A security assessment method and computer device for parallel implementation of mask circuits

By calculating the electromagnetic leakage information and differential energy attack parameters of the parallel implementation of the mask circuit and evaluating its success rate under single-variable high-order differential energy attack, the problems of security change and increase in measurement times in the security assessment of the parallel implementation of the mask circuit are solved, and efficient security assessment is achieved.

CN119583035BActive Publication Date: 2025-09-30WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411571325.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-06
Publication Date
2025-09-30
Estimated Expiration
2044-11-06

AI Technical Summary

Technical Problem

Existing parallel implementations of mask circuits suffer from security changes and exponential growth in the number of measurements during security assessment, making it difficult to effectively evaluate their ability to resist side-channel attacks.

Method used

By obtaining the electromagnetic leakage information and differential energy attack parameters of each share in the parallelized mask circuit, calculating the cryptographic algorithm-related parameters and signal-to-noise ratio, and evaluating the success rate of recovering the correct key under a single-variable high-order differential energy attack, the number of measurements is reduced to improve the efficiency of security assessment.

Benefits of technology

It achieves a fast and accurate evaluation of the security of the parallelization of mask circuits, reduces the number of evaluation measurements required by the evaluation organization, and improves the efficiency of security evaluation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583035B_ABST
    Figure CN119583035B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of security assessment of cryptographic algorithms. To address the issue of how to assess the security of a parallel implementation of a mask circuit and reduce the number of security assessment measurements, a security assessment method, computer equipment, computer-readable storage medium, and computer program product for a parallel implementation of a mask circuit are disclosed. The method comprises obtaining electromagnetic leakage information and differential energy attack parameters for each share in a mask circuit implemented using parallelization; calculating the signal-to-noise ratio of each leaked share based on the electromagnetic leakage information of each share; calculating the success rate of recovering the correct key under a single-variable high-order differential energy attack based on cryptographic algorithm-related parameters, the signal-to-noise ratio of each leaked share, and the differential energy attack parameters, when the signal-to-noise ratio satisfies a stability condition; and evaluating the security of the mask circuit implemented using parallelization based on the success rate. This method can quickly and accurately calculate the success rate, reducing the number of measurements required for security assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of security assessment of cryptographic algorithms, and more specifically, to a security assessment method for parallel implementation of mask circuits, a computer device, a computer-readable storage medium, and a computer program product. Background Art

[0002] Masking circuits are a common form of side-channel security protection for cryptographic algorithms. They prevent information leakage in energy channels by splitting the secret information related to the key in the algorithm into multiple independent shares according to specific and secure rules and distributing them to multiple sub-circuits.

[0003] When implementing mask circuits, engineers usually take some optimization measures for performance reasons, such as parallelizing sub-circuits. This will cause the power consumption or electromagnetic leakage generated when multiple shares of secret information are processed by different sub-circuits to appear in a similar or identical period of time.

[0004] For the parallel implementation of mask circuits, the existing security assessment methods have the following main defects: First, after the mask circuit is parallelized, the multivariate leakage that should be separated in the time domain degenerates into a single variable leakage with overlapping time domain, which changes the security of the protection and therefore the security assessment method; Second, as the mask order increases, the number of measurements for security assessment increases exponentially, which increases the requirements for the measurement capabilities of the assessment organization. Summary of the Invention

[0005] In order to solve the problem of how to evaluate the security of the parallel implementation of mask circuits and reduce the number of security assessment measurements, the present invention provides a security assessment method, computer equipment, computer-readable storage medium and computer program product for the parallel implementation of mask circuits, which will reduce the number of measurements of the parallelized mask circuits used in the assessment by the assessment organization and improve the efficiency of security assessment.

[0006] To achieve the above object, according to a first aspect of the present invention, a security assessment method for parallel implementation of mask circuits is provided, the method comprising:

[0007] Obtain electromagnetic leakage information and differential energy attack parameters for each share in the mask circuit implemented using parallelization. The differential energy attack parameters include intermediate variables, order, and the number of energy traces used for the attack. The intermediate variables include intermediate variables corresponding to the correct key and several intermediate variables corresponding to incorrect keys.

[0008] Calculating cryptographic algorithm-related parameters based on the intermediate variable corresponding to the correct key and the intermediate variable corresponding to each incorrect key, the cryptographic algorithm-related parameters including a confusion vector, a first confusion matrix, and a second confusion matrix;

[0009] Calculate the signal-to-noise ratio of each share of electromagnetic leakage information based on each share;

[0010] Under the condition that the signal-to-noise ratio of each leaked share meets the stability condition, the success rate of recovering the correct key under the single variable high-order differential energy attack is calculated based on the relevant parameters of the cryptographic algorithm, the signal-to-noise ratio of each leaked share, and the differential energy attack parameters;

[0011] The security of the mask circuit implemented using parallelization is evaluated based on the success rate.

[0012] Furthermore, when the signal-to-noise ratio of each leaked share meets the stability condition, the success rate of recovering the correct key under the single-variable high-order differential energy attack is calculated based on the cryptographic algorithm-related parameters, the signal-to-noise ratio of each leaked share and the differential energy attack parameters, including calculating the leakage-related parameters of the mask circuit in parallel based on the signal-to-noise ratio and order of each leaked share when the signal-to-noise ratio of each leaked share meets the stability condition, and the leakage-related parameters of the mask circuit in parallel include the first scalar, the second scalar and the third scalar; and calculating the success rate of recovering the correct key under the single-variable high-order differential energy attack based on the cryptographic algorithm-related parameters, the leakage-related parameters of the mask circuit in parallel and the differential energy attack parameters.

[0013] Furthermore, based on the cryptographic algorithm-related parameters, the mask circuit parallel implementation leakage-related parameters, and the differential energy attack parameters, the success rate of recovering the correct key under the single-variable high-order differential energy attack is calculated. This includes substituting the cryptographic algorithm-related parameters, the mask circuit parallel implementation leakage-related parameters, and the number of energy traces used for the attack into the following formula based on the parity of the order to calculate the success rate of recovering the correct key under the single-variable high-order differential energy attack:

[0014]

[0015] Among them, k is the confusion vector, is the first confusion matrix, is the second confusion matrix, a1 is the first scalar, b1 is the second scalar, b2 is the third scalar, d is the order, N is the number of energy traces used for attack, is the size of κ, function for Cumulative function of the dimensional Gaussian distribution.

[0016] Furthermore, cryptographic algorithm-related parameters are calculated based on the intermediate variables corresponding to the correct key and the intermediate variables corresponding to each incorrect key. The cryptographic algorithm-related parameters include a confusion vector, a first confusion matrix, and a second confusion matrix, including:

[0017]

[0018] Among them, κ i is the i-th element in the confusion vector, is the element in row i and column j of the first confusion matrix, is the element in row i and column j of the second confusion matrix, is the intermediate variable corresponding to the correct key, is the intermediate variable corresponding to the i-th error key.

[0019] Furthermore, the electromagnetic leakage information includes energy consumption for generating signals and noise. Based on the electromagnetic leakage information of each share, the signal-to-noise ratio of each share leakage is calculated, including calculating the ratio of the signal standard deviation to the noise standard deviation of each share to obtain the signal-to-noise ratio of each share leakage.

[0020] Furthermore, according to the signal-to-noise ratio and order of each share leakage, a leakage-related parameter of the mask circuit is calculated. The leakage-related parameter of the mask circuit includes a first scalar, a second scalar, and a third scalar, including:

[0021]

[0022]

[0023] Among them, a1 is the first scalar, b1 is the second scalar, b2 is the third scalar, δ i is the signal-to-noise ratio of each share leakage, and d is the order.

[0024] Furthermore, the security assessment method implemented in parallel by the mask circuits further includes determining that the signal-to-noise ratio of each leaked share meets a stability condition when the signal-to-noise ratio of each leaked share is within a preset range.

[0025] According to a second aspect of the present invention, a computer device is provided, which includes a memory, a processor, and a computer program stored in the memory, and the processor executes the computer program to implement the steps of any one of the above methods.

[0026] According to a third aspect of the present invention, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above methods are implemented.

[0027] According to a fourth aspect of the present invention, there is also provided a computer program product, comprising a computer program, which implements the steps of any one of the above methods when executed by a processor.

[0028] In general, the above technical solutions conceived by the present invention can achieve the following beneficial effects compared with the prior art:

[0029] The present invention provides a security assessment method for a parallel implementation of a mask circuit. For a mask circuit implemented in parallel, the method first obtains electromagnetic leakage information and differential energy attack parameters of each share, then calculates cryptographic algorithm-related parameters based on intermediate variables corresponding to the correct key and intermediate variables corresponding to each incorrect key, and calculates the signal-to-noise ratio of each share leakage based on the electromagnetic leakage information of each share; finally, when the signal-to-noise ratio of each share leakage meets a stability condition, the method calculates the success rate of recovering the correct key under a single-variable high-order differential energy attack based on cryptographic algorithm-related parameters, the signal-to-noise ratio of each share leakage, and the differential energy attack parameters, and evaluates the security of the mask circuit implemented in parallel based on the success rate, thereby achieving the purpose of evaluating the ability of the cryptographic module implemented in parallel to resist side channel attacks; and, based on the cryptographic algorithm-related parameters, the signal-to-noise ratio of each share leakage, and the differential energy attack parameters, the method can quickly and accurately calculate the success rate, and can also achieve the purpose of reducing the number of measurements required by the evaluation organization in evaluating the mask circuit implemented in parallel, thereby improving the efficiency of security assessment. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0031] Figure 1 A flowchart of a security assessment method for parallel implementation of mask circuits provided in one embodiment of the present application;

[0032] Figure 2A Schematic diagram of the key recovery attack effect of the original mask circuit provided in an embodiment of the present application;

[0033] Figure 2B A schematic diagram of the key recovery attack effect of the mask circuit implemented in parallel provided in an embodiment of the present application;

[0034] Figure 3 A flowchart of a security assessment method for parallel implementation of mask circuits provided in another embodiment of the present application;

[0035] Figure 4 A schematic diagram of the internal structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0036] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the present invention and are not intended to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below may be combined with each other as long as they do not conflict with each other.

[0037] The terms "first," "second," "third," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish between different objects, not to describe a particular order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements, but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.

[0038] like Figure 1 As shown, a security assessment method for parallel implementation of mask circuits is provided. This method can be executed by a terminal or a server communicating with the terminal via a network. The terminal may be, but is not limited to, various personal computers, laptops, smartphones, tablet computers, etc. The server may be a standalone server or a server cluster consisting of multiple servers. This method is illustrated using the terminal as an example and includes the following steps:

[0039] Step 101: Obtain electromagnetic leakage information and differential energy attack parameters of each share in the mask circuit implemented by parallelization. The differential energy attack parameters include intermediate variables, orders, and the number of energy traces used for attack. The intermediate variables include intermediate variables corresponding to the correct key and intermediate variables corresponding to several incorrect keys.

[0040] The electromagnetic leakage information of each share in the mask circuit implemented by parallelization can be measured by an oscilloscope.

[0041] Step 102: Calculate cryptographic algorithm-related parameters based on the intermediate variable corresponding to the correct key and the intermediate variable corresponding to each incorrect key. The cryptographic algorithm-related parameters include a confusion vector, a first confusion matrix, and a second confusion matrix.

[0042] Step 103: Calculate the signal-to-noise ratio of each share of leakage based on the electromagnetic leakage information of each share.

[0043] In step 104, when the signal-to-noise ratio of each leaked share meets the stability condition, the success rate of recovering the correct key under the single variable high-order differential energy attack is calculated based on the relevant parameters of the cryptographic algorithm, the signal-to-noise ratio of each leaked share and the differential energy attack parameters.

[0044] In one embodiment, when the signal-to-noise ratio of each leaked share is within a preset range, it is determined that the signal-to-noise ratio of each leaked share meets the stability condition.

[0045] Exemplarily, when the signal-to-noise ratio of each share leakage meets the stability condition, the terminal calculates the leakage-related parameters of the mask circuit in parallel according to the signal-to-noise ratio and order of each share leakage, and the leakage-related parameters of the mask circuit in parallel include a first scalar, a second scalar and a third scalar; according to the cryptographic algorithm-related parameters, the leakage-related parameters of the mask circuit in parallel and the differential energy attack parameters, the terminal calculates the success rate of recovering the correct key under the single-variable high-order differential energy attack.

[0046] Step 105 : Evaluate the security of the mask circuit implemented in parallel based on the success rate.

[0047] In the security assessment method for the parallel implementation of the above-mentioned mask circuit, the security of the mask circuit implemented in parallel is evaluated by calculating the success rate, which can achieve the purpose of evaluating the ability of the cryptographic module implemented in parallel to resist side channel attacks; and, based on the relevant parameters of the cryptographic algorithm, the signal-to-noise ratio of each share leakage and the differential energy attack parameters, the success rate can be calculated quickly and accurately, and the purpose of reducing the number of measurements of the mask circuit implemented in parallel by the evaluation organization can be achieved.

[0048] The following introduces the theoretical basis involved in the security assessment method for parallel implementation of a mask circuit provided in this embodiment.

[0049] Side channel attacks include differential energy attacks and high-order differential energy attacks.

[0050] Differential energy attacks can be divided into single-bit and multi-bit attacks. In a single-bit differential energy attack, the attacker exploits the leakage of a single-bit intermediate variable v. v Distinguish v=0 and v=1, corresponding to the two groups of leaked sizes, and recover the correct key s c .make Indicates that the attacker has access to the key s c guess, x represents the plaintext and ciphertext message disclosed to the attacker during the execution of the cipher implementation. Indicates and x are sent to the cryptographic algorithm and are generated in a certain link. For example, a bit of the AES algorithm S-box output SBOX(x,s). In the single variable leakage scenario, the single-bit differential energy attack uses the following distinguisher to calculate all Difference Select the one with the largest difference (or absolute value of difference) As

[0051] High-order differential energy attacks use a simultaneous function to map the leakage of multiple shares after splitting into a single variable leakage that is easy to analyze, and then perform a differentiation operation on the mapped leakage set to recover the key. The simultaneous function is defined as follows:

[0052]

[0053] in, is the time point τ on the energy trace L j Power consumption value at a given moment.

[0054] When multiple τ j When pointing to the same time τ, the energy attack that distinguishes on the leaked set after mapping is called a univariate high-order differential energy attack. The simultaneous function is defined as follows:

[0055]

[0056] In the energy analysis attack, the energy leakage model is used to leak the intermediate variable v v Described as signal-dependent variable h v With Gaussian variable n v A linear combination of:

[0057] l v =h v +n v or l v =h v +n.

[0058] When the mask circuit is implemented in parallel, the multivariate leakage that should be separated in time domain degenerates into single variable leakage with overlapping time domain. A degradation function ψ can be used to describe the leakage between different shares after degradation. The superposition effect of these leaks is different with different superposition coefficients ε i Acting on the final leak, recorded as:

[0059]

[0060] The success rate is a commonly used security indicator for evaluating cryptographic algorithms. The higher the success rate, the weaker the cryptographic algorithm's ability to resist side channel attacks. For the success rate indicator, in differential energy attacks, the traditional method of calculating the success rate indicator is through statistical methods, that is, the discriminator is calculated based on all Difference Sort the candidate keys by their size and the position of the correct key in the sorted result This is called key ranking. Based on the key ranking, we can conduct attacks through multiple measurements and statistically calculate the probability of correctly recovering the key under differential energy attacks, i.e., the success rate:

[0061]

[0062] Figure 2A and Figure 2B The comparison chart of the key recovery attack effect before and after the mask circuit is implemented in parallel is shown in Figure 2. Figure 2A Schematic diagram of the key recovery attack effect of the original mask circuit. Figure 2B This is a schematic diagram of the key recovery attack effect of the mask circuit implemented in parallel. In the figure, the black / gray curves represent the guess scores (correlation coefficients) of the correct / wrong keys at different times. Figure 2A The score of the correct key in is hidden in the wrong key, Figure 2B The score of the correct key is significantly higher than that of the incorrect key, so the mask protection effect of the mask circuit may be destroyed after parallelization.

[0063] In one embodiment, the protection effect changes after the mask circuit is implemented in parallel, and the number of security assessment measurements increases exponentially with the number of mask protection levels. Figure 3 As shown in the figure, a security assessment method for parallel implementation of mask circuits is provided. Based on the linear superposition and Gaussian distribution characteristics of energy leakage in parallel implementation, a mathematical expression for the success rate of parallel implementation of mask circuits under single-variable high-order differential energy attacks is constructed. The specific process is as follows:

[0064] Step 1: Input the algorithm design scheme (e.g. A+B=C, where A represents plaintext, B represents key, and C represents intermediate value, i.e. encrypted plaintext). Select the intermediate variable v (e.g., S-box of AES algorithm) and calculate the algorithm design related parameters (i.e., cryptographic algorithm related parameters), including confusion vector κ, first confusion matrix Second confusion matrix

[0065] make Indicates the correct key s c The corresponding intermediate variable, Indicates the i-th wrong key The corresponding intermediate variable, the i-th element κ in the confusion vector κ i , the first confusion matrix and the second confusion matrix The i-th row and j-th column (1≤i,j≤2 n -1) and The calculation formula is as follows:

[0066]

[0067] Among them, the size of the confusion vector κ is 1*(2 n -1), the first confusion matrix and the second confusion matrix The size of both is (2 n -1)*(2 n -1), n ​​is the number of bits of the key B, for example, if n is 8 bits, then the size of the confusion vector κ is 1*255, the first confusion matrix and the second confusion matrix The size is 255*255.

[0068] Step 2: Input the algorithm (e.g. A+D=C1, BD=C2, and the two algorithms can be operated in parallel, i.e., electromagnetic information of C1 and C2 can be collected at the same time, where A represents plaintext, B represents key, D represents random value, and C1 and C2 represent intermediate values) to realize the leakage L and estimate the signal-to-noise ratio δ of each share leakage. i (Signal standard deviation ε i and the noise standard deviation σ).

[0069] Step 3: Determine the signal-to-noise ratio δ i Check whether the estimated value of has stabilized. If not, return to step 2 and increase the input leakage; if stable, execute step 4.

[0070] In step 4, input the univariate high-order differential energy attack parameters, including the order d and the number of energy traces N used for the attack.

[0071] Step 5: Based on the signal-to-noise ratio δ of each share i The leakage-related parameters are calculated and realized by the order d (ie, the mask circuit realizes the leakage-related parameters in parallel), including the first scalar a1, the second scalar b1 and the third scalar b2. Let ζ i Taking values ​​in the range {0, 2, …, 2d} determined by the order d, the calculation formulas for the first scalar a1, the second scalar b1, and the third scalar b2 are as follows:

[0072]

[0073]

[0074] Substitute the input attack parameters, calculated algorithm design parameters, and leakage-related parameters into the following formula to calculate the success rate:

[0075]

[0076] in, is the size of the confusion vector κ, the function for Cumulative function of the dimensional Gaussian distribution.

[0077] This embodiment provides a security assessment method suitable for parallel implementation of mask circuits with low data and computational complexity. Furthermore, by constructing a mathematical expression for the success rate metric, this method not only reduces the number of measurements required for security assessment but also quantifies the security of parallel implementation of mask circuits under different algorithm design parameters and physical leakage characteristics. For example, when the intermediate variables are fixed, security assessments can be performed under different differential energy attack parameters by adjusting the order or the number of energy traces used for the attack.

[0078] The present application also provides a computer device, the internal structure of which can be as follows: Figure 4 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected via a system bus, and the communication interface, the display unit and the input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a security assessment method for parallel implementation of a mask circuit is implemented.

[0079] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0080] like Figure 4As shown, the present application also provides a computer device, which includes a memory, a processor and a computer program stored in the memory, and the processor executes the computer program to implement the steps in the above-mentioned method embodiments.

[0081] The present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-mentioned method embodiments. The computer-readable storage medium may include, but is not limited to, any type of disk, including a floppy disk, an optical disk, a DVD, a CD-ROM, a microdrive, a magneto-optical disk, a ROM, a RAM, an EPROM, an EEPROM, a DRAM, a VRAM, a flash memory device, a magnetic card or an optical card, a nanosystem (including a molecular memory IC), or any type of medium or device suitable for storing instructions and / or data.

[0082] The present application also provides a computer program product, including a computer program, which implements the steps in the above-mentioned method embodiments when executed by a processor.

[0083] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.

[0084] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0085] The above description is merely an exemplary embodiment of the present disclosure and is not intended to limit the scope of the present disclosure. That is, any equivalent changes and modifications made in accordance with the teachings of the present disclosure are still within the scope of the present disclosure. After considering the specification and practicing the disclosure herein, those skilled in the art will easily think of the implementation scheme of the present disclosure. This application is intended to cover any variations, uses or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common knowledge or customary technical means in the art that are not recorded in the present disclosure. The description and examples are to be regarded as exemplary only, and the scope and spirit of the present disclosure are defined by the claims.

[0086] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0087] It will be easily understood by those skilled in the art that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A security assessment method for parallel implementation of mask circuits, characterized in that: include: Obtaining electromagnetic leakage information and differential energy attack parameters for each share in a mask circuit implemented using parallelization. The differential energy attack parameters include intermediate variables, orders, and the number of energy traces used for the attack. The intermediate variables include intermediate variables corresponding to the correct key and several intermediate variables corresponding to incorrect keys. Calculating cryptographic algorithm-related parameters based on the intermediate variable corresponding to the correct key and the intermediate variable corresponding to each incorrect key, the cryptographic algorithm-related parameters including a confusion vector, a first confusion matrix, and a second confusion matrix; Calculating the signal-to-noise ratio of each share of leakage according to the electromagnetic leakage information of each share; When the signal-to-noise ratio of each leaked share meets a stability condition, calculate the success rate of recovering the correct key under a single variable high-order differential energy attack based on the cryptographic algorithm-related parameters, the signal-to-noise ratio of each leaked share, and the differential energy attack parameters; The security of the mask circuit implemented by parallelization is evaluated according to the success rate.

2. The method according to claim 1, wherein The method comprises calculating the success rate of recovering the correct key under a single variable high-order differential energy attack based on the cryptographic algorithm-related parameters, the signal-to-noise ratio of each leaked share, and the differential energy attack parameters, when the signal-to-noise ratio of each leaked share meets the stability condition, including: When the signal-to-noise ratio of each leaked share satisfies a stability condition, calculating, according to the signal-to-noise ratio of each leaked share and the order, leakage-related parameters of the mask circuit parallel implementation, the mask circuit parallel implementation leakage-related parameters including a first scalar, a second scalar, and a third scalar; According to the cryptographic algorithm related parameters, the mask circuit parallel implementation leakage related parameters and the differential energy attack parameters, the success rate of recovering the correct key under the single variable high-order differential energy attack is calculated.

3. The method according to claim 2, wherein The step of calculating the success rate of recovering the correct key under a single variable high-order differential energy attack based on the cryptographic algorithm-related parameters, the mask circuit parallel implementation leakage-related parameters, and the differential energy attack parameters includes: According to the parity of the order, the cryptographic algorithm parameters, the mask circuit parallel implementation leakage parameters, and the number of energy traces used for the attack are substituted into the following formula to calculate the success rate of recovering the correct key under a single variable high-order differential energy attack: Among them, k is the confusion vector, is the first confusion matrix, is the second confusion matrix, a1 is the first scalar, b1 is the second scalar, b2 is the third scalar, d is the order, N is the number of energy traces used for attack, is the size of k, function for Cumulative function of the dimensional Gaussian distribution.

4. The method according to claim 1, wherein The cryptographic algorithm-related parameters are calculated based on the intermediate variables corresponding to the correct key and the intermediate variables corresponding to each incorrect key, wherein the cryptographic algorithm-related parameters include a confusion vector, a first confusion matrix, and a second confusion matrix, including: Among them, κ i is the i-th element in the confusion vector, is the element in row i and column j of the first confusion matrix, is the element in row i and column j of the second confusion matrix, is the intermediate variable corresponding to the correct key, is the intermediate variable corresponding to the i-th error key.

5. The method according to claim 1, wherein The electromagnetic leakage information includes energy consumption for generating signals and noises, and calculating the signal-to-noise ratio of each leakage share according to the electromagnetic leakage information of each share includes: The ratio of the signal standard deviation to the noise standard deviation of each share is calculated to obtain the signal-to-noise ratio of each share leakage.

6. The method according to claim 2, wherein The calculating of leakage-related parameters implemented in parallel by the mask circuit according to the signal-to-noise ratio of each share leakage and the order, wherein the leakage-related parameters implemented in parallel by the mask circuit include a first scalar, a second scalar, and a third scalar, includes: Among them, a1 is the first scalar, b1 is the second scalar, b2 is the third scalar, δ i is the signal-to-noise ratio of each share leakage, and d is the order.

7. The method according to claim 1, wherein The method further comprises: When the signal-to-noise ratio of each leaked share is within a preset range, it is determined that the signal-to-noise ratio of each leaked share meets a stability condition.

8. A computer device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method according to any one of claims 1 to 7.

9. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer program product, characterized in that The invention comprises a computer program, which implements the steps of the method according to any one of claims 1 to 7 when the computer program is executed by a processor.

Citation Information

Patent Citations

  • Cryptographic algorithm realization protecting method used for defending energy analysis attacks

    CN102571331A

  • Side channel energy analysis method and system of cryptographic algorithm mask circuit

    CN117978353A