A Side-Channel Analysis Method Based on Firmware Instrumentation
By acquiring the execution flow in the firmware image of the target device, determining the instrumentation parameters for side channel signal monitoring, the problem of improper selection of monitoring points in the traditional side channel analysis method is solved, and more accurate side channel analysis and data quality improvement is achieved.
Patent Information
- Application Number
- CN202411851750.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-16
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2044-12-16
AI Technical Summary
Traditional side channel analysis methods lack systematization and automation, and cannot effectively select monitoring points, resulting in low data quality and insufficient analysis results.
By acquiring the execution flow in the firmware image of the target device, the instrumentation parameters for monitoring the side channel signal are determined, and the instrumentation performs side channel signal monitoring, obtains the side channel data and the current operating status of each monitoring point, and determines the target side channel analysis results based on these data.
It realizes more accurate side channel analysis, improves data quality and analysis targetedness, and enables in-depth monitoring and result analysis.
Smart Images

Figure CN119739637B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the technical field of software testing, and particularly relates to a side-channel analysis method based on firmware instrumentation. Background Art
[0002] Side-channel analysis (SCA) is a technique for inferring encryption keys or sensitive data by analyzing non-communicative data (i.e., the so-called "side-channel" information) generated by an encryption device when executing an encryption algorithm. These non-communicative data include, but are not limited to, power consumption, electromagnetic radiation, running time, acoustic noise, and micro-architecture events (such as cache access). Side-channel analysis utilizes the intersection of the physical world and the digital world to infer secret information during the encryption process through physical phenomena.
[0003] Traditional side-channel analysis methods often rely on static analysis of firmware code, but this method often fails to fully reflect the dynamic behavior at runtime, lacks systematic and automated side-channel analysis tools, and there is no effective method to select the most informative monitoring points, resulting in too much or too little data being collected, poor data quality, and inaccurate analysis results. Summary of the Invention
[0004] The embodiments of this application provide a side-channel analysis method based on firmware instrumentation, which can solve the problems of poor data quality and inaccurate analysis results caused by the lack of systematic and automated side-channel analysis tools during the side-channel analysis process.
[0005] In a first aspect, the embodiments of this application provide a side-channel analysis method based on firmware instrumentation, including:
[0006] Obtain the execution flow in the firmware image of the target device;
[0007] Determine instrumentation parameters for monitoring side-channel signals during the execution of the target device according to the execution flow in the firmware image of the target device; wherein, the instrumentation parameters include at least three monitoring points for data collection;
[0008] Perform side-channel signal monitoring through firmware instrumentation according to the instrumentation parameters to obtain side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point;
[0009] Determine the target side-channel analysis data of the target device according to the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point;
[0010] Determine the side-channel analysis result of the target device based on the target side-channel analysis data of the target device.
[0011] The above technical solutions in the embodiments of the present application have at least the following technical effects:
[0012] The side-channel analysis method based on firmware instrumentation provided by the embodiments of the present application obtains the execution flow in the firmware image of the target device, and obtains the basic basis for instrumentation monitoring. According to the execution flow in the firmware image of the target device, determine the instrumentation parameters for monitoring the side-channel signals during the execution of the target device, and quickly analyze and locate the instrumentation parameters. According to the instrumentation parameters, perform side-channel signal monitoring through firmware instrumentation, and obtain the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point, realizing instrumentation overloading and key operation monitoring. According to the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point, determine the target side-channel analysis data of the target device, enhancing the pertinence and practicality of the analysis. Finally, determine the side-channel analysis result of the target device based on the target side-channel analysis data of the target device, improve the quality of evaluation data, and achieve precise in-depth monitoring and result analysis.
[0013] In a second aspect, the embodiments of the present application provide a side-channel analysis device based on firmware instrumentation, including:
[0014] An acquisition unit, configured to acquire the execution flow in the firmware image of the target device;
[0015] A parameter unit, configured to determine instrumentation parameters for monitoring side-channel signals during the execution of the target device according to the execution flow in the firmware image of the target device; wherein, the instrumentation parameters include at least three monitoring points for data collection;
[0016] A monitoring unit, configured to perform side-channel signal monitoring through firmware instrumentation according to the instrumentation parameters, and obtain the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point;
[0017] A data unit, configured to determine the target side-channel analysis data of the target device according to the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point;
[0018] A result unit, configured to determine the side-channel analysis result of the target device based on the target side-channel analysis data of the target device.
[0019] In a third aspect, an embodiment of the present application provides a side-channel analysis device based on firmware instrumentation, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described in any one of the above first aspects is implemented.
[0020] In a fourth aspect, an embodiment of the present application provides a computer program product. When the computer program product runs on a side-channel analysis device based on firmware instrumentation, the side-channel analysis device based on firmware instrumentation is caused to execute the method described in any one of the above aspects.
[0021] It can be understood that the beneficial effects of the above second to fourth aspects can be referred to the relevant descriptions in the above aspects, and will not be elaborated here. Description of the Drawings
[0022] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0023] Figure 1 is a schematic flowchart of a side-channel analysis method based on firmware instrumentation provided by an embodiment of the present application;
[0024] Figure 2 is a schematic flowchart of step S200 in the side-channel analysis method based on firmware instrumentation provided by an embodiment of the present application;
[0025] Figure 3 is a schematic flowchart of step S230 in the side-channel analysis method based on firmware instrumentation provided by an embodiment of the present application;
[0026] Figure 4 is a schematic flowchart of step S232 in the side-channel analysis method based on firmware instrumentation provided by an embodiment of the present application;
[0027] Figure 5 is a schematic flowchart of step S400 in the side-channel analysis method based on firmware instrumentation provided by an embodiment of the present application;
[0028] Figure 6 is a schematic flowchart of step S440 in the side-channel analysis method based on firmware instrumentation provided by an embodiment of the present application;
[0029] Figure 7 is a schematic flowchart of step S500 in the side-channel analysis method based on firmware instrumentation provided by an embodiment of the present application;
[0030] Figure 8 It is a schematic flowchart of step S520 of the side-channel analysis method based on firmware instrumentation provided by an embodiment of the present application;
[0031] Figure 9 It is a schematic structural diagram of the side-channel analysis device based on firmware instrumentation provided by an embodiment of the present application;
[0032] Figure 10 It is a schematic structural diagram of the side-channel analysis device based on firmware instrumentation provided by an embodiment of the present application. Detailed implementation manners
[0033] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system architectures and technologies are presented in order to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.
[0034] It should be understood that when used in the specification of the present application and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0035] It should also be understood that the term " / and" as used in the specification of the present application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0036] As used in the specification of the present application and the appended claims, the term "if" can be interpreted as "when", "once", "in response to determining", or "in response to detecting" according to the context. Similarly, the phrases "if determined" or "if the described condition or event is detected" can be interpreted as meaning "once determined", "in response to determining", "once the described condition or event is detected", or "in response to detecting the described condition or event" according to the context.
[0037] In addition, in the description of the specification of the present application and the appended claims, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0038] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that specific features, structures, or characteristics described in connection with that embodiment are included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but rather mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "comprising", "including", "having" and their variants all mean "including but not limited to", unless otherwise specifically emphasized.
[0039] Traditional side-channel analysis methods often rely on static analysis of firmware code, but this method often fails to fully reflect the dynamic behavior at runtime. There is a lack of systematic and automated side-channel analysis tools, and there is no effective method to select the most informative monitoring points, resulting in either too much or too little data being collected, poor data quality, and inaccurate analysis results.
[0040] To solve the above problems, an embodiment of this application provides a side-channel analysis method based on firmware instrumentation. In this method, by obtaining the execution flow in the firmware image of the target device, a basis for instrumentation monitoring is obtained. Based on the execution flow in the firmware image of the target device, instrumentation parameters for monitoring side-channel signals during the execution of the target device are determined, and the instrumentation parameters are quickly analyzed and located. According to the instrumentation parameters, side-channel signal monitoring is performed through firmware instrumentation to obtain the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point, realizing instrumentation overloading and critical operation monitoring. According to the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point, the target side-channel analysis data of the target device is determined, enhancing the pertinence and practicality of the analysis. Finally, based on the target side-channel analysis data of the target device, the side-channel analysis result of the target device is determined, improving the quality of the evaluation data and realizing accurate in-depth monitoring and result analysis.
[0041] The side-channel analysis method based on firmware instrumentation provided by an embodiment of this application can be applied to a side-channel analysis device based on firmware instrumentation. At this time, the side-channel analysis device based on firmware instrumentation is the execution subject of the side-channel analysis method based on firmware instrumentation provided by an embodiment of this application, and this application does not impose any restrictions on the specific type of the side-channel analysis device based on firmware instrumentation.
[0042] For example, the side-channel analysis device based on firmware instrumentation can be a mobile detection unit, a cloud-connected analysis device, a highly integrated portable detection toolkit, a desktop computer, a handheld device with wireless communication capabilities, a computing device, a computer, a laptop computer, etc.
[0043] To better understand the side-channel analysis method based on firmware instrumentation provided by the embodiments of the present application, the following provides an exemplary introduction to the specific implementation process of the side-channel analysis method based on firmware instrumentation provided by the embodiments of the present application.
[0044] Figure 1 FIG. shows a schematic flowchart of the side-channel analysis method based on firmware instrumentation provided by the embodiments of the present application. The side-channel analysis method based on firmware instrumentation includes:
[0045] S100, obtain the execution flow in the firmware image of the target device.
[0046] It can be understood that the firmware image is a collection of all instructions and data required for the target device to run, usually a binary file provided by the device manufacturer. These files include the device operating system, drivers, applications, and other necessary codes. The execution flow refers to the actual execution order of these instructions in the device, which is a specific manifestation of each operation step during the device's operation. It can be obtained through reverse engineering or by accepting input, and the execution path in the firmware image can be parsed, that is, the code execution order when the device is running, which helps to understand the internal working principle of the device and provides a basis for the subsequent selection of monitoring points. The purpose of obtaining the execution flow is to understand the specific operations of each step during the device's operation, as well as the association and order between these operations, which is very important for the subsequent side-channel signal monitoring and analysis. Only by understanding the device's execution flow can it be determined where to insert monitoring points to collect useful side-channel data.
[0047] S200, determine the instrumentation parameters for monitoring the side-channel signals during the execution of the target device according to the execution flow in the firmware image of the target device; wherein, the instrumentation parameters include at least three monitoring points for data collection.
[0048] It can be understood that the execution flow information of the firmware image can be used to determine the instrumentation parameters required for monitoring side-channel signals. Instrumentation refers to inserting additional code or monitoring points during the device's execution to collect data or monitor the device's state. The instrumentation parameters include key information such as the location and quantity of the monitoring points, and the instrumentation parameter information will be used for data acquisition during the device's execution. Side-channel signals refer to non-direct output signals generated during the device's execution, such as power consumption, electromagnetic radiation, etc. The execution flow and sensitive field characteristics in the firmware image of the target device can be scanned, for example, through encryption and decryption algorithm functions, passing parameters, etc., to locate the location and type of the instrumentation parameters that need to be inserted, such as giving an indication signal before and after the encryption and decryption algorithm operations. Through instrumentation, these side-channel signals can be collected during the device's execution, thereby monitoring the device's operating state and identifying potential risks or faults.
[0049] In a possible implementation, please refer to Figure 2 , S200, determine the instrumentation parameters for monitoring the side-channel signals during the execution of the target device according to the execution flow in the firmware image of the target device, including:
[0050] S210, according to the execution flow in the firmware image of the target device, parse each execution module and the instruction set on the execution module in the firmware image according to the preset parsing rules, and obtain the execution nodes of each execution module in the firmware image.
[0051] It can be understood that the execution flow in the firmware image of the target device can be parsed in detail. According to the preset parsing rules, each execution module and its instruction set in the firmware image are parsed. An execution module can be regarded as a functional unit in the firmware, and each module is responsible for a specific operation. By parsing these modules and their instruction sets, the execution nodes of each module can be determined. An execution node refers to the specific position and state of an execution module during execution, which identifies the key steps and instructions in the module. The purpose of parsing the execution nodes is to better understand the working mechanism of the firmware, so as to insert monitoring points at appropriate positions for effective side-channel signal monitoring.
[0052] Exemplarily, the firmware image can be parsed by a static analysis algorithm or a dynamic analysis algorithm. Static analysis is a technique for analyzing code without actually running the program. It mainly parses the execution module and its instruction set by constructing an Abstract Syntax Tree (AST) and generating a Control Flow Graph (CFG). The AST can be generated by a lexical analyzer and a syntax analyzer in advance. The lexical analyzer decomposes the source code into a series of tokens, and the syntax analyzer constructs a tree structure reflecting the structure of the source code based on these tokens. For example, the LL(k) or LR(k) syntax analysis algorithm can be used to generate the AST. Based on the AST, the CFG is generated. By analyzing the branch and loop structures in the code, the control flow relationship between code blocks is visualized to locate the key execution nodes. Dynamic analysis requires running the target program and obtaining more detailed execution information by tracking the execution path of the program. By simulating the execution of the program and treating the input as symbolic variables, the dynamic analysis tool can explore different paths of the program, identify potential execution nodes, especially at branch and conditional judgment points. By sending random or mutated data inputs to the program and determining the behavior changes of the program, the execution nodes that may cause abnormal or undefined behavior can be discovered.
[0053] S220, scan the execution nodes of each execution module in the firmware image, and obtain the module identifier and the first location information of the execution nodes of the execution module; wherein, the first location information includes the execution position information of the execution nodes of the execution module on the instruction set.
[0054] It can be understood that the module identifier is a tag used to uniquely identify each execution module, usually the name or address of the module. The first position information includes the specific position of the execution node in the instruction set, such as the address or offset of the instruction in memory. By obtaining this information, the specific position and order of each execution module during execution can be understood. This is very important for subsequent side-channel signal monitoring because only by clarifying the position of the execution node can monitoring points be inserted at appropriate positions to ensure that the monitored side-channel signals are representative and accurate enough.
[0055] Exemplarily, a suitable binary analysis tool can be selected, such as IDA Pro, Ghidra, or Binary Ninja, etc., to trace the control flow of each execution module and determine the entry point of each execution node. The firmware image can be disassembled, the instruction set of each execution module can be analyzed, the instruction sequence constituting the execution node can be identified, and the module identifier can be extracted from the disassembly result, which can be the name, address, or other unique identifier of the module. The exact position of each execution node in the instruction set can be recorded, which can include the absolute address of the instruction corresponding to the execution node in memory, the relative offset relative to the start address of the execution module, the sequence number in the instruction set, etc., for easy positioning. An index table or database can be created to store the module identifier and the first position information of each execution node.
[0056] S230, according to the module identifier and the first position information of the execution node of the execution module, determine the instrumentation parameters for monitoring the side-channel signals during the execution of the target device.
[0057] It can be understood that according to the module identifier and the first position information of the execution node of the execution module obtained previously, determine the instrumentation parameters for monitoring the side-channel signals during the execution of the target device. These parameters include the position and number of monitoring points, which are crucial for data collection and signal monitoring during the operation of the target device. By analyzing the module identifier and position information of the execution node, it can be determined which positions are most suitable for inserting monitoring points to maximize the capture of side-channel signals during the device operation. The purpose of this step is to provide accurate parameters for subsequent instrumentation operations to ensure the effectiveness and accuracy of side-channel signal monitoring.
[0058] Optionally, please refer to Figure 3 , S230, according to the module identifier and the first position information of the execution node of the execution module, determine the instrumentation parameters for monitoring the side-channel signals during the execution of the target device, including:
[0059] S231, according to the module identifier and the first position information of the execution node of the execution module, perform dynamic grouping on the execution process of the target device.
[0060] It can be understood that dynamic grouping refers to dividing into different monitoring groups according to the module identifier based on the actual situation during the execution of the device. Each monitoring group contains a number of execution nodes, and these nodes have a certain correlation during the execution process. Through dynamic grouping, the monitoring and analysis of side-channel signals can be carried out more effectively. The purpose of grouping is to determine appropriate monitoring points within each group to ensure that the monitored signals are representative and can cover the key steps and states during the operation of the device.
[0061] Exemplarily, in step S231, dynamic grouping is performed on the execution process of the target device according to the module identifier of the execution node of the execution module, including:
[0062] S2311, determining at least one monitoring group for the execution process of the target device according to the module identifier of the execution node of the execution module; wherein, the monitoring group is used to monitor the execution module of the target device.
[0063] It can be understood that the monitoring group is a logical grouping used to monitor the execution module of the target device. Each monitoring group contains one or more execution modules. These modules have a certain correlation and similarity during the operation of the device. By grouping them according to the identified module identifier, the monitoring of side-channel signals can be carried out more systematically. The determination of the monitoring group is to insert monitoring points specifically during the execution process of the device to ensure that effective side-channel data can be collected, and then the operation state of the device can be accurately monitored and analyzed. For example, it is divided into monitoring groups of different modules such as network communication, data storage, and computing tasks according to different module identifiers.
[0064] Exemplarily, in step S231, dynamic grouping is performed on the execution process of the target device according to the first position information of the execution node of the execution module, including:
[0065] S2312, determining three monitoring positions for each monitoring group of the execution process of the target device according to the first position information of the execution node of the execution module.
[0066] It can be understood that based on the position information of the execution nodes on the instruction set, the starting monitoring position, the running detection position, and the ending detection position are determined for each monitoring group. The three monitoring positions of each monitoring group are the specific positions where the instrumentation code is inserted. By monitoring these points, side-channel signals reflecting the device execution process can be collected, and the monitoring position is the insertion point of the monitored instrumentation. Instrumentation refers to inserting additional instructions or code segments into the code to capture and record runtime information. Static code analysis tools (such as IDA Pro, Ghidra) can be used to reverse engineer the firmware to identify function entry points, exits, loop structures, conditional branches, etc., and determine the monitoring positions. The dynamic grouping and determination of the monitoring positions are to ensure the scientificity and representativeness of the selection of the monitoring points, which can cover the key nodes and states during the device operation, so as to provide reliable data support for subsequent signal analysis.
[0067] S232. According to the result of dynamically grouping the execution process of the target device, determine the instrumentation parameters for monitoring the side-channel signals during the execution process of the target device.
[0068] It can be understood that the instrumentation parameters include the positions and quantities of the monitoring points, and these parameters will be used to monitor the side-channel signals during the device execution process. Through dynamic grouping, the key nodes and states during the device execution process can be clarified, so as to insert the instrumentation code at the monitoring positions to ensure that effective side-channel data can be collected. The determination of the instrumentation parameters is the basis for subsequent actual monitoring operations, ensuring the pertinence and effectiveness of the monitoring process.
[0069] Optionally, please refer to Figure 4 S232. According to the result of dynamically grouping the execution process of the target device, determine the instrumentation parameters for monitoring the side-channel signals during the execution process of the target device, including:
[0070] S2321. According to the result of dynamically grouping the execution process of the target device, determine the monitoring positions of each monitoring group as the monitoring points, and obtain at least three monitoring points for monitoring the side-channel signals during the execution process of the target device.
[0071] It can be understood that according to the result of dynamically grouping the execution process of the target device, each monitoring position of each monitoring group is determined as a monitoring point, and a preset instrumentation code is injected into the monitoring points. These monitoring points will be used to collect the data of the side-channel signals during the device execution process. The setting of at least three monitoring points is to ensure that enough data can be collected to reflect different states and changes during the device execution process. By determining the monitoring positions as the monitoring points, targeted data collection can be carried out to ensure that the monitored signals are representative and cover the key steps and states during the device operation, providing reliable data support for subsequent signal analysis.
[0072] S2322. Determine the instrumentation parameters for monitoring the side-channel signals during the execution of the target device based on all the monitoring points for the side-channel signals during the execution of the target device.
[0073] It can be understood that the instrumentation parameters will be used for actual monitoring operations during the device execution. The instrumentation parameters include the positions, quantities of the monitoring points, and the specific content to be monitored. Based on the positions of all the monitoring points, the instrumentation is determined to ensure that effective side-channel signal data can be collected. The determination of the instrumentation parameters is the basis for actual data collection, ensuring that the monitoring process is scientific and reasonable, can reflect the real situation during the device operation, and provides reliable data support for subsequent signal analysis and device evaluation.
[0074] S300. Based on the instrumentation parameters, perform side-channel signal monitoring through firmware instrumentation to obtain the side-channel data corresponding to each monitoring point and the current operation state of the target device at each monitoring point.
[0075] It can be understood that side-channel signal monitoring can be performed through the monitoring points inserted into the firmware of the target device. Instrumentation refers to inserting additional code or instructions at specific positions in the firmware to collect side-channel signal data during the device operation. The firmware code can be instrumented and reloaded into the target device to perform the key operations of encryption and decryption and conduct side-channel signal monitoring. Through the instrumented code, the corresponding side-channel data can be obtained at each monitoring point, as well as the current operation state of the target device at these monitoring points. The side-channel data includes information such as the power consumption and electromagnetic radiation during the device execution, and these data can reflect the operation state and performance of the device. The monitored current operation state is the specific situation when the device executes a specific operation, such as the type and position of the executed instruction. The signal data and the operation state information are packed to facilitate subsequent analysis. A cache can be set on the device to periodically upload the data to the backend server or directly transmit the data to the remote server or cloud platform in real time. The data of the monitoring points will be used for subsequent signal analysis to help identify the operation characteristics and potential risks of the device.
[0076] S400. Determine the target side-channel analysis data of the target device according to the side-channel data corresponding to each monitoring point and the current operation state of the target device at each monitoring point.
[0077] It can be understood that side-channel data includes various non-direct output signals generated by the device during operation, such as power consumption, electromagnetic radiation, etc. Through these signals, the operating state and performance of the device can be indirectly reflected. The current operating state refers to the state of the device during a specific operation, such as the type and location of the instruction being executed. By combining side-channel data and the operating state, a comprehensive analysis of the device's operation can be carried out to determine the target side-channel analysis data of the target device. The target side-channel analysis data is the target analysis data selected from all side-channel data. The target side-channel analysis data will be used to identify the operating characteristics of the device, evaluate the performance and reliability of the device, and help discover potential risks or faults.
[0078] In a possible implementation, please refer to Figure 5 , S400, to determine the target side-channel analysis data of the target device according to the side-channel data corresponding to each monitoring point and the current operating state of the target device at each monitoring point, including:
[0079] S410, according to the side-channel data corresponding to each monitoring point and the current operating state of the target device at each monitoring point, for each monitoring point, determine the total operation duration and instantaneous power level corresponding to each monitoring point.
[0080] It can be understood that the total operation duration corresponding to the monitoring point refers to the total time for the device to execute an operation at a certain monitoring point, which can reflect the efficiency and stability of the device execution process. The instantaneous power level refers to the power consumption of the device at a certain moment. By monitoring the instantaneous power, the energy consumption of the device during different operations can be understood. The total operation duration and instantaneous power level data corresponding to each monitoring point are data that can be directly obtained from the monitoring data. By combining the total operation duration and the instantaneous power level, a comprehensive analysis of the device's operation can be carried out to evaluate the performance and energy consumption characteristics of the device. These data will provide a basis for subsequent signal analysis and help identify the operating characteristics and potential problems of the device.
[0081] S420, based on the total operation duration corresponding to each monitoring point, calculate the ratio of the total operation duration of each monitoring point to the current operating state to obtain the execution efficiency data corresponding to each monitoring point.
[0082] It can be understood that the total operation duration reflects the total time for the device to perform operations at a certain monitoring point, while the current operation status reflects the specific situation of the device when performing specific operations. By presetting a division algorithm, the ratio of these two can be calculated, and the execution efficiency of the device in different operation states can be evaluated. The execution efficiency data is an important indicator of the device performance, which can reflect whether there are bottlenecks or inefficiencies in the device during the execution process. By analyzing the execution efficiency data, potential problems in the device operation can be discovered, the execution process of the device can be optimized, and the overall performance can be improved.
[0083] S430. Determine the power-time analysis data corresponding to each monitoring point according to the execution efficiency data, instantaneous power level, and total operation duration corresponding to each monitoring point.
[0084] It can be understood that the execution efficiency data reflects the execution efficiency of the device in different operation states, the instantaneous power level reflects the energy consumption of the device at different operation moments, and the total operation duration is the total time for the device to perform operations. These data can be analyzed in the form of preset function fitting. The function fitting form of the power-time analysis data for each monitoring point can be obtained according to the execution efficiency data, instantaneous power level, and total operation duration corresponding to each monitoring point. It is also possible to preset the form of chart visualization to obtain the power-time analysis data in the form of a curve according to the execution efficiency data, instantaneous power level, and total operation duration corresponding to each monitoring point. The power-time analysis data refers to the relationship between energy consumption and time of the device in different operation states. Through these data, the energy consumption characteristics and performance of the device can be evaluated. The power-time analysis data provides a basis for the comprehensive evaluation of the device operation state, helping to identify the energy consumption bottlenecks and optimization opportunities of the device.
[0085] S440. Screen the power-time analysis data corresponding to all monitoring points according to the power-time analysis data corresponding to each monitoring point, and determine the target side-channel analysis data of the target device.
[0086] It can be understood that the power-time analysis data of all monitoring points is screened to determine the target side-channel analysis data of the target device. The power-time analysis data reflects the energy consumption and execution time of the device in different operation states. By screening these data, the most representative and critical monitoring points during the device operation can be identified. The screening process can include sorting the data, screening out outliers, identifying key operation states, etc. Through screening, it can be determined which monitoring point data is the most important for the operation characteristics and performance evaluation of the device, so as to obtain the target side-channel analysis data of the target device. These analysis data will be used for subsequent device performance evaluation and optimization, helping to identify the operation bottlenecks and potential problems of the device.
[0087] Optionally, please refer to Figure 6, S440, based on the power-time analysis data corresponding to each monitoring point, screen the power-time analysis data corresponding to all monitoring points to determine the target-side channel analysis data of the target device, including:
[0088] S441, obtain historical data of similar target devices; among them, the historical data of similar target devices includes the power-time analysis data corresponding to such similar devices obtained after performing in-line monitoring on devices of the same type as the target device.
[0089] It can be understood that the historical data of similar target devices can be extracted from various data sources using automated tools or manually. The data sources can be internal databases, industry sharing platforms, publicly released data sets by research institutions, etc. Extract the power consumption and time series characteristics of the device in different operating states (such as power-on, standby, performing specific tasks, etc.) from the historical data of similar target devices, and convert them into the same data form as the time-power consumption analysis data of the target device. The historical data of similar target devices includes the power-time analysis data obtained after performing in-line monitoring on devices of the same type as the target device. The historical data of similar target devices provides a reference benchmark that can be used to compare and evaluate the operation of the target device. By analyzing the power-time analysis data of similar devices, the energy consumption and execution time characteristics of these devices in different operating states can be understood. These historical data provide a reference standard for the performance evaluation of the target device. By comparing with the historical data, appropriate data can be accurately screened as the target data, so as to obtain the target-side channel analysis data of the target device.
[0090] S442, based on the power-time analysis data corresponding to each monitoring point and the historical data of similar target devices, determine the data similarity between the power-time analysis data corresponding to each monitoring point and the historical data of similar target devices.
[0091] It can be understood that the similarity analysis evaluates the operation of the target device by comparing the power-time data of the target device and similar devices in the same or similar operating states. The higher the similarity, the more similar the operating state of the target device is to that of similar devices, and the normal the operation is; the lower the similarity, there may be abnormal conditions or potential problems. The data similarity between the power-time analysis data corresponding to each monitoring point and the historical data of similar target devices can be determined by calculating the Euclidean Distance. The Euclidean Distance is applicable to the similarity measurement of one-dimensional or multi-dimensional data, calculates the straight-line distance between two power-time analysis data sequences, and the smaller the distance, the higher the similarity. For example where p i and q iThey represent the power values of the target device and the similar devices at the $i$-th moment respectively. Based on information theory, it measures the degree of mutual dependence between two random variables. The larger the mutual information value is, the more information sharing there is between the two variables and the higher the similarity is. Through similarity analysis, the differences between the operating characteristics of the target device and the historical data can be identified, and it can be determined whether there are performance bottlenecks or areas that need to be optimized in the device. The purpose of this step is to provide data support for the performance evaluation and optimization of the target device and help discover potential problems in the device operation.
[0092] S443. According to the data similarity between the power-time analysis data corresponding to each monitoring point and the historical data of the similar target device, the power-time analysis data corresponding to the monitoring point with the smallest data similarity is selected and determined as the target-side channel analysis data of the target device.
[0093] It can be understood that according to the similarity between the power-time analysis data of each monitoring point and the historical data of the similar target device, the size of the similarity can be compared through the quotient algorithm or the sorting algorithm, and the power-time analysis data corresponding to the monitoring point with the smallest similarity is selected and determined as the target-side channel analysis data of the target device. The monitoring point with the smallest similarity usually means that there are significant differences in the operating state of the target device at this monitoring point compared with the similar devices, reflecting the unique operating characteristics or potential problems of the target device. By screening out these key monitoring points, the performance and operating state of the target device can be evaluated more accurately. The target-side channel analysis data is an important basis for device performance evaluation. By analyzing these data, the operating bottlenecks of the device can be identified, the execution process of the device can be optimized, and the overall performance can be improved.
[0094] S500. According to the target-side channel analysis data of the target device, determine the side-channel analysis result of the target device.
[0095] It can be understood that, based on the previously determined target side-channel analysis data, the side-channel attack risk of the target device is analyzed and evaluated. Side-channel attack refers to analyzing the non-direct output signals (such as power consumption, electromagnetic radiation, etc.) generated during the operation of the device to obtain the sensitive information of the device or affect the normal operation of the device. The target side-channel analysis data provides the energy consumption and execution time characteristics of the device in different operating states. By analyzing this data, the potential risks of the device in terms of side channels can be identified. The side-channel data can be preprocessed first, including noise removal, normalization, etc., and then the pre-trained side-channel analysis model is used to analyze the preprocessed data to evaluate the side-channel attack risk of the target device. For cryptographic algorithms, a small amount of side-channel analysis data can also be used to crack the key to evaluate the side-channel analysis results. A detailed side-channel analysis report is generated according to the analysis results, including the risk assessment results, potential vulnerabilities, and recommended protection measures. The purpose of evaluating the side-channel attack risk is to identify the security vulnerabilities during the operation of the device, take necessary protection measures, and ensure the security and reliability of the device. By analyzing the target side-channel analysis data, potential security hazards during the operation of the device can be discovered, corresponding protection strategies can be formulated, and the risk of side-channel attacks can be reduced.
[0096] In a possible implementation, please refer to Figure 7 , S500, determines the side-channel analysis result of the target device according to the target side-channel analysis data of the target device, including:
[0097] S510, processes the target side-channel analysis data of the target device using a side-channel analysis model according to the target side-channel analysis data of the target device to obtain the side-channel risk index of the target device; wherein, the side-channel analysis model is a machine learning model pre-trained using sample data.
[0098] It can be understood that the side-channel analysis model is a machine learning model pre-trained using sample data. The sample data should include side-channel analysis data of various types of devices during normal operation and when suffering from side-channel attacks, as well as corresponding risk labels. Side-channel analysis data of a large number of devices can be collected, including data during normal operation and when under attack, and the risk levels are labeled. The data is preprocessed to extract key features, which may include frequency-domain analysis, time-domain analysis, etc. Select a suitable machine learning algorithm, such as random forest, support vector machine, or deep learning model, etc., and use the labeled dataset to train the model. Adjust the hyperparameters to optimize the model performance, and use an independent test set to verify the accuracy and generalization ability of the model. Use the side-channel analysis model to process the target side-channel analysis data of the target device to obtain the side-channel risk index. The side-channel analysis model is a model trained using machine learning algorithms. By learning a large amount of sample data, it can identify and predict the side-channel attack risks of devices in different operating states. The side-channel risk index is a quantitative indicator used to represent the risk level of a device in terms of side-channel attacks. In this way, the security of the device can be objectively evaluated, providing a basis for subsequent security protection measures. The training process of the side-channel analysis model requires a large amount of sample data and strict verification to ensure the accuracy and reliability of the model.
[0099] S520. Based on the side-channel risk index of the target device, determine the side-channel analysis result of the target device.
[0100] It can be understood that based on the side-channel risk index of the target device, the side-channel analysis result of the device is finally determined. The risk index provides a quantitative indicator for evaluating the potential risk of a device in terms of side-channel attacks. By analyzing this risk index, the security of the device in different operating states can be further determined. The side-channel analysis result is a comprehensive assessment of the overall security of the device, helping to identify potential security hazards during the operation of the device. By deeply analyzing the risk index, the weaknesses and vulnerabilities of the device in a specific state can be discovered, providing a strong basis for improving the security of the device.
[0101] Optionally, please refer to Figure 8 S520. Based on the side-channel risk index of the target device, determine the side-channel analysis result of the target device, including:
[0102] S521. Perform side-channel risk matching based on the target side-channel analysis data of the target device to obtain the side-channel risk label.
[0103] It can be understood that based on the target-side channel analysis data of the target device, side-channel risk matching is performed to obtain the side-channel risk label of the device. The risk label is a classification label used to describe the risk category of the device in terms of side-channel attacks. For example, assume that the side-channel risk index of the target device is 85 (with a full score of 100), which indicates that the device has a relatively high risk in side-channel attacks. A series of risk thresholds can be predefined. For example, "low risk" corresponds to an index < 30, "medium risk" corresponds to 30 ≤ index < 70, and "high risk" corresponds to an index ≥ 70. By comparing the side-channel risk index 85 of the target device with these thresholds, it is determined that it belongs to the "high risk" category. Through the matching of the target-side channel analysis data, the risk type of the device can be more accurately identified, providing a reference for the formulation of protection measures.
[0104] S522, based on the side-channel risk label, determine the side-channel analysis result of the target device.
[0105] It can be understood that based on the previously determined side-channel risk label, the side-channel analysis result of the device is finally determined. The risk label provides classification information about the device's risk. By comprehensively analyzing the risk label, the overall security status of the device can be determined. According to different levels of risk labels, a mapping relationship table can be preset to define the possible risk situation results under different risk levels, thereby obtaining the risk level and possible risk types of the side-channel of the target device, that is, obtaining the side-channel analysis result of the target device. For example, in the "high risk" category, the risk types are further subdivided, such as "power consumption fluctuation", "electromagnetic leakage", etc. The side-channel analysis result is a comprehensive assessment of the device in terms of side-channel attacks, helping to identify potential risks and security hazards during the device's operation. Through detailed risk label analysis, the specific weaknesses of the device in different operating states can be discovered, providing strong support for the device's security protection, improving the quality of assessment data, and achieving precise in-depth monitoring and result analysis.
[0106] Corresponding to the side-channel analysis method based on firmware instrumentation in the above embodiment, the embodiment of the present application also provides a side-channel analysis device based on firmware instrumentation. Each unit of this device can implement each step of the side-channel analysis method based on firmware instrumentation. Figure 9 The structural block diagram of the side-channel analysis device based on firmware instrumentation provided by the embodiment of the present application is shown. For the sake of convenience of description, only the parts related to the embodiment of the present application are shown.
[0107] Refer to Figure 9 , the side-channel analysis device based on firmware instrumentation includes:
[0108] An acquisition unit, configured to acquire the execution flow in the firmware image of the target device;
[0109] A parameter unit, configured to determine staking parameters for monitoring side-channel signals during the execution of the target device according to the execution flow in the firmware image of the target device; wherein the staking parameters include at least three monitoring points for data collection;
[0110] A monitoring unit, configured to perform side-channel signal monitoring through firmware staking according to the staking parameters, and obtain side-channel data corresponding to each monitoring point and the current operation state of the target device at each monitoring point;
[0111] A data unit, configured to determine target side-channel analysis data of the target device according to the side-channel data corresponding to each monitoring point and the current operation state of the target device at each monitoring point;
[0112] A result unit, configured to determine a side-channel analysis result of the target device according to the target side-channel analysis data of the target device.
[0113] It should be noted that for the information interaction, execution process, etc. between the above-mentioned devices / units, since they are based on the same concept as the method embodiment of the present application, their specific functions and the technical effects brought about can be specifically referred to the method embodiment part, and will not be elaborated here.
[0114] Those skilled in the art can clearly understand that for the convenience and conciseness of description, only the above-mentioned division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit module exists physically alone, or two or more unit modules are integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working process of the units and modules in the above device can refer to the corresponding process in the foregoing method embodiment, and will not be elaborated here.
[0115] The embodiment of the present application further provides a side-channel analysis device based on firmware staking, Figure 10 which is a schematic structural diagram of the side-channel analysis device based on firmware staking provided by an embodiment of the present application. As Figure 10 shown, the side-channel analysis device 6 based on firmware staking in this embodiment includes: at least one processor 60 ( Figure 10 only one is shown here), at least one memory 61 ( Figure 10only one is shown (not shown in the figure), and a computer program 62 stored in the at least one memory 61 and executable on the at least one processor 60. When the processor 60 executes the computer program 62, the firmware-instrumentation-based side-channel analysis device 6 is caused to implement the steps in any of the above-described embodiments of the firmware-instrumentation-based side-channel analysis methods, or the functions of the units in the above-described device embodiments are implemented in the firmware-instrumentation-based side-channel analysis device 6.
[0116] Exemplarily, the computer program 62 may be divided into one or more units, and the one or more units are stored in the memory 61 and executed by the processor 60 to complete the present application. The one or more units may be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program 62 in the firmware-instrumentation-based side-channel analysis device 6.
[0117] The firmware-instrumentation-based side-channel analysis device 6 may be a mobile detection unit, a cloud-connected analysis device, a highly integrated portable detection kit, a desktop computer, a handheld device with wireless communication function, a computing device, a computer, a laptop computer, etc. The firmware-instrumentation-based side-channel analysis device may include, but is not limited to, a processor 60 and a memory 61. Those skilled in the art can understand that Figure 10 merely examples of the firmware-instrumentation-based side-channel analysis device 6, and do not constitute a limitation on the firmware-instrumentation-based side-channel analysis device 6. It may include more or fewer components than shown in the figure, or combine certain components, or different components. For example, it may also include input / output devices, network access devices, buses, etc.
[0118] The processor 60 may be a central processing unit (CPU), and the processor 60 may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0119] The memory 61 may be an internal storage unit of the firmware instrumentation-based side-channel analysis device 6 in some embodiments, such as a hard disk or memory of the firmware instrumentation-based side-channel analysis device 6. The memory 61 may also be an external storage device of the firmware instrumentation-based side-channel analysis device 6 in other embodiments, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc., equipped on the firmware instrumentation-based side-channel analysis device 6. Further, the memory 61 may also include both an internal storage unit and an external storage device of the firmware instrumentation-based side-channel analysis device 6. The memory 61 is used to store an operating system, application programs, a BootLoader, data, and other programs, such as program codes of the computer program. The memory 61 may also be used to temporarily store data that has been output or will be output.
[0120] An embodiment of the present application also provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps in any of the above method embodiments are implemented.
[0121] An embodiment of the present application provides a computer program product, and when the computer program product runs on a firmware instrumentation-based side-channel analysis device, the firmware instrumentation-based side-channel analysis device implements the steps in any of the above method embodiments.
[0122] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above method embodiments of this application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can at least include: any entity or device capable of carrying the computer program code to the side-channel analysis device based on firmware instrumentation, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.
[0123] In the above embodiments, the descriptions of the various embodiments have their own emphases. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0124] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0125] In the embodiments provided in this application, it should be understood that the disclosed side-channel analysis device / side-channel analysis device based on firmware instrumentation and method can be implemented in other ways. For example, the above-described side-channel analysis device / side-channel analysis device based on firmware instrumentation embodiments are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in an electrical, mechanical or other form.
[0126] The unit described as a separation component may or may not be physically separated. The component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0127] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A side-channel analysis method based on firmware instrumentation, characterized in that Including: Obtain the execution flow in the firmware image of the target device; Determine the instrumentation parameters for monitoring the side-channel signals during the execution of the target device according to the execution flow in the firmware image of the target device; wherein, the instrumentation parameters include at least three monitoring points for data collection; Perform side-channel signal monitoring through firmware instrumentation according to the instrumentation parameters, and obtain the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point; Determine the target side-channel analysis data of the target device according to the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point; Determine the side-channel analysis result of the target device according to the target side-channel analysis data of the target device; Wherein, the determining the target side-channel analysis data of the target device according to the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point includes: According to the side-channel data corresponding to each monitoring point and the current operation state of the target device corresponding to each monitoring point, for each monitoring point, determine the total operation duration and the instantaneous power level corresponding to each monitoring point; Based on the total operation duration corresponding to each monitoring point, calculate the ratio of the total operation duration of each monitoring point to the current operation state, and obtain the execution efficiency data corresponding to each monitoring point; Determine the power-time analysis data corresponding to each monitoring point according to the execution efficiency data, the instantaneous power level and the total operation duration corresponding to each monitoring point; According to the power-time analysis data corresponding to each monitoring point, screen the power-time analysis data corresponding to all monitoring points, and determine the target side-channel analysis data of the target device.
2. The side-channel analysis method based on firmware instrumentation according to claim 1, wherein The determining the instrumentation parameters for monitoring the side-channel signals during the execution of the target device according to the execution flow in the firmware image of the target device includes: According to the execution flow in the firmware image of the target device, perform parsing processing on each execution module and the instruction set on the execution module in the firmware image according to a preset parsing rule, and obtain the execution nodes of each execution module in the firmware image; Scan the execution nodes of each execution module in the firmware image, and obtain the module identifier and the first position information of the execution nodes of the execution module; wherein, the first position information includes the execution position information of the execution nodes of the execution module on the instruction set; Determine the instrumentation parameters for monitoring the side-channel signals during the execution of the target device according to the module identifier and the first position information of the execution nodes of the execution module.
3. The side-channel analysis method based on firmware instrumentation according to claim 2, wherein The determining the instrumentation parameters for monitoring the side-channel signals during the execution of the target device according to the module identifier and the first position information of the execution nodes of the execution module includes: Dynamically group the execution process of the target device according to the module identifier of the execution node of the execution module and the first location information; Determine the instrumentation parameters for monitoring the side-channel signals during the execution process of the target device according to the result of dynamically grouping the execution process of the target device; 4. The side-channel analysis method based on firmware instrumentation according to claim 3, wherein Dynamically grouping the execution process of the target device according to the module identifier of the execution node of the execution module includes: Determine at least one monitoring group for the execution process of the target device according to the module identifier of the execution node of the execution module; wherein, the monitoring group is used to monitor the execution module of the target device.
5. The side-channel analysis method based on firmware instrumentation according to claim 4, wherein Dynamically grouping the execution process of the target device according to the first location information of the execution node of the execution module includes: Determine three monitoring locations for each monitoring group of the execution process of the target device according to the first location information of the execution node of the execution module.
6. The side-channel analysis method based on firmware instrumentation according to claim 5, wherein The determining the instrumentation parameters for monitoring the side-channel signals during the execution process of the target device according to the result of dynamically grouping the execution process of the target device includes: Determine the monitoring locations of each monitoring group as monitoring points according to the result of dynamically grouping the execution process of the target device, and obtain at least three monitoring points for monitoring the side-channel signals during the execution process of the target device; Determine the instrumentation parameters for monitoring the side-channel signals during the execution process of the target device according to all the monitoring points for monitoring the side-channel signals during the execution process of the target device.
7. The side-channel analysis method based on firmware instrumentation according to claim 1, characterized in that The screening the power-time analysis data corresponding to all the monitoring points according to the power-time analysis data corresponding to each monitoring point to determine the target side-channel analysis data of the target device includes: Obtain the historical data of the same-type target device; wherein, the historical data of the same-type target device includes the power-time analysis data corresponding to the same-type target device obtained by analyzing the instrumentation monitoring after the execution of the device of the same type as the target device; Determine the data similarity between the power-time analysis data corresponding to each monitoring point and the historical data of the same-type target device according to the power-time analysis data corresponding to each monitoring point and the historical data of the same-type target device; Screen out the power-time analysis data corresponding to the monitoring point with the smallest data similarity according to the data similarity between the power-time analysis data corresponding to each monitoring point and the historical data of the same-type target device, and determine it as the target side-channel analysis data of the target device.
8. The side-channel analysis method based on firmware instrumentation according to claim 1, wherein The determining the side-channel analysis result of the target device according to the target side-channel analysis data of the target device includes: Process the target side-channel analysis data of the target device using a side-channel analysis model according to the target side-channel analysis data of the target device to obtain the side-channel risk index of the target device; wherein, the side-channel analysis model is a machine learning model pre-trained using sample data. Determine the side-channel analysis result of the target device based on the side-channel risk index of the target device.
9. The side-channel analysis method based on firmware instrumentation according to claim 8, wherein The determining the side-channel analysis result of the target device based on the side-channel risk index of the target device includes: Perform side-channel risk matching based on the target side-channel analysis data of the target device to obtain a side-channel risk label; Determine the side-channel analysis result of the target device based on the side-channel risk label.
Citation Information
Patent Citations
Program crash reason determination method and device
CN115757119A
Side channel detection method and apparatus
WO2024174622A1