A Hardware Security Evaluation Method for Block Ciphers Based on Fireworks Algorithm

By applying the packet cryptographic hardware security evaluation method based on firework algorithm in side channel analysis, the problem that the single-byte model cannot fully utilize power consumption information and high computing cost is solved, and more efficient key search and security evaluation are achieved.

CN115422602BActive Publication Date: 2025-05-27HEILONGJIANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210877457.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-25
Publication Date
2025-05-27
Estimated Expiration
2042-07-25

AI Technical Summary

Technical Problem

In side channel analysis, the single-byte model cannot fully utilize power consumption information and the calculation cost is high, resulting in too large key space and it is difficult to effectively guess the key.

Method used

The packet cryptographic hardware security evaluation method based on firework algorithm is adopted. By randomly initializing fireworks, the fitness value is calculated, the explosion radius and the number of explosion sparks are determined, the explosion spark position offset operation and the generation of Gaussian mutated sparks are carried out, and the keys are iterated generation by iterating.

Benefits of technology

It effectively improves the utilization rate of power consumption information, reduces the calculation cost, improves the convergence speed of security evaluation, and significantly improves the security of multi-byte detection packet cipher devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115422602B_ABST
    Figure CN115422602B_ABST
Patent Text Reader

Abstract

The present invention provides a hardware security evaluation method for block ciphers based on the fireworks algorithm. By combining the fireworks algorithm with side-channel analysis, this method randomly generates a certain number of fireworks in the feasible solution space, calculates the fitness value of each firework to determine the quality of the firework. The better positions are selected from all the fireworks and sparks in the space as the detonation points for the next firework explosion, and explosion operations are performed within a certain radius range. By performing the above operations generation by generation, finally, the detonation points of the fireworks and the sparks generated will be concentrated near the optimal solution position of the problem. When the algorithm stops, the position where the detonation point or spark of the firework with the optimal fitness value is located is the optimal solution of the objective function searched by the algorithm. The present invention reduces the computational complexity of the evaluation and significantly improves the evaluation convergence speed, providing a good evaluation means for detecting the security of block cipher devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data encryption, and particularly relates to a hardware security evaluation method for block ciphers based on the fireworks algorithm. Background Art

[0002] As a commonly used energy analysis model for side-channel attacks, the related energy model mainly aims at the differences in energy consumption caused by the calculation of different intermediate values generated by some key bits and different plaintext information during the operation of the algorithm, such as the internal logic operations of the circuit and the changes in register values. It calculates the energy consumption of different guessed keys and known plaintext through the corresponding energy consumption model, and uses the correlation analysis method to calculate to achieve key analysis.

[0003] The related energy model analyzes a single S-box with 6 outputs or 8 outputs. The hardware implementation of block cipher algorithms usually updates the values of a k-bit register simultaneously. Therefore, operations such as shifting and byte substitution in the hardware implementation of block ciphers are parallel operations. As a result, the collected power consumption curves are the superposition of the power consumptions generated by multiple S-boxes at the same point. When the energies of multiple bytes are superimposed simultaneously, the Hamming distance is between 0 and k. However, if the brute-force key method for a single byte is still used to guess the key, the traversal space of the key will be huge. This far exceeds the acceptable computing range. Therefore, due to the excessive key space after adopting the multi-byte side-channel analysis method, it is necessary to combine the search ability of swarm intelligence algorithms to solve it. In 2016, Zhang et al. proposed a non-modeling side-channel analysis method based on artificial intelligence, which combines the genetic algorithm with the correlation power analysis. The heuristic search characteristics of the genetic algorithm make it possible to have a huge search space. In the scenario of the hardware implementation of cryptographic algorithms, when applied to side-channel analysis, it can make full use of the information of all bytes, and the information utilization rate is greatly improved compared with the classical related energy analysis model. However, the related energy analysis model based on the simple genetic algorithm has the problem of premature convergence, especially when the number of key bytes is large. To overcome this problem, Ding et al. proposed a related energy analysis model based on the multi-population genetic algorithm in 2019. Although due to premature convergence during the evolution process, a single population can only correctly guess some key bytes, each population can guess almost the same number of key bytes, and the serial numbers of the guessed key bytes are also different. By collecting the optimal individuals of multiple populations and "combining" them, there is a chance to recover all key bytes. However, the information used by Ding et al. comes from the optimal individuals evolved by each population. If the values of each byte of these individuals do not fully cover the values of each byte of the correct key, the key cannot be successfully recovered. Therefore, in 2021, Li et al. further proposed a related energy analysis model based on the multi-population genetic algorithm with secondary evolution. The secondary evolution is divided into two stages. In the first stage, each population evolves independently, and the evolution mode is the same as that of a single population. In the second stage, the optimal individuals evolved by each population form an initial population for re-evolution. Due to the crossover and mutation operations involved in the evolution process, some incorrect key bytes have the opportunity to evolve correctly to successfully recover the key. However, the method of secondary evolution improves the success rate of key guessing but greatly increases the computational complexity. Summary of the Invention

[0004] Based on the above deficiencies, the purpose of the present invention is to propose a hardware security evaluation method for block ciphers based on the fireworks algorithm to solve the problem that the single-byte model in side-channel analysis cannot make full use of power consumption information and has a high computational cost.

[0005] The technical solution adopted by the present invention is as follows: A hardware security evaluation method for block ciphers based on the fireworks algorithm, which is applicable to most block cipher algorithms, and the steps are as follows:

[0006] Step 1: Randomly initialize n fireworks x with a dimension of k in the feasible solution space i . In each round of operation of the block cipher algorithm, a k-bit round key is used. Since the space for key traversal will be 2 k , the key space is huge. To use the fireworks algorithm, the k-bit round key is split into m parts in byte order, each part containing k / m bit keys, and the m parts are randomly assigned values in turn. In this way, n initial fireworks with a dimension of k are formed;

[0007] Step 2: In each generation of fireworks, it is necessary to select a part of the individuals close to the optimal solution from the random solutions for subsequent evolution. Usually, a fitness function is used to evaluate the superiority of the fireworks. The Pearson correlation coefficient is selected as the fitness function f(x i ), and the specific mathematical expression is shown in Equation (1):

[0008]

[0009] where corr represents the Pearson correlation coefficient, P t represents the actual power consumption, HD represents the Hamming distance of the single-byte input v 1 output v 2 , and its value range is from 0 to 8. The larger the absolute value of the correlation coefficient, the closer the key value represented by the fireworks is to the true key. By accumulating the Hamming distance values of the m-byte input and output values, a hardware security evaluation model based on multiple bytes is generated.

[0010] Step 3: The fitness function f(x i ) is the only criterion for evaluating the fireworks, and it serves the function of selecting excellent sparks. Therefore, in each generation of fireworks, according to the fitness value f(x i ), calculate the explosion radius A i and the number of explosion sparks S i .

[0011] In solving the related power analysis problem, the explosion radius A i can be regarded as the number of flipped bits. The explosion radius decreases as the absolute value of the fitness function of the fireworks increases, so as to achieve the purpose of converging to the optimal solution. The normal distribution density function with an expected value of 0 and a variance of 0.4, normpdf(), is introduced, and the number of explosion sparks S i decreases as the fitness value of the fireworks decreases from high to low. For the fireworks algorithm, the explosion radius A i and the number of explosion sparks Si is defined as shown in Formulas (2) and (3).

[0012] A i (i) = round(P·normpdf(corr(i) / (3·Q / 4), 0, 0.4)+1) (2)

[0013] S i (corr_decrease[i]) = round(S·normpdf(i / (3·fire_num / 4)), 0, 0.4)+ε) (3)

[0014] Where round() is the rounding function, P and Q are explosion radius constants used to adjust the size of the explosion radius. corr_decrease is sorted in descending order of i according to the correlation coefficient, S is the explosion spark constant used to adjust the number of explosion sparks. ε is the minimum value of the machine.

[0015] Step Four: For the selected n k-dimensional fireworks x ik According to the explosion radius A i , and the number of explosion sparks S i Perform the explosion spark position offset operation to generate explosion sparks

[0016] Step Five: Randomly flip 1 bit in the k-bit fireworks x ik to generate Gaussian mutation sparks The specific expressions are shown in Formulas (4) and (5):

[0017] ver_bit = round(127·rand+1) (4)

[0018]

[0019] Where ver_bit represents the position of the flipped bit in the k bits, and mod represents the integer operation used for flipping the bit between 0 and 1.

[0020] Step Six: Determine whether the termination condition is satisfied according to the fitness value f(x i ). If it is satisfied, the position of the current spark is the optimal solution of the objective function. Stop the search; otherwise, select several individuals with the best fitness value f(x i ) from the fireworks, explosion sparks, and Gaussian mutation sparks as fireworks and jump to Step Three to perform the next generation of iterative calculation, while discarding all unselected information.

[0021] Another object of the present invention is to provide a computer device, including a memory, a processor, and a computer program stored on the memory and capable of running on the processor, where the processor processes and executes the computer program to implement the steps of the method as described above.

[0022] Beneficial effects and advantages of the present invention: The present invention adopts the superposition of multi-byte power consumption information, effectively improving the utilization rate of power consumption information and making the simulated power consumption have a greater correlation with the actual power consumption. Compared with the traditional related energy analysis model method, since the method of parallel processing of power consumption information is adopted, the calculation cost is smaller and the convergence speed of security evaluation is faster. Experimental results show that this method has significant advantages in detecting the security of multi-byte detection block cipher devices. The present invention efficiently utilizes the power consumption curve to provide a good evaluation means for detecting the security of block cipher devices, and the hardware security evaluation method of the present invention is applicable to most block cipher algorithms and has strong versatility. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 is the parallel correlation coefficient of single byte and multi-byte within the leakage interval;

[0024] Figure 2 is the influence of explosion radius constants P and Q on the result convergence;

[0025] Figure 3 is the influence of explosion spark constant S on the result convergence;

[0026] Figure 4 is the optimization flow chart based on the fireworks algorithm;

[0027] Figure 5 is the evaluation convergence situation diagram of parallel processing of different bytes;

[0028] (a) Evaluation convergence situation of 16 bytes, (b) Evaluation convergence situation of 8 bytes,

[0029] (c) Evaluation convergence situation of 4 bytes, (d) Evaluation convergence situation of 2 bytes;

[0030] Figure 6 is the calculation complexity result diagram of parallel processing of different bytes;

[0031] (a) Calculation complexity result diagram of 16 bytes, (b) Calculation complexity result diagram of 8 bytes;

[0032] (c) Calculation complexity result diagram of 4 bytes, (d) Calculation complexity result diagram of 2 bytes;. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] In the present invention, by combining the fireworks algorithm with side-channel analysis, the fireworks algorithm randomly generates a certain number of fireworks in the feasible solution space, calculates the fitness value of each firework, and thereby determines the quality of the firework. The better positions are selected from all the fireworks and sparks in the space as the detonation points for the next firework explosion, and the explosion operation is performed within a certain radius range. By performing the above operations generation by generation, finally, the detonation points of the fireworks and the sparks generated by them will concentrate near the optimal solution position of the problem. When the algorithm stops, the position where the detonation point or spark of the firework with the optimal fitness value is located is the optimal solution of the objective function searched by the algorithm. The experimental results show that the present invention effectively improves the utilization rate of power consumption information, which is of great significance. The following further describes the present invention in detail in conjunction with embodiments and drawings, but the implementation manners of the present invention are not limited thereto. The energy analysis model of the present invention is applicable to most block cipher algorithms and has strong generality.

[0034] Embodiment 1

[0035] A hardware security evaluation method for block ciphers based on the fireworks algorithm, taking the AES-128 algorithm as an example for specific illustration. The method steps are as follows:

[0036] I. Generation of initial fireworks:

[0037] Randomly initialize n fireworks x with a dimension of 128 in the feasible solution space i . In each round of operation of the AES algorithm, a 128-bit round key is used. Since the space traversed by the key will be 2 128 , the key space is huge. To use the fireworks algorithm, the 128-bit round key is sequentially divided into 16 parts, each part containing 8-bit keys, and the 16 parts are randomly assigned values in turn. In this way, n initial fireworks with a dimension of 128 are formed, and Table 1 completes the random initialization of the fireworks.

[0038] Table 1 Fireworks initialization of AES-128

[0039]

[0040] II. Selection of fitness function

[0041] In each generation of fireworks, it is necessary to select a part of the individuals close to the optimal solution from the random solutions for subsequent evolution. Usually, a fitness function is selected to evaluate the superiority of the fireworks. The Pearson correlation coefficient is selected as the fitness function f(x i ). The specific mathematical expression is shown in Equation (1):

[0042]

[0043] where corr represents the Pearson correlation coefficient, Pt represents the actual power consumption, and HD represents the single-byte input v 1 output v 2 The Hamming distance of, whose value range is from 0 to 8. The larger the absolute value of the correlation coefficient, the closer the key value represented by the firework is to the true key. By accumulating the Hamming distance values of the 16-byte input-output values, a new energy model based on multiple bytes is generated.

[0044] III. Determine the explosion radius A i and the number of explosion sparks S i

[0045] The fitness function f(x i ) is the only criterion for evaluating the fireworks, and it serves the function of selecting excellent sparks. Therefore, in each generation of fireworks, according to the fitness value f(x i ), calculate the explosion radius A of each firework i and the number of explosion sparks S i .

[0046] In solving the related energy analysis problem, the explosion radius A i can be regarded as the number of flipped bits. The explosion radius decreases as the absolute value of the fitness function of the firework increases, so as to achieve the purpose of converging to the optimal solution. The normal distribution density function with an expected value of 0 and a variance of 0.4, normpdf(), is introduced. The number of explosion sparks S i decreases as the fitness value of the fireworks decreases from high to low. For the fireworks algorithm, the explosion radius A i and the number of explosion sparks S i are defined as shown in formulas (2) and (3).

[0047] A i (i)=round(P·normpdf(corr(i) / (3·Q / 4),0,0.4)+1) (2)

[0048] S i (corr_decrease[i])=round(S·normpdf(i / (3·fire_num / 4)),0,0.4)+ε) (3)

[0049] where round() is the rounding function, and P and Q are explosion radius constants used to adjust the size of the explosion radius. corr_decrease is sorted in descending order of i according to the correlation coefficient. S is the explosion spark constant used to adjust the number of explosion sparks. ε is the minimum value of the machine.

[0050] From Figure 2It can be seen from the results of the influence of the explosion radius constants P and Q on the result convergence that both the explosion radius constants P and Q affect the convergence of the key guess results. When the explosion radius constant P is 8 and the explosion radius constant Q is 0.85, the convergence speed is the fastest.

[0051] From Figure 3 It can be seen from the results of the influence of the explosion spark constant S on the result convergence that the convergence speed does not decrease with the increase of the expansion spark constant. When the explosion spark constant S = 4, the key guess converges the fastest.

[0052] IV. Explosion Spark Generation

[0053] For the selected n k-dimensional fireworks x ik According to the explosion radius A i , the number of explosion sparks S i Perform the explosion spark position offset operation to generate explosion sparks

[0054] V. Gaussian Mutation Spark Generation

[0055] Randomly flip 1 bit in the 128-bit fireworks x ik to generate Gaussian mutation sparks The specific expressions are shown in Eqs. (9) and (10):

[0056] ver_bit = round(127·rand + 1) (9)

[0057]

[0058] where ver_bit represents the position of the flipped bit in the 128 bits, and mod represents the integer operation for flipping bits 0 and 1.

[0059] VI. Loop Judgment

[0060] Judge whether the termination condition is satisfied according to the fitness value f(x i ). If it is satisfied, the position of the current spark is the optimal solution of the objective function. Stop the search; otherwise, select several individuals with the optimal fitness value f(x i ) from the fireworks, explosion sparks, and Gaussian mutation sparks as fireworks and jump to Step 3 to perform the next-generation iterative calculation, and at the same time discard all the unselected information. The flow chart of the parallel power analysis method based on the fireworks algorithm is as Figure 4 shown.

[0061] To verify the evaluation efficiency of this model, it is respectively compared with a correlation energy analysis model based on a simple genetic algorithm proposed by Zhang et al., a correlation energy analysis model based on a multi-population genetic algorithm proposed by Ding et al., and a correlation energy analysis model based on a multi-population genetic algorithm with quadratic evolution proposed by Li et al. in terms of evaluation convergence speed and computational complexity. The comparison of the evaluation convergence completion degrees of the four models under different numbers of bytes processed in parallel is as Figure 5 . From Figure 5 , it can be seen that the evaluation convergence speed of the hardware security evaluation model of block cipher based on the fireworks algorithm proposed in this paper has more advantages, and this advantage increases with the increase in the number of bytes processed in parallel. The comparison of the computational complexities of the four methods under different numbers of bytes processed in parallel is as Figure 6 . From Figure 6 , it can be seen that the computational complexity of the hardware security evaluation method of block cipher based on the fireworks algorithm and the energy model based on the simple genetic algorithm proposed in this invention is relatively small and almost the same, while the computational complexity of the correlation energy analysis model based on the multi-population genetic algorithm is the largest and far exceeds other methods. Therefore, the hardware security evaluation method of block cipher based on the fireworks algorithm proposed in this invention has more advantages both in terms of evaluation convergence speed and evaluation computational complexity.

Claims

1. A hardware security evaluation method for block ciphers based on the fireworks algorithm, characterized in that, the method steps are as follows: Step 1: Randomly initialize n fireworks x with dimension k in the feasible solution space i , in the process of each round of operation of the block cipher algorithm, a k-bit round key is used. The k-bit round key is split into m parts in byte order, and each part contains k / m bit keys. Randomly assign values to the m parts in turn to form n initial fireworks with dimension k; Step 2: In each generation of fireworks, it is necessary to select a part of the individuals close to the optimal solution from the random solutions for subsequent evolution. The Pearson correlation coefficient is selected as the fitness function f(x i ), and the expression is shown in Equation (1): where corr represents the Pearson correlation coefficient, P t represents the actual power consumption, HD represents the Hamming distance of the single-byte input v 1 output v 2 ; the value range is 0 - 8. By accumulating the Hamming distance values of the input and output values of m bytes, a hardware security evaluation model based on multiple bytes is generated; Step 3: In each generation of fireworks, according to the fitness value f(x i ), calculate the explosion radius A i and the number of explosion sparks S i ; Using the normpdf() normal distribution density function with an expected value of 0 and a variance of 0.4, the number of explosion sparks S i decreases as the fitness value of the fireworks decreases from high to low. For the fireworks algorithm, the explosion radius A i and the number of explosion sparks S i are defined as shown in formulas (2) and (3): A i (i) = round(P·normpdf(corr(i) / (3·Q / 4), 0, 0.4) + 1) (2) S i (corr_decrease[i]) = round(S · normpdf(i / (3 · fire_num / 4)), 0, 0.4) + ε) (3) where round() is a rounding function, P and Q are explosion radius constants used to adjust the size of the explosion radius, corr_decrease is sorted in descending order of i according to the correlation coefficient, S is an explosion spark constant used to adjust the number of explosion sparks, and ε is the minimum value of the machine; Step 4: For the selected n k-dimensional fireworks x ik According to the explosion radius A i , the number of explosion sparks S i Perform the explosion spark position offset operation to generate explosion sparks Step 5: Randomly flip 1 bit in the k-bit fireworks x ik to generate Gaussian mutation sparks The specific expressions are shown in Eqs. (4) and (5): ver_bit = round(127·rand + 1) (4) where ver_bit represents the position of the flipped bit among the k bits, and mod represents the integer operation for flipping bits 0 and 1; Step 6: Determine whether the termination condition is satisfied according to the fitness value f(x i ). If it is satisfied, the position of the current spark is the optimal solution of the objective function, and the search stops; otherwise, select several individuals with the best fitness value f(x i ) from the fireworks, explosion sparks, and Gaussian mutation sparks as fireworks and jump to Step 3 to perform the next generation of iterative calculations. At the same time, discard all unselected information.

2. A computer device, comprising a memory, a processor, and a computer program stored on the memory and capable of running on the processor, characterized in that, the processor processes and executes the computer program to implement the steps of the method according to claim 1.

Citation Information

Patent Citations

  • Fireworks algorithm on basis of simulated annealing and Gauss disturbance

    CN106776469A

  • Multi-target scheduling method based on fireworks algorithm and genetic algorithm

    CN113505974A