Quick evaluation method and device for modeling type side channel attack discriminator

By collecting the power consumption curve of the cryptographic chip, calculating the leaked model label value, and building and evaluating the differentiator model, the problem of low efficiency and insufficient accuracy of modeling side channel attack differentiator evaluation is solved, and a fast and accurate differentiator evaluation is achieved.

CN119996019AActive Publication Date: 2025-05-13BEIHANG UNIV
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510224339.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-13
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

In the prior art, the evaluation method for modeling side channel attack differentiators is difficult to measure the discriminating ability and generalization of the differentiator in a short time, and the evaluation time is long, and the efficiency and accuracy are insufficient.

Method used

By collecting the power consumption curve of the target cryptographic chip when executing the target algorithm, establishing a modeling set and verification set, based on the target algorithm's attacked intermediate value object and preset leakage model, calculate the leakage model label value of each energy trace, build a target differentiator model, predict the probability distribution of the value of the intermediate value leakage model of each energy trace in the verification set, obtain a key guess score, and calculate the leading index to evaluate the distinction function.

Benefits of technology

It realizes the discriminating ability and generalization of the differentiator in a short time, improves the evaluation efficiency, meets the requirements of evaluation accuracy, and solves the problems of long evaluation time and low efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996019A_ABST
    Figure CN119996019A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, in particular to a rapid evaluation method and device for a modeling type side channel attack differentiator, and the method comprises the steps: collecting the energy trace data of a target cryptographic chip during the execution of a target algorithm, and building a modeling set and a verification set; calculating an intermediate value of each energy trace in the modeling set, and mapping the intermediate value through a leakage model to form a label so as to construct a target discriminator model; the probability distribution of the value of the intermediate value leakage model of each energy trace in the verification set is predicted through the target discriminator model, then the key guessing score of each energy trace in the verification set is obtained, the leading index of the discriminator is calculated, and the discrimination function evaluation result of the target discriminator model is determined through the leading index. According to the method, the leading index can be obtained through multi-layer calculation according to the key guessing score, the distinguishing capability and generalization of the distinguisher can be measured in a short time, and meanwhile, the efficiency and accuracy of distinguishing capability evaluation of the distinguisher are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a rapid evaluation method and device for a modeling-type side-channel attack distinguisher. Background Art

[0002] A side channel attack is an attack that infers sensitive data (such as keys) by analyzing the physical information (such as power consumption, electromagnetic radiation, time delay, sound, etc.) leaked by cryptographic devices during operation. Unlike traditional mathematical cryptanalysis, side channel attacks do not rely on weaknesses in the algorithm itself, but rather exploit information leakage in physical implementations.

[0003] In the related technology, the evaluation method for modeling side-channel attack discriminators uses the discriminator to analyze the collected data to observe its ability to extract sensitive information such as keys in the data, or conducts comparative experiments on the discriminator to be evaluated with existing discriminators with good performance on the same data set to compare their discrimination effects, running time and other indicators.

[0004] However, in the related technologies, the evaluation methods for modeling side-channel attack discriminators often find it difficult to measure the discriminative ability and generalization of the discriminator in a short period of time. The evaluation time is long and the evaluation efficiency and accuracy are insufficient, which needs to be solved urgently. Summary of the invention

[0005] The present application provides a method and device for quickly evaluating a modeling-type side-channel attack discriminator, so as to solve the problems in the related art that the evaluation method for the modeling-type side-channel attack discriminator is often difficult to measure the distinguishing ability and generalization of the discriminator in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient.

[0006] The first aspect of the present application provides a rapid evaluation method for a modeling-based side-channel attack discriminator, comprising the following steps: collecting a power consumption curve of a target cryptographic chip when executing a target algorithm, so as to establish a modeling set and a verification set according to energy trace data corresponding to the power consumption curve; calculating the leakage model label value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and a preset leakage model, so as to construct a target discriminator model according to the modeling set and the leakage model label value; predicting the probability distribution of the intermediate value leakage model value of each energy trace in the verification set through the target discriminator model, and obtaining a key guessing score for each energy trace in the verification set according to the probability distribution, so as to calculate a leading index of the target discriminator model according to the key guessing score, and determining the discrimination function evaluation result of the target discriminator model through the leading index.

[0007] Optionally, in one embodiment of the present application, the leakage model label value of each energy trace in the modeling set is calculated based on the attacked intermediate value object of the target algorithm and the preset leakage model, including: calculating the intermediate value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the plaintext and key pair corresponding to each energy trace in the modeling set; based on the preset leakage model, performing leakage model mapping on the intermediate value to calculate the leakage model label value of each energy trace in the modeling set.

[0008] Optionally, in one embodiment of the present application, constructing a target discriminator model based on the modeling set and the leakage model label value includes: determining the number of target output categories of the target discriminator model based on the number of values ​​of the preset leakage model, so as to determine the original discriminator model based on the number of target output categories; training the original discriminator model in combination with the modeling set and the leakage model label value to obtain trained new model parameters, so as to determine the target discriminator model based on the new model parameters.

[0009] Optionally, in one embodiment of the present application, obtaining the key guessing score of each energy trace in the verification set according to the probability distribution includes: based on the probability distribution, solving the key probability distribution of each energy trace in the verification set using the target relationship between key guessing and intermediate values; determining the key guessing score of each energy trace in the verification set according to the key probability distribution.

[0010] Optionally, in one embodiment of the present application, the leading index of the target distinguisher model is calculated based on the key guessing score to determine the distinguishing function evaluation result of the target distinguisher model through the leading index, including: calculating the mean and variance of the key guessing score, and calculating the comprehensive statistics of the key guessing based on the mean and variance of the key guessing score; arranging the key guesses according to the comprehensive statistics to obtain a permutation array of possible key values, and performing weighted summation on the elements in the permutation array that meet preset conditions to obtain the leading index.

[0011] Optionally, in one embodiment of the present application, the calculation formula of the leading index is:

[0012]

[0013] Among them, LD is the leading degree indicator, n is the number of elements selected from the permutation array, and C[i] is the element in the permutation array.

[0014] The second aspect of the present application provides a rapid evaluation device for a modeling-type side-channel attack discriminator, including: an acquisition module, used to collect the power consumption curve of the target cryptographic chip when executing the target algorithm, so as to establish a modeling set and a verification set according to the energy trace data corresponding to the power consumption curve; a construction module, used to calculate the leakage model label value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and a preset leakage model, so as to build a target discriminator model according to the modeling set and the leakage model label value; an evaluation module, used to predict the probability distribution of the intermediate value leakage model value of each energy trace in the verification set through the target discriminator model, and obtain the key guessing score of each energy trace in the verification set according to the probability distribution, so as to calculate the leading index of the target discriminator model according to the key guessing score, and determine the discrimination function evaluation result of the target discriminator model through the leading index.

[0015] Optionally, in one embodiment of the present application, the construction module includes: a first calculation unit, used to calculate the intermediate value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the plaintext and key pair corresponding to each energy trace in the modeling set; a second calculation unit, used to perform leakage model mapping on the intermediate value based on the preset leakage model to calculate the leakage model label value of each energy trace in the modeling set.

[0016] Optionally, in one embodiment of the present application, the construction module includes: a first determination unit, used to determine the number of target output categories of the target discriminator model according to the number of values ​​of the preset leakage model, so as to determine the original discriminator model according to the number of target output categories; an updating unit, used to train the original discriminator model in combination with the modeling set and the leakage model label value to obtain trained new model parameters, so as to determine the target discriminator model according to the new model parameters.

[0017] Optionally, in one embodiment of the present application, the evaluation module includes: a solving unit, used to solve the key probability distribution of each energy trace in the verification set based on the probability distribution and using the target relationship between the key guess and the intermediate value; a second determination unit, used to determine the key guessing score of each energy trace in the verification set according to the key probability distribution.

[0018] Optionally, in one embodiment of the present application, the evaluation module includes: a calculation unit, used to calculate the mean and variance of the key guessing scores, and calculate the comprehensive statistics of the key guessing based on the mean and variance of the key guessing scores; a processing unit, used to arrange the key guesses according to the comprehensive statistics to obtain a permutation array of possible key values, and perform weighted summation on the elements in the permutation array that meet preset conditions to obtain the leading index.

[0019] Optionally, in one embodiment of the present application, the calculation formula of the leading index is:

[0020]

[0021] Among them, LD is the leading degree indicator, n is the number of elements selected from the permutation array, and C[i] is the element in the permutation array.

[0022] The third aspect of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement a rapid evaluation method for a modeling-like side-channel attack distinguisher as described in the above embodiment.

[0023] The fourth aspect embodiment of the present application provides a computer-readable storage medium, which stores a computer program, which, when executed by a processor, implements the above-mentioned rapid evaluation method of the modeling-like side-channel attack distinguisher.

[0024] The fifth aspect embodiment of the present application provides a computer program product, including a computer program, which, when executed, is used to implement the above-mentioned rapid evaluation method of the modeling-like side-channel attack distinguisher.

[0025] The embodiment of the present application can construct a target discriminator model to predict the probability distribution of the leakage model value of the intermediate value of each energy trace, and obtain the key guessing score of each energy trace in the verification set according to the probability distribution to calculate the leading index of the target discriminator model, so as to determine the evaluation result of the distinguishing function of the target discriminator model. Thus, it is realized that the probability of the intermediate value of each energy trace in the verification set predicted by the target discriminator model is mapped to the probability distribution of key guessing, the key guessing score of the target prediction model is obtained, and the leading index is obtained through multi-layer calculation according to the key guessing score, and then the distinguishing effect of the target discriminator model is determined according to the leading index, so that while meeting the evaluation accuracy required in the actual scenario, the distinguishing ability and generalization of the discriminator can be measured in a short time, which greatly improves the efficiency of the distinguishing ability evaluation of the discriminator. Thus, it solves the problems in the related art that the evaluation method for the modeling side channel attack discriminator is often difficult to measure the distinguishing ability and generalization of the discriminator in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient.

[0026] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0028] Figure 1 A flowchart of a rapid evaluation method for a modeling-like side channel attack distinguisher provided according to an embodiment of the present application;

[0029] Figure 2 A schematic diagram of the network structure of a target distinguisher model according to an embodiment of the present application;

[0030] Figure 3 A flowchart of a rapid evaluation method for a modeling-like side channel attack distinguisher according to an embodiment of the present application;

[0031] Figure 4 A schematic diagram of the structure of a rapid evaluation device for a modeling-based side channel attack distinguisher provided according to an embodiment of the present application;

[0032] Figure 5 It is a schematic diagram of the structure of an electronic device provided according to an embodiment of the present application.

[0033] Reference numerals:

[0034] 10- Rapid evaluation device for modeling side channel attack distinguisher: 100- acquisition module, 200- construction module and 300- evaluation module; 501- memory, 502- processor and 503- communication interface. DETAILED DESCRIPTION

[0035] Embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0036] The following describes a rapid evaluation method and device for a modeling-type side-channel attack discriminator according to an embodiment of the present application with reference to the accompanying drawings. In view of the problems that the evaluation method for a modeling-type side-channel attack discriminator in the related technologies mentioned in the above background technology is often difficult to measure the distinguishing ability and generalization of the discriminator in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient, the present application provides a rapid evaluation method for a modeling-type side-channel attack discriminator, in which a target discriminator model can be constructed to predict the probability distribution of the value of the intermediate value leakage model of each energy trace, and the key guessing score of each energy trace in the verification set is obtained according to the probability distribution to calculate the leading index of the target discriminator model, thereby determining the evaluation result of the distinguishing function of the target discriminator model. Thus, the probability of the middle value of each energy trace in the target discriminator model prediction verification set is mapped to the probability distribution of key guessing, and the key guessing score of the target prediction model is obtained; and the leading index is obtained through multi-layer calculation based on the key guessing score, and then the discrimination effect of the target discriminator model is determined based on the leading index, so that while meeting the evaluation accuracy required in actual scenarios, the discriminator's discrimination ability and generalization can be measured in a short time, greatly improving the efficiency of the discriminator's discrimination ability evaluation. Thus, the problems in the related technology that the evaluation method for the modeling side channel attack discriminator is often difficult to measure the discriminator's discrimination ability and generalization in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient are solved.

[0037] Specifically, Figure 1 A flowchart of a rapid evaluation method for a modeling-like side-channel attack distinguisher provided in an embodiment of the present application.

[0038] like Figure 1 As shown, the rapid evaluation method of the modeling-like side channel attack distinguisher includes the following steps:

[0039] In step S101, a power consumption curve of a target cryptographic chip when executing a target algorithm is collected to establish a modeling set and a verification set according to energy trace data corresponding to the power consumption curve.

[0040] It is understood that the target cryptographic chip here refers to an integrated circuit chip that can perform cryptographic operations such as information encryption, decryption, and key management. The target algorithm here can be understood as a special calculation method used to encrypt or decrypt information in the target cryptographic chip.

[0041] Modeling-based side channel attacks include two stages: modeling and attack. In the modeling stage, the attacker specifies plaintext and keys on the controlled device, collects the corresponding energy traces, and builds a probabilistic mapping model from energy traces to algorithm-sensitive information, namely, a discriminator. In the attack stage, the attacker uses the established discriminator model to analyze the energy traces collected from the target device and then infer the key information. The effectiveness of modeling-based side channel attacks is highly dependent on the established discriminator, but it is usually difficult for attackers to measure the discriminative ability and generalization of the discriminator in a short period of time.

[0042] In some embodiments, when evaluating the distinguishing function of the discriminator, the present application can first collect the power consumption curve of the target cryptographic chip when executing the target algorithm, and then establish a modeling set and a verification set based on the energy trace data corresponding to the power consumption curve, so as to use the modeling set and the verification set to build a discriminator model and perform a distinguishing evaluation.

[0043] Since cryptographic chips have different power consumption performance when processing different data and performing different operations, the power consumption curve here refers to the curve of power consumption changes over time obtained by using tools such as oscilloscopes to measure and record the power consumption changes generated by a certain cryptographic chip in real time when running the target cryptographic algorithm. This curve can reflect the voltage or current changes in the cryptographic chip when running the target cryptographic algorithm. Converting it into a curve or trajectory of energy consumption changes over time is the energy trace. By extracting key-related features from the energy trace and separating them from irrelevant noise, information related to the password, such as the key, can be extracted from it.

[0044] For example, the present application may first implement the target cryptographic algorithm to be attacked on the target cryptographic chip and connect it to an acquisition device such as an oscilloscope.

[0045] Then, the embodiment of the present application can be based on the different energy trace quantity requirements of the modeling set and the verification set, that is, the number of energy traces N in the modeling set that needs to be collected P , verify the number of energy traces in the trace set N V , randomly generate N P Group 1 plaintext and key pair Then randomly generate N V Second plaintext and a fixed key k *Among them, the i-th energy trace corresponds to the j-th byte of the plaintext and the key, respectively. i,j and k i,j express.

[0046] Next, the embodiment of the present application can control the target cryptographic chip to generate the first plaintext and key pair (d i ,k i ),1≤i≤N P Execute the encryption algorithm once and save the waveform collected by the oscilloscope, which is recorded as T i =(t i,1 ,t i,2 ,…,t i,m ), where m is the number of sample points on the collected energy trace, then the modeling set energy trace can be recorded as the modeling set

[0047] Similarly, for each verification set corresponding to the second plaintext d j ,N P +1≤j≤N P +N V In this embodiment of the application, the key can be set to a fixed key k * , and control the cryptographic chip to execute an encryption algorithm, and save the waveform collected by the oscilloscope, recorded as T j =(t j,1 ,t j,2 ,…,t j,m ), finally, the energy traces of all test sets can be recorded as the validation set

[0048] It should be noted that the modeling set finally obtained in the embodiment of the present application includes but is not limited to the first plaintext, the key pair and the corresponding power consumption curve, and the verification set includes but is not limited to the second plaintext, the fixed key and the corresponding power consumption curve, wherein the modeling set can be used to construct a distinguisher model, and the verification set can be used to verify the distinguishing effect of the distinguisher model.

[0049] Step S102, based on the attacked intermediate value object of the target algorithm and the preset leakage model, calculate the leakage model label value of each energy trace in the modeling set to build a target discriminator model according to the modeling set and the leakage model label value.

[0050] It is understandable to professionals in this technical field that the energy trace can be analyzed using the discriminator model to infer the key information, and the effectiveness of modeling-type side-channel attacks is highly dependent on the established discriminator.

[0051] In certain embodiments, after obtaining the modeling set, the present application can calculate the intermediate value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the selected preset leakage model, and obtain the energy trace label value, that is, the leakage model label value, through leakage model mapping, so as to construct a target discriminator model according to the modeling set and the leakage model label value.

[0052] Among them, the preset leakage model here can be understood as different leakage models selected for the attacked intermediate value object, which can be determined according to the needs of professional and technical personnel in this field and the actual attacked intermediate value object. This is only an exemplary explanation without specific limitation. The target discriminator model here can be understood as a discriminator model constructed according to the modeling set, which will vary depending on the data and training methods in the modeling set.

[0053] The leakage model here can be understood as a model established based on the ways, rules, paths and characteristics of various information leaked by intermediate value objects during the operation of the target algorithm. Through these leakage models, the information leaked by intermediate value objects can be effectively collected and utilized.

[0054] For example, in a side channel attack based on power consumption analysis, the leakage model may describe the relationship between the power consumption changes corresponding to different operations during the execution of the algorithm and the intermediate value. By measuring the power consumption curve of the target device during the execution of the algorithm, the attacker can analyze the power consumption characteristics related to the specific intermediate value based on the leakage model, and then infer the information of the intermediate value.

[0055] And, the intermediate value here refers to the intermediate calculation results generated by the target algorithm during its operation. These intermediate values ​​play a key role in the execution process of the algorithm. They are the transition state from input to output of the algorithm. The intermediate value is the intermediate value selected from these intermediate values. The attacked intermediate value object can be understood as the intermediate value that is most valuable and likely to be attacked, which is selected from the numerous intermediate values ​​in the algorithm execution process and is most likely to be attacked, such as those that are most likely to be attacked, for attack targets such as cracking the algorithm, obtaining sensitive information, or interfering with the normal operation of the algorithm.

[0056] After determining the attacked intermediate value objects of the target algorithm and their corresponding leakage models, the embodiments of the present application can calculate the intermediate value of each energy trace in the modeling set, calculate the leakage model mapping of the intermediate value corresponding to each energy trace in the modeling set according to the mapping relationship, use it as the label value of the sample, and then combine the energy trace data in the modeling set to construct a target discriminator model.

[0057] Optionally, in one embodiment of the present application, based on the attacked intermediate value object of the target algorithm and a preset leakage model, the leakage model label value of each energy trace in the modeling set is calculated, including: based on the attacked intermediate value object of the target algorithm and the plaintext and key pair corresponding to each energy trace in the modeling set, the intermediate value of each energy trace in the modeling set is calculated; based on the preset leakage model, the intermediate value is mapped to a leakage model to calculate the leakage model label value of each energy trace in the modeling set.

[0058] In the actual execution process, based on the attacked intermediate value object of the target algorithm and the preset leakage model, when calculating the leakage model label value of each energy trace in the modeling set, this application mainly uses the known target algorithm, the attacked intermediate value object and the plaintext and key pair corresponding to each energy trace in the modeling set, and calculates the intermediate value corresponding to each energy trace according to the operation rules of the encryption algorithm. For example, in the AES encryption algorithm, the intermediate value output by a round function is calculated according to the given plaintext and key.

[0059] Then, the embodiment of the present application can use the selected leakage model to perform leakage mapping on the intermediate value, thereby calculating the leakage model label value of each energy trace in the modeling set.

[0060] Taking the key in the verification set in the AES encryption algorithm and other embodiments as an example, assuming that the bth byte of the attack key (0≤b≤15) is selected, the bth byte output by the first round of S-boxes needs to be selected as the intermediate value object; then, a suitable leakage model is selected. Let its value range be r represents the number of possible values ​​of the leakage model. If the Hamming weight is used as the leakage model, the leakage model mapping (label) of the i-th energy trace can be expressed as 1≤i≤N P , where HW(·) represents the Hamming weight function, Sbox(·) represents the S-box function, and i represents the energy trace index.

[0061] Optionally, in one embodiment of the present application, a target discriminator model is constructed based on a modeling set and a leakage model label value, including: determining the number of target output categories of the target discriminator model based on the number of values ​​of a preset leakage model, so as to determine the original discriminator model based on the number of target output categories; training the original discriminator model in combination with the modeling set and the leakage model label value to obtain new model parameters after training, so as to determine the target discriminator model based on the new model parameters.

[0062] In certain embodiments, when constructing a discriminator model, the present application first needs to determine the number of target output categories of the target discriminator model, thereby determining the original discriminator model.

[0063] For example, the embodiment of the present application may, but is not limited to, select an original discriminator model from a multivariate Gaussian noise template, a neural network, or other discriminator types, and initialize the parameters of the original discriminator model to ensure that the number of output categories of the discriminator is the same as the number of possible values ​​r of the leakage model. Taking the construction of a multilayer perceptron neural network model as an example, the network structure can be as follows: Figure 2 As shown, it includes an input layer, three intermediate layers and one output layer.

[0064] Then, the embodiment of the present application can train the original discriminator model in combination with the modeling set and the leakage model label value to obtain the trained new model parameters, and then determine the target discriminator model according to the new model parameters.

[0065] Taking the neural network model discriminator as an example, the present application can train the original discriminator model based on the target loss function, target learning rate, target number of iterations, combined with the modeling set and the leakage model label value, to obtain the trained new model parameters, so as to determine the target discriminator model according to the new model parameters.

[0066] Among them, the target loss function here can be understood as a function that measures the difference between the prediction result of the target discriminator model and the true label (that is, the leakage model mapping of the intermediate value corresponding to each energy trace in the modeling set). The target loss function can be used to quantify the performance of the target discriminator model under the current parameter settings, that is, the degree to which the predicted value of the target discriminator model deviates from the true value. The target learning rate here refers to a hyperparameter that controls the step size of the model parameter update during the training process of the target discriminator model. When updating the model parameters, the learning rate determines the magnitude of each parameter update. The target number of iterations is the number of training rounds of the original discriminator model.

[0067] For example, the training loss function can be set to the cross entropy loss function, the learning rate can be set to 0.001, the number of training rounds can be set to 100, and the energy traces and their labels in the modeling set can be used to update the discriminator parameters to obtain the trained target discriminator model.

[0068] It should be noted that when the target discriminator model is a statistical test type or a probability distribution type that does not require information such as the target loss function, target learning rate, or target number of iterations, the original discriminator model can be updated using only the modeling set and the leaked model label value to obtain the updated new model parameters, thereby determining the target discriminator model.

[0069] Step S103, predicting the probability distribution of the intermediate value leakage model value of each energy trace in the verification set through the target discriminator model, and obtaining the key guessing score of each energy trace in the verification set according to the probability distribution, so as to calculate the leading index of the target discriminator model according to the key guessing score, and determine the discrimination function evaluation result of the target discriminator model through the leading index.

[0070] As a possible implementation method, after constructing the target discriminator model, the embodiment of the present application can use the target discriminator model to predict the probability distribution of the leakage model value of the intermediate value of each energy trace in the verification set, where the leakage model here refers to the leakage model type that has been set when constructing the modeling set and the verification set.

[0071] Then, the embodiment of the present application can calculate the key guessing score of each energy trace in the verification set according to the probability distribution of the leakage model value of the intermediate value of each energy trace predicted by the target distinguisher model.

[0072] The key guessing score here can be understood as the corresponding score assigned to each key guess value. It is a quantitative indicator for measuring the reliability or possibility of the key guessing result, which helps to more intuitively evaluate the rationality and credibility of each key guess and help determine the most likely key guess.

[0073] Furthermore, in order to achieve a more accurate and faster evaluation of the target discriminator model's ability to distinguish energy traces, the embodiment of the present application proposes a leading index to evaluate the target discriminator model. Specifically, the embodiment of the present application can calculate the leading index of the discriminator based on the key guessing score, and determine the evaluation result of the distinguishing function of the target discriminator model through the leading index.

[0074] The following is a further explanation of this process.

[0075] Optionally, in one embodiment of the present application, a key guessing score for each energy trace in the verification set is obtained according to a probability distribution, including: based on the probability distribution, solving the key probability distribution of each energy trace in the verification set using a target relationship between key guessing and intermediate values; and determining the key guessing score for each energy trace in the verification set according to the key probability distribution.

[0076] Based on the relevant descriptions of other embodiments, it can be understood that the present application can calculate the key guessing score of each energy trace in the verification set according to the probability distribution of the leakage model value of the intermediate value of each energy trace predicted by the target distinguisher model.

[0077] During the actual execution process, the embodiment of the present application can use the target relationship between key guessing and intermediate values ​​to solve the key probability distribution of each energy trace in the verification set based on the probability distribution of the intermediate value leakage model value of each energy trace predicted by the target distinguisher model.

[0078] For example, the present application can verify that each energy trace T in the set i Input the target discriminator model, and then predict the leakage model of the intermediate value of the energy trace as l j The probability Pr(l j |T i ).

[0079] Next, the embodiment of the present application can use the target relationship between the key guess and the intermediate value to obtain the energy trace T i The key probability distribution is obtained, and then the key guessing score is obtained. Among them, the target relationship between the key guess and the intermediate value is usually determined based on the internal structure and operation rules of the target cryptographic algorithm in the actual scenario. Taking the AES algorithm as an example, its typical relationship involves operations such as round key addition, byte replacement, row shift, and column mixing. Therefore, the specific target relationship between the key guess and the intermediate value can be determined by professional and technical personnel in this field according to actual conditions. It is only an exemplary description here without specific limitation.

[0080] Taking the AES algorithm as an example, the energy trace T i The probability value corresponding to the key guess k is Then the key guess k is in the energy trace T i The score can be set to the logarithmic form of the above probability value s i (k) = log(Pr(k i,j =k|T i )).

[0081] Repeating this step, the score of the key guess on each energy trace of the verification set can be obtained, which can be expressed as follows but is not limited to:

[0082]

[0083] Optionally, in one embodiment of the present application, the leading index of the distinguisher is calculated according to the key guessing score to determine the distinguishing function evaluation result of the target distinguisher model through the leading index, including: calculating the mean and variance of the key guessing score, and calculating the comprehensive statistics of the key guessing based on the mean and variance of the key guessing score; arranging the key guesses according to the comprehensive statistics to obtain an array of possible key values, and performing weighted summation on the elements in the array that meet the preset conditions to obtain the leading index. The calculation formula of the leading index can be, but is not limited to, expressed as:

[0084]

[0085] Among them, LD is the leading degree indicator, n is the number of elements selected from the permutation array, and C[i] is the element in the permutation array.

[0086] In some embodiments, after obtaining different key guessing scores, the embodiments of the present application can calculate the leading index of the distinguisher according to the key guessing score, so as to determine the distinguishing function evaluation result of the target distinguisher model through the leading index.

[0087] First, the embodiment of the present application can calculate the mean and variance of the key guessing score. Take the following key guessing score as an example:

[0088]

[0089] Then the mean of the key guessing scores (μ0,…,μ 255 ) and variance (Var0,…,Var 255 ) can be expressed as follows, but not limited to:

[0090]

[0091] Then, the embodiment of the present application can calculate the comprehensive statistics of the key guessing according to the mean and variance of the key guessing score, so as to arrange the key guessing according to the comprehensive statistics to obtain the arrangement array of the possible values ​​of the key, and perform weighted summation on the elements in the arrangement array that meet the preset conditions to obtain the leading index. Among them, the preset conditions here can be understood as the conditions for selecting elements from the array after arrangement, for example, the first 5 elements, the first 10 elements, etc. of the array after arrangement.

[0092] Specifically, the embodiment of the present application can be used to perform the operation except for the correct key k * All key guesses k∈{0,…,255}\k * , calculate the statistic And sort the statistics in ascending order to obtain the array C = sorted ({c0, ..., c 255}\c k* ).

[0093] Then, the first n elements of the array C are weighted and summed to obtain the leading degree index, wherein the calculation result of the leading degree index can be, but is not limited to, expressed as:

[0094]

[0095] Here, n is usually 5.

[0096] Additionally, in order to further reduce the evaluation time, the embodiment of the present application may also calculate the mean of all key guessing scores (μ0, ..., μ 255 ) after the correct key k * All key guesses k∈{0,…,255}\k * The mean of the keys is sorted in descending order to obtain the n key guesses with the highest mean (k0,…,k n-1 ), usually n can be 5; the mean calculation formula of the key guessing score is also:

[0097]

[0098] Next, the embodiment of the present application can guess the key (k0, ..., k n-1 ), calculate the score variance and the statistics array Among them, the variance and statistic arrays can be expressed as follows:

[0099]

[0100] Finally, the weighted sum of array C is performed to obtain a simplified evaluation result of the leading degree indicator, which can be expressed as follows but is not limited to:

[0101]

[0102] According to the leading index, the embodiment of the present application can determine the evaluation result of the discrimination effect of the target discriminator model, that is, the higher the leading index, the better the discrimination effect of the target discriminator model.

[0103] The following is a specific example to further illustrate the rapid evaluation method of the modeling-based side channel attack distinguisher in the embodiment of the present application.

[0104] Figure 3 This is a flowchart of a rapid evaluation method for a modeling-like side channel attack distinguisher according to an embodiment of the present application. Figure 3 As shown:

[0105] Step S301, using an oscilloscope to collect the power consumption curve of the cryptographic chip when executing the target cryptographic algorithm, obtain energy trace data, and divide it into a modeling set and a verification set, which are used to build a distinguisher model and verify the distinguishing effect of the distinguisher model respectively;

[0106] Step S302, for the target cryptographic algorithm, determine the intermediate value object and the leakage model to be attacked, and map the leakage model of the intermediate value calculated according to each energy trace in the modeling set as a label value;

[0107] Step S303, while ensuring that the input and output of the discriminator model are adapted to the prepared data, the original discriminator model parameters are updated using the modeling set to construct a target discriminator model;

[0108] Step S304: Use the established target discriminator model to predict the intermediate value probability of the energy trace on the verification trace set, and map it to the key hypothesis score, so as to calculate the leading index and evaluate the discrimination effect of the discriminator model.

[0109] According to the rapid evaluation method of the modeling-type side channel attack distinguisher proposed in the embodiment of the present application, the probability distribution of the leakage model value of the intermediate value of each energy trace predicted by the target distinguisher model can be constructed, and the key guessing score of each energy trace in the verification set is obtained according to the probability distribution to calculate the leading index of the target distinguisher model, thereby determining the evaluation result of the distinguishing function of the target distinguisher model. Thus, it is realized that the probability of the intermediate value of each energy trace in the prediction verification set of the target distinguisher model is mapped to the probability distribution of key guessing, and the key guessing score of the target prediction model is obtained, and the leading index is obtained through multi-layer calculation according to the key guessing score, and then the distinguishing effect of the target distinguisher model is determined according to the leading index, so that while meeting the evaluation accuracy required in the actual scenario, the distinguishing ability and generalization of the distinguisher can be measured in a short time, which greatly improves the efficiency of the distinguishing ability evaluation of the distinguisher. Thus, the evaluation method for the modeling-type side channel attack distinguisher in the related art is often difficult to measure the distinguishing ability and generalization of the distinguisher in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient.

[0110] Next, a rapid evaluation device for a modeling-like side-channel attack distinguisher proposed according to an embodiment of the present application is described with reference to the accompanying drawings.

[0111] Figure 4 It is a structural schematic diagram of a rapid evaluation device for a modeling-type side-channel attack distinguisher according to an embodiment of the present application.

[0112] like Figure 4 As shown, the rapid evaluation device 10 of the modeling-type side-channel attack distinguisher includes: a collection module 100, a construction module 200 and an evaluation module 300.

[0113] The acquisition module 100 is used to acquire the power consumption curve of the target cryptographic chip when executing the target algorithm, so as to establish a modeling set and a verification set according to the energy trace data corresponding to the power consumption curve.

[0114] The construction module 200 is used to calculate the leakage model label value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the preset leakage model, so as to construct a target discriminator model according to the modeling set and the leakage model label value.

[0115] The evaluation module 300 is used to predict the probability distribution of the values ​​of the intermediate value leakage model of each energy trace in the verification set through the target discriminator model, and obtain the key guessing score of each energy trace in the verification set according to the probability distribution, so as to calculate the leading index of the target discriminator model according to the key guessing score, and determine the discrimination function evaluation result of the target discriminator model through the leading index.

[0116] Optionally, in one embodiment of the present application, the construction module 200 includes: a first computing unit and a second computing unit.

[0117] Among them, the first calculation unit is used to calculate the intermediate value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the plaintext and key pair corresponding to each energy trace in the modeling set.

[0118] The second generating unit is used to perform leakage model mapping on the intermediate value based on the preset leakage model to calculate the leakage model label value of each energy trace in the modeling set.

[0119] Optionally, in one embodiment of the present application, the construction module 200 includes: a first determination unit and an update unit.

[0120] The first determination unit is used to determine the number of target output categories of the target discriminator model according to the number of values ​​of the leakage model, so as to determine the original discriminator model according to the number of target output categories.

[0121] The second determination unit is used to train the original discriminator model in combination with the modeling set and the leakage model label value to obtain trained new model parameters, so as to determine the target discriminator model according to the new model parameters.

[0122] Optionally, in one embodiment of the present application, the evaluation module 300 includes: a solving unit and a second determining unit.

[0123] Among them, the solving unit is used to solve the key probability distribution of each energy trace in the verification set based on the probability distribution and using the target relationship between the key guess and the intermediate value.

[0124] The second determining unit is used to determine the key guessing score of each energy trace in the verification set according to the key probability distribution.

[0125] Optionally, in one embodiment of the present application, the evaluation module 300 includes: a computing unit and a processing unit.

[0126] The calculation unit is used to calculate the mean and variance of the key guessing scores, and calculate the comprehensive statistics of the key guessing based on the mean and variance of the key guessing scores.

[0127] The processing unit is used to arrange the key guesses according to the comprehensive statistics to obtain an arrangement array of possible key values, and to perform weighted summation on the elements in the arrangement array that meet the preset conditions to obtain a leading index.

[0128] Optionally, in one embodiment of the present application, the calculation formula of the leading index may be, but is not limited to, expressed as:

[0129]

[0130] Among them, LD is the leading degree indicator, n is the number of elements selected from the permutation array, and C[i] is the element in the permutation array.

[0131] It should be noted that the aforementioned explanation of the embodiment of the rapid assessment method for the modeling-type side-channel attack distinguisher is also applicable to the rapid assessment device for the modeling-type side-channel attack distinguisher of this embodiment, and will not be repeated here.

[0132] According to the rapid evaluation device of the modeling-type side channel attack distinguisher proposed in the embodiment of the present application, the probability distribution of the leakage model value of the intermediate value of each energy trace predicted by the target distinguisher model can be constructed, and the key guessing score of each energy trace in the verification set is obtained according to the probability distribution to calculate the leading index of the target distinguisher model, thereby determining the evaluation result of the distinguishing function of the target distinguisher model. Thus, it is realized that the probability of the intermediate value of each energy trace in the target distinguisher model prediction verification set is mapped to the probability distribution of key guessing, the key guessing score of the target prediction model is obtained, and the leading index is obtained by multi-layer calculation according to the key guessing score, and then the distinguishing effect of the target distinguisher model is determined according to the leading index, so that while meeting the evaluation accuracy required in the actual scene, the distinguishing ability and generalization of the distinguisher can be measured in a short time, which greatly improves the efficiency of the distinguishing ability evaluation of the distinguisher. Thus, the evaluation method for the modeling-type side channel attack distinguisher in the related art is often difficult to measure the distinguishing ability and generalization of the distinguisher in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient.

[0133] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may include:

[0134] A memory 501 , a processor 502 , and a computer program stored in the memory 501 and executable on the processor 502 .

[0135] When the processor 502 executes the program, the rapid evaluation method of the modeling-type side-channel attack distinguisher provided in the above embodiment is implemented.

[0136] Furthermore, the electronic device further comprises:

[0137] The communication interface 503 is used for communication between the memory 501 and the processor 502 .

[0138] The memory 501 is used to store computer programs that can be executed on the processor 502 .

[0139] The memory 501 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0140] If the memory 501, the processor 502 and the communication interface 503 are implemented independently, the communication interface 503, the memory 501 and the processor 502 can be connected to each other through a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0141] Optionally, in a specific implementation, if the memory 501, the processor 502 and the communication interface 503 are integrated on a chip, the memory 501, the processor 502 and the communication interface 503 can communicate with each other through an internal interface.

[0142] The processor 502 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.

[0143] An embodiment of the present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-mentioned rapid evaluation method for the modeling-like side-channel attack distinguisher.

[0144] An embodiment of the present application also provides a computer program product, including a computer program, which can run computer instructions. When the computer instructions are executed by a processor, the rapid evaluation method of the modeling-type side-channel attack distinguisher provided in the embodiment of the present application is implemented.

[0145] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.

[0146] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

[0147] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or N executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present application belong.

[0148] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in combination with these instruction execution systems, devices or apparatuses. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in combination with these instruction execution systems, devices or apparatuses. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or N wirings (electronic devices), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically by optically scanning the paper or other medium and then editing, interpreting or processing in other suitable ways as necessary and then storing it in a computer memory.

[0149] It should be understood that the various parts of the present application can be implemented by hardware, software, firmware or a combination thereof. In the above embodiment, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. If implemented by hardware, as in another embodiment, it can be implemented by any one or a combination of multiple of the following technologies known in the art: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0150] A person skilled in the art may understand that all or part of the steps in the method for implementing the above-mentioned embodiment may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiment.

[0151] In addition, each functional unit in each embodiment of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0152] The storage medium mentioned above may be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limiting the present application. A person of ordinary skill in the art may change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A fast evaluation method for modeling side channel attack distinguishers, characterized in that: The following steps are involved: Collecting a power consumption curve of a target cryptographic chip when executing a target algorithm, so as to establish a modeling set and a verification set according to energy trace data corresponding to the power consumption curve; Based on the attacked intermediate value object of the target algorithm and the preset leakage model, the leakage model label value of each energy trace in the modeling set is calculated to construct a target discriminator model according to the modeling set and the leakage model label value; The target discriminator model is used to predict the probability distribution of the values ​​of the intermediate value leakage model of each energy trace in the verification set, and the key guessing score of each energy trace in the verification set is obtained according to the probability distribution, so as to calculate the leading index of the target discriminator model according to the key guessing score, and determine the discrimination function evaluation result of the target discriminator model through the leading index.

2. The method according to claim 1, characterized in that The attacking intermediate value object of the target algorithm and the preset leakage model are used to calculate the leakage model label value of each energy trace in the modeling set, including: Based on the attacked intermediate value object of the target algorithm and the plaintext and key pair corresponding to each energy trace in the modeling set, calculate the intermediate value of each energy trace in the modeling set; Based on the preset leakage model, the intermediate value is subjected to leakage model mapping to calculate the leakage model label value of each energy trace in the modeling set.

3. The method according to claim 1, characterized in that The constructing a target discriminator model according to the modeling set and the leakage model label value includes: Determine the number of target output categories of the target discriminator model according to the number of values ​​of the preset leakage model, so as to determine the original discriminator model according to the number of target output categories; The original discriminator model is trained in combination with the modeling set and the leakage model label value to obtain trained new model parameters, so as to determine the target discriminator model according to the new model parameters.

4. The method according to claim 1, characterized in that The step of obtaining a key guessing score for each energy trace in the verification set according to the probability distribution includes: Based on the probability distribution, solving the key probability distribution of each energy trace in the verification set by using the target relationship between the key guess and the intermediate value; A key guessing score for each energy trace in the verification set is determined according to the key probability distribution.

5. The method according to claim 1, characterized in that The step of calculating the leading index of the target discriminator model according to the key guessing score to determine the discrimination function evaluation result of the target discriminator model through the leading index includes: Calculating the mean and variance of the key guessing scores, and calculating a comprehensive statistic of the key guessing based on the mean and variance of the key guessing scores; The key guesses are arranged according to the comprehensive statistics to obtain an arrangement array of possible key values, and weighted summation is performed on the elements in the arrangement array that meet preset conditions to obtain the leading index.

6. The method according to claim 1, characterized in that The calculation formula of the leading index is: Wherein, LD is the leading degree indicator, n is the number of elements selected from the permutation array, and C[i] is the element in the permutation array.

7. A rapid evaluation device for modeling side channel attack distinguisher, characterized in that: include: A collection module, used to collect the power consumption curve of the target cryptographic chip when executing the target algorithm, so as to establish a modeling set and a verification set according to the energy trace data corresponding to the power consumption curve; A construction module, configured to calculate the leakage model label value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the preset leakage model, so as to construct a target discriminator model according to the modeling set and the leakage model label value; An evaluation module is used to predict the probability distribution of the values ​​of the intermediate value leakage model of each energy trace in the verification set through the target discriminator model, and obtain the key guessing score of each energy trace in the verification set according to the probability distribution, so as to calculate the leading index of the target discriminator model according to the key guessing score, and determine the discrimination function evaluation result of the target discriminator model through the leading index.

8. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement a rapid evaluation method for a modeling-like side-channel attack distinguisher as described in any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement a rapid evaluation method for a modeling-like side-channel attack distinguisher as described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed, it is used to implement the rapid evaluation method of the modeling-like side-channel attack distinguisher as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Evaluation and training method of deep learning model for side channel attack

    CN113472515A

  • Calculation method of non-fixed-point scalar multiplication in national secret SM2 algorithm resisting SPA attack

    CN114527956A

  • XSS vulnerability detection method and device based on webpage code context

    CN116910761A

  • Side channel analysis method and device based on deep learning

    CN117792610A

  • System, Device, and Method of Detecting and Mitigating DNS Tunneling Attacks in a Communication Network

    US20220407870A1