A Hardware Security Evaluation Method for Block Ciphers Based on Template Principal Component Regression

By adopting the template principal component regression method in the security evaluation of packet cipher hardware, the problem of singular matrix in multivariate linear regression analysis in high-dimensional feature space is solved, and efficient evaluation of the security of packet cipher equipment is achieved, reducing the computational complexity.

CN115422603BActive Publication Date: 2025-05-27HEILONGJIANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210877463.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-25
Publication Date
2025-05-27
Estimated Expiration
2042-07-25

AI Technical Summary

Technical Problem

When the prior art uses multiple linear regression models in high-dimensional feature spaces, singular matrix problems are prone to occur, resulting in analysis failures, and traditional packet cryptographic chips cannot effectively detect their physical implementation security.

Method used

The hardware security evaluation method of packet cryptography based on template principal component regression is adopted. By collecting the energy traces of known and unknown keys, the Hamming distance matrix of the intermediate value is calculated, and it is reconstructed into a linearly uncorrelated matrix through orthogonal transformation and principal component analysis. The regression coefficient matrix is ​​solved by using the least squares method to construct a template to evaluate the security of packet cryptography equipment.

Benefits of technology

It effectively solves the problem of irreversible singular matrix in multivariate linear regression analysis, reduces the calculation cost of regression analysis, provides an effective evaluation method for detecting the security of packet cryptographic devices, and improves the advantages of evaluation efficiency and calculation complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115422603B_ABST
    Figure CN115422603B_ABST
Patent Text Reader

Abstract

The present invention provides a hardware security evaluation method for block ciphers based on template principal component regression. By means of principal component analysis, this method projects the original data from a high-dimensional space to a low-dimensional space through orthogonal transformation for linearly correlated variables, converting them into linearly uncorrelated variables. That is, it can solve the problem of irreversible singular matrices that may occur in multiple linear regression analysis without sacrificing the estimation performance of regression, and to a certain extent reduce the computational cost of regression analysis. Experimental results show that it has excellent performance in solving the problem of irreversible singular matrices that may occur in multiple linear regression analysis methods. The template constructed by template principal component regression has better universal value, evaluation convergence completion degree and evaluation computational complexity, providing a good evaluation means for detecting the security of block cipher devices. The present invention has the advantages of higher evaluation efficiency, lower computational complexity and better universality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data encryption, and particularly to a method for evaluating the hardware security of block ciphers based on template principal component regression. Background Art

[0002] Since Kocher proposed the timing analysis method in 1996, side-channel analysis, as a unique cryptographic analysis method different from classical cryptographic analysis, has become a research hotspot in the field of cryptography after more than 20 years of development with its powerful analysis capabilities and wide application scope. The general categories of side-channel analysis include timing analysis, power analysis, template analysis, electromagnetic analysis, collision analysis, fault analysis, and artificial intelligence side-channel analysis.

[0003] Template analysis is a new type of side-channel analysis method proposed by Chari et al. in 2002 and has received enthusiastic attention since its proposal. Due to the presence of noise interference when collecting the power consumption curves of cryptographic devices, if the signal-to-noise ratio of the collected power consumption signal is relatively low, traditional side-channel analysis methods may be limited, resulting in analysis failure. Therefore, analysts must use other methods to obtain the key. However, for template analysis, the noise in the power consumption signal can be effectively utilized, so the noise will not affect its analysis results. Soon after the proposal of template analysis, scholars proposed to use random analysis of linear regression in the analysis stage. With the in-depth study of template analysis, researchers have recognized some weaknesses in template analysis, such as using a multiple linear regression model in a high-dimensional feature space, which will bring numerical calculation problems (singular matrices). In 2018, W.J. Wang et al. proposed the method of ridge regression to impose constraints on the linear regression coefficients. Ridge regression is a biased estimation regression method dedicated to linear data analysis. It is essentially a modified least squares estimation method that obtains the regression coefficients at the cost of sacrificing the unbiasedness of the least squares method, losing some information and reducing the accuracy. However, this method at the cost of losing effective information will directly lead to the deviation universality of the constructed model itself being not good, and there is an undetermined parameter λ in ridge regression modeling, whose value will affect the modeling effect, and finding the optimal solution of parameter λ requires a large amount of computing power. Traditional block cipher chips only assume that an attacker can obtain input or output data and cannot obtain other intermediate information related to the key. Therefore, the mathematical security of block cipher algorithms cannot guarantee their physical implementation security. Therefore, a method for evaluating the hardware security of block ciphers based on template principal component regression is needed to detect and evaluate the security of block cipher devices. Summary of the Invention

[0004] Based on the above deficiencies, the object of the present invention is to propose a block cipher hardware security evaluation model based on template principal component regression to solve the problem of irreversible singular matrix in multiple linear regression analysis and provide a good evaluation method for detecting the security of block cipher devices.

[0005] The technical solution adopted by the present invention is as follows: A block cipher hardware security evaluation method based on template principal component regression, and the method steps are as follows:

[0006] Step 1: Collect a set of modeling energy traces t = {t i |i ∈ [1, n]} of known key random plaintexts. Each energy trace corresponds to m sampling points. The j-th sampling point of the i-th energy trace is denoted as t i,j , record the corresponding plaintext p = {p i |i ∈ [1, n]}, ciphertext c = {c i |i ∈ [1, n]}, and then collect a set of matching energy traces t' = {t' i |i ∈ [1, n]} of unknown key random plaintexts, record the corresponding plaintext p' = {p' i |i ∈ [1, n]}, ciphertext c' = {c' i |i ∈ [1, n]}. Step 2: Calculate the Hamming distance matrix of the intermediate values of the known keys as the feature matrix X * of multiple linear regression according to the plaintext p = {p i |i ∈ [1, n]} or the ciphertext c = {c i |i ∈ [1, n]}. The feature matrix X * is as shown in Equation (1):

[0007]

[0008] where v represents the intermediate value, and the intermediate value v varies according to different block ciphers and modeling positions.

[0009] Step 3: Reconstruct the Hamming distance matrix X * into a linearly independent matrix through orthogonal transformation

[0010] a. Calculate the reference sample mean,

[0011] Take the average value of each column of the Hamming distance matrix X * to obtain the mean matrix whose mathematical expression is as shown in Equation (2):

[0012]

[0013] b. Centralize the sample matrix

[0014] Matrix centering is to make the matrix X * Subtract the mean from each column of the matrix Get the centralized sample matrix Its mathematical expression is shown in formula (3):

[0015]

[0016] c. Calculate the centralized sample matrix The covariance matrix C of is n×n dimensional matrix, and its mathematical expression is shown in formula (4).

[0017]

[0018] d. Perform eigenvalue decomposition on the covariance matrix C and find its eigenvalue and eigenvector. Its mathematical expression is shown in formula (5).

[0019] A T CA=λ (5)

[0020] Among them, A is called the eigenvector matrix, λ is the eigenvalue diagonal matrix, the eigenvalues ​​are arranged in descending order according to the numerical size, and the eigenvectors corresponding to the eigenvalues ​​are arranged in sequence. The cumulative contribution rate of the first k principal components is the ratio of the sum of the first k eigenvalues ​​to the sum of all eigenvalues. According to the cumulative contribution rate, the eigenvectors corresponding to the first k eigenvalues ​​are selected to form the projection matrix A n×k , where k is less than n,

[0021] e. Use the projection matrix to centralize the sample matrix Projected to the new space, we get the m×k-dimensional sample principal component matrix, whose mathematical expression is shown in formula (6). At this point, the original n-dimensional vector is reduced to a k-dimensional vector.

[0022]

[0023] Step 4: Use the least squares method to reconstruct the uncorrelated matrix Solve the regression coefficient matrix W as the characteristic matrix * , so far the template construction stage is completed, and its mathematical expression is shown in formula (7):

[0024]

[0025] Step 5: According to the plaintext p′={p′ i |i∈[1,n]} and ciphertext c′={c′ i |i∈[1,n]} calculates the intermediate Hamming distance matrix of all possible unknown subkey values ​​as the feature matrix X of multivariate linear regression,

[0026] Step 6: Utilize Modeling Phase X* The eigenvector matrix of the covariance matrix reconstructs the centered matrix of matrix X into a linearly uncorrelated matrix whose mathematical expression is shown in Equation (8):

[0027]

[0028] Step Seven: Bring the regression coefficient matrix W * and matrix back into the multiple linear regression model to calculate the estimated power consumption matrix whose mathematical expression is shown in Equation (9):

[0029]

[0030] Step Eight: Calculate the similarity between the estimated power consumption matrix and the true power consumption matrix Y, output the key guess corresponding to the highest correlation coefficient, and implement the above steps for each byte of the block cipher in turn to complete the evaluation of the hardware security of the block cipher.

[0031] Another object of the present invention is to provide a computer device, including a memory, a processor, and a computer program stored on the memory and capable of running on the processor, and the processor processes and executes the computer program to implement the steps of the above method.

[0032] Beneficial effects and advantages of the present invention: The present invention can not only solve the problem that the singular matrix may be irreversible in the multiple linear regression analysis method, reduce the computational cost of the regression analysis, and provide a good evaluation method for detecting the security of block cipher devices. The intermediate value Hamming distance is used as different features x of the feature matrix X i,j , so the feature x i,j can only take values of 0 and 1. If any column vector of the feature matrix X is all 0 or all 1, it will cause X T X to be a singular matrix and irreversible, as shown in Figure 1 (a). Through principal component analysis, the present invention projects the linearly correlated variables from the high-dimensional space to the low-dimensional space through orthogonal transformation to convert them into linearly uncorrelated variables. The feature x in the new space i,j ∈R has a value range that is no longer limited to 0 and 1. Compared with the original matrix space with only 0 and 1, it is more difficult to have a multicollinearity problem. At the same time, the projection of the original data from the high-dimensional space to the low-dimensional space reduces the computational and storage costs of the data. Experimental results show that there are no eigenvectors with strong autocorrelation in the eigenvectors of the feature matrix X in the new space, and all eigenvectors have an autocorrelation estimate R(k) closer to 0, as shown in Figure 1 (d). The correlation coefficients between the vectors of matrix X T X are minimized and close to 0, as shown in Figure 2(d) shows the matrix X T There is no collinearity in X, which solves the problem that the original linear regression singular matrix cannot be solved. The present invention has the advantages of higher evaluation efficiency, lower computational complexity, and better universality. Description of the Drawings

[0033] Figure 1 is the autocorrelation detection of eigenvectors;

[0034] (a) Autocorrelation detection of eigenvectors of a non-singular matrix in multiple linear regression,

[0035] (b) Autocorrelation detection of eigenvectors of a singular matrix in multiple linear regression,

[0036] (c) Autocorrelation detection of eigenvectors of a singular matrix in ridge regression,

[0037] (d) Autocorrelation detection of eigenvectors of a singular matrix in principal component regression;

[0038] Figure 2 is the matrix X T Correlation coefficient matrix diagram between X vectors;

[0039] (a) Correlation coefficient matrix diagram between vectors of a non-singular matrix in multiple linear regression,

[0040] (b) Correlation coefficient matrix diagram between vectors of a singular matrix in multiple linear regression,

[0041] (c) Correlation coefficient matrix diagram between vectors of a singular matrix in ridge regression,

[0042] (d) Correlation coefficient matrix diagram between vectors of a singular matrix in principal component regression;

[0043] Figure 3 is the evaluation convergence situation diagram under different noise conditions;

[0044] (a) Evaluation convergence situation when the noise standard deviation is 2, (b) Evaluation convergence situation when the noise standard deviation is 4;

[0045] Figure 4 is the evaluation of computational complexity under different noise conditions;

[0046] (a) Evaluation of computational complexity when the noise standard deviation is 2, (b) Evaluation of computational complexity when the noise standard deviation is 4; Detailed Implementation Manner

[0047] The present invention models by adopting the idea of "divide and conquer", calculates the corresponding intermediate values through known sub-keys, reconstructs the intermediate value matrix by principal components into a linearly independent matrix, constructs a template by using the corresponding regression coefficient matrix, and adopting a suitable principal component threshold can not only construct a template with better universality but also shorten the modeling time. The correlation coefficients between the estimated power consumption matrix and the actual power consumption matrix for all possible key values are calculated through the constructed template, and the sub-key with the optimal correlation is matched. Taking AES-128 as an example, the following gives the specific process of the block cipher hardware security evaluation method based on template principal component regression, as shown in Algorithm 1. The following further describes the present invention in detail with AES-128 as an example in combination with the embodiments and the accompanying drawings, and the algorithm is shown in Table 1. The implementation manner of the present invention is not limited thereto and is applicable to most block cipher algorithms with strong universality.

[0048] Embodiment 1

[0049] A block cipher hardware security evaluation method based on template principal component regression, the steps are as follows:

[0050] I. Template construction and acquisition of template matching power consumption waveforms

[0051] Acquire a set of modeling energy traces t = {t i | i ∈ [1, n]} of known key random plaintexts, and each energy trace corresponds to m sampling points. The j-th sampling point of the i-th energy trace is denoted as t i,j . Record the corresponding plaintext p = {p i | i ∈ [1, n]}, ciphertext c = {c i | i ∈ [1, n]}. Then acquire a set of matching energy traces t' = {t' i | i ∈ [1, n]} of unknown key random plaintexts. Record the corresponding plaintext p' = {p' i | i ∈ [1, n]}, ciphertext c' = {c' i | i ∈ [1, n]}.

[0052] II. Construction of the feature matrix in the template construction stage

[0053] According to the plaintext p = {p i | i ∈ [1, n]} and ciphertext c = {c i | i ∈ [1, n]}, calculate the Hamming distance matrix of the intermediate value v of the known key as the feature matrix X * of the multiple linear regression, and the feature matrix X * is as shown in Equation (10):

[0054]

[0055] III. Matrix X in the template construction stage *Orthogonal transformation

[0056] The Hamming distance matrix X * is reconstructed into a linearly independent matrix through orthogonal transformation

[0057] a). Calculate the mean of the reference samples.

[0058] For the Hamming distance matrix X * take the average of each column to obtain the mean matrix whose mathematical expression is shown in Equation (11).

[0059]

[0060] b). Center the sample matrix

[0061] Matrix centering is to make the matrix X * subtract the mean matrix from each column to obtain the centered sample matrix whose mathematical expression is shown in Equation (12).

[0062]

[0063] c). Calculate the covariance matrix C of the centered sample matrix . C is an n×n-dimensional matrix, and its mathematical expression is shown in Equation (13).

[0064]

[0065] d). Perform eigenvalue decomposition on the covariance matrix C and find its eigenvalues and eigenvectors. Its mathematical expression is shown in Equation (14).

[0066] A T CA = λ (14)

[0067] where A is called the eigenvector matrix and λ is the eigenvalue diagonal matrix. Arrange the eigenvalues in descending order of magnitude, and arrange the corresponding eigenvectors in sequence. The cumulative contribution rate of the first k principal components is the ratio of the sum of the first k eigenvalues to the sum of all eigenvalues. According to the cumulative contribution rate, select the eigenvectors corresponding to the first k eigenvalues to form the projection matrix A

[0068] projection matrix A n×k , where k is less than n.

[0069] e. Use the projection matrix to project the centered sample matrix onto a new space to obtain an m×k-dimensional sample principal component matrix. Its mathematical expression is shown in Equation (15). Thus, the original n-dimensional vector is reduced to a k-dimensional vector.

[0070]

[0071] Figure 1 (a) is the matrix X T When X is a non - singular matrix, it is the autocorrelation test result of the eigenmatrix X. It can be seen that the autocorrelations of the 8 groups of eigenvectors are all very weak and basically in the micro - correlation range. Figure 1 (b)(c)(d) are the matrix X T When X is a singular matrix, it is the autocorrelation test result of the eigenmatrix X. Figure 1 (b)(c) The results show that there is 1 group of eigenvectors with strong autocorrelation in both linear regression and ridge regression, and the autocorrelation estimates R(k) of the other eigenvectors are concentrated around 0.3. Since principal component regression projects the original data of the eigenmatrix X from the original space to a new space, Figure 1 (d) The results show that there are no eigenvectors with strong autocorrelation among the eigenvectors in the new space, and all eigenvectors have autocorrelation estimates R(k) closer to 0, showing good randomness.

[0072] IV. Regression coefficient matrix W *

[0073] Using the least - squares method, with the reconstructed uncorrelated matrix as the eigenmatrix to solve the regression coefficient matrix W * , thus completing the template construction stage. Its mathematical expression is shown in Equation (16):

[0074]

[0075] By pairwise solving the correlation coefficients of the vectors of matrix X T X for linear regression and principal component regression T X and matrix X Figure 2 X + λI for ridge regression, the correlation coefficient matrix is as shown Figure 2 (a) shows that when matrix X T X is a non - singular matrix, each vector is completely correlated only with itself. As shown in Figure 2 (b) when matrix X T X is a singular matrix, vector 2 of linear regression is completely correlated with vector 1. As shown in Figure 2 (c) when matrix X T X is a singular matrix, although ridge regression solves the problem of exact correlation to a certain extent, the correlation coefficient between vector 2 and vector 1 is still strongly correlated, and the correlation coefficient reaches 0.931351829311663. As shown in Figure 2 (d) in the principal component regression we proposed, the correlation coefficients between the vectors of matrix X T X are the smallest and close to 0, indicating that matrix XT There is no collinearity in X, solving the problem that the singular matrix of the original linear regression cannot be solved.

[0076] V. Construction of Feature Matrix in Template Matching Stage

[0077] According to the plaintext p′ = {p′ i | i ∈ [1, n]} and the ciphertext c′ = {c′ i | i ∈ [1, n]}, calculate the Hamming distance matrix of intermediate values for all possible values of the unknown sub - keys as the feature matrix X of multiple linear regression.

[0078] VI. Orthogonal Transformation of Matrix X in Template Matching Stage

[0079] Use the eigenvector matrix of the covariance matrix of X in the modeling stage to * re - construct the centered matrix of matrix X into a linearly uncorrelated matrix whose mathematical expression is shown in Equation (17):

[0080]

[0081] VII. Estimation of Power Consumption Matrix Construct

[0082] Bring the regression coefficient matrix W * and the matrix back to the multiple linear regression model to calculate the estimated power consumption matrix whose mathematical expression is shown in Equation (18):

[0083]

[0084] VIII. Key Guessing

[0085] Calculate the similarity between the estimated power consumption matrix and the true power consumption matrix Y, output the key guess corresponding to the highest correlation coefficient, and perform the above steps on 16 bytes of AES - 128 in turn to complete the evaluation of the hardware security of block ciphers.

[0086] Table 1 Template Principal Component Regression

[0087]

[0088]

[0089] To verify the evaluation efficiency of this model, it is compared with the multiple linear regression model and the ridge regression model proposed by Wang et al. in terms of the evaluation convergence degree and computational complexity. Modeling is carried out under the conditions that the noise standard deviations are 2 and 4 respectively, and the evaluation convergence degree is as Figure 3 shown. FromFigure 3 It can be seen that the evaluation convergence speed of the three methods shows an upward trend with the increase in the number of model-matched waveforms. Due to the influence of noise, more template-matched waveforms are affected. Since the template attack based on ridge regression is a biased estimation, more template-matched energy traces are required to complete the security evaluation. Modeling is carried out under the conditions where the noise standard deviations are 2 and 4 respectively, and the computational complexity is compared as Figure 4 . From Figure 4 it can be seen that the computational complexities of the multiple linear regression model and the ridge regression model are almost the same. The proposed block cipher hardware security evaluation model based on template principal component regression in the present invention maps the feature matrix from high dimension to low dimension, which reduces the computational amount to a certain extent. Therefore, its computational cost is the smallest among the three methods, and this advantage of computational cost increases with the increase in the number of template-matched waveforms. Therefore, whether it is the evaluation convergence speed or the evaluation computational complexity, the proposed block cipher hardware security evaluation model based on template principal component regression in this paper has more advantages.

Claims

1. A hardware security evaluation method for block ciphers based on template principal component regression, the method steps are as follows: Step 1: Collect a set of modeled energy traces \(t = \{t i _i|i\in[1,n]\}\) of known key random plaintexts. Each energy trace corresponds to \(m\) sampling points. The \(j\)-th sampling point of the \(i\)-th energy trace is denoted as \(t i,j _{ij}\). Record its corresponding plaintext \(p = \{p i _i|i\in[1,n]\}\), ciphertext \(c = \{c i _i|i\in[1,n]\}\). Then collect a set of matching energy traces \(t'=\{t' i _i|i\in[1,n]\}\) of unknown key random plaintexts, and record its corresponding plaintext \(p'=\{p' i _i|i\in[1,n]\}\), ciphertext \(c'=\{c' i _i|i\in[1,n]\}\). Step 2: Calculate the Hamming distance matrix of the intermediate values of the known key as the feature matrix \(X i \) according to the plaintext \(p = \{p i _i|i\in[1,n]\}\) or the ciphertext \(c = \{c * _i|i\in[1,n]\}\) for multiple linear regression. The feature matrix \(X * \) is shown in Equation (1): Where v represents the intermediate value, and the intermediate value v varies according to different block ciphers and modeling positions. Step 3: Reconstruct the Hamming distance matrix X * into a linearly independent matrix through orthogonal transformation a) Calculate the reference sample mean. Hamming distance matrix X * Take the average value of each column to obtain the mean matrix Its mathematical expression is shown in Equation (2), b) Centralize the sample matrix Matrix centering is to subtract the mean matrix from each column of matrix X * to obtain the centered sample matrix The mathematical expression is shown in Equation (3), ​ c) Calculate the centralized sample matrix to obtain the covariance matrix C. C is an n×n matrix, and its mathematical expression is shown in Equation (4). d) Perform eigenvalue decomposition on the covariance matrix C and find its eigenvalues and eigenvectors. Its mathematical expression is shown in Equation (5). A T CA = λ (5) Where, Let \(A\) be the eigenvector matrix and \(\lambda\) be the diagonal matrix of eigenvalues. The eigenvalues are arranged in descending order of magnitude, and the corresponding eigenvectors are arranged in sequence. The cumulative contribution rate of the first \(k\) principal components is the ratio of the sum of the first \(k\) eigenvalues to the sum of all eigenvalues. According to the cumulative contribution rate, the eigenvectors corresponding to the first \(k\) eigenvalues are selected to form the projection matrix \(A\). n×k , where \(k\lt n\). e) Use the projection matrix to centralize the sample matrix Projected to the new space, we get the m×k-dimensional sample principal component matrix, whose mathematical expression is shown in formula (6). At this point, the original n-dimensional vector is reduced to a k-dimensional vector. Step 4: Use the least squares method to solve the regression coefficient matrix W with the reconstructed uncorrelated matrix as the feature matrix * , thus completing the template construction stage, and its mathematical expression is shown in Equation (7): Step Five: Calculate the Hamming distance matrix of intermediate values for all possible values of the unknown sub-keys as the feature matrix X for multiple linear regression based on the plaintext p′ = {p′ i | i ∈ [1, n]} and the ciphertext c′ = {c′ i | i ∈ [1, n]}. Step Six: Utilize the eigenvector matrix of the covariance matrix in the modeling stage X * to reconstruct the centered matrix of matrix X into a linearly uncorrelated matrix whose mathematical expression is shown in Equation (8): Step 7: Bring the regression coefficient matrix W * and the matrix back to the multiple linear regression model to calculate the estimated power consumption matrix whose mathematical expression is shown in Equation (9): Step 8: Calculate the estimated power consumption matrix Calculate the similarity with the true power consumption matrix Y, output the key guess corresponding to the highest correlation coefficient, and implement the above steps for each byte of the block cipher in turn to complete the evaluation of the hardware security of the block cipher.

2. A computer device, including a memory, a processor, and a computer program stored on the memory and capable of running on the processor. It is characterized in that The processor processes and executes the computer program to implement the steps of the method described in Claim 1.

Citation Information

Patent Citations

  • A method and a system for acquiring a secret key in a password chip

    CN109583235A

  • Efficient computation of bivariate statistical moments for side channel vulnerability evaluation

    US20190260572A1