A key leakage detection method for authentication encryption algorithm GIFT-COFB

By importing fault calculation differential values ​​and utilizing the impossible difference relation equation system, the problem of GIFT-COFB key leakage detection is solved, achieving fast and accurate key recovery and improving the security of the authentication encryption algorithm.

CN115714642BActive Publication Date: 2026-01-30DONGHUA UNIV +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211393375.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-08
Publication Date
2026-01-30
Estimated Expiration
2042-11-08

AI Technical Summary

Technical Problem

Existing technologies lack effective methods to detect key leakage in the GIFT-COFB authentication encryption algorithm, which affects the security of its packaged products.

Method used

By randomly generating messages and importing faults, the difference between correct and incorrect ciphertexts is calculated. The key search space is compressed using an impossible difference relation equation set. The round key is derived and the master key is recovered. Fault import is performed using methods such as software simulation, laser, electromagnetic or voltage interference.

Benefits of technology

It achieves fast and accurate key leakage detection, improves the security of the GIFT-COFB authentication encryption algorithm, and is easy to implement and fast.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115714642B_ABST
    Figure CN115714642B_ABST
Patent Text Reader

Abstract

This invention relates to a key leakage detection method for the GIFT-COFB authentication encryption algorithm, comprising: randomly generating a message X to be processed, and using the hash value V of the authentication information and message X as inputs to the GIFT-COFB algorithm; outputting correct ciphertext Y when unaffected by external irrelevant factors; then using the hash value V of the authentication information and message X as inputs to the GIFT-COFB algorithm again, and outputting incorrect ciphertext Y after introducing a fault in the fourth-to-last round. * Then, using the correct ciphertext Y and the incorrect ciphertext Y respectively * The intermediate state value A of round 39 is derived. 39 And calculate A 39 The difference ΔA between the sum and 39 Using ΔA 39 A set of impossible difference relation equations can be obtained by ≠0, which further compresses the key search space. The fault and analysis process is repeated to traverse all possible round key candidate values ​​and select the round key RK that meets the requirements. 40 and RK 39 Finally, the master key K is obtained according to the key arrangement algorithm. This invention evaluates the security of products packaged using the GIFT-COFB authentication encryption algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a method for detecting key leakage of the GIFT-COFB authentication encryption algorithm. Background Technology

[0002] With the continuous development of computer information security technology, information security issues have gradually come into focus and become particularly important. Network attacks, unauthorized intrusions, and information leaks are on the rise every year, posing significant security risks to people using the internet. Cryptography, as the cornerstone of information security, provides authentication and encryption functions to protect user information security. Authentication aims to ensure information integrity, verifying whether information has been tampered with by a third party; encryption ensures confidentiality, preventing unauthorized entities from accessing the information. The authentication encryption algorithm GIFT-COFB has been selected for the final round of the Lightweight Cryptography Standardization Project initiated by the National Institute of Standards and Technology (NIST). It can simultaneously guarantee information integrity and confidentiality. Therefore, a method is urgently needed to test the security of products packaged using the GIFT-COFB authentication encryption algorithm. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to provide a key leakage detection method for the GIFT-COFB authentication encryption algorithm, which can evaluate the security of products packaged using the GIFT-COFB authentication encryption algorithm.

[0004] The technical solution adopted by this invention to solve its technical problem is: to provide a key leakage detection method for the GIFT-COFB authentication encryption algorithm, comprising the following steps:

[0005] Randomly generate a message X to be processed;

[0006] The hash value V of the authentication information and the message X are used as inputs to the GIFT-COFB algorithm, and the correct ciphertext Y is output.

[0007] The hash value V of the authentication information and the message X are used as inputs to the GIFT-COFB algorithm, and a fault is imported at a specified position in the fourth-to-last round to obtain the erroneous ciphertext Y. * ;

[0008] Calculate the correct ciphertext Y and the incorrect ciphertext Y. * The difference value ΔY is used to determine whether the imported fault is a valid fault.

[0009] The incorrect ciphertext Y is obtained from the correct ciphertext Y and the valid fault. * Derive the intermediate state value A of the penultimate round. 39 and in, SC -1 (·) indicates that the information element is replaced by the inverse operation, PB -1 (·) represents the inverse operation of matrix permutation;

[0010] Calculate intermediate state value A 39 and The difference ΔA 39 Using ΔA 39 A set of impossible difference relation equations was obtained by ≠0. The key search space was further compressed, and the fault import and analysis process was repeated. Finally, the round key RK was derived. 40 and RK 39 All bits;

[0011] The key arrangement scheme based on GIFT-128, according to the round key RK 40 and RK 39 The master key was recovered using all its bits.

[0012] The step of determining whether the imported fault is a valid fault based on the difference value ΔY is as follows: when the difference value ΔY = 0, the fault is an invalid fault; when the difference value ΔY ≠ 0, the fault is a valid fault.

[0013] The impossible difference relation equation system is as follows: in,

[0014] The fault is modeled using a random nibble fault model.

[0015] The fault is introduced through software simulation, laser, electromagnetic and / or voltage interference.

[0016] Beneficial effects

[0017] By adopting the above-mentioned technical solution, this invention has the following advantages and positive effects compared with the prior art: This invention obtains erroneous ciphertext by introducing faults, and then establishes a set of impossible difference relationship equations based on the difference between the intermediate state values ​​of the correct ciphertext and the erroneous ciphertext, thereby further compressing the key search space. By repeating the fault introduction and analysis process, the round key RK can finally be derived. 40 and RK 39 All bits, then based on the GIFT-128 key arrangement scheme, using RK 40 and RK 39 The correct master key can then be recovered. The method provided by this invention is easy to implement, fast, and highly accurate, and is of great significance to the security research of the GIFT-COFB authentication encryption algorithm. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating the steps of an embodiment of the present invention;

[0019] Figure 2 Fault propagation diagram for impossible differential fault analysis in the GIFT-COFB encryption process;

[0020] Figure 3 This is a schematic diagram of the experimental environment in an embodiment of the present invention;

[0021] Figure 4 Analysis diagram of the GIFT-COFB authentication encryption algorithm;

[0022] Figure 5 An encryption analysis diagram of the underlying block cipher algorithm GIFT-128 used in the GIFT-COFB authentication encryption algorithm. Detailed Implementation

[0023] The present invention will be further illustrated below with reference to specific embodiments. It should be understood that these embodiments are for illustrative purposes only and are not intended to limit the scope of the invention. Furthermore, it should be understood that after reading the teachings of this invention, those skilled in the art can make various alterations or modifications to the invention, and these equivalent forms also fall within the scope defined by the appended claims.

[0024] The symbols used in the embodiments of this invention are explained as follows:

[0025] X: Message, X∈{{0,1} 4} 32 ;

[0026] |X|: The length of message X, in bits;

[0027] m: Total number of message packets;

[0028] X j The j-th message group, 1≤j≤m;

[0029] V: The hash value of the authentication information;

[0030] K: Key, K∈{{0,1} 4} 32 ;

[0031] Y: The correct ciphertext output, Y∈{{0,1} 4} 32 ;

[0032] Y j The j-th ciphertext block, 1≤j≤m;

[0033] Y * : Output erroneous ciphertext, Y* ∈{{0,1} 4} 32 ;

[0034] SC: Cell Substitution Operation;

[0035] PB: Matrix permutation operation;

[0036] SC -1 : Information element substitution inverse operation;

[0037] PB -1 Matrix permutation inverse operation;

[0038] A r : The intermediate state output value of the round key addition operation in the r-th round, 1≤r≤40;

[0039] B r The intermediate state output value of the information cell substitution operation in the r-th round, 1≤r≤40;

[0040] C r : The intermediate state output value of the matrix permutation operation in the r-th round, 1≤r≤40;

[0041] After importing the fault, the intermediate state output value of the round key addition operation in the r-th round is 1≤r≤40;

[0042] After the fault is imported, the information cell of the rth round replaces the intermediate state output value of the operation, 1≤r≤40;

[0043] After importing the fault, the intermediate state output value of the matrix permutation operation in the r-th round is 1≤r≤40;

[0044] The i-th half-byte of the intermediate state output value of the round key addition operation in the r-th round, 1≤r≤40, 1≤i≤32;

[0045] The i-th half-byte of the intermediate state output value of the cell substitution operation in the r-th round, 1≤r≤40, 1≤i≤16;

[0046] The i-th half-byte of the intermediate state output value of the matrix permutation operation in the r-th round, 1≤r≤40, 1≤i≤16;

[0047] E K Input key K and perform 40 rounds of encryption transformation.

[0048] XOR operation;

[0049] ∪: OR operation.

[0050] The embodiments of the present invention relate to a key leakage detection method for the authentication encryption algorithm GIFT-COFB, such as... Figure 1 As shown, it includes the following steps:

[0051] Step 1: Randomly generate a message to be processed, denoted as X, where X∈{{0,1} 4} 32 ;

[0052] Step 2: Input the hash value V of the authentication information and the message X into the GIFT-COFB algorithm, and output the correct ciphertext Y, where Y∈{{0,1} 4} 32 The process of the GIFT-COFB algorithm is as follows: Figure 4 As shown.

[0053] Step 3: Using the hash value V of the authentication information and the message X as input to the GIFT-COFB algorithm, a fault is introduced into the cryptographic system during operation. The fault location is the fourth to last round (round 37), thus obtaining the output erroneous ciphertext Y. * Y * ∈{{0,1} 4} 32 The fault imported in this step adopts a random half-byte fault model with a fault size of half a byte. It can be implemented by software simulation or by processing real hardware through technologies such as laser, electromagnetic, and voltage interference.

[0054] In steps 2 and 3, during the processing of the hash value V of the authentication information and message X using the GIFT-COFB authentication encryption algorithm, strict control of the experimental environment is required to ensure the accuracy of the experimental results (see...). Figure 3 This process generates the GIFT-COFB input message X using a computer, and processes and analyzes the output after the GIFT-COFB algorithm is applied to the input message. The device that encapsulates the GIFT-COFB algorithm processes the input message and obtains the corresponding output. The device that imports faults performs the fault import action during the GIFT-COFB algorithm's execution, thereby obtaining the erroneous ciphertext output. The specific operation method is as follows:

[0055] Experimental Environment 1: Input the hash value V of the authentication information and the message X. Strictly control the process to prevent interference from irrelevant external factors, so that the GIFT-COFB algorithm can accurately output the correct ciphertext Y during its operation.

[0056] Experimental Environment 2: Input the hash value V of the authentication information and the message X. During the execution of the GIFT-COFB algorithm, a fault is introduced. The fault location is the fourth to last round (round 37), and the fault type is a random half-bit fault, thus obtaining the erroneous ciphertext Y. * .

[0057] Step 4: Calculate Y and Y * The difference value is denoted as ΔY. After a fault is introduced, if ΔY≠0, the introduced fault can be considered a valid fault; if ΔY=0, the introduced fault can be considered an invalid fault.

[0058] Step 5: Obtain the incorrect ciphertext Y using the correct ciphertext Y and the valid fault. * Derive the intermediate state value A for round 39 (the penultimate round). 39 and

[0059]

[0060] The above derivation process is based on Figure 2 The diagram shows the fault propagation of impossible differential fault analysis in the GIFT-COFB encryption process.

[0061] Step 6: Calculate A 39 and The difference is denoted as ΔA. 39 Using ΔA 39 ≠0, that is Where 1≤i≤32, the key search space is further compressed. The fault import and analysis process is repeated, and finally the round key RK can be derived. 40 and RK 39 All bits.

[0062] The impossible difference relation equation system is as follows:

[0063]

[0064] in, and The meaning is as follows:

[0065]

[0066] Using the aforementioned impossible difference equations as constraints, we iterate through all possible candidate round keys and select the round key RK that meets the requirements. 40 and RK 39 .

[0067] Step 7: Key arrangement scheme based on GIFT-128 (see...) Figure 5 The attacker only needs RK40 and RK 39 By obtaining all bits, the master key can be recovered.

[0068] Using the above analysis method, this invention simulated the import failure and GIFT-COFB authentication encryption algorithm processing process on a computer with an Intel(R) Core(TM) i7-8550U CPU@1.80GHz 3.75GHz 8GB memory using the IDEA development tool, repeating the process 1000 times. The experimental results show that the above detection method is accurate.

[0069] It is not difficult to see that this invention obtains erroneous ciphertext by importing faults, and then establishes a set of impossible difference relationship equations based on the difference between the intermediate state values ​​of the correct and erroneous ciphertexts, thereby further compressing the key search space. By repeating the fault import and analysis process, the round key RK can finally be derived. 40 and RK 39 All bits, then based on the GIFT-128 key arrangement scheme, using RK 40 and RK 39 The correct master key can then be recovered. The method provided by this invention is easy to implement, fast, and highly accurate, and is of great significance to the security research of the GIFT-COFB authentication encryption algorithm.

Claims

1. A method for key-recovery detection of an authenticated encryption algorithm GIFT-COFB, characterized in that, The method comprises the following steps: Randomly generating a message X to be processed; Taking a hash value V of authentication information and the message X as inputs of a GIFT-COFB algorithm, and outputting correct ciphertext Y; The hash value V of the authentication information and the message X are inputted as the GIFT-COFB algorithm, and the fault is introduced at the designated position of the fourth last round to obtain the error ciphertext Y * ; Calculate the correct ciphertext Y and the incorrect ciphertext Y. * The difference value ΔY is used to determine whether the imported fault is a valid fault. According to the correct ciphertext Y and the valid fault, the error ciphertext Y is obtained * , the penultimate round intermediate state value A is derived 39 and Wherein, SC -1 (·) represents a bit instead of an inverse operation, PB -1 (·) represents a matrix permutation inverse operation; The intermediate state value A 39 and The difference value ΔA 39 , using ΔA 39 ≠0 to obtain a set of impossible differential relation equations, further compress the key search space, repeat the fault introduction and analysis process, and finally deduce all the bits of the round key RK 40 and RK 39 ​ The impossible differential relation equation set is: wherein A key schedule scheme based on GIFT-128 recovers the master key from all bits of round keys RK 40 and RK 39 .

2. The key leakage detection method of the authenticated encryption algorithm GIFT-COFB according to claim 1, wherein, The determining whether the introduced fault is an effective fault according to the differential value ΔY is specifically: when the differential value ΔY=0, the fault is an ineffective fault; and when the differential value ΔY≠0, the fault is an effective fault. 3.The key leakage detection method of the authenticated encryption algorithm GIFT-COFB according to claim 1, wherein, The fault adopts a random half-byte fault model. 4.The key leakage detection method of the authenticated encryption algorithm GIFT-COFB according to claim 1, wherein, The fault is introduced in a manner of software simulation, laser, electromagnetic interference and / or voltage interference.

Citation Information

Patent Citations

  • Secret key leakage detection method of SILC (Subscriber Identity Link Control) algorithm

    CN114124353A

  • Differential fault analysis and detection method for SM4 cryptographic algorithm

    CN114696994A