Capability Testing Method and System for Fault Attack Based on Hamming Weight

Through the fault attack method based on Hanming weight, the problem that existing leakage models cannot take into account data requirements, data volume and attack efficiency are solved, and an accurate leakage model and efficient fault attack are achieved.

CN116388959BActive Publication Date: 2025-07-08NAVAL UNIV OF ENG PLA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310355079.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-04
Publication Date
2025-07-08
Estimated Expiration
2043-04-04

AI Technical Summary

Technical Problem

The existing fault attack leakage model cannot take into account data requirements, data volume, fault tolerance and attack efficiency at the same time, and has certain limitations.

Method used

The fault attack method based on Hanming weight is adopted, and fault response statistics, leakage function establishment and effective time attack window selection are adopted, and fault injection controller and current amplification module are combined to achieve fault injection and response analysis of the target equipment.

Benefits of technology

A relatively accurate leakage model was established, which reduced data requirements, improved fault tolerance, reduced data volume and high attack efficiency, and had better practicality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116388959B_ABST
    Figure CN116388959B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of device testing, and particularly to a method and system for testing the ability of fault attacks based on Hamming weight, including fault response classification, establishment of a fault leakage function, selection of an effective time attack window, and selection of voltage glitches for fault injection attacks; selection of an effective fault injection parameter interval, and injecting a large number of faults within the above time window; according to the response distribution of each slice within the time window, selecting any appropriate combination of fault parameters, and reducing the entropy of the unknown key of the target device by analyzing the fault information. The present invention grasps the essence of the fault based on the fault probability of Hamming weight, accurately establishes a leakage model, has low requirements for data, strong fault tolerance, greatly reduces the data volume compared with the existing model, has good practicability, and solves the problem that most of the existing leakage models have certain limitations and cannot simultaneously take into account the requirements for data, data volume, fault tolerance, and attack efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of device testing, and particularly to a method and system for testing the ability of fault attacks based on Hamming weight. Background Art

[0002] Fault attacks usually introduce faults in the target environment. By means of electromagnetic attacks, optical injection attacks, voltage and clock glitches, and temperature changes, etc., the operating state of the target device is changed to generate controllable faults, and the fault information is analyzed to reduce the entropy of the unknown key. The current leakage models of fault attacks include the leakage model based on information theory, which constructs leakage functions with information quantity, mutual information quantity, etc.; the leakage model based on fault-sensitive information, which constructs leakage functions with fault sensitivity, the number of affected fault bits, and so on.

[0003] The leakage model is an important tool for side-channel attack evaluation, and its accuracy will affect the reliability of the evaluation. The fault model requires less data, but has high requirements for data and is vulnerable to noise interference; the fault sensitivity model is not affected by noise interference, but requires a large amount of data and has low attack efficiency. Most of the existing leakage models have certain limitations and cannot simultaneously take into account the requirements for data, the amount of data, fault tolerance ability, and attack efficiency. Therefore, we propose a method and system for testing the ability of fault attacks based on Hamming weight. Summary of the Invention

[0004] Based on the technical problems existing in the background art, the present invention proposes a method and system for testing the ability of fault attacks based on Hamming weight. The fault probability based on Hamming weight grasps the essence of faults, accurately establishes a leakage model, has low requirements for data, strong fault tolerance ability, greatly reduces the amount of data compared with the existing models, has good practicability, and solves the problem that most of the existing leakage models have certain limitations and cannot simultaneously take into account the requirements for data, the amount of data, fault tolerance ability, and attack efficiency.

[0005] The present invention provides the following technical solutions: A method for testing the ability of fault attacks based on Hamming weight, including the following steps:

[0006] S1. Fault response statistics: Inject faults into the target device, distinguish between "damaged" responses and other responses, and count the device fault probability at each time point;

[0007] S2. Establishment of a fault leakage function: Assume that all values occur with the same probability;

[0008] The Hamming weight of a single-byte data follows a binomial distribution. The probability distribution of the Hamming weight of uniformly distributed 8-bit data has the smallest probabilities for the data with Hamming weights of 0 and 8, and the largest probability for the data with a Hamming weight of 4;

[0009] Assume that the probability of a single-bit 0 to 1 transition is p0, and the probability of a 1 to 0 transition is p1. Then, for a single byte with Hamming weight HW = i, where 0 ≤ i ≤ 8, the probability of a fault occurring due to bit flipping is:

[0010]

[0011] S3. Select the effective time attack window and inject fault attacks by selecting voltage glitches.

[0012] S4. Select the effective fault injection parameter range. Within the above time window, select a voltage range from 0V to the extreme value of the glitch level -6V, and a fault length from hundreds of nanoseconds to thousands of nanoseconds, and inject a large number of faults.

[0013] Narrow the parameter range until there is an approximate mixture of 50% damaged and 50% non-damaged response results in each time slice of the time window.

[0014] The glitch voltage, the interval length, the step length of the length, and the number of attack times in each time slice will all affect the selection of the effective range. Select any suitable combination of fault injection parameters to implement the attack.

[0015] Preferably, after injecting faults into the target device in step S1, observe the feedback of the target device. If the target device returns an incorrect response, classify this response as "damaged", and classify all other responses as "other".

[0016] Preferably, in step S3, to ensure that the glitch can affect the execution of the first S-box operation in the first round of encryption

[0017] Introduce a delay before this operation. First, add a trigger signal and a reset signal before and after the instruction of the S-box operation. This trigger signal is called the "small trigger" signal. Add 1 trigger signal within a few microseconds before the small trigger, which is called the "big trigger" signal. Inject a glitch between the big trigger signal and the small trigger signal to ensure that the glitch can affect the S-box operation.

[0018] A capability test system for fault attacks based on Hamming weight includes a fault injection controller, a current amplification module, and an MCU cipher target.

[0019] The fault injection controller is used to generate a glitch signal from the trigger signal given by the MCU development board during encryption and decryption operations.

[0020] The current amplifier is used to generate the voltage glitch required for the attack experiment from the glitch signal of the fault injection controller, and supply this glitch to the target device to perform a fault injection attack.

[0021] Preferably, after receiving the plaintext of the attack, the target device encrypts it and sends the ciphertext to the storage module for storage.

[0022] Compared with the prior art, the present invention has the following advantages:

[0023] 1. As the memory capacity has increased significantly, the capacitors storing bit positions have become smaller and are arranged closer together, making it increasingly difficult to prevent mutual interference between adjacent capacitors and more likely to occur bit - flip phenomena. The fault probability based on Hamming weight grasps the essence of the fault and more accurately establishes the leakage model;

[0024] 2. Fault probability information is easy to collect. Without knowing the details of the algorithm and the detailed implementation of the operation, only by observing the response of the target device, it is hardly affected by noise; this model has low requirements for data, strong fault - tolerance ability, and the amount of data is greatly reduced compared with the existing models, having good practicability. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 Probability distribution diagram of HW for uniformly - distributed single - byte data;

[0026] Figure 2 Frequency distribution diagram of fault probabilities with different Hamming weights in the embodiment of the present invention;

[0027] Figure 3 Attack result diagram with Hamming weight of 0 in the embodiment of the present invention;

[0028] Figure 4 Attack result diagram with Hamming weight of 1 in the embodiment of the present invention;

[0029] Figure 5 Attack result diagram with Hamming weight of 2 in the embodiment of the present invention;

[0030] Figure 6 Attack result diagram with Hamming weight of 3 in the embodiment of the present invention;

[0031] Figure 7 Attack result diagram with Hamming weight of 4 in the embodiment of the present invention;

[0032] Figure 8 Attack result diagram with Hamming weight of 5 in the embodiment of the present invention;

[0033] Figure 9 Attack result diagram with Hamming weight of 6 in the embodiment of the present invention;

[0034] Figure 10 Attack result diagram with Hamming weight of 7 in the embodiment of the present invention;

[0035] Figure 11The attack result graph with Hamming weight of 8 in the embodiments of the present invention;

[0036] Figure 12 The comparison graph of the measured results and the model calculation results of the present invention. Specific implementation manners

[0037] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0038] The present invention provides a technical solution: a method for testing the ability of fault attack based on Hamming weight, including the following steps:

[0039] S1. Fault response classification

[0040] We do not need to master the specific data and algorithm details, but only need to observe the feedback of the target device. If the target device returns an incorrect response, the response is classified as "damaged". All other responses are classified as "other". After a large number of fault injections, the model counts the fault probability at each time point, that is, the proportion of "damaged" responses.

[0041] S2. Establishment of fault leakage function

[0042] In this model, it is assumed that the data to be processed all follow a uniform distribution, that is, it is assumed that all values appear with the same probability.

[0043] The Hamming weight of a single-byte data follows a binomial distribution. The probability distribution of the Hamming weight of 8-bit data with a uniform distribution is as Figure 1 shown. The probabilities of data with Hamming weight of 0 and 8 are the smallest, and the probability of data with Hamming weight of 4 is the largest.

[0044] Assume that the probability of a single-bit 0 to 1 conversion is p0, and the probability of a 1 to 0 conversion is p1. Then the probability of a single byte with HW of i (0 ≤ i ≤ 8) having a fault due to bit flipping is

[0045]

[0046] S3. Selection of effective time attack window

[0047] Select voltage glitches for fault injection attacks. To ensure that the glitches can affect the execution of the first S-box operation in the first round of encryption, a delay is introduced before this operation. First, trigger signals and reset signals are added before and after the instruction of the S-box operation. This trigger signal is called the "small trigger" signal. One trigger signal is added within a few microseconds before the small trigger, which is called the "large trigger" signal. Injecting glitches between the large trigger signal and the small trigger signal can ensure that the glitches can affect the S-box operation.

[0048] Inject a large number of voltage glitches between the two trigger signals, and select the time window with a "corrupted" response as the attack window.

[0049] S4. Selection of the effective fault injection parameter range

[0050] Within the above time window, select the voltage range from 0V to the extreme value of the glitch level (-6V), and the fault length from hundreds of nanoseconds to thousands of nanoseconds, and inject a large number of faults. Select the appropriate fault injection parameter range in a step-by-step manner so that the proportion of corrupted responses in each slice within the time window is approximately 50%.

[0051] The interval length, step length of the glitch depth and width, and the number of attack times for each time slice will all affect the selection of the effective range. Just select a suitable set of fault parameters.

[0052] The ability test system for fault attacks based on Hamming weight includes a fault injection controller, a current amplification module, and an MCU cipher target;

[0053] The fault injection controller is used to generate glitch signals from the trigger signals given by the MCU development board during encryption and decryption operations;

[0054] The current amplifier is used to generate the voltage glitches required for the attack experiment from the glitch signals of the fault injection controller, and use this glitch to provide it to the target device to enter the fault injection attack.

[0055] The trigger signals given by the MCU development board during encryption and decryption operations generate glitch signals through the fault injection controller, and through the current amplification module, generate the voltage glitches required for the attack experiment, and provide this glitch to the MCU cipher target to enter the fault injection attack. The PC side continuously sends plaintext through the Attacker software. After the attack target receives the plaintext, it encrypts it and sends the ciphertext to the PC side for storage.

[0056] Use the DMCU-F405 cryptographic target as the target device, and its MCU is STM32F405RGT6. After the device is triggered, the output voltage connected to the target can be changed to generate glitches of any length at a given pulse delay. The device provides four parameters: pulse delay (the delay between the trigger and the glitch, with a resolution of approximately 4 ns), the level of the glitch (0 to -6 V), the length of the glitch (resolution less than 1 ns), and the baseline level.

[0057] Conduct a fault attack experiment using effective fault injection parameters (glitch width from 100 ns to 300 ns, depth from -6 V to 0) in the attack window (880 ns - 900 ns).

[0058] Histogram analysis

[0059] According to the fault response distribution in the attack window, draw a histogram as Figure 2 shown.

[0060] It can be seen that Figure 2 the frequencies of the fault probability values in are uneven, and the distribution of this histogram is approximately composed of 9 normal distributions with different amplitudes, and the attack effect is good. The mean of the first distribution is about 0.2911, the mean of the second distribution is about 0.3333, the mean of the third distribution is about 0.3337, etc., corresponding to 9 HW (abbreviation for Hamming Weight) respectively.

[0061] Figures 3 - 11 shows the attack results of the Hamming weight data. Each HW data has its own fault mode and a fixed mean.

[0062] Obviously, under this technical solution, 9 different Hamming weight data can be directly identified through the fault response mode.

[0063] Correlation analysis

[0064] The correlation between the measured data and the model data under the attack reflects the attack effect. The stronger the correlation, the better the attack effect.

[0065] Select the sliding window filtering method to process the attack results. When the time delay window size is 6, the correlation coefficient between the fault probability of the 6th time slice and the Hamming weight is the strongest, up to -0.9455, showing a strong negative correlation. The fault probability of the Hamming weight data output in the attack model is negatively correlated with the HW, which is consistent with the actual results, indicating that this technical solution is effective.

[0066] Select the measured data when HW is 0 and 8, and combine it with the attack model (Model basedData) to calculate that p0 is 0.0534 and p1 is 0.0360. The failure probabilities of HW1 to 7 are calculated as follows in the table:

[0067]

[0068] The correlation coefficient between the measured attack results and the model calculation results for each Hamming weight is as high as 0.9403, as Figure 12 shown, indicating that the performance of this technical solution is good.

[0069] In the present invention, a leakage function is constructed with the failure probabilities of data with different Hamming weights undergoing bit flips. During the effective time attack window, a valid fault injection parameter interval is used for fault injection attacks. The value of the leakage function is used as the hypothesized intermediate value for correlation analysis, mutual information analysis, etc. with the measured intermediate value to recover the key. Finally, based on the MCU experiment implemented with unprotected AES, during the effective time attack window, a valid fault injection parameter interval is used, voltage glitches are repeatedly injected at each time point, and the response is analyzed. The measured data proves that this attack has good effects.

[0070] The above is only the preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and all should be covered by the protection scope of the present invention.

Claims

1. A method for testing the ability of a fault attack based on Hamming weight, characterized in that: It includes the following steps: S1. Fault response statistics: Inject faults into the target device, distinguish "broken" responses from other responses, and statistically calculate the device fault probability at each time point; S2. Establishment of the fault leakage function: All values occur with the same probability; The Hamming weight of single-byte data follows a binomial distribution. For the probability distribution of the Hamming weight of 8-bit data with a uniform distribution, the probabilities of data with Hamming weights of 0 and 8 are the smallest, and the probability of data with a Hamming weight of 4 is the largest; The probability of a single-bit 0 to 1 transition is p 0, and the probability of a 1 to 0 transition is p 1. Then the Hamming weight HW is i , and for a single byte where 0 ≤ i ≤ 8, the probability of a fault occurring due to a bit flip is: ; S3. Selection of the effective time attack window: Select voltage glitches for fault injection attacks; S4. Selection of the effective fault injection parameter range: Within the above time attack window, select a voltage range from 0V to the extreme value of the glitch level -6V, and a fault length from hundreds of nanoseconds to thousands of nanoseconds, and inject a large number of faults; Narrow the parameter range until there is an approximate mixture of 50% broken and 50% non-broken response results in each time slice of the time attack window; The glitch voltage, the interval length, the step length, and the number of attacks in each time slice will all affect the selection of the effective range. Select any suitable combination of fault injection parameters to implement the attack.

2. The method for testing the ability of a fault attack based on Hamming weight according to claim 1, wherein: After injecting faults into the target device in step S1, observe the feedback of the target device. If the target device returns an incorrect response, classify this response as "broken", and classify all other responses as "other".

3. The method for testing the ability of a fault attack based on Hamming weight according to claim 1, wherein: In step S3, to ensure that the glitch can affect the execution of the first S-box operation in the first round of encryption, introduce a delay before this operation. First, add a trigger signal and a reset signal before and after the instruction of the S-box operation. This trigger signal is called the "small trigger" signal. Add 1 trigger signal within a few microseconds before the small trigger, which is called the "big trigger" signal. Inject a glitch between the big trigger signal and the small trigger signal to ensure that the glitch can affect this S-box operation.

4. The ability test system for the fault attack based on Hamming weight according to any one of claims 1-3, characterized in that: It includes a fault injection controller, a current amplification module, and an MCU password target; The fault injection controller is used to generate a glitch signal from the trigger signal given by the MCU development board during encryption and decryption operations; The current amplification module is used to generate the voltage glitch required for the attack experiment from the glitch signal of the fault injection controller and supply this glitch to the target device to enter the fault injection attack; 5. The ability testing system according to claim 4, characterized in that: After receiving the attacked plaintext, the target device encrypts it and sends the ciphertext to the storage module for storage.

Citation Information

Patent Citations

  • Cryptographic algorithm realization protecting method used for defending energy analysis attacks

    CN102571331A

  • Fault attack detection method based on power consumption analysis

    CN112653546A