the second set is the fourth quantity; the first calculation sub-module is used to calculate the ratio of the first quantity to the third quantity to obtain the first ratio; the second calculation sub-module is used to calculate the ratio of the second quantity to the fourth quantity to obtain the second ratio; the third determination sub-module is used to determine the correlation degree according to the first ratio and the second ratio.

[0132] Optionally, the above third determination sub-module further includes: a difference calculation sub-unit and an absolute value calculation sub-unit. Among them, the difference calculation sub-unit is used to calculate the difference between the first ratio and the second ratio; the absolute value calculation sub-unit is used to determine the absolute value of the difference to obtain the correlation degree, where J intermediate values correspond to J correlation degrees, and each intermediate value corresponds to a correlation degree.

[0133] As Figure 4 shown, for the Mth byte of the output result, the analysis device first exhaustively guesses the key k h , and then for each k h according to the selection function Sel and the output result o e , calculate the analog value. Since k h ranges from 0 to 255, a total of 256 keys, so for each kh , record the analog value corresponding to each o e .

[0134] As Figure 4 shown, Figure 4 in which i is used to count the keys, representing the i-th key currently. Starting from i = 0, calculate the analog value corresponding to each key k h until i is greater than 255 and then exit the calculation of the analog value.

[0135] In addition, the analysis device will record the obtained analog values into the three-dimensional table Sim

[256] [n][8]. Specifically, as Figure 5 shown, since the analog value is in the format of 8-bit binary, therefore, store the value of each bit in the corresponding position according to the bit order. For example, Figure 5 Sel(o e , k h , 0) represents the value of the first bit (the first bit among 8 bits) of the analog value corresponding to the key k h , and Sel(o e , k h , 0) will be correspondingly stored in Sim[k h [e][0]. After all the analog values corresponding to one output result are stored, the analysis device will continue to store the analog values corresponding to the next output result until all the analog values corresponding to N output results are stored in the three-dimensional table.

[0136] Optionally, after obtaining the analog value, the analysis device will next classify the motion trajectory. First, the analysis device initializes two empty sets, namely the first set A 0 and the second set A 1 , and then the analysis device fills the data into these two sets according to the data in the Sim three-dimensional table. The specific method is as Figure 6 shown. For each k h , classify each bit s e [i] of the motion trajectory s e . When flag = Sim[k h [e][j] = 1, the value of v = s e [i] will enter the second set A 1 , and when flag = Sim[k h [e][j] = 0, the value of s e [i] will enter the first set A 0 . After classifying all the motion trajectories of the i-th bit, calculate the average values of the sets A 0 , A 1 respectively calculate their differences and save the result to the three-dimensional table M[k h [j][i].

[0137] Among them, Table 1 shows a schematic table for classifying motion trajectories.

[0138] Table 1

[0139] Analog value Intermediate value A Intermediate value B 0 0 1 1 1 0 0 0 1 1 1 1 0 0 0 0 0 0 0 0 0

[0140] As shown in Table 1, according to the principle that in the intermediate values, which set each value is placed in depends on whether the analog value at the corresponding position is 0 or 1, the first set A is placed in the intermediate value A 0 has a value of (0, 0, 0, 0, 0), and the second set A 1 has a value of (1, 1) in it. So for the intermediate value A, the average value (corresponding to the first ratio) of the first set A 0 is 0, and the average value (corresponding to the second ratio) of the second set A 1 is 1. The correlation degree is equal to the absolute value of the difference between the first ratio and the second ratio. Therefore, the correlation degree between the intermediate value A and the analog value in Table 1 is 1.

[0141] Similarly, the first set A is placed in the intermediate value B 0 has a value of (1, 1, 0, 1, 0), and the second set A 1 has a value of (0, 1) in it. So for the intermediate value B, the average value of the first set A 0 is 3 / 5, and the average value of the second set A 1 is 1 / 2. The correlation degree is equal to the absolute value of the difference between 3 / 5 and 1 / 2. Therefore, the correlation degree between the intermediate value B and the analog value in Table 1 is 0.1.

[0142] Optionally, the above-mentioned second determination module further includes: a detection unit, a fifth determination unit, and a sixth determination unit. Among them, the detection unit is used to detect whether there is at least one correlation degree greater than a preset threshold among the J correlation degrees corresponding to the analog value; the fifth determination unit is used to determine that the key corresponding to the analog value is the candidate key for the Mth byte in the case that there is at least one correlation degree greater than the preset threshold among the J correlation degrees corresponding to the analog value; the sixth determination unit is used to determine the correct key for the Mth byte according to the candidate key.

[0143] Optionally, the above-mentioned preset threshold can be custom-set. Generally speaking, if the correlation degree is between 0.7 and 1, it indicates that the correlation between the analog value and the intermediate value is strong. If the correlation degree is below 0.3, it indicates that there is no correlation between the analog value and the intermediate value. Therefore, the preset threshold can be set to 0.7.

[0144] Optionally, the sixth determination unit further includes: a fourth determination submodule, a sorting submodule and a fifth determination submodule. The fourth determination submodule is used to determine all candidate keys from N*K keys, wherein the N*K keys are all keys corresponding to the Mth byte in the N output results; the sorting submodule is used to sort all candidate keys according to the relevance of each candidate key to obtain a sorting result; and the fifth determination submodule is used to determine, according to the sorting result, that the candidate key with the greatest relevance is the correct key of the Mth byte.

[0145] Optionally, in the analysis device all k h After the correlation between the corresponding simulation value and the running trajectory is calculated, the analysis device will obtain a complete three-dimensional array M

[256] [8][m]. On this basis, the analysis device will calculate M[k h ] is expanded, the number of keys with correlation greater than the preset threshold 0.7 is counted, and these keys are stored in the array Corr[k h ], finally, the analysis device checks the array Corr[k h ] with the highest correlation h is the correct key of the Mth byte. It is easy to notice that, when the correct keys of all bytes are determined, the analysis device can obtain the round key of the encryption program.

[0146] It can be seen from the above content that in the present application, the encryption program analysis method based on output reverse can reverse analyze the intermediate process of the last round of execution of the encryption program through the output of the encryption program, and extract the key in combination with the running trajectory, which can not only avoid the problem of being unable to accurately obtain the correct key due to the encryption program performing external input encoding or adding redundant rounds and other obfuscation components in the first round, but also bypass the anti-debugging component, thereby improving the efficiency of obtaining the correct key. Secondly, the automated analysis device uses the cross-architecture and cross-operating system QilingCPU simulation program to simulate the operation of the encryption program, and then obtain the running trajectory of the encryption program, which can solve the problem that the prior art needs to rebuild the environment for different operating systems and CPU architectures, resulting in a very large cost in the early stage, thereby achieving the effect of reducing R&D costs.

[0147] Example 3

[0148] According to another aspect of an embodiment of the present application, a computer-readable storage medium is further provided, in which a computer program is stored, wherein the computer program is configured to execute the analysis method of the encryption program in the above-mentioned embodiment 1 when running.

[0149] Example 4

[0150] According to another aspect of the embodiments of the present application, an electronic device is further provided. The electronic device includes one or more processors; a storage device for storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement a method for running a program, wherein the program is configured to execute the analysis method of the encryption program in Embodiment 1 above when running.

[0151] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.

[0152] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0153] In the several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of units can be a logical function division, and in actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of units or modules can be in electrical or other forms.

[0154] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0155] In addition, the functional units in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0156] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.

[0157] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A method for analyzing an encryption program, characterized in that, it includes: Obtain N running trajectories of the encryption program and N output results, where the output result is a file encrypted by the encryption program, each output result corresponds to one of the running trajectories, the output result includes at least one byte, and at least J intermediate values generated by the encryption program during the operation are included in the running trajectory; Exhaust K keys corresponding to the Mth byte in the output result; perform reverse analysis on the output result according to a pre-constructed selection function and the key to obtain a simulated value, where the simulated value is a predicted intermediate value predicted by the selection function according to the output result and the key, the K keys correspond to K simulated values, and each key corresponds to one simulated value; Determine the correlation between the simulated value and the intermediate value; determine the correct key for the Mth byte according to the correlation; Among them, determining the correlation between the simulated value and the intermediate value includes: Determine that the simulated value is a first bit sequence and the intermediate value is a second bit sequence, where both the first bit sequence and the second bit sequence are sequences composed of the numerical value 1 and / or the numerical value 0; when the value at the C position of the first bit sequence is the numerical value 0, determine that the value at the C position of the second bit sequence is a value in the first set; when the value at the C position of the first bit sequence is the numerical value 1, determine that the value at the C position of the second bit sequence is a value in the second set; Determine that the number of numerical values 1 in the first set is the first quantity, and the number of numerical values 1 in the second set is the second quantity; determine that the total number of all numerical values in the first set is the third quantity, and the number of all numerical values in the second set is the fourth quantity; calculate the ratio of the first quantity to the third quantity to obtain a first ratio; calculate the ratio of the second quantity to the fourth quantity to obtain a second ratio; calculate the difference between the first ratio and the second ratio; determine the absolute value of the difference to obtain the correlation.

2. The method according to claim 1, characterized in that, Obtaining N running trajectories of the encryption program and N output results includes: Step 1, obtain an unencrypted file; Step 2, run the encryption program according to the emulator and encrypt the unencrypted file according to the encryption program to obtain the running trajectory and the output result, where the emulator is an application program that calls the encryption program to perform a simulated encryption operation; Step 3, loop and execute Step 1 and Step 2 N times to obtain the N running trajectories and the N output results.

3. The method according to claim 1, characterized in that, The J intermediate values correspond to J correlations, and each intermediate value corresponds to one of the correlations.

4. The method according to claim 1, characterized in that, Determining the correct key for the Mth byte according to the correlation includes: Detect whether there is at least one correlation greater than a preset threshold among the J correlations corresponding to the simulated value; When there is at least one correlation greater than the preset threshold among the J correlations corresponding to the analog value, determine the key corresponding to the analog value as the candidate key for the M-th byte; Determine the correct key for the M-th byte according to the candidate key.

5. The method according to claim 4, wherein, Determining the correct key for the M-th byte according to the candidate key includes: Determine all candidate keys from N*K keys, where the N*K keys are all the keys corresponding to the M-th byte in the N output results; Sort all the candidate keys according to the correlation of each candidate key to obtain a sorting result; According to the sorting result, determine the candidate key with the highest correlation as the correct key for the M-th byte.

6. An analysis device for an encryption program, wherein, comprising: An acquisition module, configured to acquire N running traces of the encryption program and N output results, where the output result is the file encrypted by the encryption program, each output result corresponds to one of the running traces, the output result includes at least one byte, and the running trace at least contains J intermediate values generated by the encryption program during the operation process; An exhaustive module, configured to exhaust K keys corresponding to the M-th byte in the output result; An analysis module, configured to perform reverse analysis on the output result according to a pre-constructed selection function and the key to obtain an analog value, where the analog value is the predicted intermediate value predicted by the selection function according to the output result and the key, the K keys correspond to K analog values, and each key corresponds to one analog value; A first determination module, configured to determine the correlation between the analog value and the intermediate value; A second determination module, configured to determine the correct key for the M-th byte according to the correlation; wherein, the first determination module includes: a first determination unit, configured to determine the analog value as a first bit sequence, and the intermediate value as a second bit sequence, where both the first bit sequence and the second bit sequence are sequences composed of the numerical value 1 and / or the numerical value 0; a second determination unit, configured to determine that the value at the C position of the second bit sequence is a value in the first set when the value at the C position of the first bit sequence is the numerical value 0; a third determination unit, configured to determine that the value at the C position of the second bit sequence is a value in the second set when the value at the C position of the first bit sequence is the numerical value 1; a fourth determination unit, configured to determine the correlation according to the first set and the second set; The fourth determination unit includes: a first determination sub-module, configured to determine that the number of the value 1 in the first set is a first quantity, and the number of the value 1 in the second set is a second quantity; a second determination sub-module, configured to determine that the total number of all values in the first set is a third quantity, and the number of all values in the second set is a fourth quantity; a first calculation sub-module, configured to calculate a ratio of the first quantity to the third quantity to obtain a first ratio; a second calculation sub-module, configured to calculate a ratio of the second quantity to the fourth quantity to obtain a second ratio; a third determination sub-module, configured to determine a relevance according to the first ratio and the second ratio. The third determination sub-module includes: a difference calculation sub-unit, configured to calculate a difference between the first ratio and the second ratio; an absolute value calculation sub-unit, configured to determine an absolute value of the difference to obtain the relevance.

7. The apparatus according to claim 6, wherein, the obtaining module includes: a first execution unit, configured to execute step 1 to obtain an unencrypted file; a second execution unit, configured to execute step 2, run the encryption program according to a simulator, and encrypt the unencrypted file according to the encryption program to obtain the running track and the output result, wherein the simulator is an application program that calls the encryption program to perform a simulation encryption operation; a third execution unit, configured to execute step 3, and loop to execute step 1 and step 2 for N times to obtain the N running tracks and the N output results.

8. The apparatus according to claim 6, wherein, the second determination module includes: a detection unit, configured to detect whether there is at least one relevance greater than a preset threshold among the J relevances corresponding to the simulation value; a fifth determination unit, configured to determine that the key corresponding to the simulation value is the candidate key for the Mth byte in the case that there is at least one relevance greater than the preset threshold among the J relevances corresponding to the simulation value; a sixth determination unit, configured to determine a correct key for the Mth byte according to the candidate key.

9. The apparatus according to claim 8, wherein, the sixth determination unit includes: a fourth determination sub-module, configured to determine all candidate keys from N*K keys, where the N*K keys are all keys corresponding to the Mth byte in the N output results; a sorting sub-module, configured to sort all the candidate keys according to the relevance of each candidate key to obtain a sorting result; a fifth determination sub-module, configured to determine, according to the sorting result, that the candidate key with the greatest relevance is the correct key for the Mth byte.

10. A computer-readable storage medium, wherein, a computer program is stored in the computer-readable storage medium, and the computer program is configured to execute the analysis method of the encryption program described in any one of claims 1-5 when running.

11. An electronic device, wherein, The electronic device includes one or more processors; a storage device for storing one or more programs, which, when executed by the one or more processors, cause the one or more processors to implement a method for running a program, wherein the program is configured to execute the analysis method of the encryption program described in any one of claims 1-5 when running.

Citation Information

Patent Citations

  • Application method of Hamming distance model on SM4 cryptographic algorithm lateral information channel energy analysis and based on S box input

    CN103138917A

  • Novel piecewise linear chaotic mapping image encrypting and encoding method

    CN104751401A