An improved comprehensive protection method based on threshold technology
By adding the compensation function after the cryptographic algorithm is executed, the probability of failure spread is improved, and the problem of incomplete protection of side channel attacks and fault attacks in the prior art is solved, thereby achieving a higher security and low-cost comprehensive protection solution.
Patent Information
- Application Number
- CN202211642859.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-20
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-12-20
AI Technical Summary
The prior art lacks an effective comprehensive protection solution when defending against side channel attacks and fault attacks, resulting in high resource consumption and inability to theoretically fully resist two types of attacks.
After the execution of the cryptographic algorithm is completed, the compensation function is added to increase the number of exchanges and the probability of failure spreading is increased, thereby constructing a safer comprehensive protection solution.
It effectively solves the problem of uneven spread of fault injection at the last wheel, improves the fault protection safety of the comprehensive protection plan, and maintains the advantage of low cost.
Smart Images

Figure CN118233115B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of block cipher algorithm protection, and in particular to a comprehensive protection method for resisting side channel attacks and fault attacks based on threshold implementation technology. Background Art
[0002] In the traditional black-box attack model, the attacker mainly analyzes the security of the cryptographic algorithm through the input and output information of the cryptographic algorithm. The security of the existing block cipher algorithm under the black-box model has been fully theoretically demonstrated. However, under the gray-box model, the security of the block cipher algorithm faces huge challenges. Under the gray-box model, the adversary's attack capability is enhanced. In addition to the input and output of the cryptographic algorithm, the adversary can also use the physical information leaked during the execution of the cryptographic algorithm or interfere with the execution of the cryptographic algorithm to attack. Among them, the attack using the physical information leaked during the execution of the cryptographic algorithm is called a side channel attack. According to the different physical information used, it can be divided into energy side channel attack, electromagnetic side channel attack, optical side channel attack and sound side channel attack. Side channel attacks pose a huge threat to the security of the implementation of cryptographic algorithms due to their simplicity of implementation and higher attack efficiency than black-box attacks. Attacks carried out by interfering with the execution of the cryptographic algorithm are called fault attacks. Fault attacks require more stringent attack conditions than side channel attacks, but the attack efficiency is relatively higher, which is also a huge threat to the security of the implementation of cryptographic algorithms.
[0003] In response to the threat of side channel attacks, corresponding protection strategies have been proposed. The essence of side channel attacks is to use the correlation between side channel information and the intermediate values of cryptographic operations to attack, so the protection strategy achieves protection by destroying this correlation. According to different specific protection ideas, side channel protection can be divided into hiding technology and masking technology. Hiding technology mainly destroys the correlation between side channel information and intermediate states by changing the original distribution of side channel information. Specifically, it can be achieved by reducing the signal-to-noise ratio and balancing the side channel information of a single clock. Studies have shown that protection schemes designed based on hiding technology can increase the difficulty of attackers to a certain extent, but they can be broken by increasing the number of collected side channel curves, signal preprocessing, etc., so they cannot provide theoretically complete security. Masking technology is a side channel protection idea based on secret sharing. It destroys the correlation between intermediate values and side channel information by randomly splitting the original intermediate values. Since masking technology has a more complete theoretical support, it has received extensive research and attention since it was proposed. In early mask protection schemes, it was assumed that the operation was strictly performed in a predetermined order, ignoring the impact of burrs in CMOS circuits on the security of protection schemes. Subsequent studies have shown that protection schemes designed by ignoring the impact of burrs are mostly unsafe.
[0004] In order to deal with the impact of burr phenomenon on the security of mask protection, the threshold implementation protection idea is proposed. In order to deal with the threat of d-order side channel attack, it is necessary to implement d-order threshold implementation. A d-order threshold implementation includes two parts: input variable splitting and operation splitting. Taking y=f(x) as an example, in the input variable splitting stage, use S x -1 random number Split the input variable x into satisfy Where S x is the number of shares of the input variable split, and the d-order threshold implementation needs to satisfy S x ≥d+1. In the operation splitting stage, the split input variables are brought into the original operation, and we can get Then split the above operation into output components Where S y represents the number of shares of the function decomposition. The above division needs to meet three major properties: (1) correctness, (2) Incompleteness: the combination of any d output components is independent of at least one component of the input variable, ensuring d-order side channel security in a glitch environment; (3) Output uniformity: each possible output partition appears with equal probability, meeting the security requirements of the next stage during the iterative operation of the cryptographic algorithm.
[0005] The protection strategies against fault attacks can be roughly divided into two categories: "check-block" and fault randomization. In the "check-block" type of fault protection, the fault injection is first detected by means of time redundancy, space redundancy, etc. When the fault injection is detected, the output of the fault ciphertext will be blocked, thereby achieving protection against fault attacks that rely on the fault ciphertext. This type of protection strategy requires a judgment statement to determine whether the fault is injected or not. This judgment statement is often a vulnerable point for fault attacks. When the judgment statement is skipped by the fault attack, the protection strategy will fail. Different from the "check-block" type of fault protection, the fault randomization protection strategy allows the output of the ciphertext during fault injection without the need for a judgment statement, so it does not have the security defects of the "check-block" type of fault protection. Infection protection is a mainstream protection scheme in fault randomization. Joye et al. proposed an infection protection scheme based on the exchange mechanism in 2007. In this scheme, by exchanging some bytes of the intermediate state, the ciphertext finally output during fault injection cannot be used by the adversary. However, in this protection scheme, the swap operation is a deterministic step without any increase in randomness. When the implementation scheme is known, the adversary can implement the attack through logical deduction. This scheme only increases the difficulty of fault attacks to a certain extent and cannot achieve the theoretical fault attack security.
[0006] At present, the research on protection against side channel attacks and fault attacks is often carried out independently. The protection scheme for one type of attack is often unable to resist the other type of attack, and vice versa. The current comprehensive protection scheme is often a simple superposition of two protection strategies, which has brought a large increase in resource consumption. In response to this situation, Feng Jingyi et al. proposed a low-cost comprehensive protection method (patent number: ZL201911359164.2) by combining the threshold realization idea and the exchange mechanism. In this comprehensive scheme, first, in order to resist the d-order side channel attack, a d-order original threshold realization is implemented for the cryptographic algorithm to be protected; secondly, a completely identical redundant threshold realization is implemented for the cryptographic algorithm to be protected; thirdly, the propagation of faults is realized by exchanging some components of the intermediate operation of the original threshold realization and the redundant threshold realization, and the randomness of the components in the threshold realization scheme is used to achieve the uniform randomness of the final output ciphertext. However, in the above scheme, its exchange operation is a probabilistic event for the propagation of faults. For block cipher algorithms, their operations often include multiple rounds of iterative operations. When faults are injected in the first few rounds of cryptographic operations, the injected faults can be diffused to the two-way operations with a probability close to 1 after multiple rounds of exchanges, and the final output presents uniform randomness, thereby achieving protection against fault attacks. However, when faults are injected in the later rounds of the cryptographic algorithm, especially in the last round, the number of exchanges is small, and the injected faults may not be diffused to the two-way operations, so that one operation retains all the information of the injected fault, and finally causes the leakage of the faulty ciphertext. Summary of the invention
[0007] In view of the above situation, the present invention considers adding a compensation function after the execution of the cryptographic algorithm and before the ciphertext output, thereby increasing the probability of fault diffusion by increasing the number of exchanges, thereby constructing a more secure comprehensive protection scheme.
[0008] The present invention is an improved comprehensive protection method based on threshold technology, which comprises the following steps:
[0009] 1) To resist d-order side channel attacks, a d-order threshold implementation scheme is constructed for the protected cryptographic algorithm, which is called the original threshold implementation;
[0010] 2) Treating the d-order threshold implementation whose protection cryptographic algorithm construction is exactly the same as that in step 1) as redundant threshold implementation;
[0011] 3) Using the same plaintext as encryption input, synchronously execute the algorithm flow of step 1) and step 2), and after each nonlinear operation, exchange the partial shares of the original threshold realization and the redundant threshold realization;
[0012] 4) To increase the probability of fault diffusion, a compensation function is added to both the original threshold implementation and the redundant threshold implementation, and the same exchange operation as step 3) is performed during the execution of the compensation function;
[0013] 5) After step 4) is completed, the output ciphertext of the original threshold implementation or the redundant threshold implementation is selected as the output ciphertext of the comprehensive protection.
[0014] Preferably, the d-order thresholds described in step 1) and step 2) divide the encrypted input, the encrypted intermediate value and the encrypted result into at least s shares, s≥d+1.
[0015] Preferably, the number of exchange shares in step 3) is (0, d] ∪ (0, sd], and the exchanged shares are in the same position in the original threshold implementation and the redundant threshold implementation. That is, 1 to d shares can be exchanged, or other shares after removing d shares can be exchanged.
[0016] Preferably, the compensation function described in step 4) includes two design methods: one based on an inversion structure and the other based on a Feistel structure.
[0017] In block cipher algorithms, a mainstream method for constructing S-boxes is to use inversion operations on finite fields. For example, the S-boxes of AES and SM4 can be considered as constructed by inversion operations on finite fields. In the threshold implementation of such algorithms, it is necessary to convert the S-box into an inversion operation on a finite field and then construct the protection scheme. Therefore, the compensation function can be constructed by connecting an even number of inversion operations in series. Its basic unit construction is as follows: Figure 1 As shown, x -1 The inversion operation after adding the threshold implementation in the S-box. After two inversion operations, the operation restores the original value. The additional nonlinear operation increases the probability of fault diffusion to the two-way operation. And because the inversion operation can reuse the inversion operation of the S-box, it does not increase the additional implementation cost. The compensation function can contain multiple basic unit structures. The increase in the number will increase the probability of fault diffusion and improve security, but it will also increase the calculation delay of the algorithm. It should be selected according to the actual situation.
[0018] When the S-box of the block cipher algorithm is not constructed by inversion operation, the compensation function based on the inversion structure is no longer applicable. Consider the compensation function based on the Feistel structure, with the S-box of the block cipher algorithm as the nonlinear component of the compensation function. Its basic unit structure is as follows: Figure 2As shown. Its input L0 and R0 are the data of the mask input bit width of two adjacent S-boxes in the cryptographic operation, specifically 2sL, where L represents the input bit width of the S-box, s represents the number of shares to be realized by the threshold, and the S-box operation after the S-box multiplexing block cipher algorithm threshold is realized. The basic unit structure consists of the first exchange iterative operation, the second non-exchange iterative operation, the third exchange iterative operation, and the fourth non-exchange iterative operation. After 4 rounds of iterative operations, the intermediate value of the left-path operation changes to L1=R0, After 4 iterations, the intermediate value of the right-hand operation changes to
[0019] R4=R3=R0, S stands for XOR. As described in the above formula, after four iterations, both the left and right paths are restored to their original values. The additional nonlinear operation increases the probability of fault diffusion to the two-way operation. The S-box of the basic unit construction multiplexing block cipher algorithm is a nonlinear component, so it does not add additional implementation cost. The compensation function can contain multiple basic unit constructions. The increase in the number will increase the probability of fault diffusion, but it will also increase the calculation delay of the algorithm. It should be selected according to the actual situation.
[0020] Compared with the prior art, the present invention has the following advantages:
[0021] 1. The present invention effectively solves the problem of uneven diffusion of fault injection in the last round, and improves the fault protection security of the comprehensive protection scheme;
[0022] 2. The compensation function of the present invention is constructed by reusing the original components in the cryptographic algorithm, so the added implementation cost can be ignored, maintaining the low-cost advantage of the comprehensive protection solution. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 Schematic diagram for inverse compensation function;
[0024] Figure 2 It is a schematic diagram of the Feistel structure compensation function;
[0025] Figure 3 This is a schematic diagram of the comprehensive protection S-box for the AES algorithm;
[0026] Figure 4 It is a flow chart of the present invention. DETAILED DESCRIPTION
[0027] The specific implementation techniques of the present invention are described below by way of examples, but are not intended to limit the scope of the present invention in any way.
[0028] This example uses the AES algorithm as the block cipher algorithm to be protected, and designs a comprehensive protection scheme that can resist fault attacks and first-order side channel attacks.
[0029] The block length of the AES block cipher algorithm can support 128 bits, 192 bits and 256 bits. The present invention takes the 128-bit AES algorithm encryption operation as an example to illustrate. The AES round iteration operation consists of S-box, row shift, column confusion and key XOR operation. The S-box is the only nonlinear operation, and the exchange operation of the comprehensive protection scheme is only performed in the S-box part. The specific implementation of the AES comprehensive protection scheme includes the following steps:
[0030] 1) To resist the first-order side channel attack, the original threshold implementation splits the plaintext input and key input into three parts. The key to the threshold implementation of the AES algorithm lies in the nonlinear component, namely the S-box. To achieve the threshold implementation of the S-box, first consider the S-box as GF(2 8 ) finite field and affine operation, and then further perform composite domain decomposition to convert GF(2 8 ) is transformed into GF(2 4 ) and GF(2 2 ). The specific structure of the original threshold implementation part of the S-box is as follows Figure 3 As shown in the upper part, it contains 6 stages. Stage 1 is the affine operation M1; Stage 2 contains GF(2 4 ) and the linear operation L1; stage 3 contains GF(2 2 ) and the linear operation L2; stage 4 contains GF(2 2 ) inverse operation L3 and multiplication operation; stage 5 contains 2 GF (2 4 ) is a multiplication operation on the S-box; and stage 6 is an affine operation M2. Based on the above decomposition, three shares of threshold protection are performed for the operations at different stages of the S-box.
[0031] 2) Implement a redundant threshold implementation for the AES algorithm that is exactly the same as the original threshold implementation.
[0032] 3) The exchange operation occurs after the nonlinear operation, that is, the S-box part, such as Figure 3 As shown, the multiplication operation is the only nonlinear operation, and there are 4 stages with multiplication operations, so 4 exchange operations are performed, and one of the 3 shares is exchanged during the exchange process.
[0033] 4) After the encryption operation is completed and before the ciphertext is output, a compensation function is added to increase the number of exchange operations in the last round of fault injection and increase the probability of fault diffusion. For the AES algorithm, its S-box is constructed by inversion operation, so it can be constructed based on the inversion compensation function, with GF(28 ) is used as the compensation function. When the S-box is not constructed by the inversion operation, a compensation function based on the Feistel structure can be considered.
[0034] 5) After step 4), without loss of generality, the encryption result achieved by the original threshold is used as the ciphertext output of the comprehensive protection scheme.
[0035] In terms of side channel protection security. In the structure of comprehensive protection, both the original encryption and redundant encryption are designed for side channel protection using the threshold protection principle. According to the side channel security properties of the threshold implementation technology, the two circuits protected by the first-order threshold implementation can resist the first-order side channel attack. In addition, the exchange function is performed on the basis of the threshold implementation, and it is a linear operation that does not involve interactive operations between different shares, so it does not destroy the incompleteness of the threshold implementation. One intermediate mask component always maintains an independent relationship with the original intermediate value, which can resist the first-order side channel attack, so it can meet the side channel security. In summary, the comprehensive protection scheme can resist the first-order side channel attack as a whole.
[0036] In terms of fault protection security. The injected fault will undergo an exchange operation after nonlinear operation. If the fault injection component is diffused to the original threshold implementation and the redundant threshold implementation respectively, the final output ciphertext will be random due to the randomness of the threshold implementation share, thereby making the fault attack that relies on the faulty ciphertext invalid. When the fault is injected into the last round of the AES algorithm, after only one round of nonlinear operation, the exchange operation may not be able to diffuse the fault to the two-way operation; the addition of the compensation function further increases the number of exchange operations, increasing the protection capability against fault attacks; and because the compensation function is constructed by reusing the inverse operation of the S-box, it will not increase the additional implementation cost too much.
[0037] Although the specific embodiments of the present invention are disclosed for the purpose of illustration, the purpose is to help understand the content of the present invention and implement it accordingly, those skilled in the art will understand that various substitutions, changes and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the content disclosed in the best embodiment, and the scope of the present invention is subject to the scope defined in the claims.
Claims
1. An improved comprehensive protection method based on threshold technology, the steps of which include: 1) To resist d-order side channel attacks, a d-order threshold implementation scheme is constructed for the protected cryptographic algorithm, which is called the original threshold implementation; 2) Treating the d-order threshold implementation whose protection cryptographic algorithm construction is exactly the same as that in step 1) as redundant threshold implementation; 3) Using the same plaintext as encryption input, the original threshold implementation and the redundant threshold implementation are synchronously executed; wherein after the nonlinear operation at the same stage of the original threshold realization and the redundant threshold realization, partial shares of the original threshold realization and the redundant threshold realization are exchanged; 4) using a compensation function to exchange partial shares of the final output of the original threshold implementation and the final output result of the redundant threshold implementation, as the ciphertext output of the original threshold implementation and the ciphertext output result of the redundant threshold implementation; wherein the compensation function is a compensation function based on a Feistel structure, which includes at least one basic unit; the left input of the basic unit is denoted as L0, and the right input is denoted as R0, L0 and R0 are data of the mask input bit width of two adjacent S-boxes for cryptographic operation, the data size of L0 and R0 is 2sL, L represents the input bit width of the S-box, and s represents the number of threshold implementation shares; the basic unit is composed of the first exchange iterative operation, the second non-exchange iterative operation, the third exchange iterative operation and the fourth non-exchange iterative operation; after four rounds of iterative operations, the changes of the intermediate values of the left operation are L1=R0, After 4 iterative operations, the intermediate values of the right-hand operation change as follows: R4=R3=R0,where S is the XOR operation; 5) After step 4) is completed, the output ciphertext of the original threshold implementation or the redundant threshold implementation is selected as the output ciphertext of the comprehensive protection.
2. The method according to claim 1, characterized in that The original threshold implementation and the redundant threshold implementation divide the encrypted input, the encrypted intermediate value and the encrypted result into at least s shares, s≥d+1.
3. The method according to claim 2, characterized in that In step 3), the number of the partial shares exchanged is (0, d]∪(0, sd], and the exchanged shares are in the same position in the original threshold implementation and the redundant threshold implementation.
4. The method according to claim 1, characterized in that The compensation function is a series structure of a plurality of the basic units.
Citation Information
Patent Citations
Comprehensive protection method for resisting side channel and fault attacks based on threshold technology
CN111224770A