A Method for Analyzing Dilithium Fast Side-Channel Attacks, Electronic Device, and Medium

Through the Gaussian mixed difference method and signature information classification, the time overhead problem of small sample leakage in Dilithium side channel attack is solved, and the effect of quickly recovering the private key under high noise is achieved. It is suitable for the security detection of Dilithium cipher equipment of the ARM platform.

CN119652565BActive Publication Date: 2025-07-29NANJING UNIV OF SCI & TECH +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411647216.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2025-07-29
Estimated Expiration
2044-11-18

Smart Images

  • Figure CN119652565B_ABST
    Figure CN119652565B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for rapid side-channel attack analysis of Dilithium, belonging to the technical field of information security. The Gaussian mixture difference method is used to detect leakage, and the detection and selection of feature points are completed; the signature information is used to classify the actual leakage involving the private key, and the difference in distribution is used to recover the private key in the normal domain. The present invention solves the problem of large time overhead in existing non-template attacks under small-sample leakage. Using the side information leakage generated by a small number of signatures, the complete private key can be recovered within a few minutes under a high noise level. Compared with existing leakage detection methods, the Gaussian mixture difference method can complete the detection and selection of feature points without obtaining sensitive intermediate values. The present invention can be used to detect whether the cryptographic device and cryptographic chip are safe and reliable, such as in the fields of bank cards in financial economy, digital currency physical cards, and mobile phone chips in mobile communication, to detect whether there are security risks in the device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a method for analyzing Dilithium against side-channel attacks quickly. Background Art

[0002] In recent years, quantum computers have developed rapidly. Once a general-purpose quantum computer is successfully developed, traditional public-key cryptography algorithms constructed based on difficult problems such as large integer factorization and discrete logarithm may be cracked within polynomial time using the quantum algorithms proposed in 1994, and the widely deployed cryptographic systems will face great risks.

[0003] To address the challenges of the quantum computing era, the National Institute of Standards and Technology of the United States issued a global call for proposals for post-quantum public-key cryptography algorithm standards in December 2016. The first batch of PQC standard documents were announced in August 2024, including the signature standard algorithm DL-DSA (formerly CRYSTALS-Dilithium, hereinafter referred to as Dilithium), SLH-DSA (formerly SPHINCS+), and the key encapsulation standard algorithm ML-KEM (formerly CRYSTALS-Kyber). To ensure timely response to the threats brought by quantum computing, countries are accelerating the research and implementation of post-quantum cryptography.

[0004] Although post-quantum algorithms theoretically have the ability to resist attacks from traditional computers and quantum computers, during the algorithm implementation and actual deployment process, they will inevitably suffer from actual attacks. The most typical and common type of actual attack is side-channel analysis. Side-channel analysis directly or indirectly obtains the secret information during the chip operation by using various forms of information leakage that will be actively or passively generated during the operation of cryptographic devices and platforms, combined with cryptography and statistical knowledge.

[0005] The cryptographic community and the chip industry have long reached a broad consensus on the significant practical threat posed by side-channel attacks to the security of cryptographic implementations, and have proposed specific security requirements and recommended evaluation processes. For example, the "Security Chip Cryptography Detection Criteria" GM / T 0008-2012 and the "Security Technical Requirements for Cryptographic Modules" GM / T 0028-2014 promulgated in China clearly stipulate that cryptographic modules must have the security protection ability to resist typical side-channel attacks (including power analysis attacks, electromagnetic analysis attacks, and timing attacks, etc.).

[0006] Therefore, studying the side-channel analysis resistance of the first batch of standard post-quantum signature algorithm Dilithium is of great significance to the actual security of public-key cryptography systems in the post-quantum era, and promotes the development and application of post-quantum cryptography technologies. Summary of the Invention

[0007] Technical problems to be solved by the present invention: Provide a method for analyzing Dilithium fast side-channel attacks against the ARM platform, which can generate side information leakage with a small number of signatures and recover the complete private key within minutes under a high noise level; it can complete the detection and selection of feature points without obtaining sensitive intermediate values, and can be used to detect whether the cryptographic device and cryptographic chip are secure and reliable.

[0008] Technical solution: To solve the above technical problems, the technical solution adopted by the present invention is as follows:

[0009] A method for analyzing Dilithium fast side-channel attacks uses the Gaussian mixture difference method to detect the leakage, complete the detection and selection of feature points; classify the actual leakage involving the private key using the signature information, and use the difference in distribution to recover the private key in the normal domain. Specifically, it includes the following steps:

[0010] S1: Collect the power consumption curves of the cryptographic device platform running Dilithium and obtain the corresponding signature information ;

[0011] S2: Align and segment the power consumption curves using static alignment for subsequent analysis;

[0012] S3: Use the Gaussian mixture model difference method to detect feature points on the power consumption curves, and determine and the feature points available for side-channel analysis;

[0013] S4: For recovering the th private key coefficient , classify the side information leakage of the feature points according to whether the th coefficient in the signature information is 1 or -1, and calculate and record the difference between the non-negative numbers and negative numbers of the two types of data after classification as the corresponding result;

[0014] S5: Loop and execute step S4 until all private keys , have their coefficient results;

[0015] S6: Use the Gaussian mixture model to classify the coefficient results of the private keys , , give the specific numerical value of each coefficient, and finally complete the recovery of the complete private key.

[0016] Furthermore, in step S3, after obtaining the complete leakage information, use the Gaussian mixture model to fit the data, split the overall distribution into two Gaussian distributions, and calculate the expected values corresponding to the two Gaussian distributions.

[0017] Further, The overall energy leakage model is:

[0018]

[0019] in, and Respectively is the total leakage distribution of non-negative and negative numbers, Represents a numerical value The corresponding leakage model, For different The probability of occurrence is a fixed coefficient

[0020] Furthermore, in step S4, the classification of feature points includes the following three types:

[0021] when When , the linear combination is ;

[0022] when When , the linear combination is ;

[0023] when When , the linear combination is .

[0024] Furthermore, the distribution of the three groups of data is calculated based on the classification of the feature points:

[0025] ;

[0026] Where N represents Gaussian distribution, Indicates the private key coefficients;

[0027] Energy leakage can take the following forms:

[0028] ;

[0029] Among them, i represents the i-th coefficient of the private key and signature c, and x represents and Possible value range, P(xc i s i )express and The probability of each possible value of the coefficient outcome.

[0030] Furthermore, record , The difference in the number of samples within the interval is used , Restore based on the difference in the number of samples within the interval ; First, calculate Within the interval and The difference in the number of samples, denoted as Δ ni ; Then calculate Within the interval and The difference in the number of samples is denoted as Δ pi ; Finally, record as The corresponding total difference in the number of samples.

[0031] Furthermore, after obtaining all Use the Gaussian mixture model to complete Classification; Through the expectation-maximization algorithm, iteratively estimate the expectation, variance, and weight of each Gaussian distribution to find the optimal parameters.

[0032] Beneficial effects: Compared with the prior art, the present invention has the following advantages:

[0033] (1) By using the signature information c of Dilithium, the present invention classifies the actual leakage of the private key involved in and and uses the difference in distribution to recover the Dilithium normal domain private key, solving the problem of large time overhead in the case of small sample leakage in existing non-template attacks. The side information leakage generated by using a small number of signatures can recover the complete Dilithium private key within a few minutes at a high noise level.

[0034] (2) In the actual side-channel analysis process, the attacker needs to determine the accurate leakage location of the target data. The present invention proposes a Gaussian mixture difference method for detecting the leakage of cs. Compared with the existing leakage detection methods, it can complete the detection and selection of feature points without obtaining sensitive intermediate values.

[0035] (3) By using the signature information c of Dilithium, the present invention classifies the actual leakage of the private key involved in and and uses the difference in distribution to quickly judge the private key. Compared with the common non-template side-channel analysis that judges the correct private key by enumerating all candidate values, the present invention does not need to enumerate all candidate values.

[0036] (4) The present invention can still use a small amount of leakage to complete fast private key recovery under a high noise level of the collected side information leakage. By combining multiple feature points, the present invention is still effective under a high noise level and can be applied to actual attacks on the ARM platform in different actual fields.

[0037] (5) The present invention can be used to analyze a cryptographic device deploying the Dilithium algorithm to detect whether the cryptographic device is secure and reliable. Specifically, it can be applied to the reliability detection of cryptographic chips, such as in the fields of bank cards in financial economy, digital currency physical cards, and mobile phone chips in mobile communication, to detect whether there are security risks in the device.

[0038] (6) The Dilithium fast side-channel attack analysis method of the present invention focuses on the actual side-channel analysis of Dilithium and provides suggestions for the secure deployment of post-quantum cryptography. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 is the overall flowchart of the method of the present invention;

[0040] Figure 2 is a partial power consumption curve graph collected by the present invention;

[0041] Figure 3 is the comparison graph of feature point detection by the Gaussian mixture model difference method of the present invention;

[0042] Figure 4 is the present invention in the case of, according to the distribution graph after classifying the power consumption curve;

[0043] Figure 5 is the present invention in the case of, according to the distribution graph after classifying the power consumption curve;

[0044] Figure 6 is the present invention in the case of, according to the distribution graph after classifying the power consumption curve;

[0045] Figure 7 is the present invention in the case of, according to the distribution graph after classifying the power consumption curve;

[0046] Figure 8 is the present invention in the case of, according to the distribution graph after classifying the power consumption curve. DETAILED DESCRIPTION OF THE INVENTION

[0047] The present invention will be further clarified below in conjunction with specific embodiments. The embodiments are implemented on the premise of the technical solution of the present invention. It should be understood that these embodiments are only used to illustrate the present invention and not to limit the scope of the present invention.

[0048] Embodiment 1

[0049] AsFigure 1 As shown in the figure, this embodiment discloses a method for analyzing Dilithium's fast side-channel attacks implemented on the ARM platform. This method is a new type of non-template side-channel attack method. By using the signature information c of Dilithium, it classifies the actual leakage involved in the private key and uses the difference in distribution to recover the normal domain private key of Dilithium, solving the problem of large time overhead in existing non-template attacks under small sample leakage. Using the side information leakage generated by a small number of signatures, the complete private key of Dilithium can be recovered within a few minutes under a high noise level. Specifically, it includes the following steps: and As shown in the figure, this embodiment discloses a method for analyzing Dilithium's fast side-channel attacks implemented on the ARM platform. This method is a new type of non-template side-channel attack method. By using the signature information c of Dilithium, it classifies the actual leakage involved in the private key and uses the difference in distribution to recover the normal domain private key of Dilithium, solving the problem of large time overhead in existing non-template attacks under small sample leakage. Using the side information leakage generated by a small number of signatures, the complete private key of Dilithium can be recovered within a few minutes under a high noise level. Specifically, it includes the following steps:

[0050] S1: Collect the power consumption curves of the password device platform running Dilithium and obtain the corresponding signature information c;

[0051] S2: Align and segment the power consumption curves using the generally recognized static alignment method in the side-channel field for subsequent analysis;

[0052] S3: Use the Gaussian mixture model difference method to detect the feature points of the power consumption curves and determine the feature points that can be used for side-channel analysis; and feature points that can be used for side-channel analysis;

[0053] S4: For recovering the i-th private key coefficient (vector contains multiple elements, and each element contains 256 polynomial coefficients), classify the side information leakage of the feature points according to whether the i-th coefficient in the signature information c is 1 or -1, and calculate the difference between the non-negative numbers and negative numbers of the two types of classified data and record it as the corresponding result; (vector , contains multiple elements, and each element contains 256 polynomial coefficients), classify the side information leakage of the feature points according to whether the i-th coefficient in the signature information c is 1 or -1, and calculate the difference between the non-negative numbers and negative numbers of the two types of classified data and record it as the corresponding result; corresponding result;

[0054] S5: Loop through step S4 until all the coefficients of the private key are obtained; , coefficient results;

[0055] S6: Use the Gaussian mixture model proposed in the present invention to classify the coefficient results of the private key and give the specific numerical value of each coefficient, and finally complete the recovery of the complete private key. , coefficient results of the private key and give the specific numerical value of each coefficient, and finally complete the recovery of the complete private key.

[0056] Embodiment 2

[0057] Based on Embodiment 1, this embodiment provides a more preferred implementation.

[0058] In step S1, the power consumption curve of the cryptographic device platform running Dilithium2 is collected, and the corresponding signature information c is obtained. In this embodiment, the Dilithium reference implementation is compiled and run on the ARM Cortex-M4 platform recommended by the National Institute of Standards and Technology of the United States, and the power consumption curves regarding and operations are collected by an oscilloscope, where and represent the signature c and the private key , the multiplication result in the finite field polynomial ring , which appears in the signature process of Dilithium.

[0059] Step S2: The power consumption curve is aligned and segmented in a way of static alignment recognized in the side-channel field for subsequent analysis;

[0060] In this embodiment, after the power consumption curves regarding and are collected, the power consumption curve is segmented using the static alignment method, that is, first a small part of the power consumption curve is selected, and then the Pearson correlation coefficient between this part of the power consumption curve and the power consumption curves at different time points is calculated. The time points with larger values within an interval are used as segmentation points, and finally the power consumption curve can be segmented, as shown in Figure 2 .

[0061] Step S3: The Gaussian mixture model difference method is used to detect the feature points of the power consumption curve to determine and the feature points available for side-channel analysis;

[0062] Among the 256 coefficients of the signature information c in Dilithium, only a few are 1 or -1, and the rest are 0. The value range of each coefficient of its private key also follows a uniform distribution on . Thus, the distribution of each coefficient in and can be calculated as a Gaussian distribution with the following parameters:

[0063]

[0064]

[0065] where E[cs] represents the expectation, cs represents the variable composed of the multiplication result of the signature c and the private key , in the finite field polynomial ring ; c i represents the i-th coefficient of the signature information c; s iDenote the \(i\)-th coefficient in the private key; \(Var[cs]\) represents the variance. Denote the number of non-zero elements in the signature information \(c\) in Dilithium, and \(\eta\) represents the value range of each coefficient of the private key in Dilithium.

[0066] While in the 32-bit ARM platform recommended by NIST, The related calculations and storage are all completed in the form of two's complement. Therefore, for different values at The energy leakage model can be expressed as:

[0067] ;

[0068] Among them, \(a\) t0 Denotes The proportionality coefficient at time, \(x\) represents The actual value of, \(b\) t0 Denotes The constant variable at time, \(\delta\) t0 Denotes The variance of the Gaussian noise at time, and \(HW\) represents the Hamming weight of the corresponding value.

[0069] Thus, the overall energy leakage model in the statistical sense can be obtained:

[0070]

[0071] Among them, And Respectively represent The overall leakage distributions of non-negative numbers (including 0 and positive numbers) and negative numbers. Since the leakage models Are all Gaussian distributions, Represents the probability of \(x\) appearing, is a fixed coefficient, and the linear combination of multiple Gaussian distributions still follows a Gaussian distribution. Therefore, And .

[0072] Therefore, after obtaining the complete leakage information, use the Gaussian mixture model to fit the data, split the overall distribution into 2 Gaussian distributions, and calculate the And The expectations corresponding to the distributions , . When Is larger, it indicates that the overlapping part of the distributions of And Is smaller. The method of the present invention is named the Gaussian mixture difference method.

[0073] In this embodiment, after the acquisition and segmentation of the power consumption curve, the Gaussian mixture model difference method of the present invention is used to determine the characteristic points. As Figure 3 shown, the calculation results using 1,000 samples are presented. The blue curve is the Gaussian mixture model difference method, and the red curve is under the Hamming weight model. and The Pearson correlation coefficients between the

[0074] values and the power consumption curve are common deterministic leakage detection methods in side-channel analysis. Figure 3 Analysis shows that the Gaussian mixture model difference method accurately detects the most significant part of the leakage, that is, the interval from sampling point 280 to 400. The Pearson correlation coefficient is very high in the interval from sampling point 400 to 500, but the Gaussian mixture model difference method detects a relatively small leakage level, indicating that there is significant leakage in this interval. However, after fitting, and the expected difference in distribution is small and there is an overlap, which is not conducive to subsequent analysis.

[0075] Step S4: For recovering the i-th private key coefficient , classify the side information leakage of the characteristic points according to whether the i-th coefficient in the signature information c is 1 or 0 or -1, and calculate and record the difference between the non-negative numbers and negative numbers of the two types of data after classification as the corresponding result.

[0076] Specifically:

[0077] When , the linear combination at this time is ;

[0078] When , the linear combination at this time is ;

[0079] When , the linear combination at this time is .

[0080] Obviously, the main difference among the three classifications is the constant offset regarding . By analogy with the previous derivation process, the distributions of the three groups of data are:

[0081] ;

[0082] where, N represents the Gaussian distribution, represents the i-th coefficient in the private key;

[0083] For energy leakage, it has the following form:

[0084] ;

[0085] Among them, i represents the i-th coefficient of the private key and the signature information c, and x represents and the possible value range, and P(x - c i s i ) represents and the probability that each coefficient result may take a value.

[0086] When , the amount of data will increase, the amount of data will decrease, and the change amount will also increase as the value increases. When , the opposite result will be obtained, which can help the attacker determine the value of.

[0087] Next, record , the difference in the number of samples in the interval. Use , the difference in the number of samples in the interval to recover .

[0088] First, calculate in the interval, and the difference in the number of samples, denoted as:

[0089]

[0090] Then, calculate in the interval, and the difference in the number of samples, denoted as:

[0091]

[0092] Finally, record as the corresponding total difference in the number of samples.

[0093] In this embodiment, the feature points with relatively significant leakage are shown (corresponding to Figure 3 Point Index = 316 in), in the case of after classifying the power consumption curves according to Figures 4 to 8 The power consumption distribution is as shown. The horizontal axis is the power consumption, i.e., the energy leakage, and the vertical axis is the number of samples with this energy leakage. It can be found that the actual leakage can be clearly divided into two parts. The left side represents the leakage of non-negative numbers, i.e., ; the right side represents the leakage of negative numbers, i.e., When as shown in the appendix Figure 4 there are clearly more samples in the classification of part and the sample size of part will be larger. When as shown in the appendix Figure 5 there are also more classifications in part but the gap with becomes smaller than when and part also has the same result. When as shown in the appendix Figure 6 the two distributions of are almost the same. When the results are as shown in the appendix Figure 7 8 respectively, and their distributions are exactly opposite to the negative number case.

[0094] S5: Loop and execute step S4 until all private keys , coefficient results are obtained;

[0095] In this embodiment, analogous to step S4, different are classified, and then all are obtained through an attack.

[0096] Through loop calculation, the private key , all coefficients obtain corresponding values. At a high noise level, the actual analysis can be completed under the condition of combining multiple noise points.

[0097] S6: Use the Gaussian mixture model to classify the coefficient results of the private key , give the specific values of each coefficient, and finally complete the recovery of the complete private key.

[0098] After all are obtained, use the Gaussian mixture model to complete classification. This method is a very mature probability-based clustering technique, based on the assumption that the data consists of a linear combination of multiple Gaussian distributions. Its basic principle is to use the expectation-maximization algorithm to iteratively estimate the expectation, variance, and weight of each Gaussian distribution to find the optimal parameters, which is very suitable for the clustering task in the scenario where the data has overlapping features in this attack.

[0099] The Gaussian Mixture Model (GMM) models the distribution of data through a weighted combination of multiple Gaussian distributions. Suppose there is a dataset containing N data points , and each data point is a D-dimensional vector . The parameters of the GMM model include the mixing coefficients of each Gaussian distribution (representing the weight of this distribution), the mean vector and the covariance matrix . The goal is to estimate these parameters by maximizing the log-likelihood function so that the model can optimally fit the data. Since the log-likelihood function is non-linear, the commonly used optimization method is the Expectation-Maximization (EM) algorithm.

[0100] The EM algorithm performs optimization iteratively and specifically consists of two main steps: the Expectation step (E-step) and the Maximization step (M-step). In the E-step, based on the current parameters , calculate the posterior probability that each data point belongs to each Gaussian distribution, that is, the responsibility , where represents the iteration number. The responsibility indicates the probability that the data point belongs to the k-th Gaussian distribution, and its calculation formula is:

[0101]

[0102] where, is the probability density function of the k-th Gaussian distribution, and its specific form is:

[0103]

[0104] In the M-step, use the responsibilities calculated in the E-step to update the model parameters. First, update the mixing coefficients of each Gaussian distribution:

[0105]

[0106] Next, update the mean of each Gaussian distribution:

[0107]

[0108] Finally, update the covariance matrix of each Gaussian distribution:

[0109] ;

[0110] In the formula, represents the iteration number.

[0111] The EM algorithm continuously repeats the E-step and the M-step until the log-likelihood function converges or reaches the preset maximum number of iterations. Each iteration increases the value of the log-likelihood function, thus gradually approaching the optimal solution for the parameters. Through this iterative optimization process, the EM algorithm can ultimately find the model parameters that maximize the log-likelihood, thereby achieving the optimal fitting of the GMM to the data.

[0112] In this embodiment, since the private key of Dilithium2 has only five values: -2, -1, 0, 1, 2, and the overall distribution follows a Gaussian distribution, after obtaining all the Gaussian mixture model is executed to cluster the data, obtaining a classification result, and then the complete private key is restored.

[0113] Table 1 shows the attack success rates for different security levels of Dilithium in this embodiment. A 100% success rate can be obtained with a small number of power consumption curves. Table 2 shows the time to restore the complete private key, and the complete private key can be restored within 1 minute. The present invention is still effective in scenarios with a high noise level (corresponding to a low signal-to-noise ratio). Table 3 shows the actual attack results of Dilithium2 at different signal-to-noise ratios.

[0114] Table 1 Attack success rates of Dilithium2, 3, 5 (%)

[0115]

[0116] Table 2 Single feature point attack times of Dilithium2, 3, 5 (s)

[0117]

[0118] (Note: The superscript * represents that the private key coefficient can be restored with a 100% success rate at this time)

[0119] Table 3 Attack success rates of Dilithium2 multi-feature points at different signal-to-noise ratios (%)

[0120]

[0121] Starting from the implementation security of the post - quantum cryptographic algorithm Dilithium, the present invention proposes a practical attack against the implementation of the Dilithium algorithm based on the ARM platform. The existing non - template - type side - channel analysis for Dilithium implementation has a large attack time overhead when the side - information leakage is small. Under a high - noise level, the existing non - template - type attack methods require a large amount of side - information leakage, while the present invention requires very little side - information leakage. The existing non - template - type attacks do not have a clear method for selecting feature points, while the present invention proposes a new feature - point detection method. The present invention has the characteristics of small attack time overhead, little required side - information leakage, being able to accurately identify feature points, and still being applicable under a high - noise level, and can quickly complete the practical analytical analysis of Dilithium implementation in a low - leakage scenario.

[0122] The implementation method of the present invention is applicable to the implementation of Dilithium based on the ARM platform, as well as other cryptographic analysis platforms based on the pre - charge architecture.

[0123] Example 3

[0124] An electronic device, comprising: at least one processor; and a memory, the memory storing instructions, when the instructions are executed by the at least one processor, causing the at least one processor to execute the Dilithium fast side - channel attack analysis method of Example 1 or Example 2.

[0125] Example 4

[0126] A computer - readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the Dilithium fast side - channel attack analysis method of Example 1 or Example 2 are implemented.

[0127] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A method for analyzing Dilithium fast side-channel attacks, characterized in that: Detect the leakage of cs using the Gaussian mixture difference method, and complete the detection and selection of feature points; classify the actual leakage involving the private key using the signature information, and use the difference in distribution to recover the private key in the normal domain, which specifically includes the following steps: S1: Collect the power consumption curves of the password device platform running Dilithium, and obtain the corresponding signature information c; S2: Align and segment the power consumption curves in a static alignment manner for subsequent analysis; S3: Detect feature points of the power consumption curve using the Gaussian mixture difference method to determine and feature points that can be used for side-channel analysis; the specific implementation process is as follows: Among the 256 coefficients of the signature information c in Dilithium, the value range of each coefficient of its private key also follows a uniform distribution on, from which and the distribution of each coefficient in is a Gaussian distribution with the following parameters: , , Among them, E[cs] represents the expectation, and cs represents the signature c and the private key , in the finite field polynomial ring which is a variable composed of the multiplication results; c i represents the i-th coefficient of the signature information c; s i represents the i-th coefficient in the private key; Var[cs] represents the variance; represents the number of non-zero elements in the signature information c in Dilithium, represents the value range of each coefficient of the private key in Dilithium; In the 32-bit ARM platform, the relevant calculations and storage of cs are all completed in the form of two's complement. Therefore, for different values, the energy leakage model is expressed as follows at the ; Among them, a t0 represents the proportionality coefficient at the moment, x represents the actual value of cs, b t0 represents the constant variable at the moment, δ t0 represents the variance of the Gaussian noise at the moment, HW represents the Hamming weight of the corresponding value; Thus, the overall energy leakage model of cs in the statistical sense is obtained: ; Among them, and represent the overall leakage distributions where cs is non - negative and negative respectively; Since the leakage models are all Gaussian distributions, represents the probability of x occurring, which is a fixed coefficient. After the linear combination of multiple Gaussian distributions, it still follows a Gaussian distribution, and there are and ; Therefore, after obtaining the complete leakage information, the Gaussian mixture model is used to fit the data, and the overall distribution is split into two Gaussian distributions, and the expectations corresponding to the distributions of and are calculated , ; when is larger, it indicates that the overlapping part of the distributions of and is smaller. This method is the Gaussian mixture difference method; S4: For restoring the i-th private key coefficient , classify the side information leakage of feature points according to whether the i-th coefficient in the signature information c is 1 or -1, and calculate the difference between the non-negative numbers and negative numbers of the two types of data after classification respectively, and record it as the corresponding result; S5: Loop and execute step S4 until all private keys are obtained , the coefficient result of S6: Classify the coefficient results of the private key , using the Gaussian mixture model, give the specific value of each coefficient, and finally complete the recovery of the complete private key.

2. The Dilithium fast side-channel attack analysis method according to claim 1, wherein: In step S4, for the i-th coefficient in the private key The classification of feature points includes the following three types: When the linear combination at this time is ; When the linear combination at this time is ; When the linear combination at this time is .

3. The Dilithium fast side-channel attack analysis method according to claim 2, characterized in that: Calculate the distributions of three groups of data according to the classification of feature points: ; where N represents a Gaussian distribution, denotes the i-th coefficient in the private key; For energy leakage, it has the following form: ; Among them, i represents the i-th coefficient of the private key and the signature c, and x represents and the possible value range, and P(x - c i s i ) represents and the probability of each coefficient result's possible value.

4. The Dilithium fast side-channel attack analysis method according to claim 3, characterized in that: Record , the difference in the number of samples within the interval, and use , the difference in the number of samples within the interval to recover ; First, calculate within the interval, and the difference in the number of samples, denoted as Δ ni ; Then calculate within the interval, and the difference in the number of samples, denoted as Δ pi ; Finally, record as the total difference in the number of samples corresponding to 5. The Dilithium fast side-channel attack analysis method according to claim 4, characterized in that: After obtaining all , use the Gaussian mixture model to complete classification; through the expectation-maximization algorithm, iteratively estimate the expectation, variance, and weight of each Gaussian distribution to find the optimal parameters.

6. An electronic device, characterized in that, Including: At least one processor; And a memory that stores instructions, which, when executed by the at least one processor, cause the at least one processor to execute the Dilithium fast side-channel attack analysis method according to any one of claims 1 to 5.

7. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the Dilithium fast side-channel attack analysis method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Fast side channel attack method and system for NTT polynomial multiplication

    CN117728933A

  • Side channel attack method of Diithium signature algorithm

    CN117938402A