Light signal based illumination side-channel analysis method, apparatus and storage medium

By acquiring and processing the LED light signal waveforms of cryptographic devices, and utilizing dimensionality reduction clustering and related energy analysis methods, the limitations of side-channel analysis technology in overcoming long distances were overcome, enabling accurate recovery of cryptographic device keys under long-distance conditions.

CN118432877BActive Publication Date: 2025-12-30BEIJING INST OF TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410507308.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-25
Publication Date
2025-12-30
Estimated Expiration
2044-04-25

AI Technical Summary

Technical Problem

Existing side-channel analysis techniques cannot overcome the limitations of long distances, making it difficult to effectively recover the keys of cryptographic devices.

Method used

By acquiring the LED light signal waveform of the cryptographic device under long-distance conditions, and after preprocessing, the key of the cryptographic algorithm is recovered using dimensionality reduction clustering methods or related energy analysis methods, including filtering, noise reduction, PCA dimensionality reduction, and hierarchical clustering or related energy analysis.

Benefits of technology

This method enables the recovery of cryptographic device keys over long distances, overcoming the long-distance limitations of side-channel analysis techniques. The method is easy to implement and highly accurate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118432877B_ABST
    Figure CN118432877B_ABST
Patent Text Reader

Abstract

The present application relates to the method and device of the illumination side channel analysis based on the light signal and storage medium, apply in key analysis technical field, including: the LED lamp of the password device with LED lamp in reality is generally connected with the power supply of the device directly or indirectly, when as power indicator light, there is the hidden danger of key leakage, therefore, the present application obtains the light signal waveform of the LED lamp of the password device of the password algorithm running under the condition of long distance, removes the interference factors by preprocessing the light signal waveform, then according to the type of password algorithm, the light signal waveform after preprocessing is processed by using the dimension reduction clustering method or the related energy analysis method, so as to recover the key of the password algorithm running by the password device, solve the problem that the side channel analysis technology in the prior art cannot break through the limitation of long distance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of key parsing technology, and more specifically to a method, apparatus, and storage medium for illuminance side-channel analysis based on optical signals. Background Technology

[0002] In recent years, traditional cryptanalysis techniques—that is, techniques that analyze plaintext and ciphertext information through normal channels to recover keys—have been widely studied. However, with the increase in key length and the complexity of cryptographic algorithms, traditional cryptanalysis techniques have become increasingly inefficient in analyzing cryptographic algorithms. In real-world scenarios, however, cryptographic devices inevitably experience power consumption leakage, electromagnetic radiation leakage, sound leakage, and delay leakage, and this leakage information is closely related to the encryption process performed by the device. Therefore, compared to traditional cryptanalysis techniques, side-channel analysis, proposed by Kocher in 1996, which utilizes effective information from these leaks, has two advantages: first, it can obtain intermediate value information during the operation of the cryptographic algorithm; and second, longer keys do not affect key recovery.

[0003] Side-channel analysis technology is highly practical and destructive. A large number of encryption algorithms in encryption devices (such as AES, DES, RSA, etc.) have been attacked. However, side-channel analysis technology has not yet been able to overcome the limitations of long distances.

[0004] The technical solution of this invention is limited to use under legal circumstances. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide an illumination side-channel analysis method, apparatus and storage medium based on optical signals, so as to solve the problem that the side-channel analysis technology in the prior art has been unable to overcome the limitation of long distance.

[0006] According to a first aspect of the present invention, an illuminance-side channel analysis method based on optical signals is provided, the method comprising:

[0007] Acquire the light signal waveform of the LED light of a cryptographic device running a cryptographic algorithm under long-distance conditions;

[0008] The type of cryptographic algorithm being run by the cryptographic device is obtained from the optical signal waveform, and the optical signal waveform is preprocessed according to the type of cryptographic algorithm.

[0009] Based on the type of cryptographic algorithm, the preprocessed optical signal waveform is subjected to dimensionality reduction clustering or related energy analysis methods to obtain the key of the cryptographic algorithm running on the cryptographic device.

[0010] Preferably,

[0011] The types of cryptographic algorithms include asymmetric cryptographic algorithms and symmetric cryptographic algorithms.

[0012] Preferably,

[0013] The preprocessing of the optical signal waveform according to the type of the cryptographic algorithm includes:

[0014] The optical signal waveform is filtered and noise reduced.

[0015] Preferably,

[0016] If the cryptographic algorithm is an asymmetric cryptographic algorithm, the optical signal waveform is first filtered to remove its power system harmonics;

[0017] The optical signal waveforms of multiple filtered asymmetric cryptographic algorithms are obtained, and the first optical signal waveform is obtained by performing a moving average processing on the optical signal waveforms of multiple filtered asymmetric cryptographic algorithms.

[0018] Preferably,

[0019] If the cryptographic algorithm is a symmetric cryptographic algorithm, the optical signal waveform is first filtered to remove its power system harmonics;

[0020] The optical signal waveforms of multiple filtered symmetric cryptographic algorithms are obtained. The optical signal waveforms of multiple filtered asymmetric cryptographic algorithms are first subjected to low-pass filtering. Then, the optical signal waveforms after low-pass filtering are vertically aligned to obtain the second optical signal waveform.

[0021] Preferably,

[0022] The key of the cryptographic algorithm running the cryptographic device is recovered by using a dimensionality reduction clustering method on the first optical signal waveform;

[0023] The key of the cryptographic algorithm running the cryptographic device is recovered by using correlation energy analysis on the second optical signal waveform.

[0024] Preferably,

[0025] The key for recovering the cryptographic algorithm running the cryptographic device by using a dimensionality reduction clustering method on the first optical signal waveform includes:

[0026] The first optical signal waveform is first subjected to principal component analysis dimensionality reduction method to map the high-dimensional data to the low-dimensional space through linear transformation, and the dimensionality-reduced data is obtained.

[0027] The hierarchical clustering method is used on the dimensionality-reduced data to calculate the similarity between any two clusters, and the most similar clusters are continuously merged to finally obtain the key of the cryptographic algorithm running on the cryptographic device.

[0028] Preferably,

[0029] The key for recovering the cryptographic algorithm running the cryptographic device by using correlation energy analysis on the second optical signal waveform includes:

[0030] For the encryption algorithm to be analyzed, assuming different candidate key values, based on each value in the candidate key values ​​and the input value of the second optical signal waveform, an expected energy consumption model of the intermediate value of the cryptographic algorithm is generated. The expected energy consumption model is used to assume that the energy consumption is proportional to the weight of the number of bits occupied by the intermediate value.

[0031] Analyze the correlation between the generated expected energy consumption model and the second optical signal waveform, and select the candidate key value corresponding to the expected energy consumption model with the highest correlation as the key for the cryptographic algorithm running by the cryptographic device.

[0032] According to a second aspect of the present invention, an illuminance-side channel analysis apparatus based on optical signals is provided, the apparatus comprising:

[0033] Optical signal waveform acquisition module: used to acquire the optical signal waveform of the LED light of a cryptographic device running a cryptographic algorithm under long-distance conditions;

[0034] Preprocessing module: used to obtain the type of cryptographic algorithm being run by the cryptographic device through the optical signal waveform, and to preprocess the optical signal waveform according to the type of cryptographic algorithm;

[0035] Recovery module: used to obtain the key of the cryptographic algorithm running by the cryptographic device by applying a dimensionality reduction clustering method or a related energy analysis method to the preprocessed optical signal waveform according to the type of the cryptographic algorithm.

[0036] According to a third aspect of the present invention, a storage medium is provided, the storage medium storing a computer program, which, when executed by a host controller, implements the steps of the above-described method.

[0037] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:

[0038] This application utilizes the fact that there are many types of cryptographic devices with LED lights in reality, and that LED lights are generally directly or indirectly connected to the device's power supply as power indicators, which poses a risk of key leakage. Therefore, this application obtains the optical signal waveform of the LED light of a cryptographic device running a cryptographic algorithm under long-distance conditions, preprocesses the optical signal waveform to remove interference factors, and then applies dimensionality reduction clustering or related energy analysis methods to the preprocessed optical signal waveform according to the type of cryptographic algorithm, thereby recovering the key of the cryptographic algorithm running on the cryptographic device. This solves the problem that the side-channel analysis technology in the prior art has been unable to overcome the long-distance limitation.

[0039] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the invention. Attached Figure Description

[0040] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0041] Figure 1 This is a flowchart illustrating an illumination side-channel analysis method based on optical signals according to an exemplary embodiment;

[0042] Figure 2 This is an optical signal waveform of an asymmetric cryptographic algorithm illustrated according to another exemplary embodiment;

[0043] Figure 3 This is an optical signal waveform of a symmetric cryptography algorithm illustrated according to another exemplary embodiment;

[0044] Figure 4 This is a waveform diagram of an asymmetric cryptography algorithm before and after noise reduction, according to another exemplary embodiment.

[0045] Figure 5 This is a waveform diagram before and after noise reduction of a symmetric cryptography algorithm according to another exemplary embodiment;

[0046] Figure 6 This is a system schematic diagram of an illumination side-channel analysis device based on optical signals, according to another exemplary embodiment.

[0047] In the attached diagram: 1-Optical signal waveform acquisition module, 2-Preprocessing module, 3-Recovery module. Detailed Implementation

[0048] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the invention as detailed in the appended claims.

[0049] Example 1

[0050] Figure 1 This is a flowchart illustrating an illumination side-channel analysis method based on optical signals, according to an exemplary embodiment. Figure 1 As shown, the method includes:

[0051] S1, acquire the light signal waveform of the LED light of the cryptographic device running the cryptographic algorithm under long-distance conditions;

[0052] S2, obtain the type of cryptographic algorithm being run by the cryptographic device through the optical signal waveform, and preprocess the optical signal waveform according to the type of cryptographic algorithm;

[0053] S3, according to the type of cryptographic algorithm, the preprocessed optical signal waveform is subjected to a dimensionality reduction clustering method or a related energy analysis method to obtain the key of the cryptographic algorithm running by the cryptographic device;

[0054] Understandably, this application targets a cryptographic device running the RSA (asymmetric cryptographic algorithm) signature algorithm. At a distance of approximately 15 meters, a telescope is used to aim at the LED light of the cryptographic device, while a light sensor is placed behind the eyepiece to collect the light signal waveform. The collected waveform is shown in the attached figure. Figure 2 As shown; For a cryptographic device running AES (symmetric encryption algorithm), at a distance of approximately 20 cm, a telescope is used to aim at the LED light of the device, while a light sensor is placed behind the eyepiece to collect the light signal waveform. The collected waveform is shown in the attached figure. Figure 3 As shown;

[0055] The optical signal waveforms of any cryptographic algorithm type collected above are filtered to remove the harmonic noise of the power system.

[0056] Then, for the optical signal waveforms of asymmetric cryptographic algorithms, after filtering, further noise reduction processing is performed, such as averaging multiple waveforms or performing a moving average. The waveforms before and after processing are shown in the attached figure. Figure 4 As shown;

[0057] For optical signal waveforms of symmetric cryptographic algorithms, after filtering, further noise reduction processing is performed, such as low-pass filtering followed by vertical alignment. The waveforms before and after processing are shown in the attached figure. Figure 5 As shown;

[0058] For asymmetric cryptographic algorithms, PCA (Principal Component Analysis) dimensionality reduction is first performed, followed by hierarchical clustering for analysis. Of course, other common dimensionality reduction or clustering methods can also be used. By performing PCA dimensionality reduction on the processed RSA algorithm optical signal waveform and then using hierarchical clustering, the key of the RSA cryptographic algorithm running on the cryptographic device can be directly recovered. PCA dimensionality reduction is a commonly used data dimensionality reduction technique that can map high-dimensional data to a low-dimensional space through linear transformation while preserving as many features of the original data as possible. PCA simplifies the dataset by finding the principal components, which are the directions with the largest variance in the dataset. Specifically, PCA dimensionality reduction methods include:

[0059] (1) Standardize the data: First, center each feature of the data so that its mean is 0. If the scales of the features are inconsistent, it may be necessary to scale them to the standard deviation (even if they have unit variance). This step is necessary because PCA is very sensitive to the scale of the data.

[0060] (2) Calculate the covariance matrix: PCA uses the covariance matrix of the data to find the principal components of the data. The covariance matrix represents the correlation between data features.

[0061] (3) Calculate eigenvalues ​​and eigenvectors: The eigenvalues ​​and corresponding eigenvectors of the covariance matrix can tell us in which directions the data has the largest variance, i.e., the principal components of the data. The eigenvector is the orthogonal eigenvector of the covariance matrix, while the eigenvalue corresponds to the variance of the data in the direction of that eigenvector.

[0062] (4) Selecting principal components: Once all eigenvalues ​​have been calculated, they are sorted in descending order, and then the eigenvectors corresponding to the k largest eigenvalues ​​are selected, where k is a user-defined number that represents the target dimension after dimensionality reduction. The size of k depends on how much information of the original data you want to retain.

[0063] (5) Forming an eigenvector matrix: Put these eigenvectors into a matrix, which will serve as a mapping from the original space to the lower-dimensional space.

[0064] (6) Transform to a new space: Multiply the original dataset by the eigenvector matrix to transform the data into a new space formed by the selected principal components. The resulting data is the dimensionality-reduced data.

[0065] Hierarchical clustering is a common unsupervised learning method used to classify data. Unlike other types of clustering, hierarchical clustering aims to establish a hierarchical cluster structure, specifically including:

[0066] (1) First, choose a distance or similarity metric to quantify the similarity between any two clusters, such as Euclidean distance, Manhattan distance or cosine similarity.

[0067] (2) Next, in the cohesive algorithm, each object is initially treated as a separate cluster, and then the most similar clusters are continuously merged according to the similarity defined by the metric method.

[0068] (3) In the splitting algorithm, the starting point is a single cluster containing all objects, which is then split into smaller and smaller clusters.

[0069] (4) There are also various methods for merging similarity criteria between two clusters, such as single-linkage, complete-linkage and average-linkage. This application does not impose any restrictions on these methods.

[0070] Correlation energy analysis was performed on the symmetric cryptography algorithm. Specifically, the AES algorithm optical signal waveform after the above processing was analyzed, allowing direct recovery of the AES cryptographic algorithm key running on the cryptographic device. The correlation energy analysis is detailed below:

[0071] (1) Hypothetical key: For the encryption algorithm to be analyzed, different candidate key values ​​are assumed, and these hypothetical keys are used to perform partial encryption operations on the collected plaintext or ciphertext data.

[0072] (2) Generate intermediate values ​​for the model: Generate an expected energy consumption model based on each value in the candidate keys. This involves making assumptions about the energy consumption of the device when performing a certain operation. These operations are related to the key. The model may be based on actual power consumption behavior, such as the Hamming weight model, which assumes that energy consumption is proportional to the weight of the number of bits occupied by the data (i.e., the number of 1s).

[0073] (3) Calculate the correlation coefficient: Analyze the correlation between the waveform and the generated expected energy consumption model. The correlation coefficient indicates the degree of similarity between the actual energy trace and the assumed energy consumption model.

[0074] (4) Recovery key: Identify the candidate key values ​​with the highest correlation coefficient, as they are most likely to be the correct key value or a part of the correct key value.

[0075] This application utilizes the fact that there are many types of cryptographic devices with LED lights in reality. However, LED lights are generally directly or indirectly connected to the device's power supply and used as power indicator lights, which poses a risk of key leakage. Therefore, this application obtains the optical signal waveform of the LED light of a cryptographic device running a cryptographic algorithm under long-distance conditions. By preprocessing the optical signal waveform to remove interference factors, and then applying dimensionality reduction clustering or related energy analysis methods to the preprocessed optical signal waveform according to the type of cryptographic algorithm, the key of the cryptographic algorithm running on the cryptographic device can be recovered. This solves the problem that the existing side-channel analysis technology has been unable to overcome the long-distance limitation. Moreover, the method is easy to implement and has high accuracy.

[0076] Example 2:

[0077] Figure 6 This is a system schematic diagram of an illuminance side-channel analysis apparatus based on optical signals, according to another exemplary embodiment, the apparatus comprising:

[0078] Optical signal waveform acquisition module 1: used to acquire the optical signal waveform of the LED light of a cryptographic device running a cryptographic algorithm under long-distance conditions;

[0079] Preprocessing module 2: used to obtain the type of cryptographic algorithm being run by the cryptographic device through the optical signal waveform, and preprocess the optical signal waveform according to the type of cryptographic algorithm;

[0080] Recovery module 3: used to apply a dimensionality reduction clustering method or a related energy analysis method to the preprocessed optical signal waveform according to the type of the cryptographic algorithm, to obtain the key of the cryptographic algorithm running by the cryptographic device;

[0081] Understandably, the optical signal waveform acquisition module 1 is used to acquire the optical signal waveform of the LED light of the cryptographic device running a cryptographic algorithm under long-distance conditions; the preprocessing module 2 is used to obtain the type of cryptographic algorithm being run by the cryptographic device through the optical signal waveform, and preprocess the optical signal waveform according to the type of cryptographic algorithm; the recovery module 3 is used to obtain the key of the cryptographic algorithm being run by the cryptographic device by applying a dimensionality reduction clustering method or a correlation energy analysis method to the preprocessed optical signal waveform according to the type of cryptographic algorithm.

[0082] Example 3:

[0083] This embodiment provides a storage medium storing a computer program, which, when executed by a host controller, implements the various steps in the above method.

[0084] It is understood that the storage medium mentioned above can be a read-only memory, a hard disk, or an optical disk, etc.

[0085] It is understood that the same or similar parts in the above embodiments can be referred to each other, and the contents not described in detail in some embodiments can be referred to the same or similar contents in other embodiments.

[0086] It should be noted that in the description of this invention, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this invention, unless otherwise stated, "a plurality of" means at least two.

[0087] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as will be understood by those skilled in the art to which embodiments of the invention pertain.

[0088] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0089] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0090] Furthermore, the functional units in the various embodiments of the present invention can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0091] The storage media mentioned above can be read-only memory, disk, or optical disk, etc.

[0092] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0093] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.

Claims

1. A method of illumination side-channel analysis based on optical signals, characterized in that, The method comprises: acquiring a light signal waveform of an LED light of a cryptographic device running a cryptographic algorithm under a long-distance condition; obtaining the type of the cryptographic algorithm running on the cryptographic device through the light signal waveform, and pre-processing the light signal waveform according to the type of the cryptographic algorithm; the pre-processing of the light signal waveform according to the type of the cryptographic algorithm comprises: filtering and noise reduction processing of the light signal waveform; if the type of the cryptographic algorithm is an asymmetric cryptographic algorithm, the light signal waveform is first filtered to remove the harmonics of the power system thereof; a plurality of filtered light signal waveforms of the asymmetric cryptographic algorithm are acquired, and the plurality of filtered light signal waveforms of the asymmetric cryptographic algorithm are subjected to sliding average processing to obtain a first light signal waveform; if the type of the cryptographic algorithm is a symmetric cryptographic algorithm, the light signal waveform is first filtered to remove the harmonics of the power system thereof; a plurality of filtered light signal waveforms of the symmetric cryptographic algorithm are acquired, and the plurality of filtered light signal waveforms of the asymmetric cryptographic algorithm are first subjected to low-pass filtering processing, and then the light signal waveforms subjected to the low-pass filtering processing are subjected to vertical alignment processing to obtain a second light signal waveform; the pre-processed light signal waveform is subjected to a dimension reduction clustering method or a correlation energy analysis method according to the type of the cryptographic algorithm to obtain the key of the cryptographic algorithm running on the cryptographic device; the first light signal waveform is subjected to a dimension reduction clustering method to recover the key of the cryptographic algorithm running on the cryptographic device; the second light signal waveform is subjected to a correlation energy analysis method to recover the key of the cryptographic algorithm running on the cryptographic device; the first light signal waveform is subjected to a dimension reduction clustering method to recover the key of the cryptographic algorithm running on the cryptographic device comprises: the first light signal waveform is first subjected to a principal component analysis dimension reduction method to map high-dimensional data to a low-dimensional space through linear transformation to obtain dimension-reduced data; the dimension-reduced data is subjected to a hierarchical clustering method to constantly merge the most similar clusters by calculating the similarity between any two clusters, and finally obtain the key of the cryptographic algorithm running on the cryptographic device; the second light signal waveform is subjected to a correlation energy analysis method to recover the key of the cryptographic algorithm running on the cryptographic device comprises: for an encryption algorithm to be analyzed, different candidate key values are assumed, and an expected energy consumption model of an intermediate value of a cryptographic algorithm is generated according to each numerical value in the candidate key value and an input value of the second light signal waveform, the expected energy consumption model being used to assume that the energy consumption is proportional to the weight of the number of bits occupied by the intermediate value; the correlation between the generated expected energy consumption model and the second light signal waveform is analyzed, and the candidate key value corresponding to the expected energy consumption model with the highest correlation is selected as the key of the cryptographic algorithm running on the cryptographic device.

2. The method according to claim 1, wherein the type of the cryptographic algorithm comprises an asymmetric cryptographic algorithm and a symmetric cryptographic algorithm.

3. Apparatus for side-channel analysis based on the luminosity of a light signal, characterized in that the device comprises: The light signal waveform acquisition module is configured to acquire a light signal waveform of an LED lamp of a cryptographic device running a cryptographic algorithm under a long-distance condition. The preprocessing module is configured to obtain a type of the cryptographic algorithm running on the cryptographic device through the light signal waveform, and to pre-process the light signal waveform according to the type of the cryptographic algorithm. The pre-processing of the light signal waveform according to the type of the cryptographic algorithm comprises: filtering and noise reduction processing of the light signal waveform; if the type of the cryptographic algorithm is an asymmetric cryptographic algorithm, filtering processing is performed on the light signal waveform first to remove harmonics of a power system thereof; a plurality of filtered light signal waveforms of the asymmetric cryptographic algorithm are acquired, and sliding average processing is performed on the plurality of filtered light signal waveforms of the asymmetric cryptographic algorithm to obtain a first light signal waveform; if the type of the cryptographic algorithm is a symmetric cryptographic algorithm, filtering processing is performed on the light signal waveform first to remove harmonics of a power system thereof; a plurality of filtered light signal waveforms of the symmetric cryptographic algorithm are acquired, and low-pass filtering processing is performed on the plurality of filtered light signal waveforms of the asymmetric cryptographic algorithm first, and then longitudinal alignment processing is performed on the light signal waveforms after the low-pass filtering processing to obtain a second light signal waveform; The recovery module is configured to obtain a key of the cryptographic algorithm running on the cryptographic device by using a dimension reduction clustering method or a correlation energy analysis method according to the type of the cryptographic algorithm. The first light signal waveform is recovered by using the dimension reduction clustering method to obtain the key of the cryptographic algorithm running on the cryptographic device. The second light signal waveform is recovered by using the correlation energy analysis method to obtain the key of the cryptographic algorithm running on the cryptographic device. The recovery of the first light signal waveform by using the dimension reduction clustering method to obtain the key of the cryptographic algorithm running on the cryptographic device comprises: the first light signal waveform is first mapped to a low-dimensional space by using a principal component analysis dimension reduction method through linear transformation to obtain dimension-reduced data; the dimension-reduced data is clustered by using a hierarchical clustering method through calculation of similarity between any two clusters to constantly merge the most similar clusters, and finally the key of the cryptographic algorithm running on the cryptographic device is obtained. The recovery of the second light signal waveform by using the correlation energy analysis method to obtain the key of the cryptographic algorithm running on the cryptographic device comprises: for an encryption algorithm to be analyzed, different candidate key values are assumed, and an expected energy consumption model of an intermediate value of a cryptographic algorithm is generated according to each numerical value in the candidate key values and an input value of the second light signal waveform, the expected energy consumption model being used to assume that energy consumption is proportional to a weight of a bit number occupied by the intermediate value; correlation between the generated expected energy consumption model and the second light signal waveform is analyzed, and a candidate key value corresponding to an expected energy consumption model with the highest correlation is selected as the key of the cryptographic algorithm running on the cryptographic device.

4. A storage medium, characterized by The storage medium stores a computer program, and the computer program is executed by the host controller to implement each step in the light signal-based illumination side channel analysis method according to any one of claims 1-2.

Citation Information

Patent Citations

  • Public key cryptographic algorithm side channel analysis method and device and related equipment

    CN115065481A

  • Cryptographic algorithm artificial intelligence side channel analysis method based on dimension reduction and clustering

    CN117579244A