Integrated circuit side channel security assessment method and system based on attribute verification
By building a formal model of integrated circuit hardware and a formal model of side channel information, and using inverse T test to generate security attributes, the problems of incomplete risk inspection and high later repair costs in the existing technology are solved, and high-level complete verification and evaluation of side channel security of integrated circuits are realized.
Patent Information
- Application Number
- CN202310266343.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-17
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2043-03-17
AI Technical Summary
In the prior art, the risk inspection is incomplete, the cost of post-repair and the low versatility of inspection strategies make it difficult to comprehensively evaluate the side channel security of the integrated circuit during the design stage.
Using the method based on attribute testing, by obtaining the symbol information and logical information of the cryptographic chip, a formalized model of the integrated circuit hardware is constructed, a formalized model of the side channel information is established, and a statistical method is used to generate security attributes based on inverse T test, a security verification attribute library is constructed to verify the side channel security of the integrated circuit.
During the design stage, complete verification of all the chip status is achieved to achieve high-level complete verification and evaluation of side channel security, avoid problems with high cost of repair in the later stage, and improve the universality of inspection strategies.
Smart Images

Figure CN116306422B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to chip security detection technology, and in particular to an integrated circuit side channel security assessment method and system based on attribute verification. Background Art
[0002] Side channel information refers to physical information such as electromagnetic radiation and power consumption generated by the chip during operation. The leakage of side channel information seriously threatens the information security of cryptographic chips and is one of the main security risks faced by cryptographic chips. At present, the side channel security assessment methods for cryptographic chips mainly include: pre-silicon simulation and post-silicon testing. The evaluation method of pre-silicon simulation is difficult to fully cover all the operating states of the circuit, and the evaluation needs to be closely combined with the characteristics of the cryptographic algorithm itself, and lacks universality. The evaluation method of post-silicon testing is costly and time-consuming, and once the risk of side channel leakage is found in the post-silicon stage, it is extremely difficult to repair. Therefore, the side channel security assessment in the pre-silicon stage becomes the first choice. Among them, in terms of side channel leakage modeling, the French Secure-IC company designed Virtualyzer software, which can simulate electromagnetic side channel information using chip source code according to the abstract model pre-set by the user. Peeters et al. of the University of Leuven proposed an electromagnetic side channel leakage model based on the flipped Hamming distance model. Scholars from Cambridge University introduced layout post-simulation into electromagnetic radiation simulation. Amit Kumar and others from the University of Texas improved and optimized the electromagnetic simulation process of integrated circuits. Through gate-level and transistor-level mixed simulation, the current changes of each branch were obtained, and the electromagnetic radiation calculation of the metal layer was reasonably simplified. Sehatbakhsh et al. proposed a side channel leakage modeling method at the microarchitecture level, and fitted the leakage model parameters through actual tests. In order to achieve quantitative evaluation of side channel security, a variety of side channel evaluation technologies have been proposed, such as differential power analysis (DPA), correlated power analysis (CPA), mutual information analysis (MIA) signal-to-noise ratio (SNR) and test vector leakage assessment (TVLA). For example, the existing invention patent application document "Side Channel Protection Capability Detection System" with publication number CN114500022A includes a power acquisition module and a security evaluation module connected to it; wherein, the security evaluation module includes a cryptographic algorithm operation unit, a power consumption data preprocessing unit, a correlation analysis unit, and a vulnerability analysis unit.It can be seen from the specific implementation content of the technology that the system includes: a power consumption acquisition module and a security assessment module communicated with the module; wherein the security assessment module includes a cryptographic algorithm running unit, a power consumption data preprocessing unit, a correlation analysis unit, and a vulnerability analysis unit; wherein the power consumption acquisition module is used to perform algorithm-level, RTL-level, circuit-level, FPGA-level or chip-level cryptographic algorithm simulation on the encryption device according to the information to be analyzed, generate an actual power consumption curve, and send it to the power consumption data preprocessing unit; the cryptographic algorithm running unit is used to run the cryptographic algorithm according to the information to be analyzed to generate inferred power consumption information; the power consumption data preprocessing unit is used to obtain the actual power consumption curve and generate actual power consumption information; the correlation analysis unit is used to perform correlation analysis on the inferred power consumption information and the actual power consumption information to generate a power consumption analysis result; the vulnerability analysis unit is used to determine the power consumption vulnerability points according to the power consumption analysis result. The existing invention patent application document "Cryptographic Chip Security Detection Method" with publication number CN114328269A includes: simulating the register transfer level implementation code of the target cryptographic chip according to multiple groups of plaintext and multiple groups of keys to generate register transfer level side channel information; statistically analyzing the correlation between the side channel variable value set and the register transfer level side channel information to generate a register transfer level correlation result; judging whether to modify and iterate the register transfer level implementation code according to the register transfer level correlation result. It can be seen from the above-mentioned prior art that, on the whole, the current side channel security assessment technology is still mainly based on simulation, and the relevant technology is relatively mature, but lacks higher-level and more complete verification and detection means.
[0003] In summary, the existing technologies have technical problems such as incomplete risk inspection, high subsequent repair costs, and low versatility of inspection strategies. Summary of the invention
[0004] The technical problem to be solved by the present invention is how to solve the technical problems of incomplete risk inspection, high post-repair cost and low universality of inspection strategy in the prior art.
[0005] The present invention adopts the following technical solution to solve the above technical problem: the integrated circuit side channel security assessment method based on attribute verification includes:
[0006] S1. Obtaining the symbol information and logic information of the cryptographic chip, having the capability to construct a formalized model of integrated circuit hardware, and performing symbolic expression of side channel information according to the formalized model of integrated circuit hardware to construct a formalized model of integrated circuit side channel information;
[0007] S2. Using statistical methods and the security attribute generation method based on the inverse T test, write the side channel security verification attributes of the integrated circuit and build a security verification attribute library based on it;
[0008] S3. Verify the side channel security of the integrated circuit based on the security verification attribute library and the formalized model of the integrated circuit side channel information.
[0009] The present invention adopts formal methods for verification, and can fully check all states of the chip during the design phase. The present invention realizes high-level complete verification and evaluation of the side channel security during the chip design phase by constructing a formal model of the cryptographic chip hardware and extracting key attributes for side channel security assessment and verification.
[0010] In a more specific technical solution, in step S1, the input signal of the cryptographic chip is extracted according to the gate-level netlist of the cryptographic chip, and the symbolic declaration operation of the formal model is performed to analyze and integrate the formal model of the logic unit of the cryptographic chip to construct the formal model of the integrated circuit hardware.
[0011] In a more specific technical solution, in step S1, a logical relationship with the side channel information is established based on the integrated circuit hardware formal model, and the integrated circuit side channel information formal model is constructed accordingly.
[0012] The present invention constructs a formalized model of integrated circuits covering side channel information, and can fully verify whether there is a risk of side channel leakage in the integrated circuit during the design phase, making the side channel leakage risk monitoring more comprehensive.
[0013] In a more specific technical solution, step S2 includes:
[0014] S21. Preset at least 2 sets of model input scenarios;
[0015] S22, using the side channel symbol in the case of model input as the input of the T test, and using the preset logic to process to obtain the statistic t value and the degree of freedom v of the T test;
[0016] S23. Taking the t-value of the T-test statistic as the core of the security attribute, setting the threshold of the t-value based on the evaluation criteria of the side channel security, constructing the verification attribute, and forming the side channel security verification attribute of the integrated circuit.
[0017] In a more specific technical solution, in step S21, the model input scenarios include: random input and fixed weight input.
[0018] In a more specific technical solution, in step S22, the statistical value t is obtained by using the following logical processing:
[0019]
[0020] Where μ0, μ1 and s0, s1 represent the sampling mean and variance of the two test data sets respectively, and n0 and n1 represent the basis of each test data set respectively.
[0021] In a more specific technical solution, in step S22, the degree of freedom v is obtained by using the following logical processing:
[0022]
[0023] In a more specific technical solution, step S3 includes:
[0024] S31. Solving the associated intermediate value according to the security verification attribute library;
[0025] S32, obtaining Hamming features according to the associated intermediate values, wherein the Hamming features include: Hamming weight and Hamming distance matrix;
[0026] S33, solving the input vector according to the Hamming feature;
[0027] S34. When a solution exists, determine that there is a side channel leakage risk in the integrated circuit.
[0028] The present invention verifies whether there is a risk of side channel leakage in the chip based on the attribute verification method during the design stage before the chip is put into production, thereby avoiding the high repair cost caused by discovering the side channel risk through evaluation means after manufacturing is completed.
[0029] In a more specific technical solution, the generation logic of the side channel security verification attribute also includes:
[0030]
[0031] T-value ≥ T threshold
[0032] Where T-value is the T-test value of the circuit Hamming weight or Hamming distance model corresponding to the two sets of input vectors.
[0033] The present invention performs side channel leakage security assessment on integrated circuits in the early stages of design, starting from circuit design, without the need for additional parameters or processes. At the same time, when the circuit scale increases to a certain extent, a solution time constraint is set to improve the versatility of the inspection strategy.
[0034] In a more specific technical solution, the integrated circuit side channel security assessment system based on attribute verification includes:
[0035] A formal model building module is used to obtain the symbol information and logic information of the cryptographic chip, and has the function of building a formal model of integrated circuit hardware, and performing symbolic expression of side channel information based on the formal model of integrated circuit hardware to build a formal model of integrated circuit side channel information;
[0036] An attribute construction module is used to write the side channel security verification attributes of the integrated circuit using statistical methods and the security attribute generation method based on the inverse T test, so as to construct a security verification attribute library;
[0037] The side channel security verification module is used to verify the side channel security of the integrated circuit based on the security verification attribute library and the formalized model of the integrated circuit side channel information. The side channel security verification module is connected to the formalized model construction module and the attribute construction module.
[0038] Compared with the prior art, the present invention has the following advantages: the present invention adopts formal methods for verification, and can fully check all states of the chip during the design phase. The present invention constructs a formal model of cryptographic chip hardware and extracts key attributes for side channel security assessment and verification, thereby achieving high-level complete verification and assessment of the side channel security during the chip design phase.
[0039] The present invention constructs a formalized model of integrated circuits covering side channel information, and can fully verify whether there is a risk of side channel leakage in the integrated circuit during the design phase, making the side channel leakage risk monitoring more comprehensive.
[0040] During the design phase before the chip is put into production, the risk of side channel leakage in the chip is verified based on the attribute inspection method, avoiding the high repair costs caused by discovering side channel risks through evaluation methods after manufacturing is completed.
[0041] The present invention performs side channel leakage security assessment on integrated circuits in the early stages of design, starting from circuit design, without the need for additional parameters or processes. At the same time, when the circuit scale increases to a certain extent, a solution time constraint is set to improve the versatility of the inspection strategy.
[0042] The present invention solves the technical problems existing in the prior art of incomplete risk inspection, high post-repair cost and low universality of inspection strategies. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 This is a schematic diagram of basic steps of an integrated circuit side channel security assessment method based on attribute verification according to Embodiment 1 of the present invention;
[0044] Figure 2 A schematic diagram of specific steps for constructing a formalized model of a cryptographic chip according to Embodiment 1 of the present invention;
[0045] Figure 3 A schematic diagram of specific steps for generating security attributes in Example 1 of the present invention;
[0046] Figure 4 This is a schematic diagram of specific steps for verifying the side channel security of an integrated circuit according to Embodiment 1 of the present invention;
[0047] Figure 5 This is a schematic diagram of risk assessment data flow processing of the S-box module which is highly related to the key information in the AES encryption circuit of Example 2 of the present invention;
[0048] Figure 6 Schematic diagram of chip side channel leakage risk detection steps according to Embodiment 2 of the present invention. DETAILED DESCRIPTION
[0049] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in combination with the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0050] Example 1
[0051] like Figure 1 As shown, the integrated circuit side channel security assessment method based on attribute verification provided by the present invention includes the following basic steps:
[0052] S1. Construct a formal model of integrated circuit side channel information;
[0053] like Figure 2 As shown, in this embodiment, step S1 includes the following specific steps:
[0054] S11, construction of cryptographic chip hardware model;
[0055] In this embodiment, according to the gate-level netlist of the cryptographic chip, its input signal is extracted, and the symbolic declaration of the wire network and register in the formal model is performed simultaneously; then the standard format of its logic unit is analyzed, and based on its logical function and semantic conversion algorithm, the formal model of the corresponding logic unit is generated; finally, it is integrated in the model parser to form a hardware formal model that can fully describe the function of the cryptographic chip.
[0056] S12. Symbolic expression of side channel information.
[0057] In this embodiment, on the basis of the hardware formal model, the side channel information symbol is declared, and based on the Hamming weight model describing the circuit logic state and the Hamming distance model describing the circuit logic flip situation, a direct logical connection between the side channel information symbol and the hardware formal model is established to form a cryptographic chip formal model that can cover the side channel information.
[0058] S2. Write side channel security verification properties based on classical statistical methods.
[0059] In this embodiment, in the field of statistics, the T-test evaluates whether there is a significant difference between two data sets by calculating the probability value that the two data sets have different specific moments.
[0060] In this embodiment, it is assumed that the two data sets have the same statistical moments, and the probability of rejecting the hypothesis is obtained by calculating the T statistic, thereby completing the quantitative evaluation of the difference;
[0061] In this embodiment, Q0 and Q1 represent two test data sets, and μ0(μ1) and s0(s1) represent the sampling mean and variance of the data set Q0(Q1) respectively. n0 and n1 represent the basis of each data set respectively. Then the T statistic of the T test can be expressed as:
[0062]
[0063] like Figure 3 As shown, in this embodiment, step S2 adopts a security attribute generation method based on an inverse T test, and the specific steps include:
[0064] S21, pre-set two groups of model input conditions, one group is random input, and the other group is fixed weight input;
[0065] S22, using the side channel symbols in the two groups of input as inputs for T-test;
[0066] S23. The t-value statistic of the T test is taken as the core of the security attribute. The threshold of the t-value is set according to the evaluation criteria of the side channel security. Then, the verification attribute is constructed based on the threshold reachability to form a special security attribute for side channel security.
[0067] S3. After completing the model construction and attribute extraction, the security of the integrated circuit side channel will be verified;
[0068] like Figure 4 As shown, in this embodiment, step S3 includes the following specific steps:
[0069] In this embodiment, the security attribute based on T test is taken as an example:
[0070] S31. Based on the dedicated security attribute library, firstly solve the relevant statistical intermediate value;
[0071] S32, then solving the Hamming weight or Hamming distance matrix that satisfies the intermediate value;
[0072] S33. Finally, the input vector that generates the Hamming weight or the Hamming distance matrix is solved. If a solution exists, it proves that there is a risk of side channel leakage in the integrated circuit.
[0073] Example 2
[0074] like Figure 5 As shown, in this embodiment, the S-box module in the AES encryption circuit, which is highly related to the key information, is selected as an example. First, the integrated circuit hardware formal model is constructed, and a formal model that can fully describe the behavior function of the S-box circuit is formed in the solver. D represents circuit design, M represents formal model, and F represents modeling process.
[0075]
[0076] In this embodiment, a formalized model of the S-box side channel information is constructed. Classical models of side channel information leakage include Hamming distance, Hamming weight, and improved Hamming distance and Hamming weight models.
[0077] In this embodiment, taking the power consumption model as an example, the Hamming distance model assumes that the state change in the CMOS circuit (conversion from 1—>0, conversion from 0-->1) will generate a certain amount of power consumption, and if the state does not change, there will be no excessive power consumption. That is to say, when the initial state x0 contained in the CMOS device is converted to the final state x1, the actual side channel leakage is related to the Hamming distance between these states, that is, HD(x0, x1) = HD(x0⊕x1). The Hamming weight model assumes that the power consumption (or electromagnetic radiation) is related to the output state of the CMOS device. That is, when the current state value calculated by the device is x0, the actual side channel leakage is related to the Hamming weight of the value, that is, HW(x0).
[0078] In this embodiment, taking the Hamming weight model as an example, based on the circuit behavior function formal model, a variable hw representing the circuit Hamming weight is designed. When the variable in the S-box module is assigned a value of 1, the variable hw is synchronously increased by 1.
[0079] At this point, the entire model can be used to describe the side-channel behavior of the circuit.
[0080]
[0081] Among them, M side -channel is a formal model of the side channel.
[0082] like Figure 6 As shown, in this embodiment, in order to verify whether the S-box has a risk of side channel leakage, a security attribute is set. Based on traditional statistical methods, a side channel security assessment attribute is generated. Consider two groups of input vectors. The following specific steps are included:
[0083] S1', set 1000 completely random input vectors;
[0084] S2', set 1000 fixed weight input vectors;
[0085] In this embodiment, each input vector will cause the circuit to be verified to generate a Hamming weight value, and each group of input vectors corresponds to a group of Hamming weight values.
[0086] S3',When the two groups of Hamming weight values are statistically different, the risk of side channel information leakage in the current circuit design is high;
[0087] In this embodiment, if the two groups of Hamming weight values representing the side channel leakage levels are statistically significantly different, it means that the input vector has a significant influence on the side channel behavior of the circuit, further indicating that the circuit design has a higher risk of side channel information leakage.
[0088] This proposal uses T-test as a method to evaluate the difference between two groups of Hamming weight values. The following security properties are designed:
[0089]
[0090] T-value ≥ T t hreshold;
[0091] In this embodiment, T-threshold is a threshold for determining whether a circuit has a side channel leakage risk in side channel assessment. If T>T-threshold, it means that there is a leakage risk, otherwise it does not exist.
[0092] S4', determine whether the model has a solution that satisfies the aforementioned safety properties;
[0093] S5', if yes, it means that the circuit design has the risk of side channel leakage;
[0094] S6', if no, there is no risk of side channel leakage.
[0095] In this embodiment, based on the above logic, a side channel leakage security assessment is performed on the integrated circuit in the early stage of design. This method starts from the circuit design and does not require additional parameters or processes. Its computing resource overhead will continue to increase with the increase of circuit scale. When the circuit scale increases to a certain extent, the strong constraint condition of whether there is a solution or not can be replaced by setting a solution time constraint.
[0096] In summary, the present invention adopts formal methods for verification, which can fully check all states of the chip during the design phase. The present invention constructs a formal model of the cryptographic chip hardware and extracts key attributes for side channel security assessment and verification, thereby achieving high-level complete verification and evaluation of the side channel security during the chip design phase.
[0097] The present invention constructs a formalized model of integrated circuits covering side channel information, and can fully verify whether there is a risk of side channel leakage in the integrated circuit during the design phase, making the side channel leakage risk monitoring more comprehensive.
[0098] During the design phase before the chip is put into production, the risk of side channel leakage in the chip is verified based on the attribute inspection method, avoiding the high repair costs caused by discovering side channel risks through evaluation methods after manufacturing is completed.
[0099] The present invention performs side channel leakage security assessment on integrated circuits in the early stages of design, starting from circuit design, without the need for additional parameters or processes. At the same time, when the circuit scale increases to a certain extent, a solution time constraint is set to improve the versatility of the inspection strategy.
[0100] The present invention solves the technical problems existing in the prior art of incomplete risk inspection, high post-repair cost and low universality of inspection strategies.
[0101] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An integrated circuit side channel security assessment method based on attribute verification, characterized in that: The method comprises: S1. Obtaining the symbol information and logic information of the cryptographic chip, having the capability to construct a formalized model of integrated circuit hardware, and performing symbolic expression of side channel information according to the formalized model of integrated circuit hardware to construct a formalized model of integrated circuit side channel information; S2. Using statistical methods and the security attribute generation method based on the inverse T test, write the side channel security verification attributes of the integrated circuit and build a security verification attribute library based on it; S2 includes: S21. Preset at least 2 sets of model input scenarios; S22, using the side channel symbol in the case of model input as the input of the T test, and using the preset logic to process to obtain the statistic t value and the degree of freedom v of the T test; S23, taking the t value of the T test statistic as the security attribute core, setting the threshold of the t value according to the evaluation criteria of whether the side channel is safe or not, constructing the verification attribute, and forming the side channel security verification attribute of the integrated circuit; S3. Verify the side channel security of the integrated circuit based on the security verification attribute library and the formalized model of the integrated circuit side channel information.
2. The integrated circuit side channel security assessment method based on attribute verification according to claim 1 is characterized in that: In the step S1, the input signal of the cryptographic chip is extracted according to the gate-level netlist of the cryptographic chip, and the symbolic declaration operation of the formal model is performed, and the logic unit formal model of the cryptographic chip is analyzed and integrated to construct the integrated circuit hardware formal model.
3. The integrated circuit side channel security assessment method based on attribute verification according to claim 1 is characterized in that: In the step S1, a logical relationship with the side channel information is established according to the integrated circuit hardware formalized model, thereby constructing the integrated circuit side channel information formalized model.
4. The integrated circuit side channel security assessment method based on attribute verification according to claim 1, characterized in that: In the step S21, the model input scenarios include: random input and fixed weight input.
5. The integrated circuit side channel security assessment method based on attribute verification according to claim 1, characterized in that: In step S22, the statistical value t is obtained by using the following logical processing: Wherein, μ0, μ1 and s0, s1 represent the sampling mean and variance of the two test data sets respectively, and n0 and n1 represent the basis of each of the test data sets respectively.
6. The integrated circuit side channel security assessment method based on attribute verification according to claim 1, characterized in that: In step S22, the degree of freedom v is obtained by using the following logic processing: Wherein, μ0, μ1 and s0, s1 represent the sampling mean and variance of the two test data sets respectively, and n0 and n1 represent the basis of each of the test data sets respectively.
7. The integrated circuit side channel security assessment method based on attribute verification according to claim 1, characterized in that: The step S3 comprises: S31, solving the associated intermediate value according to the security verification attribute library; S32, obtaining Hamming features according to the associated intermediate values, wherein the Hamming features include: Hamming weight and Hamming distance matrix; S33, solving the input vector according to the Hamming feature; S34. When a solution exists, determine that there is a side channel leakage risk in the integrated circuit.
8. The integrated circuit side channel security assessment method based on attribute verification according to claim 1, characterized in that: The generation logic of the side channel security verification attributes also includes: T-value≥T threshold Wherein, T-value is the T-test value of the circuit Hamming weight or Hamming distance model corresponding to the two sets of input vectors, μ0, μ1 and s0, s1 represent the sampling mean and variance of the two test data sets respectively, and n0 and n1 represent the basis of each of the test data sets respectively.
9. An integrated circuit side channel security assessment system based on attribute verification, used to execute the integrated circuit side channel security assessment method based on attribute verification as described in any one of claims 1 to 8, characterized in that: The system comprises: A formal model building module is used to obtain the symbol information and logic information of the cryptographic chip, and has the function of building a formal model of integrated circuit hardware, and performing symbolic expression of side channel information according to the formal model of integrated circuit hardware to build a formal model of integrated circuit side channel information; An attribute construction module, used to compile the side channel security verification attributes of the integrated circuit by using a statistical method and a security attribute generation method based on an inverse T test, so as to construct a security verification attribute library; A side channel security verification module is used to verify the side channel security of the integrated circuit based on the security verification attribute library and the integrated circuit side channel information formalized model, and the side channel security verification module is connected to the formalized model construction module and the attribute construction module.
Citation Information
Patent Citations
Cryptographic chip security detection method
CN114328269A
Side channel protection capability detection system
CN114500022A
High-level comprehensive energy hidden channel hardware safety optimization method
CN111832025A
CAD framework for power side-channel vulnerability assessment
US20210026994A1