A Mask Security Verification Method Based on Probe Set Reduction

By verifying the security of the anti-side channel mask protection scheme based on the detection intensive reduction method, the problem of cumbersome and error-prone verification of complex mask schemes in the prior art is solved, and efficient and accurate mask security verification is achieved.

CN116545612BActive Publication Date: 2025-06-24INST OF SOFTWARE - CHINESE ACAD OF SCI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310467882.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-27
Publication Date
2025-06-24
Estimated Expiration
2043-04-27

AI Technical Summary

Technical Problem

The prior art is difficult to efficiently verify the security of the anti-side channel mask protection scheme, especially in complex mask schemes, where manual analysis is cumbersome and error-prone.

Method used

A mask security verification method based on detection intensive reduction is proposed. By reducing the detection intensive detected by the enemy in a given mask scheme to an empty set, the detection set is proved to be safe. The method includes parsing the hardware mask scheme as a directed acyclic graph, calculating the auxiliary data structure of each vertex, and judging its security through the perfect mask matrix of the probe set.

Benefits of technology

This method can efficiently verify the security of the complex anti-side channel mask scheme, which is significantly improved in efficiency compared to the traditional method, and can effectively detect the leakage of unsafe mask schemes in the public literature.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116545612B_ABST
    Figure CN116545612B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for verifying the security of a mask based on probe set reduction, and the steps are as follows: 1) Parse a given mask protection scheme into a directed acyclic graph G, and calculate the auxiliary data structure for each vertex n in the graph G; 2) Select a set N composed of d vertices in the graph G without repetition in lexicographical order d , if there are still unselected combinations, calculate the d-order probe set #imgabs0# otherwise determine that the given mask scheme passes the security verification and exit; 3) Divide #imgabs1# into several subsets that do not share masks with each other according to the mask situation of the variables; 4) When a certain subset does not follow the independent uniform distribution, if it is not extensible, output N d and exit, otherwise expand #imgabs2# and enter step 3); 5) When a certain subset follows the independent uniform distribution, delete the subset from #imgabs3# and enter step 3). Using this method, the security of the side-channel resistant mask protection scheme can be efficiently verified with less memory and processor resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of anti-side-channel mask protection, and particularly to a mask security verification method based on probe set reduction, which can be used to verify the security of anti-side-channel mask protection. Background Art

[0002] In today's society, cryptographic algorithms and cryptographic devices are widely used, protecting data security in various fields. Although cryptographic algorithms have extremely strong theoretical security, in practical applications, since the cryptographic devices running the cryptographic algorithms will leak the physical characteristics of sensitive information, such as electromagnetic radiation, sound, etc. Attackers can use this physical information to perform side-channel attacks such as differential power analysis and correlation power analysis attacks, thereby recovering sensitive information.

[0003] To resist such side-channel analysis techniques, different protection techniques have been proposed, and one of the most effective techniques is the mask technique. The mask technique is based on the threshold idea of secret sharing and also has strong security in theory. For complex cryptographic algorithms, it is not easy to design corresponding anti-side-channel mask schemes. Due to the negligence of the designer, the mask scheme may still have security vulnerabilities. And manually analyzing each set of variables (probe set) that can be detected by an adversary in the mask scheme is a cumbersome, time-consuming, and error-prone task. Therefore, it is of great significance to use techniques such as formalization to automatically verify the security of the mask scheme.

[0004] To characterize the security of mask protection, different security concepts have been proposed. Among them, the two most widely used security concepts are probe security and strong probe security. Probe security can be used to evaluate the security of a software-implemented mask scheme, and the probability distribution of a variable that an adversary can detect using one probe. Compared with software implementation, the hardware implementation of the mask scheme also needs to consider the existence of clock glitches in the hardware circuit. Therefore, an adversary can detect the joint distribution of a set of variables using one probe. The attack ability of an adversary is determined by the number of probes it can use. The set of variables that an adversary can detect using its probes is called a probe set. For a given mask scheme, if the joint distribution of the variables in each probe set that an adversary can detect in the mask scheme is statistically independent of the secret variable (sensitive information), then the mask scheme is secure.

[0005] To prove the strong probing security of the masking scheme, different techniques have been proposed. Roderick Bloem et al. proposed a verification method based on Fourier expansion. The principle of this method is that if the Fourier coefficients of all non-empty subsets of the set of secret variables in the Fourier expansion of the variables probed by the adversary are all 0, then the set of secret variables is statistically independent of the probed variable. Since the cost of directly calculating the Fourier coefficients is relatively high, Roderick Bloem et al. encoded the problem of whether the Fourier coefficients are 0 as a SAT formula and determined whether the Fourier coefficients are 0 by whether the SAT formula has a solution. Since this method requires calling a solver, its cost is very high. Gilles Barthe et al. proposed a verification method based on programming languages and probabilistic information flow analysis. This method uses the bijective relationship between the random mask and the expression, and replaces each occurrence of the expression in the probe set with the random mask. This replacement preserves the semantics of the masked program corresponding to the masking scheme and does not affect the joint distribution of the variables in the probe set. After this replacement, if the expression in the final probe set does not contain secret variables, then this probe set is secure. This method is more efficient, but because it uses nested expressions and regularizes the expressions when the expression replacement is unsuccessful, it will encounter a stack overflow problem when verifying some complex masking schemes and thus cannot complete the verification. David Knichel et al. proposed a method for verifying the statistical independence of Boolean variable sets based on ROBDD. This method constructs an ROBDD for each variable in the probe set and the set of secret variables, and uses the ROBDD to calculate the probability that all variable values in any subset of the probe set and any subset of the set of secret variables are all 1 and the product of the probabilities that all variable values in these two subsets are all 1 respectively, and proves the statistical independence of the probe set and the set of secret variables by verifying that these two probabilities are always equal under different subset combinations. This method will not have the false negative problem (i.e., judging a secure masking scheme as insecure) that occurs in the method based on Fourier expansion and the method based on programming languages and probabilistic information flow analysis, but because it needs to construct ROBDDs, it consumes extremely large processor and memory resources and has performance deficiencies. Summary of the Invention

[0006] The object of the present invention is to provide a reduction method for the probe set probed by the adversary for a given masking scheme, and prove that the probe set is secure by reducing this probe set to an empty set. If all probe sets that the adversary can detect can be reduced to an empty set, then the given masking scheme is secure. The method of the present invention is a new method for verifying masking security and can efficiently verify the security of relatively complex side-channel resistant masking schemes.

[0007] The technical solution of the present invention to achieve the above object is a masking security verification method based on probe set reduction, and the process of this method is asFigure 1 As shown in the figure, it includes the following steps:

[0008] 1) For a given hardware mask scheme containing several gates, parse it into a directed acyclic graph G. The gates in the mask scheme include input gates, intermediate gates, and output gates. According to whether they are linear, intermediate gates can be divided into linear gates (XOR gates, XNOR gates, NOT gates, registers, etc.) and non-linear gates (AND gates, OR gates, NAND gates, NOR gates, etc.). According to the number of operands, intermediate gates can be divided into unary gates (NOT gates, registers, etc.) and binary gates (AND gates, OR gates, NAND gates, NOR gates, XOR gates, XNOR gates, etc.). The parsing process is as follows: Corresponding each gate in the mask scheme to a vertex n in the graph G. Specifically, corresponding the input gate of the mask scheme to a vertex n in the graph G with an in-degree of 0 and an out-degree that can be any value; corresponding the output gate to a vertex n in the graph G with an in-degree of 1 and an out-degree of 0; corresponding the unary gate to a vertex n in the graph G with an in-degree of 1 and an out-degree that can be any value; corresponding the binary gate to a vertex n in the graph G with an in-degree of 2 and an out-degree that can be any value. The incoming edge of the vertex n corresponding to the unary gate and the output gate points to the vertex n.lft corresponding to its operand; the two incoming edges of the vertex n corresponding to the binary gate point to the vertices n.lft and n.rgt corresponding to the two operands respectively.

[0009] 2) Calculate the auxiliary data structures for each vertex n in the graph G, namely the support set, the single-path reach mask set, the perfect mask set, and the probe set, denoted by supp(n), unq(n), perf(n), and O n respectively. According to whether the input is the sharing value of the mask circuit sensitive information, the input gate can be divided into a sharing gate and a random gate. In the following text, \ represents the set difference operation, ∪ represents the set union operation, ∩ represents the set intersection operation, {·} represents the set composed of the elements · in the parentheses, denotes the empty set, and s ∈ S means that s is an element of the set S. The mask scheme divides the sensitive information x into d + 1 (d ≥ 1) sharing values x1,..., x d+1 , which respectively correspond to d + 1 vertices in the directed acyclic graph For the j-th vertex among these d + 1 vertices The calculation method of the corresponding auxiliary data structure is: when 1 ≤ j ≤ d, When j = d + 1, the sharing value x d+1 The corresponding vertex The calculation method of the corresponding auxiliary data structure is The random gate corresponds to a random number r, and the calculation method of the auxiliary data structure of the vertex n corresponding to it in the directed acyclic graph is supp(n) = unq(n) = perf(n) = O n= {r}. The calculation methods of the auxiliary data structures corresponding to the unary gate and the output gate for vertex n are supp(n) = supp(n.lft), unq(n) = unq(n.lft), perf(n) = perf(n.lft), and O n = O n.lft . For the binary gate, the calculation methods of the support set and the single-path reach mask set corresponding to vertex n are supp(n) = supp(n.ltf) ∪ supp(n.rgt), unq(n) = (unq(n.lft) ∪ unq(n.rgt)) \ (unq(n.lft) ∩ unq(n.rgt)). For the binary linear gate, the calculation method of the perfect mask set corresponding to vertex n is pref(n) = pref(n.lft) ∪ perf(n.rgt) ∩ unq(n). For the binary non-linear gate, the calculation method of the perfect mask set corresponding to vertex n is . The calculation method of the probe set corresponding to vertex n of the binary gate is: If the gates corresponding to n.lft and n.rgt are both registers, then O n = {n.lft} ∪ {n.rgt}; If the gates corresponding to n.lft and n.rgt are not registers, then O n = O n.lft ∪ O n.rgt ; If the gate corresponding to n.lft is a register and the gate corresponding to n.rgt is not a register, then O n = {n.ltf} ∪ O n.rgt ; If the gate corresponding to n.lft is not a register and the gate corresponding to n.rgt is a register, then O n = O n.lft ∪ {n.rgt}. {n.lft} represents the set composed of vertex n.lft; {n.rgt} represents the set composed of vertex n.rgt.

[0010] 3) Select a previously unselected combination N of d-order vertices from all possible combinations of d vertices in G d (d is a positive integer), N d contains vertices n1,..., n d , calculate the d-order probe set (where represents the probe set corresponding to the j-th vertex in N d ) and perform the detection in step 4). If there is no unselected combination of d vertices in G, the given mask scheme is secure and the step is exited. Each time, select d different vertices from all vertices in G as a combination, and require that each selected combination is different from the previously selected combinations.

[0011] 4) If the probe sets entered into this step from steps 3), 5), and 6) ( If the probing sets such as () are empty sets, go to step 3). If the probing sets entering this step from steps 3), 5), and 6) are not empty sets, rename them as and divide the variables into several subsets that do not share masks pairwise according to the mask situation of the variables That is (where represents the union operation of disjoint sets), and for any 1 < i ≠ j < t, there is established. From i = 1 to t, calculate the i-th probing subset of (Suppose contains p vertices, which are represented by n1,..., n p respectively) of the perfect mask set (Suppose contains q random numbers, which are represented by r1,..., r q respectively). According to calculate the perfect mask matrix If r j ∈ perf(n k ), then Otherwise

[0012] 5) From i = 1 to t, if the i-th subset does not satisfy the conditions (rank() represents the rank of the matrix in the parentheses) and the condition that when 1 ≤ j ≤ p, (where perf(n j ) represents the perfect mask set of the j-th vertex n j ; represents excluding n j from other vertices n k (1 ≤ k ≤ q and j ≠ k) of the union of the difference sets between the support set supp(n k ) and the perfect mask set perf(n k ); represents excluding from the union of the support sets supp(n) of the vertices n in the other probing subsets) of does not follow the independent uniform distribution. If is not extensible then the given mask scheme may have security problems, output the d-order vertex combination N d that may have leakage, and exit the step. If this subset is extensible, then select the vertices n in the probing subset j (1 ≤ j ≤ p) in descending order of topological order. If If the intersection with is not empty, then expand to obtain the detection set and enter step 4) to reduce the detection set . If 1 ≤ j ≤ p, and has an empty intersection, then expand to obtain the detection set and enter step 4) to reduce the detection set .

[0013] 6) From i = 1 to t, if the i-th subset satisfies the condition and the condition that when 1 ≤ j ≤ p, (the explanation is the same as in step 5)), then obeys the independent uniform distribution. Delete from to obtain the detection set and enter step 4) to reduce the detection set .

[0014] The technical solution of the present invention has the following advantages:

[0015] The present invention can efficiently determine whether a detection set is secure according to the perfect mask matrix of the detection set. Compared with the methods using technologies such as SMT, ROBDD, and SAT, the efficiency of this method is very high. For example, for the 1st-order DOM mask scheme and the 1st-order CMS mask scheme of the AES encryption algorithm, the efficiency of this method is thousands of times that of the method using ROBDD; it can effectively detect the leakage of insecure mask schemes in the public literature. For example, this method can detect the leakage points in the insecure mask schemes found in the 2013 FSE conference. Description of the Drawings

[0016] Figure 1 is the flowchart of the present invention.

[0017] Figure 2 is the data flow diagram of the 1st-order DOM mask algorithm fragment of the AES encryption algorithm. Detailed Embodiments

[0018] The present invention will be further described in detail below with reference to the drawings. The examples given are only used to explain the present invention and are not intended to limit the scope of the present invention.

[0019] First, take the fragment in the 1st-order DOM mask scheme of the AES encryption algorithm (shown below) as an example to introduce the construction of the perfect mask matrix in the present invention.

[0020]

[0021] In this masking scheme, the secret variables are a, b, c, d, e, f, g, h, satisfying a = a0 + a1, b = b0 + b1, …, h = h0 + h1. For ease of understanding, the masking scheme shown above can be transformed into Figure 1 the data flow graph shown. This data flow graph is a directed acyclic graph. Among them, linear operations (XOR, equivalence) are represented by circles, non-linear operations are represented by squares, random numbers are represented by red circles, components of secret values are represented by double circles, both random numbers and components of secret values are stored in registers, and other registers storing intermediate variables are represented by diamonds. Under the strong probing model, if the adversary probes the register node n 326 , then the joint distribution of the probing variables in the set of upper-level registers connected to it can be obtained. In this example, the set of nodes that the adversary can probe is From Figure 2 it can be seen that among them, the perfect mask of n 19 is r0, which is not used by other probing variables. Therefore, the probing set is divided into two subsets and Among them, the perfect mask matrix is (1), the rank is 1, equal to the number of variables, so it follows an independent uniform distribution and can be deleted from . Therefore, next, is reduced.

[0022] The 8 probing variables in

[0023]

[0024] can be expressed as

[0025]

[0026] n 19 's perfect mask is {r0}, n 56 's mask is {h0}, n 78 's mask is {b0, c0, g0, h0}, and so on. At this time, according to the mask situation of each node, it is represented in a matrix:

[0027]

[0028] Among them, the digital matrix is the perfect mask matrix The perfect mask matrix is calculated as The rank of [] is 8, which is equal to the number of variables in the probing set. Therefore, they are independently and identically distributed, and thus secure.

[0029] The following uses the second example to illustrate the use of the extension rule and how this method detects leakage. This example is a defective second-order masking scheme discovered by Jean-Sebastien Coron et al. in the 2013 FSE conference. This scheme involves the following variables: where a is a secret variable, and a = a0 + a1 + a2; two random numbers r0 and r1 are used to re-mask a to obtain three new masked components b0 = a0 + r0 + r1, b1 = a1 + r0, b2 = a2 + r1; and the set of probing variables of the adversary is {n1 = a0 + r0, n2 = a2 ∧ b1}. It is easy to know that the perfect mask of n1 is {a0, r0}, and the perfect mask of n2 is Thus, the rank of the perfect mask matrix is 1. Therefore, the node n2 needs to be extended to {a2, b1}, and the extended set of probing variables is obtained as {n0 = a0 + r0, n1 = a2, n2 = b1 = a1 + r0}. In matrix representation, that is

[0030]

[0031] The digital matrix is the perfect mask matrix. This matrix is a matrix over the binary field. Its rank can be calculated to be 2, which is less than the number of probing variables. Therefore, there may be leakage in this masking scheme.

[0032] Although specific embodiments of the present invention are disclosed for illustrative purposes, the purpose is to help understand the content of the present invention and implement it accordingly. Those skilled in the art can understand that: without departing from the spirit and scope of the present invention and the appended claims, various substitutions, changes, and modifications are possible. Therefore, the present invention should not be limited to the content disclosed in the best embodiments, and the scope of protection claimed by the present invention is subject to the scope defined by the claims.

Claims

1. A mask security verification method based on probe set reduction, the steps of which include: 1) For a given hardware mask scheme containing several gates, parse it into a directed acyclic graph G; 2) Calculate the auxiliary data structures for each vertex n in the directed acyclic graph G, namely the support set supp(n), the set of single-path reachability masks unq(n), the set of perfect masks perf(n), and the probe set O n ; 3) Select a set \(N\) consisting of \(d\) vertices from the directed acyclic graph \(G\) corresponding to the given mask scheme without repetition in lexicographical order d =\(\{n_1,\ldots,n\) d \}\), calculate the \(d\)-order detection set and proceed to step 4); if there is no combination of \(d\) unselected vertices in \(G\), then determine that the given mask scheme is secure and the mask scheme passes the security verification; denote the detection set corresponding to the \(j\)-th vertex in \(N\) d ; 4) If the current given probe set is an empty set, the original d-order probe set is secure, go to step 3); name the current probe set and divide the variables into several subsets that do not share masks pairwise according to the mask situation of the variables and calculate each subset 's perfect mask matrix Then proceed to step 5); 5) From i = 1 to i = t, if the i-th subset does not follow a uniform distribution and is extensible, then expand the probe set to the probe set and enter step 4) to operate on the probe set ; if does not follow a uniform distribution and is not extensible, then it is determined that there may be a security problem with the given mask scheme, and the set N d of d-order vertices that may have leakage is output, and the verification ends; if the i-th subset follows a uniform distribution, then delete the subset from to obtain And proceed to step 4) to operate on the detection set for operations.

2. The method according to claim 1, characterized in that, The hardware masking scheme divides the sensitive information x into d + 1 sharing values x j ; where d ≥ 1, 1 ≤ j ≤ d + 1; and the hardware masking scheme includes a number of input gates, intermediate gates, and output gates; according to whether the input is a sharing value of the masked circuit sensitive information, the input gates can be divided into sharing gates and random gates; according to whether it is linear, the intermediate gates in the masking scheme can be divided into linear gates and non-linear gates; according to the number of operands, the intermediate gates are divided into unary gates and binary gates.

3. The method according to claim 2, wherein The process of parsing the hardware mask scheme into the directed acyclic graph G is as follows: Corresponding the input gate of the hardware mask scheme to a vertex n in the graph G with an in-degree of 0 and an out-degree that can be any value; Corresponding the output gate to a vertex n in the directed acyclic graph G with an in-degree of 1 and an out-degree of 0; Corresponding the unary gate to a vertex n in the directed acyclic graph G with an in-degree of 1 and an out-degree that can be any value; Corresponding the binary gate to a vertex n in the directed acyclic graph G with an in-degree of 2 and an out-degree that can be any value; The in-edge of the vertex n corresponding to the unary gate and the output gate points to the vertex n.lft corresponding to its operand; The two in-edges of the vertex n corresponding to the binary gate respectively point to the vertices n.lft and n.rgt corresponding to the two operands.

4. The method according to claim 3, wherein The d + 1 sharing values of the sensitive information x correspond to d + 1 vertices in the directed acyclic graph The calculation method of the auxiliary data structure for each vertex is as follows: when 1 ≤ j ≤ d, when j = d + 1, The calculation method of the auxiliary data structure of the vertex n corresponding to the random gate r in the directed acyclic graph is supp(n) = unq(n) = perf(n) = O n = {r}; The calculation methods of the auxiliary data structures of the vertices n corresponding to the unary gates and output gates are supp(n) = supp(n.lft), unq(n) = unq(n.lft), perf(n) = perf(n.lft) and O n = O n.lft ; The calculation methods of the support set and the single-path reachability mask set of the vertex n corresponding to the binary gate are supp(n) = supp(n.ltf) ∪ supp(n.rgt), unq(n) = (unq(n.lft) ∪ unq(n.rgt)) \ (unq(n.lft) ∩ unq(n.rgt)); The calculation method of the perfect mask set of the vertex n corresponding to the binary linear gate is perf(n) = perf(n.lft) ∪ perf(n.rgt) ∩ unq(n), and the calculation method of the perfect mask set of the vertex n corresponding to the binary non-linear gate is The calculation method of the probe set of the vertex n corresponding to the binary gate is: If the gates corresponding to n.lft and n.rgt are both registers, then O n = {n.lft} ∪ {n.rgt}; If the gates corresponding to n.lft and n.rgt are not registers, then O n = O n.lft ∪ O n.rgt ; if the gate corresponding to n.lft is a register and the gate corresponding to n.rgt is not a register, then O n = {n.lft} ∪ O n.rgt ; if the gate corresponding to n.lft is not a register and the gate corresponding to n.rgt is a register, then O n = O n.lft ∪ {n.rgt}.

5. The method according to claim 1, wherein The subset described in step 4) of the perfect masking matrix is calculated as follows: 1) Calculate the perfect mask set of the i-th detection subset of 2) According to Calculate the perfect mask matrix If r j ∈ perf(n k ), then the element in the j-th row and k-th column of the perfect mask matrix Otherwise Otherwise 6. The method according to claim 1, wherein If the said subset satisfies the following conditions 1) and 2), then it follows an independent uniform distribution, otherwise it does not follow an independent uniform distribution; 1) When 1 ≤ j ≤ p, 2) 7. The method according to claim 1, characterized in that If the subset described in step 5) satisfies then it is not extensible; otherwise it is extensible.

8. The method according to claim 1, wherein The subset described in step 5) is expanded to in the following process: The vertices n in the detection subset j are selected in descending order of topological order, where 1 ≤ j ≤ p; if and have a non-empty intersection, then is expanded to obtain the detection set If, when 1 ≤ j ≤ p, and have an empty intersection, then is expanded to obtain the detection set 9. A server, characterized in that, Comprising a memory and a processor, the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing the steps in any one of claims 1 to 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Comprehensive protection method for resisting side channel and fault attacks

    CN112187444A

  • Service logic verification method and device based on questionnaire questions

    CN113868369A