Comprehensive protection method for resisting side channel attack and fault attack and related device

By processing initial data, deduplication, culling and calculating XOR results in each round of the symmetric cryptographic algorithm, the problem that the prior art is difficult to resist side channel attacks and fault attacks is solved, and effective resistance to statistically invalid fault attacks and security guarantees for data transmission are achieved.

CN119995836APending Publication Date: 2025-05-13BEIJING CEC HUADA ELECTRONIC DESIGN CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510265422.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art is difficult to effectively resist side channel attacks and fault attacks encountered by symmetric cryptographic algorithms in application scenarios such as IoT edge devices and smart cards, especially statistically invalid fault attacks, which are ineffective against existing protection methods.

Method used

In each round of the symmetric cryptographic algorithm, by obtaining initial data (including input data, multiple random numbers and the XOR result of input data and random numbers), the data is processed using the linear operation module and the nonlinear operation module to process, deduplication and culling, divide the data groups and calculate the XOR result, and judge whether the XOR result is equal to determine whether the output result is determined, thereby resisting side channel attacks and fault attacks.

Benefits of technology

Through this method, it can effectively resist side channel attacks and fault attacks, especially statistical invalid fault attacks, reduce computing links, reduce protection resource overhead, and ensure the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995836A_ABST
    Figure CN119995836A_ABST
Patent Text Reader

Abstract

The invention provides a comprehensive protection method for resisting side channel attack and fault attack and a related device. The method comprises the following steps: in each round of a symmetric cryptographic algorithm, processing input data, a plurality of random numbers and an XOR result of the input data and the random numbers in initial data through a first operation module adopting linear operation of the symmetric cryptographic algorithm to obtain a plurality of first components; performing duplicate removal processing on results obtained by pairwise differencing the plurality of first components, and removing the first components obtained by processing the input data to obtain intermediate data; processing data included in the intermediate data through a second operation module of the symmetric cryptographic algorithm to obtain a plurality of second components; dividing the plurality of second components into a plurality of data groups, processing to obtain data of the second components in the same data group, performing XOR to obtain input data, and processing to obtain a first component; and judging whether the XOR results of the data included in the plurality of data groups are equal or not, and if not, not outputting the XOR result of the data included in any data group.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of information security technology, and in particular to a comprehensive protection method and related device against side channel attacks and fault attacks. Background Art

[0002] Symmetric cryptographic algorithms are encryption and decryption mechanisms in which the sender and receiver use the same key. When data transmission is required in edge devices of the Internet of Things and application scenarios such as smart cards, symmetric cryptographic algorithms are used for encryption and decryption. Common symmetric cryptographic algorithms include DES (Data Encryption Standard), AES (Advanced Encryption Standard), SM4 (Commercial Secret Algorithm No. 4), and ASCON. Each symmetric cryptographic algorithm includes linear operations (such as shift operations, etc.) and nonlinear operations (such as S-box permutation, etc.). Compared with asymmetric cryptographic algorithms, symmetric cryptographic algorithms have the characteristics of fast speed and low implementation cost, but in the above application scenarios, symmetric cryptographic algorithms deployed in embedded devices or chip systems will still encounter information leakage risks. The more common methods of attacking symmetric cryptographic algorithms can be roughly divided into two categories, namely side channel attacks and fault attacks.

[0003] Side channel attack is a passive attack technique that uses physical effects (such as clock glitches, power consumption characteristics, and electromagnetic characteristics) to attack encryption and decryption related devices. Over the years, it has been proven that the most effective protection against side channel attacks is masking technology. The idea of ​​masking technology is to split the data to be protected into multiple shares and make each share statistically independent of the data to be protected, so that the privacy of the data to be protected will not be compromised when observing a part of the shares. Among the many masking technologies, a threshold implementation technology based on secret sharing and multi-party computing proposed by Nikova et al. stands out. The threshold implementation technology is essentially based on the secret sharing mechanism constructor and applies the constructed function to the execution of the secret sharing mechanism to split multiple incomplete shares from the data to be protected. The threshold implementation technology is designed for hardware implementation, and it has been proven that even if the chip circuit that performs encryption and decryption is interfered by clock glitches, the chip circuit can still be effectively protected.

[0004] Fault attack is an active attack technology that injects faults into devices that are performing encryption and decryption operations. This fault injection will cause the encryption and decryption results to output erroneous values ​​or correct values. Based on this, fault attacks include differential fault attacks (DFA) that attack by analyzing the output erroneous values ​​and statistical ineffective fault attacks (SIFA) that attack by analyzing the output correct values. For differential fault attacks, the mainstream resistance method in the industry is to achieve the purpose of protection through redundancy detection or infection detection. Among them, redundancy detection will set up the original circuit and the redundant circuit, so that when the original circuit is attacked by a fault attack and the redundant circuit is not attacked by a fault, the fault can be found by comparing the data output. The error can be corrected by adopting methods such as minority obeys majority voting, so that the data required for the differential fault attack method cannot be generated; infection detection is to randomize the data output by the original circuit when the original circuit is attacked by a fault, so that the attacker cannot obtain valid data for relevant analysis of the differential fault attack method. Statistical invalid fault attacks use the dependency between fault propagation to output and intermediate values ​​to perform relevant analysis of the attack. Since no erroneous values ​​are output, redundant detection and infection detection are cleverly bypassed. That is, the above-mentioned protection method against differential fault attacks does not work for statistical invalid fault attacks.

[0005] At present, some protection methods have been proposed for statistical invalid fault attacks, such as: (1) Daemen et al. proposed using reversible operations to ensure that faults propagate to the output and using error detection methods to detect faults in the output. However, as the complexity of the functions used in the encryption and decryption process increases, the implementation efficiency of such countermeasures will continue to decline; (2) Some scholars have proposed polynomial multiplication masking technology to reduce the threat of statistical invalid fault attacks to cryptographic modules, but multiplication masking technology cannot resist zero-value attacks, and therefore cannot fully resist statistical invalid fault attacks and side channel attacks; (3) Some scholars have proposed gate-level protection and Hamming code error correction, but such methods pose great challenges to the back-end layout and routing of encryption and decryption chips; (4) Some scholars have proposed voting mechanisms, that is, using voting methods based on threshold technology to reduce the probability that faults cannot propagate to the output, but in this method, the calculation results of each layer basically need to adopt a voting mechanism, so the implementation cost is relatively high. Summary of the invention

[0006] In order to solve the above technical problems, the present disclosure provides a comprehensive protection method and related devices against side channel attacks and fault attacks.

[0007] A first aspect of the present disclosure provides a comprehensive protection method against side channel attacks and fault attacks, comprising performing the following steps in each round of a symmetric cryptographic algorithm:

[0008] Acquire initial data, the initial data including input data, a plurality of random numbers, and an XOR result of the input data and the random numbers;

[0009] The data included in the initial data are processed respectively by a first operation module using a linear operation of a symmetric cryptographic algorithm to obtain a plurality of first components;

[0010] Performing deduplication processing on the results obtained by performing pairwise differences on a plurality of the first components and removing the first components obtained by processing the input data to obtain intermediate data;

[0011] The data included in the intermediate data are processed respectively by a second operation module of the symmetric cryptographic algorithm to obtain a plurality of second components;

[0012] Divide the plurality of the second components into a plurality of data groups, perform XOR on the data of the second components in the same data group obtained through processing to obtain the first component obtained through processing of the input data;

[0013] Calculate the XOR results of the second components included in each of the multiple data groups, and determine whether the multiple XOR results calculated are equal. If they are equal, output any of the XOR results calculated; if they are not equal, do not output any of the XOR results calculated.

[0014] Optionally, there are multiple first operation modules in the symmetric cryptographic algorithm, the operation rules adopted by the multiple first operation modules are the same and the multiple first operation modules are arranged in a predetermined order;

[0015] The comprehensive protection method further comprises: constructing a first random sequence, and arranging the data included in the initial data according to the first random sequence;

[0016] The data included in the initial data are processed respectively by the first operation module of the symmetric encryption algorithm, including: for a data included in the initial data, the data is processed by the first operation module having the same arrangement sequence number as the data.

[0017] Optionally, there are multiple second operation modules in the symmetric cryptographic algorithm, the operation rules adopted by the multiple second operation modules are the same and the multiple second operation modules are arranged in a predetermined order;

[0018] The comprehensive protection method further comprises: constructing a second random sequence, and arranging the data included in the intermediate data according to the second random sequence;

[0019] The data included in the intermediate data are processed respectively by the second operation module of the symmetric encryption algorithm, including: for one data included in the intermediate data, the data is processed by the second operation module having the same arrangement sequence number as the data.

[0020] Optionally, constructing the first random sequence includes: extracting a plurality of first sub-data from an XOR result of at least two of the random numbers, wherein the first sub-data have a one-to-one correspondence with data included in the initial data; for a data included in the initial data, determining a size arrangement sequence number of the first sub-data corresponding to the data in the plurality of the first sub-data as the arrangement sequence number of the data to generate the first random sequence;

[0021] Constructing a second random order includes: extracting a plurality of second sub-data from the XOR results of at least two of the first components, wherein the second sub-data have a one-to-one correspondence with the data included in the intermediate data; for a data included in the intermediate data, determining the size arrangement sequence number of the second sub-data corresponding to the data in the plurality of the second sub-data as the arrangement sequence number of the data to generate the second random order.

[0022] Optionally, extracting a plurality of first sub-data from an XOR result of at least two of the random numbers comprises: splitting a plurality of binary numbers arranged successively in an XOR result of at least two of the random numbers into a plurality of the first sub-data;

[0023] Extracting a plurality of second sub-data from the XOR results of at least two of the first components includes: splitting a plurality of binary numbers arranged successively in the XOR results of at least two of the first components into a plurality of the second sub-data.

[0024] Optionally, dividing the plurality of second components into a plurality of data groups includes: selecting second components included in the same data group from the plurality of second components according to the first random order and the second random order.

[0025] Optionally, the comprehensive protection method further includes:

[0026] Determine an XOR result of at least two of the data included in the initial data as a random number used in the next round;

[0027] An XOR result of at least two of the second components is determined as another random number used in the next round.

[0028] Optionally, the second operation module includes a nonlinear operation unit, and the nonlinear operation unit adopts a multi-stage pipeline structure divided based on a preset threshold condition.

[0029] The second aspect of the present disclosure provides an integrated protection device for resisting side channel attacks and fault attacks, comprising: a processor, a memory, and a computer program stored on the memory and executable on the processor, wherein when the computer program is executed by the processor, the steps of any one of the integrated protection methods described in the first aspect are implemented.

[0030] A third aspect of the present disclosure provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of any one of the comprehensive protection methods described in the first aspect are implemented.

[0031] Beneficial effects of the present disclosure:

[0032] The comprehensive protection method against side channel attacks and fault attacks provided by the present disclosure comprises the following steps executed in each round of a symmetric cryptographic algorithm: the input data, a plurality of random numbers and the XOR results of the input data and the random numbers included in the initial data are processed respectively by a first operation module of the symmetric cryptographic algorithm using linear operation to obtain a plurality of first components; the results obtained by performing pairwise XOR processing on the plurality of first components and the first components obtained by processing the input data are eliminated to obtain intermediate data; the data included in the intermediate data are processed respectively by a second operation module of the symmetric cryptographic algorithm to obtain a plurality of second components; the plurality of second components are divided into a plurality of data groups, and the data of the second components in the same data group obtained by processing are XORed to obtain the first components obtained by processing the input data; the XOR results of the second components included in each of the plurality of data groups are calculated, and it is judged whether the plurality of XOR results obtained by calculation are equal, if they are equal, any one of the XOR results obtained by calculation is output, and if they are not equal, any one of the XOR results obtained by calculation is not output.

[0033] In the above-mentioned comprehensive protection method, the side channel information generated by the operation of multiple random numbers and the XOR results of the input data and the random numbers is used as noise to cover the side channel information generated by the input data during the operation process; and, during the operation process, the results obtained by the XOR of multiple first components are deduplicated and the first components obtained by the input data are eliminated, so that the subsequent operations will not increase the correlation due to the participation of multiple random numbers and the XOR results of the input data and the random numbers in the operation, and the side channel information generated by the input data during the operation process using the correlation analysis cannot be realized. Therefore, the side channel information generated by the input data during the operation process cannot be obtained during the entire operation process, which can effectively resist side channel attacks. In addition, the deduplication of the results obtained by the XOR of multiple first components and the elimination of the first components obtained by the input data can reduce the computing link, thereby reducing the protection resource overhead.

[0034] In addition, in the above-mentioned comprehensive protection method, the XOR results of the second components included in each of the multiple data groups are calculated and it is determined whether the multiple XOR results obtained by calculation are equal, wherein, if they are equal, any one of the XOR results obtained by calculation is output so as to continue to perform subsequent operations of the symmetric cryptographic algorithm or obtain encryption or decryption results; if they are not equal, it means that some data groups include erroneous second components due to fault injection. In this case, any XOR result obtained by calculation is not output, including not outputting the correct XOR result obtained by calculation to prevent statistical invalid fault attacks from propagating to subsequent operations, and also including not outputting the erroneous XOR result obtained by calculation to resist differential fault attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] The above and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings.

[0036] Figure 1 Shown are the steps performed in each round of a symmetric cryptographic algorithm by a comprehensive protection method provided by an embodiment of the present disclosure;

[0037] Figure 2 FIG. 1 is a schematic diagram of an exemplary implementation process of data sharing in an embodiment of the present disclosure;

[0038] Figure 3 The figure is a schematic diagram of an exemplary implementation process of the first round of protected AES encryption in one embodiment of the present disclosure;

[0039] Figure 4 Shown is an exemplary data flow and random number flow of each of the sequence selector, arbitrator A and arbitrator B in the first round of implementation of AES encryption in one embodiment of the present disclosure;

[0040] Figure 5 Shown is a schematic diagram of the structure of a comprehensive protection device for resisting side channel attacks and fault attacks in another embodiment of the present disclosure. DETAILED DESCRIPTION

[0041] In order to facilitate the understanding of the present disclosure, the present disclosure will be described more comprehensively below with reference to the relevant drawings. The preferred embodiments of the present disclosure are given in the drawings. However, the present disclosure can be implemented in different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the understanding of the content of the present disclosure more thorough and comprehensive.

[0042] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which the present disclosure belongs. The terms used in the specification of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.

[0043] An embodiment of the present disclosure provides a comprehensive protection method against side channel attacks and fault attacks. Figure 1 The following are the steps performed by the comprehensive protection method in each round of the symmetric cryptographic algorithm. Figure 1 As shown, the comprehensive protection method performs the following steps in each round of the symmetric cryptographic algorithm:

[0044] Step S110, obtaining initial data, the initial data including input data, multiple random numbers, and an XOR result of the input data and the random numbers.

[0045] Step S120: Process the data included in the initial data respectively by using a first operation module using linear operation of a symmetric cryptographic algorithm to obtain a plurality of first components.

[0046] Specifically, in this step, the first operation module processes the input data to obtain a corresponding first component, processes a random number to obtain a corresponding first component, and processes an XOR result of the plaintext and the random number to obtain a corresponding first component. Therefore, the number of first components is equal to the number of data included in the initial data.

[0047] Step S130, performing deduplication processing on the results obtained by performing pairwise differences on the plurality of first components and removing the first components obtained by processing the input data to obtain intermediate data.

[0048] It should be noted that the result of XORing the first components obtained by processing the first operation module for the two data included in the initial data is equal to the first component obtained by processing the XOR result of the two data by the first operation module, so the result obtained by XORing the multiple first components pairwise is the first component obtained by processing the result obtained by XORing the data included in the initial data by the first operation module. Since the initial data includes input data, multiple random numbers and the XOR result of the input data and the random numbers, it is determined according to the XOR operation rules that the input data and repeated data exist in the result obtained by XORing the data included in the initial data pairwise, so the result obtained by XORing the multiple first components pairwise correspondingly contains the first component obtained by processing the input data and repeated data, and the above de-duplication processing is to leave only one data in the repeated data.

[0049] Step S140: Process the data included in the intermediate data respectively through the second operation module of the symmetric encryption algorithm to obtain a plurality of second components.

[0050] It should be noted that the first operation module and the second operation module are two operation modules used in the process of symmetric cryptographic algorithms performing encryption or decryption. The first operation module and the second operation module used by different symmetric cryptographic algorithms may be completely different, and the second operation module may use linear operation and / or nonlinear operation.

[0051] Step S150, dividing the plurality of second components into a plurality of data groups, wherein the data of the second components in the same data group obtained by processing are XORed with the input data to obtain the first component obtained by processing.

[0052] It should be noted that the data obtained by processing the second component is the data included in the intermediate data. As described above, the intermediate data includes the first component obtained by processing the XOR result of the two data included in the initial data by the first operation module. Since the order of the operation and XOR operation of the first operation module is interchanged and does not affect the operation result, the data included in the intermediate data can be XORed by the XOR result of the two data included in the initial data and then processed by the first operation module after XOR. In this way, there are multiple groups of data combinations in the intermediate data that can obtain the first component obtained by processing the input data after XOR, and correspondingly, multiple second components can also be divided into multiple data groups as mentioned above.

[0053] Step S160, calculating the XOR results of the second components included in each of the multiple data groups, and determining whether the multiple XOR results calculated are equal, wherein if they are equal, executing step S170, otherwise executing step S180.

[0054] It should be noted that when the correct input data is obtained in the above step S110 and no faults are injected into the first operation module and the second operation module of the symmetric encryption algorithm, the multiple XOR results obtained by the above calculation are equal. Therefore, this step is to determine whether there is a fault injected into the operation process of at least part of the data.

[0055] Step S170, output any XOR result obtained by calculation.

[0056] Specifically, the symmetric cryptographic algorithm performs encryption or decryption through round iterations, so if the current round is not the last round, any XOR result calculated is output as input data for the next round; if the current round is the last round, any XOR result calculated is output as the final result of encryption or decryption of the symmetric cryptographic algorithm. Since step S170 is executed based on the judgment result in step S160, the input data for the next round or the final result of encryption or decryption of the symmetric cryptographic algorithm output by step S170 is credible.

[0057] Step S180: Do not output any XOR result obtained by calculation.

[0058] It should be noted that, when the multiple XOR results calculated in step S160 are not equal, all or part of the multiple XOR results are erroneous due to fault injection. If the XOR results that are erroneous due to fault injection are output, they will be attacked by differential faults. For the case where some of the XOR results are erroneous due to fault injection, if the XOR results that are not erroneous are output, they may be attacked by statistical invalid faults. Step S180 includes not outputting the correct XOR results calculated, which can prevent the statistical invalid fault attacks from propagating to subsequent operations; step S180 also includes not outputting the erroneous XOR results calculated, which can resist differential fault attacks.

[0059] In practice, an alarm can be issued in time when the calculated XOR results are not equal, so that relevant staff can be notified in time to take measures to assist in resisting attacks. In addition, the output data can be set to zero when the calculated XOR results are not equal, so that the differential fault attack cannot use valid data for analysis.

[0060] In an optional embodiment, there are multiple first operation modules in the symmetric encryption algorithm, the multiple first operation modules use the same operation rules and the multiple first operation modules are arranged in a predetermined order, and the above-mentioned comprehensive protection method also includes: constructing a first random order, and arranging the data included in the initial data in the first random order; step S120, processing the data included in the initial data respectively by the first operation modules of the symmetric encryption algorithm, including: for a data included in the initial data, processing the data by the first operation module having the same arrangement sequence number as the data, so that the first operation module for processing each data in the initial data is random, thereby avoiding attackers from attacking the data link in a targeted manner, which is conducive to strengthening resistance to attacks.

[0061] Furthermore, there are multiple second operation modules in the symmetric encryption algorithm, and the operation rules adopted by the multiple second operation modules are the same and the multiple second operation modules are arranged in a predetermined order. The above-mentioned comprehensive protection method also includes: constructing a second random order, and arranging the data included in the intermediate data in the second random order; step S140, processing the data included in the intermediate data respectively by the second operation modules of the symmetric encryption algorithm, including: for a data included in the intermediate data, processing the data by the second operation module having the same arrangement sequence number as the data, so that the second operation module for processing each data in the intermediate data is also random, thereby effectively avoiding attackers from attacking the data link in a targeted manner, which is conducive to further strengthening resistance to attacks.

[0062] The following is an illustrative description of the comprehensive protection method provided by the embodiment of the present disclosure using the symmetric encryption algorithm AES. In this example, the initial data includes plaintext, multiple random numbers, and the XOR result of the plaintext and the random numbers, wherein the plaintext exists as input data. Therefore, this example is described by using the first round of operations in the AES encryption process.

[0063] In the AES specification, the plaintext block length is 128 bits, and the key length can be any of 128 bits, 192 bits, and 256 bits. This article takes the key length of 128 bits as an example. AES is an iterative symmetric encryption algorithm. Each round of encryption includes byte replacement, row shift, column mixing, and round key addition. Each round of decryption includes reverse row shift, reverse byte replacement, round key addition, and reverse column mixing. Among them, byte replacement is completed through a defined replacement table. Specifically, the encryption process is implemented through an S box, and the decryption process is implemented through an inverse S box.

[0064] It should be noted that the S-box implementation adopts the idea of ​​secret sharing and multi-party computing based on threshold implementation. Each set of input data input into the symmetric encryption algorithm is shared and can be shared as multiple inputs. Figure 2 As shown in the figure, the input data x of the symmetric encryption algorithm is shared as x0, x1 and x2, while the input data y of the symmetric encryption algorithm is shared as y0, y1 and y2. The three shared components enter the nonlinear operation, and the output data after the expansion layer and the compression layer are also three shared components. Figure 2 The function f output in is divided into functions f0, f1 and f2.

[0065] Figure 3 The figure shows an exemplary implementation process of the first round of AES encryption protected by the comprehensive protection method provided by the embodiment of the present application, wherein there are two random numbers in the initial data; Figure 4 FIG. 2 shows an exemplary data flow and random number flow of the sequence selector, arbitrator A and arbitrator B respectively during the first round of implementation. Figure 3 and Figure 4 As shown, the first round of implementation of AES encryption includes:

[0066] 1) The initial data includes plaintext Variable (i.e. data A), the XOR result of plaintext Variable and random number R1 (i.e. data B), random number R1 (i.e. data C), the XOR result of plaintext Variable and random number R2 (i.e. data D), and random number R2 (i.e. data E) and is sequentially input into the sequence selector. It should be understood that the random number R1 and the random number R2 are each equal to the bit length of the plaintext Variable, so that each can perform a bitwise XOR operation with the plaintext Variable.

[0067] 2) The sequence selector constructs a first random sequence, and arranges the input data in the first random sequence and then outputs them to a plurality of first operation modules. Specifically, the operation rules adopted by the plurality of first operation modules are the same and the plurality of first operation modules are arranged in a predetermined sequence. For a data included in the initial data, the data is input to a first operation module having an arrangement sequence number that is the same as the arrangement sequence number of the data in the first random sequence.

[0068] In some examples, the sequence selector can construct the first random order through the following process: extracting multiple first sub-data from the XOR result of at least two random numbers, and the first sub-data has a one-to-one correspondence with the data included in the initial data; for a data included in the initial data, determining the size arrangement number of the first sub-data corresponding to the data in the multiple first sub-data as the arrangement number of the data to generate the first random order.

[0069] For example, the 25-bit binary numbers arranged successively in the XOR result of the random number R1 and the random number R2 are split into 5-bit units, thereby successively extracting five first sub-data 0x9, 0x6, 0x8, 0x3 and 0x5. Moreover, the arrangement sequence number of any first sub-data in the XOR result of the random number R1 and the random number R2 is equal to the arrangement sequence number of the data included in the corresponding initial data when input to the sequence selector, so that the first sub-data 0x9 corresponds to data A, the first sub-data 0x6 corresponds to data B, the first sub-data 0x8 corresponds to data C, the first sub-data 0x3 corresponds to data D, and the first sub-data 0x5 corresponds to data E. Since the five first sub-data are arranged from small to large as follows: 0x3<0x5<0x6<0x8<0x9, the first random order is shown in the figure: data D, data E, data B, data C, data A. It should be understood that in other examples, the first random order can be generated according to the order in which multiple first sub-data are arranged from large to small. The above-mentioned 25-bit binary number is, for example, the upper 25 bits or the lower 25 bits of the XOR result of the random number R1 and the random number R2. In this example, the number of bits included in the data of multiple first sub-data extracted is less than the number of bits included in the XOR result of the random number R1 and the random number R2. In other examples, the number of bits included in the data of multiple first sub-data extracted may also be equal to the number of bits included in the XOR result of the random number R1 and the random number R2.

[0070] In addition, the sequence selector may also determine the XOR result of at least two of the data included in the initial data as the random number R2 used in the next round. For example, the sequence selector XORs the result of the XOR of the plaintext Variable and the random number R1 of the current round with the random number R2 of the current round to obtain the random number R2 used in the next round.

[0071] 3) The linear operation used by the first operation module is row shift (Shift_Row), so for one of the input initial data, a first component obtained by row shift will be output accordingly. If the function used for row shift is recorded as g, a total of five first components g(D), g(E), g(B), g(C) and g(A) will be output. Then the five first components g(D), g(E), g(B), g(C) and g(A) are input to arbitrator A.

[0072] 4) Arbitrator A performs deduplication processing on the results of pairwise differences of the five first components g(D), g(E), g(B), g(C) and g(A), and removes the first component obtained by processing the plain text to obtain intermediate data.

[0073] Specifically, the first component g(D)=g(Variable⊕R2), g(E)=g(R2), g(B)=g(Variable⊕R1), g(C)=g(R1), and g(A)=g(Variable). Since the XOR result of the first components obtained by processing the first operation module for the two data included in the initial data is equal to the first component obtained by processing the XOR result of the two data by the first operation module, the XOR results of the five first components are: g(Variable), g(R1⊕R2), g(Variable⊕R1⊕R2), g(R2), g(Variable⊕R1⊕R2), g(R1⊕R2), g(Variable⊕R2), g(Variable), g(R1) and g(Variable⊕R1), so the intermediate data includes six data: g(R1⊕R2), g(Variable⊕R1⊕R2), g(R2), g(Variable⊕R2), g(R1) and g(Variable⊕R1).

[0074] In addition, arbitrator A will also construct a second random order, and arrange the data included in the obtained intermediate data in the second random order and output it to multiple second operation modules. Specifically, the multiple second operation modules use the same operation rules and the multiple second operation modules are arranged in a predetermined order. For a data included in the intermediate data, the data is input into a second operation module whose arrangement number is the same as the arrangement number of the data in the second random order.

[0075] In some examples, arbitrator A can construct a second random order through the following process: extract multiple second sub-data from the XOR result of at least two first components, and the second sub-data has a one-to-one correspondence with the data included in the intermediate data; for one data included in the intermediate data, determine the size arrangement sequence number of the second sub-data corresponding to the data in the multiple second sub-data as the arrangement sequence number of the data to generate a second random order. Among them, extracting multiple second sub-data from the XOR result of at least two first components can include: splitting the multiple binary numbers arranged successively in the XOR result of at least two first components into multiple second sub-data. The above shows how the sequence selector generates the first random order according to the XOR result of at least two random numbers. Here, the above content can be referred to to generate the second random order according to the XOR result of at least two first components, and the specific process will not be repeated. Figure 4 It is shown that the arbitrator A generates a second random sequence according to the XOR result of the first components g(C) and g(E).

[0076] 5) The second operation module includes a linear operation unit and a nonlinear operation unit, wherein the nonlinear operation unit is an S-box, and the nonlinear operation adopted is byte replacement; the linear operation adopted by the linear operation unit is column mixing (Mix_column) or round key addition (Add Round key). In some examples, the nonlinear operation unit can adopt a multi-stage pipeline structure divided based on a preset threshold condition, such as a three-stage pipeline structure, which can effectively resist the side channel attack on the nonlinear operation using clock glitches. Since the linear operation unit and the nonlinear operation unit each process an input data and then output a data, when the function adopted by the second operation module is recorded as H, a total of six second components H(g(Variable⊕R1⊕R2)), H(g(R1)), H(g(R1⊕R2)), H(g(Variable⊕R2)), H(g(R2)), and H(g(Variable⊕R1)) are output, and then these six second components are input to the arbitrator B.

[0077] 6) Arbitrator B receives the first random sequence input by the sequence selector and the second random sequence input by the arbitrator A, and selects the second component included in the same data group from the multiple second components according to the first random sequence and the second random sequence, then calculates the XOR results of the second components included in the multiple data groups, and determines whether the multiple XOR results calculated are equal. If they are equal, any one of the XOR results calculated is output; if they are not equal, any one of the XOR results calculated is not output and the output data can be set to zero in some instances.

[0078] for Figure 3In the example shown, the second components H(g(Variable⊕R1)) and H(g(R1)) form a data group, or the second components H(g(B)) and H(g(C)) form a data group; the second components H(g(Variable⊕R2)) and H(g(R2)) form another data group, or the second components H(g(D)) and H(g(E)) form a data group; the second components H(g(R1⊕R2)) and H(g(Variable⊕R1⊕R2)) form another data group. It can be seen that the second components included in the same data group can be determined according to the arrangement order of each data in the initial data received by the sequence selector. Since the sequence selector and arbitrator A each randomly scramble the data calculation link, arbitrator B needs to adjust the order according to the first random order and the second random order.

[0079] In addition, the arbitrator B further determines the XOR result of the at least two second components as another random number R2 used in the next round. Figure 3 and Figure 4 In , data flow is represented by solid lines with arrows, and random number flow is represented by dashed lines with arrows. Figure 3 and Figure 4 The dotted line with an arrow in the middle shows that during the round iteration of the symmetric encryption algorithm, only the random number input at the beginning of the symmetric encryption algorithm is needed, and the first random sequence and the second random sequence thereafter and the two random numbers used in the next round can all be generated within the algorithm steps, and the required random numbers are less than other methods.

[0080] It should be understood that after the first round of the AES encryption is completed, the next round of AES encryption is to be performed. For the example in which the puncher B sets the output data to zero when the multiple XOR results calculated are not equal, the next round of AES encryption will set the input data to the output data of the arbitrator B and continue the operation using the next round R2 output by the sequence selector and the next round R1 output by the arbitrator B, wherein, when the multiple XOR results calculated by the puncher B are not equal, the relevant staff can also terminate the operation based on the alarm.

[0081] The embodiment of the present disclosure also provides a comprehensive protection device 1300 for resisting side channel attacks and fault attacks, such as Figure 5 As shown, it includes a memory 1310 and a processor 1320, and a program stored in the memory 1310 and executable on the processor 1320. When the program is executed by the processor 1320, each process of each embodiment of the above-mentioned comprehensive protection method can be implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0082] Of course, the integrated protection device 1300 for resisting side channel attacks and fault attacks may also include auxiliary sub-devices such as a power supply component 1330 , a network interface 1340 , and an input / output interface 1350 .

[0083] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions, or by controlling related hardware through instructions, and the instructions can be stored in a computer-readable storage medium and loaded and executed by a processor. To this end, the embodiments of the present disclosure also provide a computer-readable storage medium, on which a computer program or instruction is stored, and when the computer program or instruction is executed by the processor, each process of each embodiment of the above-mentioned comprehensive protection method can be implemented. Among them, computer-readable storage media, such as U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (RandomAccess Memory, RAM), disk or optical disk, etc., can store program code.

[0084] Since the instructions stored in the readable storage medium can execute the steps in any of the comprehensive protection methods provided in the embodiments of the present disclosure, the beneficial effects that can be achieved by any of the comprehensive protection methods provided in the embodiments of the present disclosure can be achieved. For details, please refer to the previous embodiments, which will not be repeated here. The specific implementation of each of the above operations can be referred to the previous embodiments, which will not be repeated here.

[0085] It should be noted that, when describing each embodiment in this specification, the focus is on the differences from other embodiments, and the same or similar parts between the embodiments can be understood by reference to each other. For the system embodiment, since it is basically similar to the method embodiment, the relevant parts can refer to the description of the method embodiment.

[0086] In addition, it should be noted that in the apparatus and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. Moreover, the steps of performing the above-mentioned series of processing can be naturally performed in chronological order according to the order of description, but it is not necessary to perform them in chronological order, and some steps can be performed in parallel or independently of each other. For those of ordinary skill in the art, it is understood that all or any steps or components of the method and apparatus of the present invention can be implemented in any computing device (including processors, storage media, etc.) or a network of computing devices in hardware, firmware, software or a combination thereof, which can be achieved by those of ordinary skill in the art using their basic programming skills after reading the description of the present invention.

[0087] Finally, it should be noted that: Obviously, the above embodiments are only examples for clearly illustrating the present disclosure, and are not intended to limit the implementation methods. For ordinary technicians in the relevant field, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to list all the implementation methods here. The obvious changes or modifications derived from this are still within the scope of protection of the present disclosure.

Claims

1. A comprehensive protection method against side channel attacks and fault attacks, comprising performing the following steps in each round of a symmetric cryptographic algorithm: Acquire initial data, the initial data including input data, a plurality of random numbers, and an XOR result of the input data and the random numbers; The data included in the initial data are processed respectively by a first operation module using a linear operation of a symmetric cryptographic algorithm to obtain a plurality of first components; Performing deduplication processing on the results obtained by performing pairwise differences on a plurality of the first components and removing the first components obtained by processing the input data to obtain intermediate data; The data included in the intermediate data are processed respectively by a second operation module of the symmetric cryptographic algorithm to obtain a plurality of second components; Divide the plurality of the second components into a plurality of data groups, perform XOR on the data of the second components in the same data group obtained through processing to obtain the first component obtained through processing of the input data; Calculate the XOR results of the second components included in each of the multiple data groups, and determine whether the multiple XOR results obtained by calculation are equal. If they are equal, output any of the XOR results obtained by calculation; if they are not equal, do not output any of the XOR results obtained by calculation.

2. The comprehensive protection method according to claim 1, wherein: There are multiple first operation modules in the symmetric cryptographic algorithm, the operation rules used by the multiple first operation modules are the same and the multiple first operation modules are arranged in a predetermined order; The comprehensive protection method further comprises: constructing a first random sequence, and arranging the data included in the initial data according to the first random sequence; The data included in the initial data are processed respectively by the first operation module of the symmetric encryption algorithm, including: for a data included in the initial data, the data is processed by the first operation module having the same arrangement sequence number as the data.

3. The comprehensive protection method according to claim 2, wherein: There are multiple second operation modules in the symmetric cryptographic algorithm, the operation rules used by the multiple second operation modules are the same and the multiple second operation modules are arranged in a predetermined order; The comprehensive protection method further comprises: constructing a second random sequence, and arranging the data included in the intermediate data according to the second random sequence; The data included in the intermediate data are processed respectively by the second operation module of the symmetric encryption algorithm, including: for one data included in the intermediate data, the data is processed by the second operation module having the same arrangement sequence number as the data.

4. The comprehensive protection method according to claim 3, wherein: Constructing a first random sequence, comprising: extracting a plurality of first sub-data from an exclusive OR result of at least two of the random numbers, wherein the first sub-data have a one-to-one correspondence with the data included in the initial data; for a data included in the initial data, determining a size arrangement sequence number of the first sub-data corresponding to the data in the plurality of the first sub-data as the arrangement sequence number of the data to generate the first random sequence; Constructing a second random order includes: extracting a plurality of second sub-data from the XOR results of at least two of the first components, wherein the second sub-data have a one-to-one correspondence with the data included in the intermediate data; for a data included in the intermediate data, determining the size arrangement sequence number of the second sub-data corresponding to the data in the plurality of the second sub-data as the arrangement sequence number of the data to generate the second random order.

5. The comprehensive protection method according to claim 4, wherein: Extracting a plurality of first sub-data from the XOR result of at least two of the random numbers comprises: splitting a plurality of binary numbers arranged successively in the XOR result of at least two of the random numbers into a plurality of the first sub-data; Extracting a plurality of second sub-data from the XOR results of at least two of the first components includes: splitting a plurality of binary numbers arranged successively in the XOR results of at least two of the first components into a plurality of the second sub-data.

6. The comprehensive protection method according to claim 3, wherein: Dividing the plurality of second components into a plurality of data groups comprises: selecting second components included in the same data group from the plurality of second components according to the first random order and the second random order.

7. The comprehensive protection method according to claim 3, further comprising: Determine an XOR result of at least two of the data included in the initial data as a random number used in the next round; An XOR result of at least two of the second components is determined as another random number used in the next round.

8. The comprehensive protection method according to claim 1, wherein: The second operation module includes a nonlinear operation unit, and the nonlinear operation unit adopts a multi-stage pipeline structure divided based on a preset threshold condition.

9. A comprehensive protection device against side channel attacks and fault attacks, comprising: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the steps of the comprehensive protection method according to any one of claims 1 to 8 when executed by the processor.

10. A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the comprehensive protection method according to any one of claims 1 to 8.