Active countermeasure method and device for password chip side channel based on active shielding layer
By generating an active shielding layer and constructing an electromagnetic interference circuit in integrated circuits, the problem of various physical attacks on integrated circuits is solved, achieving effective protection against invasive and semi-invasive attacks and improving the security of integrated circuits.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- THE ACAD OF TIANJIN UNIV HEFEI
- Filing Date
- 2022-11-23
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies are insufficient to simultaneously combat multiple physical attacks on integrated circuits, especially invasive and semi-invasive attacks, which threaten chip security.
A side-channel active countermeasure method based on an active shielding layer is adopted. This method generates an active shielding layer to cover the protected area of the cryptographic circuit and constructs an electromagnetic confusion circuit. The generated code stream is input into the active shielding layer to generate a strong magnetic field to interfere with the operation of the underlying cryptographic circuit, thereby encrypting information and confusing electromagnetic information.
It effectively resists invasive and semi-invasive attacks, improves the security of integrated circuits, reduces the signal-to-noise ratio, and enhances the ability to resist various physical attacks.
Smart Images

Figure CN115834052B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of integrated circuit security technology, and more specifically to a method and apparatus for active countermeasures against cryptographic chips using an active shielding layer. Background Technology
[0002] In recent years, integrated circuits have made significant progress and are widely used in various fields related to national economy and people's livelihood, such as industrial production, transportation, and electronic payment. Security chips, with the hardware implementation of cryptographic algorithms at their core, play an important role in protecting data security. However, with the continuous advancement of attack techniques, attack methods targeting security chips are also increasing. A large number of physical attack threats and new attack methods, represented by invasive, non-invasive, and semi-invasive attacks, can bring truly catastrophic security problems to cryptographic chips and systems.
[0003] Intrusive attacks are currently the most effective and thorough attack methods. They disrupt integrated circuit packaging and, through reverse engineering, microprobes, focused ion beams, and other techniques, obtain chip layout information and modify chip traces. Attackers can easily obtain critical information such as the chip's circuit structure, stored data, and bus data. Semi-intrusive attacks also require disrupting the chip packaging, but do not modify the chip itself. Instead, they affect the chip's operating state through methods such as optical fault injection and localized thermal fault injection. Non-intrusive attacks do not require disrupting the chip packaging. Instead, they obtain information such as power consumption, electromagnetic radiation, and setup time during chip use. Based on the relationship between this information and input / output data and algorithm keys, they can steal critical data through certain analytical methods. However, existing protection measures are all single-type protection strategies and cannot simultaneously protect against invasive and semi-invasive attacks. Therefore, a composite protection method for cryptographic chips is urgently needed.
[0004] In summary, physical attacks are a powerful attack method that can easily capture, crack, or even copy private information stored in integrated circuit chips, seriously threatening integrated circuits and national defense security. Active shielding layers are considered a highly effective technology for resisting invasive attacks and are widely used in various security chips. By designing a code stream detection circuit, the generated code stream is compared with the code stream flowing through the active shielding layer, enabling real-time monitoring of invasive attacks. Furthermore, considering the high electromagnetic radiation characteristics of the upper metal layer, electromagnetic side-channel attacks can steal information such as keys by detecting electromagnetic leakage from the upper metal layer.
[0005] However, current protection methods mostly focus on one type of attack. For example, the random Hamiltonian circuit generation method based on the artificial fish swarm algorithm disclosed in Chinese Patent Publication No. CN107688848A is mainly applied to the generation of wiring structures in the active metal shielding layer of the chip to combat intrusive attacks, and is difficult to resist multiple physical attacks. In order to ensure the normal operation of integrated circuits and even national defense systems, it is necessary to carry out research on composite anti-physical attack technologies for integrated circuits to proactively counter the various physical attacks faced by integrated circuits. Summary of the Invention
[0006] The technical problem to be solved by this invention is how to proactively counter various physical attacks faced by integrated circuits.
[0007] This invention solves the above-mentioned technical problems through the following technical means: a side-channel active countermeasure method for cryptographic chips based on an active shielding layer, the method comprising:
[0008] Step a: Obtain the protected area of the cryptographic circuit;
[0009] Step b: Generate an active shielding layer to cover the area of the cryptographic circuit to be protected;
[0010] Step c: Construct the electromagnetic confusion circuit;
[0011] Step d: Input the code stream generated by the electromagnetic confusion circuit into the active shielding layer.
[0012] Beneficial Effects: This invention constructs an electromagnetic obfuscation circuit. When the generated code stream is input to the active shielding layer, the changing current creates a strong magnetic field on the active shielding layer. This magnetic field interferes with the encrypted information generated during the operation of the underlying cryptographic circuit, effectively countering semi-intrusive electromagnetic side-channel attacks. Meanwhile, the active shielding layer effectively resists invasive attacks. Therefore, the entire structure can actively counter side-channel attacks while resisting invasive attacks, thus providing the effect of actively resisting various physical attacks faced by integrated circuits.
[0013] Further, step a includes:
[0014] Electromagnetic side-channel analysis is performed on unprotected cryptographic circuits to locate the weak points and leakage areas of the cryptographic algorithm that are vulnerable to side-channel attacks, which are then identified as the areas of the cryptographic circuit to be protected.
[0015] Further, step b includes:
[0016] Based on the area of the cryptographic circuit to be protected, an active shielding layer with a Hamiltonian loop structure is generated using the artificial fish swarm algorithm and placed over the area of the cryptographic circuit to be protected.
[0017] Furthermore, the electromagnetic confusion circuit includes a linear feedback shift register, an RO oscillation circuit, and a selector. The linear feedback shift register is connected to the RO oscillation circuit and the selector, respectively. The RO oscillation circuit receives multiple oscillation signals and the selection signal of the linear feedback shift register. The selector receives a clock signal, a signal from the linear feedback shift register, and an oscillation signal input from the RO oscillation circuit, and outputs an electromagnetically confused code stream.
[0018] Furthermore, the selector receives a high-frequency clock signal and, for the electromagnetic traces during the period when the cryptographic circuit clock is 0, uses a linear feedback shift register to generate random peaks. For the electromagnetic traces during the period when the cryptographic circuit clock is 1, it uses the output of the linear feedback shift register to randomly select one of the four input signals of the RO oscillation circuit to achieve confusion of the electromagnetic traces.
[0019] Furthermore, after the code stream generated by the electromagnetic obfuscation circuit is input to the active shielding layer, the changing current generates a strong magnetic field on the active shielding layer. Compared to the cryptographic circuit below, the active shielding layer is closer to the attacker's electromagnetic probe, so the electromagnetic information actually measured by the attacker is obfuscated by the information of the magnetic field of the active shielding layer.
[0020] This invention also provides a cryptographic chip side-channel active countermeasure device based on an active shielding layer, the device comprising:
[0021] The region segmentation module is used to obtain the protected region of the cryptographic circuit;
[0022] The first protection module is used to generate an active shielding layer that covers the area of the cryptographic circuit to be protected.
[0023] The circuit construction module is used to build electromagnetic interference circuits;
[0024] The second protection module is used to input the code stream generated by the electromagnetic interference circuit into the active shielding layer.
[0025] Furthermore, the region division module is also used for:
[0026] Electromagnetic side-channel analysis is performed on unprotected cryptographic circuits to locate the weak points and leakage areas of the cryptographic algorithm that are vulnerable to side-channel attacks, which are then identified as the areas of the cryptographic circuit to be protected.
[0027] Furthermore, the first protection module is also used for:
[0028] Based on the area of the cryptographic circuit to be protected, an active shielding layer with a Hamiltonian loop structure is generated using the artificial fish swarm algorithm and placed over the area of the cryptographic circuit to be protected.
[0029] Furthermore, the electromagnetic interference circuit includes a linear feedback shift register, an RO oscillation circuit, and a selector. The linear feedback shift register is connected to both the RO oscillation circuit and the selector. The RO oscillation circuit receives multiple oscillation signals and randomly selects one signal from the multiple signals input to the linear feedback shift register as one of the signals to be passed into the active shielding layer. It then selects two signals as selection signals for the RO oscillation circuit to randomly select one of the multiple oscillation signals. The output signal of the RO oscillation circuit is also one of the signals to be passed into the active shielding layer. The selector receives the two signals that need to be passed into the active shielding layer and selects one of them to be passed into the active shielding layer according to the rising edge of the clock.
[0030] Furthermore, the selector receives a high-frequency clock signal and, for the electromagnetic traces during the period when the cryptographic circuit clock is 0, uses a linear feedback shift register to generate random peaks. For the electromagnetic traces during the period when the cryptographic circuit clock is 1, it uses the output of the linear feedback shift register to randomly select one of the four input signals of the RO oscillation circuit to achieve confusion of the electromagnetic traces.
[0031] Furthermore, after the code stream generated by the electromagnetic obfuscation circuit is input to the active shielding layer, the changing current generates a strong magnetic field on the active shielding layer. Compared to the cryptographic circuit below, the active shielding layer is closer to the attacker's electromagnetic probe, so the electromagnetic information actually measured by the attacker is obfuscated by the information of the magnetic field of the active shielding layer.
[0032] The advantages of this invention are:
[0033] (1) The present invention constructs an electromagnetic obfuscation circuit. After the generated code stream is input to the active shielding layer, the changing current generates a strong magnetic field on the active shielding layer, which can interfere with the encrypted information generated during the operation of the underlying cryptographic circuit, effectively resisting semi-intrusive electromagnetic side-channel attacks. The active shielding layer can effectively resist intrusive attacks. Therefore, the entire structure can actively resist side-channel attacks and resist intrusive attacks, thus having the effect of actively resisting various physical attacks faced by integrated circuits.
[0034] (2) The present invention uses an artificial fish swarm algorithm to generate an active shielding layer with a Hamiltonian circuit structure, which can generate random Hamiltonian circuits in a short time, thus accelerating the generation rate of the protective layer topology and improving the applicability of the random Hamiltonian circuit shielding layer. The active shielding layer generation process is independent of the process and can be applied to the generation of protective layers under all process conditions, greatly increasing the difficulty of protective layer identification.
[0035] (3) After the code stream generated by the electromagnetic confusion circuit of the present invention is input into the active shielding layer, it covers the two peaks of the encryption process and the electromagnetic traces generated by subsequent logic operations, so that the electromagnetic information actually measured by the attacker is confused by the information of the magnetic field of the active shielding layer, which greatly reduces the signal-to-noise ratio and effectively resists semi-intrusive electromagnetic side-channel attacks.
[0036] (4) The shielding layer wiring generated by the artificial fish swarm algorithm in this invention, combined with the electromagnetic confusion circuit, forms an active protection layer network, which can be applied to various intelligent systems such as smart cards, embedded devices, and unattended systems to achieve effective detection of physical attacks such as focused ion beam attacks, micro probe attacks, and electromagnetic side channels, thereby improving the anti-attack security protection level of various systems. Attached Figure Description
[0037] Figure 1 This is an architecture diagram of the cryptographic chip side-channel active countermeasure method based on an active shielding layer provided in Embodiment 1 of the present invention;
[0038] Figure 2 The electromagnetic curve of the S-box byte substitution operation in the AES encryption circuit of the cryptographic chip side-channel active countermeasure method based on active shielding layer provided in Embodiment 1 of the present invention is shown in the figure under 1000 plaintext inputs.
[0039] Figure 3 This is a schematic diagram of the AES encryption circuit-related electromagnetic side-channel attack results in the active shielding layer-based cryptographic chip side-channel active countermeasure method provided in Embodiment 1 of the present invention.
[0040] Figure 4 This is the execution diagram of the artificial fish swarm algorithm used to generate Hamiltonian circuits in the active countermeasure method for the side channel of a cryptographic chip based on an active shielding layer provided in Embodiment 1 of the present invention.
[0041] Figure 5 This is a schematic diagram of the electromagnetic confusion circuit in the cryptographic chip side-channel active countermeasure method based on an active shielding layer provided in Embodiment 1 of the present invention;
[0042] Figure 6 This is a schematic diagram of the electromagnetic trace obfuscation using an electromagnetic obfuscation circuit in the active shielding layer-based cryptographic chip side-channel active countermeasure method provided in Embodiment 1 of the present invention.
[0043] Figure 7 The simulated electromagnetic curve of the AES circuit after protection in the active shielding layer-based cryptographic chip side-channel active countermeasure method provided in Embodiment 1 of the present invention. Detailed Implementation
[0044] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0045] Example 1
[0046] A side-channel active countermeasure method for cryptographic chips based on active shielding layer 2, the method comprising:
[0047] S1. Side-channel analysis of cryptographic circuit 1: Perform electromagnetic side-channel analysis on the unprotected cryptographic circuit 1 to locate the weak points and leakage areas of the cryptographic algorithm that are vulnerable to side-channel attacks, and use them as the areas to be protected for cryptographic circuit 1, providing guidance for protection measures.
[0048] Taking an AES encryption circuit as an example, the byte substitution operation of the S-box is a common location for side-channel attacks. When the circuit is unprotected, a leakage model is constructed for the first round of byte substitution operations in the AES circuit, and electromagnetic curves are simulated. A correlational electromagnetic side-channel analysis attack is then performed on the byte substitution of the S-box. Under 1000 plaintext inputs, the electromagnetic curve of the S-box byte substitution operation is as follows: Figure 2 As shown, the results of the correlated electromagnetic side-channel attack are as follows: Figure 3 As shown. The correlation curve of the correct key separates from the correlation curve of the incorrect key at the 150th curve, meaning that for an unprotected AES circuit, the key can be cracked by looking at the 150th curve.
[0049] S2. Active shielding layer 2 structure design: Based on the area of the region to be protected in the cryptographic circuit 1, an active shielding layer 2 with a Hamiltonian loop structure is generated using the artificial fish swarm algorithm and covers the region to be protected in the cryptographic circuit 1. Figure 4 The execution graph of the artificial fish swarm algorithm used to generate Hamiltonian circuits is shown.
[0050] During the algorithm's initialization phase, the length and width of the wiring region are normalized to grid points by the wire width and spacing of the metal wires (e.g., ...). Figure 4 In (a)), a square formed by four adjacent grid points is defined as a fish (e.g., ...). Figure 4(b) This section demonstrates the execution process of the artificial fish swarm algorithm using 25 artificial fish as an example. Each artificial fish is marked with an activity level attribute and exhibits three behaviors: foraging, tail chasing, and swarming. Activity level is inversely proportional to the distance between the fish swarm and the food; the closer the distance, the higher the activity level. Artificial fish with an activity level of 0 are considered a free swarm, representing the initial swarm after algorithm initialization. Artificial fish with an activity level of 1 are active fish closer to the food than the free swarm; the free swarm can join the active swarm through tail chasing. Artificial fish with an activity level of 2 are the central swarm currently feeding. When food is randomly placed at the location of an artificial fish, its activity level will become 2 through foraging, and the active swarm can join the central swarm through swarming. The number of artificial fish in the central swarm is recorded on a bulletin board, and the data on the bulletin board is continuously updated during algorithm execution until the data on the bulletin board reaches a specified value.
[0051] Randomly select a fish and merge it with the nearest fish to it, generating a circuit C (e.g., ...). Figure 4 (cd) Next, continue to randomly select one fish from the fish closest to the loop for merging, until all fish are included in the loop (e.g., ...). Figure 4 (ef)), the active shielding layer 2 is generated. The method of generating Hamiltonian circuit structure using the artificial fish swarm algorithm is existing technology. It can adopt the random Hamiltonian circuit generation method based on the artificial fish swarm algorithm disclosed in patent publication number CN107688848A, or other methods described in other literature, which will not be elaborated here.
[0052] S3. Electromagnetic Information Confusion Circuit Design: Based on the electromagnetic leakage characteristics of the underlying circuit, the linear feedback shift register 31 is combined with the RO oscillation circuit 32 to generate an electromagnetic confusion signal that enters the active shielding layer 2. The electromagnetic confusion circuit 3 is as follows... Figure 5 As shown, the electromagnetic confusion circuit 3 includes a linear feedback shift register 31, an RO oscillation circuit 32, and a selector 33. The linear feedback shift register 31 is connected to the RO oscillation circuit 32 and the selector 33 respectively. The RO oscillation circuit 32 receives four kinds of RO oscillation signals and the selection signal of the linear feedback shift register 31. The selector 33 receives the clock signal, the signal of the linear feedback shift register 31, and the oscillation signal input to the RO oscillation circuit 32, and outputs the electromagnetically confused code stream.
[0053] Among them, the linear feedback shift register 31 is the most common method for generating pseudo-random numbers. It consists of several D flip-flops and XOR gates. This invention utilizes primitive polynomials to construct a 15-bit linear feedback shift register 31. First, a signal is randomly selected from the 15-bit signal input to the linear feedback shift register 31 as one of the signals fed into the active shielding layer 2. Second, two more signals are selected as selection signals for the RO oscillation circuit 32, used to randomly select one of four RO oscillation signals. The output signal of the RO oscillation circuit 32 is also one of the signals fed into the active shielding layer 2. The selector 33 receives the above two signals and selects one to be fed into the active shielding layer 2 according to the rising edge of the clock, thereby achieving the protection effect.
[0054] After the code stream generated by the electromagnetic obfuscation circuit 3 is input to the active shielding layer 2, the changing current generates a strong magnetic field on the active shielding layer 2. Compared with the cryptographic circuit 1 below, the active shielding layer 2 is closer to the attacker's electromagnetic probe. Therefore, the electromagnetic information actually measured by the attacker is obfuscated by the information of the magnetic field of the active shielding layer 2, which greatly reduces the signal-to-noise ratio.
[0055] The purpose of electromagnetic obfuscation circuit 3 is to mask the two peaks in the encryption process and the electromagnetic traces generated by subsequent logic operations, thereby reducing the signal-to-noise ratio and lowering the success rate of side-channel attacks. For example... Figure 6 As shown, the selector 33 receives a high-frequency clock signal. For the electromagnetic trace during the period when the clock of the cryptographic circuit 1 is 0, it uses the linear feedback shift register 31 to generate random peaks. For the electromagnetic trace during the period when the clock of the cryptographic circuit 1 is 1, it uses the output of the linear feedback shift register 31 to randomly select one of the four input signals of the RO oscillation circuit 32 to achieve confusion of the electromagnetic trace.
[0056] S4. Protection Effectiveness Verification: An active shielding layer 2 is placed over the encryption circuit, and the bitstream signal generated by the electromagnetic obfuscation circuit 3 is introduced to perform a correlated electromagnetic side-channel attack. The simulated electromagnetic curve of the protected AES circuit is shown below. Figure 7 As shown, the correlation curves of the correct hypothetical key and the incorrect key always overlap, making the key unbreakable, thus proving the side-channel protection capability of the electromagnetic confusion circuit.
[0057] Through the above technical solutions, this invention achieves composite protection against both invasive and non-invasive attacks by combining a rapid generation algorithm for a large-area active shielding layer 2 with an electromagnetic obfuscation circuit 3. The generation process is process-independent and applicable to shielding layer generation under all process conditions, significantly increasing the difficulty of shielding layer identification. The designed electromagnetic obfuscation circuit 3 can interfere with the encrypted information generated during the computation of the underlying encryption chip, effectively combating semi-invasive electromagnetic side-channel attacks. The shielding layer wiring generated by the rapid generation algorithm, combined with the electromagnetic obfuscation circuit 3, forms an active protection layer network that can be applied to various intelligent systems such as smart cards, embedded devices, and unattended systems. This enables effective detection of physical attacks such as focused ion beam attacks, micro-probe attacks, and electromagnetic side-channel attacks, thereby improving the anti-attack security level of various systems.
[0058] Example 2
[0059] Based on Embodiment 1, Embodiment 2 of the present invention also provides a cryptographic chip side-channel active countermeasure device based on an active shielding layer 2, the device comprising:
[0060] The region segmentation module is used to obtain the protected region of cryptographic circuit 1;
[0061] The first protection module is used to generate an active shielding layer 2 that covers the area to be protected of the cryptographic circuit 1.
[0062] The circuit construction module is used to construct the electromagnetic confusion circuit 3;
[0063] The second protection module is used to input the code stream generated by the electromagnetic interference circuit 3 into the active shielding layer 2.
[0064] Specifically, the region division module is also used for:
[0065] Electromagnetic side-channel analysis is performed on the unprotected cryptographic circuit 1 to locate the weak points and leakage areas of the cryptographic algorithm that are vulnerable to side-channel attacks, which are then identified as the areas to be protected for cryptographic circuit 1.
[0066] Specifically, the first protection module is also used for:
[0067] Based on the area of the region to be protected in cryptographic circuit 1, an active shielding layer 2 with a Hamiltonian loop structure is generated using the artificial fish swarm algorithm and placed over the region to be protected in cryptographic circuit 1.
[0068] Specifically, the electromagnetic interference circuit 3 includes a linear feedback shift register 31, an RO oscillation circuit 32, and a selector 33. The linear feedback shift register 31 is connected to the RO oscillation circuit 32 and the selector 33. The RO oscillation circuit receives multiple oscillation signals and randomly selects one signal from the multiple signals input to the linear feedback shift register as one of the signals to be passed into the active shielding layer. It then selects two signals as selection signals for the RO oscillation circuit to randomly select one of the multiple oscillation signals. The output signal of the RO oscillation circuit is also one of the signals to be passed into the active shielding layer. The selector receives the two signals that need to be passed into the active shielding layer and selects one of them to be passed into the active shielding layer according to the rising edge of the clock.
[0069] More specifically, the selector 33 receives a high-frequency clock signal and generates random peaks using a linear feedback shift register 31 for the electromagnetic traces during the period when the clock of the cryptographic circuit 1 is 0. For the electromagnetic traces during the period when the clock of the cryptographic circuit 1 is 1, the output of the linear feedback shift register 31 is used to randomly select one of the four input signals of the RO oscillation circuit 32 to confuse the electromagnetic traces.
[0070] More specifically, after the code stream generated by the electromagnetic obfuscation circuit 3 is input to the active shielding layer 2, the changing current generates a strong magnetic field on the active shielding layer 2. Compared with the cryptographic circuit 1 below, the active shielding layer 2 is closer to the attacker's electromagnetic probe. Therefore, the electromagnetic information actually measured by the attacker is obfuscated by the information of the magnetic field of the active shielding layer 2.
[0071] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A side-channel active countermeasure method for cryptographic chips based on an active shielding layer, characterized in that, The method includes: Step a: Obtain the protected area of the cryptographic circuit; perform electromagnetic side-channel analysis on the unprotected cryptographic circuit to locate the weak points and leakage intervals of the cryptographic algorithm that are vulnerable to side-channel attacks, and use these as the protected area of the cryptographic circuit. Step b: Generate an active shielding layer to cover the area of the cryptographic circuit to be protected; Step c: Construct an electromagnetic obfuscation circuit; the electromagnetic obfuscation circuit includes a linear feedback shift register, an RO oscillation circuit, and a selector. The linear feedback shift register is connected to the RO oscillation circuit and the selector respectively. The RO oscillation circuit receives multiple oscillation signals and the selection signal of the linear feedback shift register. The selector receives a clock signal, a signal from the linear feedback shift register, and an oscillation signal input from the RO oscillation circuit, and outputs an electromagnetically obfuscated bitstream. Step d: Input the code stream generated by the electromagnetic obfuscation circuit into the active shielding layer; after the code stream generated by the electromagnetic obfuscation circuit is input into the active shielding layer, the changing current generates a strong magnetic field on the active shielding layer above the cryptographic circuit, so as to obfuscate the electromagnetic information actually measured by the attacker's electromagnetic probe.
2. The cryptographic chip side-channel active countermeasure method based on an active shielding layer according to claim 1, characterized in that, Step b includes: Based on the area of the cryptographic circuit to be protected, an active shielding layer with a Hamiltonian loop structure is generated using the artificial fish swarm algorithm and placed over the area of the cryptographic circuit to be protected.
3. The cryptographic chip side-channel active countermeasure method based on an active shielding layer according to claim 1, characterized in that, The selector receives a high-frequency clock signal. For the electromagnetic traces during the period when the clock of the cryptographic circuit is 0, it uses a linear feedback shift register to generate random peaks. For the electromagnetic traces during the period when the clock of the cryptographic circuit is 1, it uses the output of the linear feedback shift register to randomly select one of the four input signals of the RO oscillation circuit to confuse the electromagnetic traces.
4. A cryptographic chip side-channel active countermeasure device based on an active shielding layer, characterized in that, The device includes: The region segmentation module is used to obtain the protected region of the cryptographic circuit; it performs electromagnetic side-channel analysis on the unprotected cryptographic circuit to locate the weak points and leakage intervals of the cryptographic algorithm that are vulnerable to side-channel attacks, and uses these as the protected region of the cryptographic circuit. The first protection module is used to generate an active shielding layer that covers the area of the cryptographic circuit to be protected. A circuit construction module is used to construct an electromagnetic interference circuit. The electromagnetic interference circuit includes a linear feedback shift register, an RO oscillation circuit, and a selector. The linear feedback shift register is connected to the RO oscillation circuit and the selector, respectively. The RO oscillation circuit receives multiple oscillation signals and the selection signal of the linear feedback shift register. The selector receives a clock signal, a signal from the linear feedback shift register, and an oscillation signal input from the RO oscillation circuit, and outputs an electromagnetically interfered bitstream. The second protection module is used to input the code stream generated by the electromagnetic obfuscation circuit into the active shielding layer. After the code stream generated by the electromagnetic obfuscation circuit is input into the active shielding layer, the changing current generates a strong magnetic field on the active shielding layer above the cryptographic circuit, so as to obfuscate the electromagnetic information actually measured by the attacker's electromagnetic probe.
5. The cryptographic chip side-channel active countermeasure device based on an active shielding layer according to claim 4, characterized in that, The first protection module is also used for: Based on the area of the cryptographic circuit to be protected, an active shielding layer with a Hamiltonian loop structure is generated using the artificial fish swarm algorithm and placed over the area of the cryptographic circuit to be protected.
6. The cryptographic chip side-channel active countermeasure device based on an active shielding layer according to claim 4, characterized in that, The electromagnetic confusion circuit randomly selects one signal from multiple signals input to the linear feedback shift register as one of the signals to be passed into the active shielding layer, and then selects two signals as selection signals for the RO oscillation circuit to randomly select one of multiple oscillation signals. The output signal of the RO oscillation circuit is also one of the signals to be passed into the active shielding layer. The selector receives two signals that need to be passed into the active shielding layer and selects one of them to be passed into the active shielding layer according to the rising edge of the clock.
Citation Information
Patent Citations
Artificial fish school algorithm based random Hamiltonian hoop generation method
CN107688848A
Integrated circuit chip protection against physical and / or electrical alterations
CN107787499A
Wiring method for reinforcing protection on important region of metal protection layer at top layer of chip
CN109585419A