A universal side channel analysis method, device and storage device for establishing a lattice key

By combining the side channel analysis method of deep learning and fixed-length encoding, the problem of excessive overhead in the key recovery process in the prior art is solved, and efficient and low-overhead key recovery is achieved, which is suitable for general side channel analysis of grid key establishment.

CN116192378BActive Publication Date: 2025-05-16CHINA UNIV OF GEOSCIENCES (WUHAN)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310131732.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-16
Publication Date
2025-05-16
Estimated Expiration
2043-02-16

AI Technical Summary

Technical Problem

The existing side channel analysis method cannot take into account both the analysis efficiency and overhead costs, resulting in excessive overhead during key recovery.

Method used

The combination of deep learning and fixed-length encoding is adopted to reduce the number of inquiries on the oracle during the key recovery process and reduce the noise impact through the ciphertext recovery stage, the construction ciphertext stage, the key inspection stage and the re-acquisition and key update stage.

Benefits of technology

On the premise of ensuring high correctness of the key, the number of inquiries and overhead required for key recovery is reduced, the analysis efficiency is improved, and the generality is higher.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192378B_ABST
    Figure CN116192378B_ABST
Patent Text Reader

Abstract

The present invention discloses a universal side channel analysis method, device and storage device for lattice key establishment, the method includes four stages, namely, key recovery stage, ciphertext construction stage, key check stage, re-collection and key update stage; the first stage adopts a combination of deep learning and fixed-length coding to obtain multi-bit information coding, and recovers the unique identification complete key according to different coding; the second stage establishes a corresponding combination table of correct keys according to different private key coefficients; the third stage checks the complete key and records the wrong key combination position; the fourth stage recovers the wrong key combination; wherein the second stage only needs to construct once for different lattice key establishment schemes, and then the constructed ciphertext can be reused for key checking. The beneficial effects of the present invention are: higher efficiency, lower overhead, and more universality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information encryption and decryption, and in particular to a universal side channel analysis method, device and storage device for establishing a lattice key. Background Art

[0002] With the development of quantum computers, the existing cryptographic systems based on discrete logarithms and the difficulty of large integer factorization are under serious threat, and the security of cryptographic algorithms such as RSA, which are widely used today, is also facing severe challenges. Therefore, the US National Institute of Standards and Technology (NIST) has been soliciting public key cryptographic algorithms with quantum computer resistance worldwide since 2016. The public key cryptographic algorithm that was finally selected is the lattice-based quantum-resistant cryptographic algorithm KYBER.

[0003] In the security assessment of quantum-resistant cryptographic algorithms, side channel analysis is now considered the main threat. By utilizing the side channel information measured by physical devices, side channel analysis can recover secret information such as private keys, plaintext, etc.

[0004] Side channel information includes energy consumption, electromagnetic information, and execution time generated when implementing cryptographic algorithms. However, since side channel information is collected through physical devices, the noise in real life, such as human influence and insufficient device accuracy, has a significant impact on side channel analysis.

[0005] Among the feasible solutions, in order to reduce the impact of noise on side channel analysis and improve the robustness of side channel analysis, one method is to use deep learning methods to fully explore the effective features in side channel information and reduce the overhead required for key recovery. However, in order to improve the accuracy of the model, the number of voting times is increased, resulting in an exponential increase in the overhead of side channel analysis of cryptographic algorithms.

[0006] Some have also proposed new error checking methods, which greatly reduce the overhead of side channel analysis compared to voting. However, this method has low efficiency in analyzing valid information in side channel information, which leads to higher overhead in the key recovery stage. Summary of the invention

[0007] In order to solve the problem that the side channel analysis method cannot take into account both the analysis efficiency and the overhead cost, the present invention proposes a universal side channel analysis method for establishing a lattice key, comprising the following steps:

[0008] Ciphertext recovery phase, ciphertext construction phase, key checking phase, and re-collection and key update phase;

[0009] Key recovery stage: A combination of deep learning and fixed-length coding is used to obtain multi-bit information encoding, and the unique identification complete key sk = {sk[1], sk[2], ...sk[t], ..., sk[K-1], sk[K]} is recovered according to different encodings; where sk[t] represents one of the private key coefficients of the complete key, sk[t]∈[-u, u], t∈[0, K]; u is the range of the private key coefficient, and K is the number of private key coefficients;

[0010] Ciphertext construction phase: construct multiple ciphertext combinations SK according to different private key coefficients i Input to the oracle to establish the corresponding combination table of the correct key Table = (ct′1, ct′2, code);

[0011] Key checking stage: According to the combination table Table = (ct′1, ct′2, code), the recovered complete key sk is checked to find out the key combination with errors in the complete key, and the position of the incorrect key combination is recorded;

[0012] Re-collection and key update phase: Recover the wrong key combination based on the wrong key combination location record.

[0013] A storage device stores instructions and data for implementing a universal side channel analysis method for establishing a lattice key.

[0014] A universal side channel analysis device for establishing a lattice key comprises: a processor and a storage device; the processor loads and executes instructions and data in the storage device to implement a universal side channel analysis method for establishing a lattice key.

[0015] The beneficial effects provided by the present invention are: the number of inquiries required to restore the complete key is small and the overhead is low while ensuring the high correctness of the key. With the optimization of the deep learning model and the network, the overhead required by the method can be further reduced. It is more efficient, has less overhead, and is more versatile. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a schematic diagram of the method of the present invention;

[0017] Figure 2 It is a schematic diagram of the operation of the hardware device in the embodiment of the present invention. DETAILED DESCRIPTION

[0018] To make the objectives, technical solutions and advantages of the present invention more clear, the embodiments of the present invention will be further described below with reference to the accompanying drawings.

[0019] Please refer to Figure 1 , Figure 1Schematic diagram of the method of the present invention. The present invention provides a universal side channel analysis method for establishing a lattice key, which specifically includes:

[0020] Ciphertext recovery phase, ciphertext construction phase, key checking phase, and re-collection and key update phase;

[0021] Key recovery stage: A combination of deep learning and fixed-length coding is used to obtain multi-bit information encoding, and the unique identification complete key sk = {sk[1], sk[2], ...sk[t], ..., sk[K-1], sk[K]} is recovered according to different encodings; where sk[t] represents one of the private key coefficients of the complete key, sk[t]∈[-u, u], t∈[0, K]; u is the range of the private key coefficient, and K is the number of private key coefficients;

[0022] Among them, by using deep learning methods, the effective features in the side channel information can be fully explored, so that a single query of the oracle model can obtain multi-bit information, thereby achieving the purpose of efficiently and parallelly recovering multiple keys.

[0023] It should be noted that the specific process of the ciphertext recovery phase is as follows:

[0024] S11. Obtain the public-private key pair (pk, sk) and plaintext m in the lattice key establishment scheme; wherein ct = (c1, c2) is the valid ciphertext corresponding to the plaintext m;

[0025] It should be explained that sk here is fixed, and the attacker does not know what sk is. In the key recovery phase, sk is first recovered (some coefficients of the recovered sk may be wrong). The attacker can only obtain the public key pk and m, and can choose the ciphertext by himself.

[0026] S12, modify the valid ciphertext ct to the invalid ciphertext ct′=(c′1, c′2);

[0027] S13. Use invalid ciphertext to access the MV-PC oracle and get the oracle output where Dec.PKE(ct′,sk)=m i , Dec.PKE is the decryption algorithm; each visit to the oracle obtains log22 N =N bits of information;

[0028] It should be noted that the MV-PC oracle simulates the decryption process of the decryption party.

[0029] S14. Use multiple visits to obtain The bit information is encoded and the complete key sk is recovered to determine the unique identifier.

[0030] In contrast, each query to the MV-PC oracle obtains log22 = 1 bit of information each time, and can obtain at most log22 N =N bits of information.

[0031] The private key coefficient sk[t]∈[-u,u], t∈[0,K], uses fixed-length encoding for the key coefficient, only The bit information can determine the unique codeword of the key, and recovering the complete key only requires Inquiry.

[0032] It should be noted that fixed-length coding is an existing coding scheme, in which each key coefficient has a corresponding binary code, and the codeword lengths are equal.

[0033] Ciphertext construction phase: construct multiple ciphertext combinations SK according to different private key coefficients i Input to the oracle to establish the corresponding combination table of the correct key Table = (ct′1, ct′2, code);

[0034] The ciphertext construction phase is as follows:

[0035] S21, select M private key coefficients in the key sk to form a key combination

[0036] Among them, there are M private key coefficients with a total of B num =(2u+1) M Combination of situations;

[0037] S22. Modify the valid ciphertext ct = (c1, c2) to make it invalid ciphertext ct′ = (c′1, c′2). When the invalid ciphertext ct′ = (c′1, c′2) is used to access the MV-PC oracle, the output of the oracle is:

[0038]

[0039] S23. According to the oracle output of 0 or 1, the key combination SK i =(sk[M·i], sk[M·i+1, sk[M·i+M-1]) encoding;

[0040] Get two sets of ciphertext ct′1, ct′2 so that the key combination SK i The corresponding codewords are:

[0041]

[0042] Get the key combination SK that is unique to other keys j , And the code word corresponding to j≠i is:

[0043]

[0044] S24, check the code word of the key combination SKi, if the code word is code i , then the M private key coefficients of the key combination SKi are all correct, otherwise they are wrong;

[0045] S25, adopt step S24 for B num The key combinations in the above cases are all tested, the correct key coefficient combination is found, and the corresponding combination table of the correct key is established. Table = (ct′1, ct′2, code).

[0046] Key checking stage: According to the combination table Table = (ct′1, ct′2, code), the recovered complete key sk is checked to find out the key combination with errors in the complete key, and the position of the incorrect key combination is recorded;

[0047] Specifically, every M private key coefficients of the recovered complete key sk[t]∈[-u,u],t∈[0,K] are checked.

[0048] Find the table entry according to the table created in the previous stage c =(ct′ c,1, ct′ c,2, code c ), using the ciphertext ct′ in the table entry c,1 , ct′ c,2 Visit the oracle and observe the output code out Whether to record the code in the table c Match, such as code out =code c , it means that the M private keys in the key combination are recovered correctly, as shown in code out ≠code c , it means that there are recovery errors in the M private keys in the key combination. The error position will be recorded and the private key coefficients at the error position will be restored in the next stage. Inquiry.

[0049] Re-collection and key update phase: Recover the wrong key combination based on the wrong key combination location record.

[0050] The key coefficients of the wrong position recorded in the previous stage are restored again. The specific method is the same as the ciphertext recovery stage. After the key coefficients of the wrong position are restored, the newly restored key coefficients are updated to the complete key restored in the first stage. Repeat the third and fourth stages for N rounds to finally obtain the complete key.

[0051] See also Figure 2 , Figure 2 4 is a schematic diagram of the working of the hardware device of an embodiment of the present invention, wherein the hardware device specifically comprises: a universal side channel analysis device 401 for establishing a lattice key, a processor 402 and a storage device 403.

[0052] A universal side-channel analysis device 401 for establishing a lattice key: The universal side-channel analysis device 401 for establishing a lattice key implements the universal side-channel analysis method for establishing a lattice key.

[0053] Processor 402: The processor 402 loads and executes instructions and data in the storage device 403 to implement the universal side channel analysis method for establishing a lattice key.

[0054] Storage device 403: The storage device 403 stores instructions and data; the storage device 403 is used to implement the universal side channel analysis method for establishing a lattice key.

[0055] The key technical points of the present invention are:

[0056] In the key recovery stage, the deep learning classification method and fixed-length coding scheme are combined to enable multiple bits of information to be obtained by accessing the MV-PC oracle once, which greatly reduces the number of inquiries required to access the oracle during the key recovery process, thereby reducing the number of keys that are incorrectly recovered due to noise.

[0057] Moreover, with the optimization of deep learning models and network structures, the amount of available bit information will also increase, providing more ideas for subsequent research on side channel attacks against quantum cryptographic algorithms.

[0058] Combining the deep learning classification method with the error coefficient checking method not only avoids the huge overhead brought by the voting method but also reduces the number of error coefficient checking inquiries in the key recovery stage and the re-acquisition stage.

[0059] The key recovery and error checking methods are not specific to a particular algorithm characteristic, but are applicable to all key establishment schemes and are universal.

[0060] In summary, the beneficial effects of the present invention are: the number of inquiries required to restore the complete key is small and the overhead is low while ensuring the high correctness of the key. With the optimization of the deep learning model and the network, the overhead required by this method can be further reduced. It is more efficient, has less overhead, and is more versatile.

[0061] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A general side channel analysis method for lattice key establishment, characterized by: It includes the following four stages: ciphertext recovery stage, ciphertext construction stage, key checking stage, and re-collection and key update stage; Key recovery stage: A combination of deep learning and fixed-length coding is used to obtain multi-bit information encoding, and the unique identification complete key sk = {sk[1], sk[2], ...sk[t], ..., sk[K-1], sk[K]} is recovered according to different encodings; where sk[t] represents one of the private key coefficients of the complete key, sk[t]∈[-u, u], t∈[0, K]; u is the range of the private key coefficient, and K is the number of private key coefficients; Ciphertext construction phase: construct multiple ciphertext combinations SK according to different private key coefficients i Input to the oracle to establish the corresponding combination table of the correct key Table = (ct′1, ct′2, code); Key checking stage: According to the combination table Table = (ct′1, ct′2, code), the recovered complete key sk is checked to find out the key combination with errors in the complete key, and the position of the incorrect key combination is recorded; Re-collection and key update phase: Recover the wrong key combination based on the wrong key combination location record.

2. A universal side channel analysis method for lattice key establishment as claimed in claim 1, characterized in that: The specific process of the ciphertext recovery phase is as follows: S11. Obtain the public-private key pair (pk, sk) and plaintext m in the lattice key establishment scheme; wherein ct = (c1, c2) is the valid ciphertext corresponding to the plaintext m; S12, modify the valid ciphertext ct to the invalid ciphertext ct′=(c′1, c′2); S13. Use invalid ciphertext to access the MV-PC oracle and get the oracle output where Dec.PKE(ct′,sk)=m i , Dec.PKE is the decryption algorithm; each visit to the oracle obtains log22 N =N bits of information; S14. Use multiple visits to obtain The bit information is encoded and the complete key sk is recovered to determine the unique identifier.

3. A universal side channel analysis method for lattice key establishment as claimed in claim 2, characterized in that: The ciphertext construction phase is as follows: S21, select M private key coefficients in the key sk to form a key combination Among them, there are M private key coefficients with a total of B num =(2u+1) M Combination of situations; S22. Modify the valid ciphertext ct = (c1, c2) to make it invalid ciphertext ct′ = (c′1, c′2). When the invalid ciphertext ct′ = (c′1, c′2) is used to access the MV-PC oracle, the output of the oracle is: S23. According to the oracle output of 0 or 1, the key combination SK i =(sk[M·i], sk[M·i+1, sk[M·i+M-1]) encoding; Get two sets of ciphertext ct′1, ct′2 so that the key combination SK i The corresponding codewords are: Get the key combination SK that is unique to other keys j , And the code word corresponding to j≠i is: S24. Check the key combination SK i Code word, if the code word is code i , then the key combination SK i The M private key coefficients are all correct, otherwise they are wrong; S25, adopt step S24 for B num The key combinations in the above cases are all tested, the correct key coefficient combination is found, and the corresponding combination table of the correct key is established. Table = (ct′1, ct′2, code).

4. A universal side channel analysis method for lattice key establishment as claimed in claim 3, characterized in that: The specific process of the key checking phase is as follows: According to the combination table Table = (ct′1, ct′2, code) established in the ciphertext construction stage, use the ciphertext ct′ in the table entry c,1 , ct′ c,2 Visit the MV-PC oracle and observe the output codeword code out Whether to record the code in the table c Match, such as code out =code c , it means that the M private keys in the key combination are recovered correctly; otherwise, it means that there are private key coefficients of the M private keys in the key combination that have been recovered incorrectly, and the wrong position is recorded.

5. A storage device, characterized in that: The storage device stores instructions and data for implementing any one of the universal side channel analysis methods for establishing a lattice key as described in claims 1 to 4.

6. A universal side channel analysis device for lattice key establishment, characterized in that: include: A processor and a storage device; the processor loads and executes instructions and data in the storage device to implement any universal side channel analysis method for establishing a lattice key as described in claims 1 to 4.