A Time Detection Method and System for Stateless Algorithm Substitution Attacks
By sampling encryption or signature time in the OpenSSL library and performing 0,1 conversion and NIST randomness detection, the problem of stateless algorithm replacement attacks is solved in the actual deployment environment, and the detection of all known stateless algorithm replacement attacks is realized, which improves the security of the cryptographic algorithm.
Patent Information
- Application Number
- CN202211683910.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-27
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-12-27
AI Technical Summary
The prior art fails to provide detection solutions for stateless algorithms instead of attacks in actual deployment environments, especially when time-sampling data is leveraged.
A time detection method is proposed. By calling symmetric encryption and digital signature algorithms in open source libraries such as OpenSSL library, the encryption or signature time is sampled under different security strengths, and through 0,1 conversion and random detection of NIST SP800-22 specifications, it is determined whether the algorithm to be detected is subject to stateless algorithm replacement attack.
It supports the detection of all known general stateless algorithm alternative attacks at the software level, provides an effective detection solution for stateless algorithm alternative attacks, and improves the security of the password algorithm.
Smart Images

Figure CN116318651B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cryptographic algorithm security detection, and particularly relates to a time detection method and system for stateless algorithm substitution attacks. Background Art
[0002] As a user of cryptographic products, the user is often restricted by input / output access rights. In other words, for the black-box implementation of a cryptographic algorithm, the user must trust that the encryption algorithm implemented by the developer is honest and does not contain any backdoors. For this reason, substitution attacks and defenses for black-box cryptographic implementations have become a research hotspot in the academic community.
[0003] The purpose of an algorithm substitution attack (ASA) is to replace an honest implementation with a malicious one, thereby allowing the leakage of personal secret information while ensuring that the malicious implementation is indistinguishable from the honest implementation in the black-box (input / output) scenario. The malicious implementation is generally achieved by the attacker adding a backdoor during the design or implementation of the cryptographic algorithm. The security of the vast majority of cryptographic algorithms depends on the random numbers used in the algorithms, and usually a pseudo-random number generation algorithm is used to obtain the random numbers required in the cryptographic algorithm. Given the important position of random numbers in cryptographic algorithms, the algorithm substitution attack focuses on attacking the random number generator component in the cryptographic algorithm to further crack the secret information.
[0004] The algorithm substitution attacks given in the current literature can be divided into two categories according to whether there is additional intermediate state storage in the malicious implementation algorithm: stateless algorithm substitution attacks and stateful algorithm substitution attacks, and the proofs of undetectability and recoverability have been given at the theoretical level. However, the underlying security models of these proofs restrict the detector to only accessing the input and output of the cryptographic algorithm in a black-box manner. In actual cryptographic applications, in addition to the input and output of the cryptographic algorithm, the detector can also observe the execution time of the algorithm. Therefore, in order to detect whether the algorithm has suffered a stateless algorithm substitution attack, there is naturally such a question: "For standardized cryptographic algorithms and quantum-resistant cryptographic algorithms that are being standardized, can the currently known stateless algorithm substitution attacks that have been proven (black-box) undetectable be detected during actual deployment?"
[0005] In the existing literature describing algorithm substitution attacks, the undetectability and recoverability of the given stateless algorithm substitution attacks have been proven at the theoretical level.
[0006] 1. None of them consider the detection method at the actual application level;
[0007] 2. The stateless algorithm substitution attack performs rejection sampling on a random algorithm, enabling an attacker with a backdoor key (Bdk) to recover secrets from a public channel. The algorithms suffering from this type of attack exhibit a "bounded hypergeometric distribution" in terms of running time. Without knowing the mean running time of the specific algorithm, it is impossible to distinguish the time distributions of honest and malicious implementations through general hypothesis testing methods, and no detection scheme for distinguishing stateless algorithm substitution attacks based on time sampling data has been proposed yet. Summary of the Invention
[0008] In view of the fact that in the existing literature describing algorithm substitution attacks, the undetectability and recoverability of the presented stateless algorithm substitution attacks have been proven at the theoretical level, but the detection methods at the practical application level have not been considered, and no detection scheme for distinguishing stateless algorithm substitution attacks based on time sampling data has been proposed yet, the present invention proposes a time detection method and system for stateless algorithm substitution attacks.
[0009] To achieve the above object, the present invention adopts the following technical solutions:
[0010] On the one hand, the present invention proposes a time detection method for stateless algorithm substitution attacks, including:
[0011] Step 1, call symmetric encryption and digital signature algorithms in open source libraries such as the OpenSSL library, and sample their encryption or signature times under different security strengths;
[0012] Step 2, after grouping the sampled data, perform 0,1 conversion to obtain a 0,1 sequence as the sequence to be detected in the next step;
[0013] Step 3, use the NIST SP800-22 specification to detect the converted data and determine whether the algorithm to be detected is suffering from an algorithm substitution attack.
[0014] Furthermore, the symmetric encryption and digital signature algorithms include standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms, as well as post-quantum algorithms Dilithium, Falcon, and SPHINCS+.
[0015] Furthermore, the Step 2 includes:
[0016] Replacement Algorithm Time Grouping and 0,1 Conversion: Based on the original algorithm, introduce rejection sampling for algorithm substitution attacks, record the time when the algorithm successfully encrypts or signs, approximate the mean of the original algorithm time with the mean of the first 1 / 2 sampling time, group all sampling samples. Assume it can be divided into s groups, and the specific grouping corresponds to the upper bound value of the rejection sampling attack. Reset the sample time of the samples belonging to the i-th group in the experimentally obtained sample data to 0, set the sample data belonging to the group >i to 1, and delete all the sample data in the <i group. Then, an s - 1 group of 0,1 sequences can be obtained.
[0017] Further, step 3 includes:
[0018] 0,1 Randomness Detection: Select 4 detection criteria from the 15 NIST randomness detection criteria for key detection: frequency detection, in-block frequency test, overlapping subsequence detection, and cumulative sum test. Perform the above 4 detections on the obtained s - 1 0,1 sequences respectively. If any one of the randomness detections passes during the detection process, it is considered that the algorithm to be detected is very likely to be subject to algorithm substitution attacks.
[0019] On the other hand, the present invention proposes a time detection system for stateless algorithm substitution attacks, including:
[0020] An execution time sampling module, which is used to call symmetric encryption and digital signature algorithms in open source libraries such as the OpenSSL library, and sample their encryption or signature times under different security strengths;
[0021] A data type conversion module, which is used to perform 0,1 conversion after grouping the sampled data to obtain a 0,1 sequence as the next sequence to be detected;
[0022] A substitution attack detection module, which is used to detect the converted data using the NIST SP800 - 22 specification to determine whether the algorithm to be detected is subject to algorithm substitution attacks.
[0023] Further, the symmetric encryption and digital signature algorithms include standard AES encryption, RSA - PSS signature, and ECDSA signature algorithms, as well as post - quantum algorithms Dilithium, Falcon, and SPHINCS+.
[0024] Further, the data type conversion module is specifically used for:
[0025] Replacement algorithm time grouping and 0, 1 conversion: Based on the original algorithm, introduce rejection sampling for algorithm substitution attack, record the time when the algorithm successfully encrypts or signs, take the mean of the first 1 / 2 sampling time as the approximation of the mean time of the original algorithm, group all sampling samples. Assume it can be divided into s groups, and the specific grouping corresponds to the upper bound value of the rejection sampling attack. Reset the sample time of the samples belonging to the i-th group in the sample data obtained from the experiment to 0, set the sample data belonging to the group > i to 1, and delete all the sample data in the groups < i. Then, an s - 1 group of 0, 1 sequences can be obtained.
[0026] Furthermore, the substitution attack detection module is specifically used for:
[0027] 0, 1 randomness detection: Select 4 detection criteria from the 15 NIST randomness detection criteria for key detection: frequency detection, intra-block frequency test, overlapping subsequence detection, and cumulative sum test. Conduct the above 4 detections on the obtained s - 1 0, 1 sequences respectively. If any one of the randomness detections passes during the detection process, it is considered that the algorithm to be detected input is very likely to be subjected to algorithm substitution attack.
[0028] Compared with the prior art, the beneficial effects of the present invention are:
[0029] In current existing literature, no detection scheme for stateless algorithm substitution attack in the actual deployment environment has been given. Cryptographic libraries such as OpenSSL have open-source complexity, and the number of experts reviewing the code is very small, making it very likely that algorithm substitution attacks are carried out against open-source software. In addition, even if the code seems to be "clean", there is always a possibility of being damaged during compilation or runtime by destroying the compiler or interpreter. The present invention innovatively proposes the 0, 1 conversion of time sampling data and uses the NIST randomness detection results to give a conclusion on whether there is an algorithm substitution attack. The present invention supports detecting all known general stateless algorithm substitution attacks at the software level. The implementation of this detection method and system has important guiding significance for the related research on cryptographic algorithm substitution attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a flowchart of a time detection method for a stateless algorithm substitution attack according to an embodiment of the present invention;
[0031] Figure 2 It is a flowchart of 0, 1 conversion according to an embodiment of the present invention;
[0032] Figure 3 It is one of the time detection results according to an embodiment of the present invention;
[0033] Figure 4 It is another time detection result according to an embodiment of the present invention;
[0034] Figure 5 This is a schematic diagram of the architecture of a time detection system for stateless algorithm substitution attacks in an embodiment of the present invention. Specific embodiments
[0035] The present invention will be further explained below in conjunction with the accompanying drawings and specific embodiments:
[0036] In this solution, we propose a time detection method for stateless algorithm substitution attacks. At the actual implementation level of the algorithm, by sampling the running time of the algorithm to be detected in large quantities and analyzing the sampled data, a detection conclusion on whether there is a state algorithm substitution attack can be given. The detection flow chart of the solution is given in Figure 1 as follows, and the specific solution is as follows:
[0037] Call the standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms in open source libraries such as the OpenSSL library, as well as the C source code of the post-quantum algorithms Dilithium, Falcon, and SPHINCS+, and sample their encryption (signature) times under different security strengths. Through testing, it is found that the time of the original algorithm remains basically constant in the application, that is, it fluctuates within a very small interval of the standard running time t of the algorithm.
[0038] At the same time, on the basis of the original code, rejection sampling is introduced for ASA, the time when the algorithm successfully encrypts (signs) is recorded, and the sampled time under ASA is further analyzed to extract its features, which are used to give a standard for judging whether any input algorithm is suffering from ASA. The rejection sampling attack adopted by stateless ASA is shown in Table 1. This algorithm only gives the algorithm output when it successfully obtains 1 bit of the user key or reaches the attempt limit. Let the original algorithm time be a, then the time required for the replacement algorithm to successfully achieve the output follows a "geometric distribution with an upper limit":
[0039] Table 1
[0040]
[0041] We transform and borrow the principle of randomness detection, perform 0,1 transformation on the sampled data, and use the NIST SP800-22 specification to detect the sampled data to judge whether the algorithm to be detected is suffering from an algorithm substitution attack.
[0042] We sampled the running time of the above-mentioned method under ASA one million times, filtering out obvious incorrect time data (time noise introduced during system calls), which would have an adverse impact on the processing of sampled data. From the fact that the algorithm time under ASA follows a "finite geometric distribution", it can be known that after large-sample sampling (filtering out abnormal samples) and arranging the times in order, theoretically the first 1 / 2 of the sample values should be within a small interval of the original algorithm running time. Therefore, we approximated the mean of the original algorithm time by taking the mean of the first 1 / 2 of the sampling times, grouped all the sampling samples, and assumed that they could be divided into s groups. Since each run of the algorithm is independent, the lengths of the running times recorded each time are independent. According to the output time probability distribution, the probability that any output time belongs to the i-th group is equivalent to the probability that it belongs to the group >i. Based on this characteristic, we reset the sample times of the samples belonging to the i-th group in the sample data obtained from the experiment to 0, set the sample data belonging to the group >i to 1, and deleted all the sample data in the <i group. Then the obtained 0,1 data should satisfy the frequency test of the randomness test and pass the relevant independence test. The data conversion process is as Figure 2 shown.
[0043] The NIST randomness test consists of 15 standards in total. This article mainly involves the following 4 test standards:
[0044] Table 2
[0045]
[0046] According to the test requirements, we converted the data within the group into 0 or 1 for storage, and used the randomness test standard to detect the randomness of the 0,1 data. Let the significance level be α (0.001 - 0.01). The specific test method is as follows:
[0047] (1) Frequency test:
[0048] According to the algorithm time distribution under ASA shown in Figure 6, it can be seen that for every increase of t in the algorithm running time under ASA, its output probability is halved. The amount of data output when the sampling time is at count = 1 accounts for about 1 / 2, and the remaining all other cases account for 1 / 2. Also, because each execution of the algorithm is independent, the probability that the time recorded each time in the sampling appears in the case of count = 1 and count > 1 is equal. Therefore, if we replace the data within the first group with 1, and record the number as n1, and replace the data within the remaining groups with 0, and record the number as n0, calculate the statistic
[0049]
[0050] This statistic should follow a chi - square distribution with 1 degree of freedom. Using the frequency test (F - test) of randomness detection, the 0, 1 frequencies are detected. Compare V with the corresponding critical value. If V ≤ B, it is considered to pass the test at the corresponding significance level (the corresponding P - value can be calculated:
[0051] P value =igamc(1 / 2,V / 2)
[0052] If P value ≥α, it is considered that the sequence to be tested passes this test).
[0053] Similarly, if the sampling times with count = 1 are discarded, the probability that the sampling times with count = 2 and the sampling times with count>2 account for the total sampling data is equal. After the data is converted to 0, 1, it should meet the randomness detection standard, and so on.
[0054] Table 3
[0055] Significance level α Critical value V ≤ B 0.05 3.841 0.01 6.635 0.001 10.828 0.0001 15.137
[0056] It can be seen from the "finite geometric distribution" table that except that the probability of the first interval is equal to the sum of the probabilities of all the remaining intervals, the probability that the sample is in the i - th interval is equal to the sum of the probabilities of all intervals greater than i. Therefore, if the samples in the first interval are deleted from the original sampling sample set (retaining the recording order during sampling), the data samples in the i - th interval are marked as 0, and all the remaining interval samples are marked as 1, the 0, 1 data under ASA should also pass the 0, 1 frequency test.
[0057] (2) Intra - block frequency test:
[0058] It is used to test whether the number of 1s in the M - bit long subsequence (referred to as a block) in the sequence to be detected is close to M / 2. The bit string to be detected is divided into non - overlapping subsequences of length M, and the extra bits are discarded. In this work, M = 128 is taken. Calculate the proportion of 1s in each subsequence:
[0059]
[0060] Calculate the statistic
[0061]
[0062] and the P - value If P value ≥α, it is considered that the sequence to be tested passes this test.
[0063] This work focuses on observing whether the sampling time data passes the 0,1 frequency detection, as it can best reflect the probability distribution of time samples. We believe that if the sample data passes any of the above tests, then the algorithm has ASA, and the software outputs "There is ASA, prompting the user of a security risk."
[0064] (3) Overlapping subsequence detection (couple test):
[0065] Since each time data obtained by sampling is independently encrypted, there should be no correlation between times. By verifying the numbers of 00, 01, 10, and 11 in the sampled data, which are denoted as n 00 , n 01 , n 10 , n 11 , the independence of each time data is verified.
[0066] Calculate the test statistic
[0067]
[0068] This test statistic approximately follows a chi-square distribution with 2 degrees of freedom. The statistic V and its corresponding critical value B (partial values of the significance level α and the critical value B are shown in the following table), that is, if V ≤ B, then the sequence to be tested is considered to pass this test (similarly, the P-value can be compared: P value = igamc(1, V / 2), if P value ≥ α, then the sequence to be tested is considered to pass this test).
[0069] Table 4
[0070] Significance level α Critical value V ≤ B 0.05 5.991 0.01 9.210 0.001 13.816 0.0001 18.421
[0071] (4) Cumulative sum test
[0072] This test mainly observes the maximum deviation degree of the random walk of the sequence. The random walk is defined as the cumulative sum of -1 and +1 after adjustment in the sequence. The purpose of the test is to determine whether the cumulative sum of the sequence is too large or too small compared to the expected cumulative sum. This cumulative sum can be regarded as a random walk. For a truly random sequence, the deviation of the random walk should be near 0. For a non-random sequence, this random walk deviation will be much larger than 0.
[0073] The sample data is divided into the first interval and converted into 0,1 data as the sequence to be tested, where 0 and 1 are respectively converted into -1 and 1, and the i-th bit is X i , calculate S i = S i-1 + X i , S1 = X1. Calculate z = max 1≤i≤n |S i |, calculate the P-value:
[0074]
[0075] If P value ≥α, it is considered that the sequence to be detected passes the cumulative sum test, and this sequence can be considered a random walk.
[0076] We propose the above four metrics as items to be detected here. If any randomness test passes during the detection process, it is considered that the input algorithm to be detected is very likely to be subject to substitution attacks.
[0077] As an implementable method, the above algorithm is detected with different security strengths and different upper bounds of rejection sampling attacks (s = 5 or 10). One million samples are taken for the running time of the original algorithm and the algorithm under ASA, and the time data with obvious deviations is filtered. The sampling time of the randomly input algorithm is detected. First, according to the distribution of the sampling time, the s value is simulated to find the s (s>1) value that conforms to the sampling data presenting a "geometric distribution with an upper bound", and the upper bound of the number of loop iterations set in the algorithm is determined (when the simulation result is s = 1, that is, the algorithm has not passed ASA, and the sampling data is distributed in the same interval). According to the s value, the sampling data is divided into s groups, and a histogram is drawn to visually display the time distribution. And the sample mean and variance of the sampling data, as well as the time mean of the first group after grouping, are given.
[0078] After that, according to the proposed 0,1 conversion detection scheme, the sampling data is respectively converted into 0,1 data according to the first group of data and the remaining data, the second group and the remaining data except the 1st and 2nd groups. The obtained 0,1 sequences are subjected to randomness tests, mainly including the 0,1 frequency test, the within-block frequency test, the couplet test, and the cumulative sum test mentioned. The more randomness detection metrics pass, the greater the probability that the group of sampling data is subject to substitution attacks.
[0079] Test Data and Results
[0080] In terms of time detection, in this section, the proposed method is simulated with ASA under different security strengths, and the distribution of time sampling data and the passing situation of randomness detection under different upper bounds of rejection sampling attacks (s) are shown.
[0081] Time Side-Channel Analysis
[0082] (1) ECDSA
[0083] ECDSA128
[0084] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filtering out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.000488, the (N - 1) times of the sample variance is 0.092470, and the mean of the samples in the first interval is 0.000268. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 0.991458, the frequency detection in the second interval is 0, the P value of the frequency detection within the block is 0, the P value of the run test is 0.783884, and the P value of the cumulative sum test is 0. That is, it passes the frequency detection in the first interval and the run test, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0085] ECDSA192
[0086] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filtering out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.001008, the (N - 1) times of the sample variance is 0.402289, and the mean of the samples in the first interval is 0.000553. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 0.532407, the frequency detection in the second interval is 0.291974, the P value of the frequency detection within the block is 0, the P value of the run test is 0.998819, and the P value of the cumulative sum test is 0. That is, it passes the frequency detection in the first interval, the frequency detection in the second interval and the run test, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0087] ECDSA256
[0088] When the input sampling sample comes from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples to calculate the mean, which is used as an approximation of the mean of the original algorithm. Use this mean to filter all data samples, filter out the samples with too large time, and then group them. After calculation, the mean of the data samples is 0.001706, the (N - 1) times of the sample variance is 1.239989, and the mean of the samples in the first interval is 0.000925. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 0.688347, the P value of the frequency detection in the second interval is 0, the P value of the frequency detection within the block is 0.000006, the P value of the run test is 0.911558, and the P value of the cumulative sum test is 0. That is, the frequency detection in the first interval and the run test are passed, indicating that there is an algorithm substitution attack on the algorithm that generates the data sample.
[0089] ECDSA512
[0090] When the input sampling sample comes from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples to calculate the mean, which is used as an approximation of the mean of the original algorithm. Use this mean to filter all data samples, filter out the samples with too large time, and then group them. After calculation, the mean of the data samples is 0.008840, the (N - 1) times of the sample variance is 35.071959, and the mean of the samples in the first interval is 0.004556. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 0.947454, the P value of the frequency detection in the second interval is 0, the P value of the frequency detection within the block is 0, the P value of the run test is 0.947454, and the P value of the cumulative sum test is 0. That is, the frequency detection in the first interval and the run test are passed, indicating that there is an algorithm substitution attack on the algorithm that generates the data sample.
[0091] (2)RSA-PSS
[0092] RSA-PSS1024
[0093] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the original algorithm mean. Then use this mean to filter all data samples, filtering out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.001240, the (N - 1) times of the sample variance is 0.628631, and the mean of the first interval samples is 0.000679. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.401439, the P value of the second interval frequency detection is 0, the P value of the in-block frequency detection is 0.018946, the P value of the run test is 0.886553, and the P value of the cumulative sum test is 0. That is, it passes the first interval frequency detection, the in-block frequency detection, and the run test, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0094] RSA-PSS2048
[0095] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the original algorithm mean. Then use this mean to filter all data samples, filtering out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.006121, the (N - 1) times of the sample variance is 16.620645, and the mean of the first interval samples is 0.003150. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.720299, the P value of the second interval frequency detection is 0.753476, the P value of the in-block frequency detection is 0.118753, the P value of the run test is 0.873334, and the P value of the cumulative sum test is 0.604476. That is, it passes the first interval frequency detection, the second interval frequency detection, the in-block frequency detection, the run test, and the cumulative sum test, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0096] RSA-PSS3072
[0097] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 samples after sorting to calculate the mean, which is used as an approximation of the mean of the original algorithm. Use this mean to filter all data samples, filter out the samples with too large time, and then group them. After calculation, the mean of the data samples is 0.016429, the (N - 1) times of the sample variance is 103.110670, and the mean of the samples in the first interval is 0.009585. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 0.194135, the P value of the frequency detection in the second interval is 0, the P value of the frequency detection within the block is 0, the P value of the run test is 0.953866, and the P value of the cumulative sum test is 0. That is, it passes the frequency detection in the first interval and the run test, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0098] (3)AES
[0099] AES128
[0100] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 samples after sorting to calculate the mean, which is used as an approximation of the mean of the original algorithm. Use this mean to filter all data samples, filter out the samples with too large time, and then group them. After calculation, the mean of the data samples is 0.000007, the (N - 1) times of the sample variance is 0.000018, and the mean of the samples in the first interval is 0.000004. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 0.635080, the P value of the frequency detection in the second interval is 0, the P value of the frequency detection within the block is 0, the P value of the run test is 0.782453, and the P value of the cumulative sum test is 0.178243. That is, it passes the frequency detection in the first interval, the cumulative sum test and the run test, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0101] AES192
[0102] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filter out the samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.000008, the (N - 1) times of the sample variance is 0.000021, and the mean of the samples in the first interval is 0.000004. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 0.330334, the P value of the frequency detection in the second interval is 0.669657, the P value of the frequency detection within the block is 0.000462, the P value of the run test is 0.936112, and the P value of the cumulative sum test is 0.417151. That is, it passes the frequency detection in the first interval, the frequency detection in the second interval, the frequency detection within the block, the run test, and the cumulative sum test, indicating that there is an algorithm substitution attack on the algorithm that generates this data sample.
[0103] AES256
[0104] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filter out the samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.000007, the (N - 1) times of the sample variance is 0.000021, and the mean of the samples in the first interval is 0.000004. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 0.978609, the P value of the frequency detection in the second interval is 0.096582, the P value of the frequency detection within the block is 0.000123, the P value of the run test is 0.847858, and the P value of the cumulative sum test is 0.355013. That is, it passes the frequency detection in the first interval, the frequency detection in the second interval, the frequency detection within the block, the run test, and the cumulative sum test, indicating that there is an algorithm substitution attack on the algorithm that generates this data sample.
[0105] (4)Dilithium
[0106] Dilithium2
[0107] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filter out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.001403, the (N - 1) times of the sample variance is 0.705835, and the mean of the first interval samples is 0.000739. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.920510, the P value of the second interval frequency detection is 0.000494, the P value of the in-block frequency detection is 0, the P value of the run test is 0.997019, and the P value of the cumulative sum test is 0. That is, it passes the first interval frequency detection, the second interval frequency detection, the run test and the run test, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0108] Dilithium2-AES
[0109] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filter out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.001634, the (N - 1) times of the sample variance is 0.910112, and the mean of the first interval samples is 0.000851. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.588831, the P value of the second interval frequency detection is 0, the P value of the in-block frequency detection is 0, the P value of the run test is 0.988501, and the P value of the cumulative sum test is 0. That is, it passes the first interval frequency detection and the run test, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0110] Dilithium3
[0111] When the input sampling sample comes from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filtering out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.001270, the (N - 1) times of the sample variance is 0.580267, and the mean of the first interval samples is 0.000669. Convert the data into 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.743296, the P value of the second interval frequency detection is 0, the P value of the within-block frequency detection is 0, the P value of the run test is 0.925531, and the P value of the cumulative sum test is 0. That is, the first interval frequency detection and the run test are passed, indicating that there is an algorithm substitution attack on the algorithm that generates this data sample.
[0112] Dilithium3-AES
[0113] When the input sampling sample comes from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filtering out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.001696, the (N - 1) times of the sample variance is 1.041574, and the mean of the first interval samples is 0.000880. Convert the data into 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.473960, the P value of the second interval frequency detection is 0, the P value of the within-block frequency detection is 0, the P value of the run test is 0.958313, and the P value of the cumulative sum test is 0. That is, the first interval frequency detection and the run test are passed, indicating that there is an algorithm substitution attack on the algorithm that generates this data sample.
[0114] Dilithium5
[0115] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Use this mean to filter all data samples, filter out samples with too large time values, and then group them. After calculation, the mean of the data samples is 0.001340, the (N - 1) times of the sample variance is 0.681060, and the mean of the first interval samples is 0.000695. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.946166, the P value of the second interval frequency detection is 0, the P value of the in-block frequency detection is 0, the P value of the run test is 0.895636, and the P value of the cumulative sum test is 0. That is, the first interval frequency detection and the run test are passed, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0116] Dilithium5-AES
[0117] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Use this mean to filter all data samples, filter out samples with too large time values, and then group them. After calculation, the mean of the data samples is 0.001730, the (N - 1) times of the sample variance is 1.092372, and the mean of the first interval samples is 0.000901. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.713300, the P value of the second interval frequency detection is 0, the P value of the in-block frequency detection is 0, the P value of the run test is 0.992340, and the P value of the cumulative sum test is 0. That is, the first interval frequency detection and the run test are passed, indicating that the algorithm generating the data samples has an algorithm substitution attack.
[0118] (5)Falcon
[0119] Falcon512
[0120] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 samples after sorting to calculate the mean, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filter out the samples with too large time, and then group them. After calculation, the mean of the data samples is 0.000669, the (N - 1) times of the sample variance is 0.143419, and the mean of the first interval samples is 0.000346. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.809428, the P value of the second interval frequency detection is 0, the P value of the within-block frequency detection is 0.007710, the P value of the run test is 0.952485, and the P value of the cumulative sum test is 0.362327. That is, it passes the first interval frequency detection, run test and cumulative sum test, indicating that there is an algorithm substitution attack in the algorithm that generates this data sample.
[0121] Falcon1024
[0122] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 samples after sorting to calculate the mean, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filter out the samples with too large time, and then group them. After calculation, the mean of the data samples is 0.000944, the (N - 1) times of the sample variance is 0.333893, and the mean of the first interval samples is 0.000481. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the first interval frequency detection can reach 0.708673, the P value of the second interval frequency detection is 0, the P value of the within-block frequency detection is 0.001487, the P value of the run test is 0.970382, and the P value of the cumulative sum test is 0.479233. That is, it passes the first interval frequency detection, run test and cumulative sum test, indicating that there is an algorithm substitution attack in the algorithm that generates this data sample.
[0123] (6)SPHINCS+
[0124] SPHINCS+128
[0125] When the input sampling sample comes from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filtering out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.570830, the (N - 1) times of the sample variance is 1270.166496, and the mean of the samples in the first interval is 0.317445. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 1.000000, the P value of the frequency detection in the second interval is 0.577484, the P value of the frequency detection within the block is 0, the P value of the run test is 0.951565, and the P value of the cumulative sum test is 0. That is, it passes the frequency detection in the first interval, the frequency detection in the second interval, and the run test, indicating that the algorithm generating the data sample has an algorithm substitution attack.
[0126] SPHINCS+192
[0127] When the input sampling sample comes from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples for mean calculation, which is used as an approximation of the mean of the original algorithm. Then use this mean to filter all data samples, filtering out samples with too large time values, and then group the data. After calculation, the mean of the data samples is 0.639205, the (N - 1) times of the sample variance is 2046.733551, and the mean of the samples in the first interval is 0.377781. Convert the data to 0, 1 according to the grouping, and perform randomness detection on the 0, 1 data. The P value of the frequency detection in the first interval can reach 0.837612, the P value of the frequency detection in the second interval is 0.600313, the P value of the frequency detection within the block is 0, the P value of the run test is 1.000000, and the P value of the cumulative sum test is 0. That is, it passes the frequency detection in the first interval, the frequency detection in the second interval, and the run test, indicating that the algorithm generating the data sample has an algorithm substitution attack.
[0128] SPHINCS+256
[0129] When the input sampling samples come from the ASA attack with s = 5, first select some data from the first 1 / 2 of the sorted samples to calculate the mean, which is used as an approximation of the mean of the original algorithm. Use this mean to filter all data samples, filter out the samples with too large time, and then group them. After calculation, the mean of the data samples is 0.665308, the (N - 1) times of the sample variance is 1789.194684, and the mean of the samples in the first interval is 0.329956. Convert the data to 0,1 according to the grouping, and perform randomness detection on the 0,1 data. The P value of the frequency detection in the first interval can reach 0.196511, the P value of the frequency detection in the second interval is 0.160223, the P value of the intra-block frequency detection is 0, the P value of the couplet detection is 0.975222, and the P value of the cumulative sum test is 0, that is, it passes the frequency detection in the first interval, the frequency detection in the second interval and the couplet detection, indicating that the algorithm generating the data sample has an algorithm substitution attack.
[0130] Summarize the above test conclusions with s = 5 to obtain Table 5 showing the situation of data passing randomness detection as follows, where "1" represents passing the randomness test item and "0" represents not passing.
[0131] Table 5
[0132]
[0133]
[0134] The corresponding histogram is shown as Figure 3 shown.
[0135] The experimental test process for the case of s = 10 is similar to the above. We directly give the corresponding table of detection results. Select the significance level α = 0.01, and the specific data is shown in Table 6.
[0136] Table 6
[0137]
[0138] The corresponding histogram is shown as Figure 4 shown.
[0139] Based on the above embodiments, as Figure 5 shown, the present invention also proposes a time detection system for stateless algorithm substitution attack, including:
[0140] An execution time sampling module, which is used to call symmetric encryption and digital signature algorithms in open source libraries such as the OpenSSL library to sample the encryption or signature time under different security strengths;
[0141] A data type conversion module, which is used to perform 0,1 conversion after grouping the sampled data to obtain a 0,1 sequence as the next sequence to be detected;
[0142] The substitution attack detection module is used to detect the transformed data by using the NIST SP800-22 specification to determine whether the algorithm to be detected is subject to an algorithm substitution attack.
[0143] Furthermore, the symmetric encryption and digital signature algorithms include the standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms, as well as the post-quantum algorithms Dilithium, Falcon, and SPHINCS+.
[0144] Furthermore, the data type conversion module is specifically used for:
[0145] Replacement algorithm time grouping and 0,1 conversion: On the basis of the original algorithm, introduce rejection sampling for algorithm substitution attack, record the time when the algorithm successfully encrypts or signs, approximate the mean of the first 1 / 2 sampling time as the mean of the original algorithm time, group all sampling samples. Assume that it can be divided into s groups, and the specific grouping corresponds to the upper bound value of the rejection sampling attack. Reset the sample time of the samples belonging to the i-th group in the experimentally obtained sample data to 0, set the sample data belonging to the group >i to 1, and delete all the sample data in the summary <i group, then an s-1 group 0,1 sequence can be obtained.
[0146] Furthermore, the substitution attack detection module is specifically used for:
[0147] 0,1 randomness detection: Select 4 detection criteria from the 15 criteria of NIST randomness detection for key detection: frequency detection, in-block frequency test, overlapping subsequence detection, and cumulative sum test. Perform the above 4 detections on the obtained s-1 0,1 sequences respectively. If any randomness detection passes during the detection process, it is considered that the algorithm to be detected input is very likely to be subject to an algorithm substitution attack.
[0148] In summary, in the current existing literature, no detection scheme for stateless algorithm substitution attacks in the actual deployment environment has been given. Cryptographic libraries such as OpenSSL have open-source complexity, and there are few experts reviewing the code, making it very likely that algorithm substitution attacks are carried out against open-source software. In addition, even if the code looks "clean", there is always a possibility of being damaged during compilation or runtime by damaging the compiler or interpreter. The present invention innovatively proposes the 0,1 conversion of time-sampled data and uses the NIST randomness detection results to give a conclusion on whether there is an algorithm substitution attack. The present invention supports the detection of all known general stateless algorithm substitution attacks at the software level. The implementation of this detection method and system has important guiding significance for the related research on cryptographic algorithm substitution attacks.
[0149] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. A time detection method for stateless algorithm substitution attacks, characterized in that, including: Step 1, call the symmetric encryption and digital signature algorithms in the open-source library, and sample their encryption or signature times under different security strengths; The open-source library includes the OpenSSL library; Step 2, perform 0,1 conversion after grouping the sampled data to obtain a 0,1 sequence as the next sequence to be detected; Step 3, use the NIST SP800-22 specification to detect the converted data to determine whether the algorithm to be detected is under an algorithm substitution attack; The said Step 2 includes: Replacement algorithm time grouping and 0,1 conversion: On the basis of the original algorithm, introduce rejection sampling for algorithm substitution attack, record the time when the algorithm successfully encrypts or signs, approximate the mean of the first 1 / 2 sampling time as the mean of the original algorithm time, group all sampling samples. Assume it can be divided into s groups, and the specific grouping corresponds to the upper bound value of the rejection sampling attack. Reset the sample time of the samples belonging to the i-th group in the experimentally obtained sample data to 0, set the sample data belonging to the j-th group to 1, j > i, and delete the sample data of the k-th group in all data summaries, k < i, then s - 1 groups of 0,1 sequences can be obtained; The said Step 3 includes: 0,1 randomness detection: Select 4 detection criteria from 15 criteria of NIST randomness detection for key detection: frequency detection, within-block frequency test, overlapping subsequence detection, cumulative sum test. Perform the above 4 detections on each of the s - 1 0,1 sequences obtained. If any one of the randomness detections passes during the detection process, it is considered that the algorithm to be detected input is under an algorithm substitution attack.
2. The time detection method for stateless algorithm substitution attack according to claim 1, wherein The symmetric encryption and digital signature algorithms include the standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms, as well as the post-quantum algorithms Dilithium, Falcon, SPHINCS+; 3. A time detection system for stateless algorithm substitution attacks, characterized in that, including: An execution time sampling module for calling the symmetric encryption and digital signature algorithms in the open-source library and sampling their encryption or signature times under different security strengths; The open-source library includes the OpenSSL library; A data type conversion module for performing 0,1 conversion after grouping the sampled data to obtain a 0,1 sequence as the next sequence to be detected; An alternative attack detection module for using the NIST SP800-22 specification to detect the converted data to determine whether the algorithm to be detected is under an algorithm substitution attack; The data type conversion module is specifically used for: Replacement algorithm time grouping and 0,1 conversion: On the basis of the original algorithm, introduce rejection sampling for algorithm substitution attack, record the time when the algorithm successfully encrypts or signs, approximate the mean of the first 1 / 2 sampling time as the mean of the original algorithm time, group all sampling samples. Assume it can be divided into s groups, and the specific grouping corresponds to the upper bound value of the rejection sampling attack. Reset the sample time of the samples belonging to the i-th group in the experimentally obtained sample data to 0, set the sample data belonging to the j-th group to 1, j > i, and delete the sample data of the k-th group in all data summaries, k < i, then s - 1 groups of 0,1 sequences can be obtained; The alternative attack detection module is specifically used for: 0,1 Randomness Detection: Select 4 detection criteria from the 15 criteria of NIST randomness detection for key detection: frequency detection, within-block frequency test, overlapping subsequence detection, and cumulative sum test. Perform the above 4 detections on the obtained s-1 0,1 sequences respectively. If any randomness detection passes during the detection process, it is considered that the algorithm to be detected input has suffered an algorithm substitution attack.
4. A time detection system for stateless algorithm substitution attacks according to claim 3, characterized in that, The symmetric encryption and digital signature algorithms include the standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms, as well as the post-quantum algorithms Dilithium, Falcon, and SPHINCS+.
Citation Information
Patent Citations
LDoS attack detection method based on PSO-K algorithm
CN112261000A
Black box attack-oriented substitution model automatic selection method, storage medium and terminal
CN113407939A