Fast evaluation method and device for modeling side-channel attack distinguisher

By constructing a target discriminator model to predict the probability distribution of the middle value of the energy trace and the key guessing score, and using the leading index to evaluate the modeled side-channel attack discriminator, the problems of long evaluation time and low efficiency in the existing technology are solved, and a fast and accurate discriminator evaluation is achieved.

CN119996019BActive Publication Date: 2025-10-17BEIHANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510224339.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-10-17
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

In the existing technology, the evaluation method of modeling side-channel attack discriminators is difficult to measure the discriminative ability and generalization of the discriminator in a short time, and the evaluation time is long and the efficiency and accuracy are insufficient.

Method used

By collecting the power consumption curve of the target cryptographic chip, establishing a modeling set and a verification set, building a target discriminator model, predicting the probability distribution of the energy trace intermediate value leakage model value, and calculating the key guessing score, the leading index is used to evaluate the discrimination function of the discriminator model.

Benefits of technology

While meeting the evaluation accuracy requirements in actual scenarios, it can measure the discriminative ability and generalization of the discriminator in a short time, greatly improving the evaluation efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996019B_ABST
    Figure CN119996019B_ABST
Patent Text Reader

Abstract

The present application relates to the field of information security technology, and in particular to a rapid evaluation method and device for a modeling-type side-channel attack discriminator, wherein the method comprises: collecting energy trace data of a target cryptographic chip when executing a target algorithm to establish a modeling set and a verification set; calculating the median value of each energy trace in the modeling set and mapping it through a leakage model to form a label to construct a target discriminator model; predicting the probability distribution of the leakage model value of the median value of each energy trace in the verification set through the target discriminator model, and then obtaining the key guessing score of each energy trace in the verification set to calculate the leading index of the discriminator, and determining the discrimination function evaluation result of the target discriminator model through the leading index. The present application can obtain the leading index through multi-layer calculation based on the key guessing score, which can measure the discrimination ability and generalization of the discriminator in a short time, while greatly improving the efficiency and accuracy of the evaluation of the discrimination ability of the discriminator.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and in particular to a fast evaluation method and device for a modeling side-channel attack discriminator. BACKGROUND

[0002] A side-channel attack is an attack method that infers sensitive data (such as a key) by analyzing physical information (such as power consumption, electromagnetic radiation, time delay, sound, etc.) leaked by a cryptographic device during operation. Unlike traditional mathematical password analysis, a side-channel attack does not rely on weaknesses in the algorithm itself, but rather exploits information leakage in physical implementation.

[0003] In related technologies, the evaluation method for a modeling side-channel attack discriminator uses the discriminator to analyze the collected data, observes the extraction ability of the discriminator for sensitive information such as a key in the data, or compares the evaluation of the discriminator to be evaluated with an existing discriminator with better performance on the same data set, and compares their discrimination effect, running time, etc.

[0004] However, in related technologies, the evaluation method for a modeling side-channel attack discriminator often has difficulty measuring the discrimination ability and generalization of the discriminator in a short period of time, and the evaluation time is relatively long, and the evaluation efficiency and accuracy are insufficient, which needs to be solved. SUMMARY

[0005] The present application provides a fast evaluation method and device for a modeling side-channel attack discriminator to solve the problems in related technologies that the evaluation method for a modeling side-channel attack discriminator often has difficulty measuring the discrimination ability and generalization of the discriminator in a short period of time, and the evaluation time is relatively long, and the evaluation efficiency and accuracy are insufficient, etc.

[0006] The first aspect embodiment of the present application provides a fast evaluation method for a modeling side-channel attack discriminator, comprising the following steps: collecting power consumption curves of a target cryptographic chip when executing a target algorithm, to establish a modeling set and a verification set according to energy trace data corresponding to the power consumption curves; calculating a leakage model label value of each energy trace in the modeling set based on an attacked intermediate value object of the target algorithm and a preset leakage model, to construct a target discriminator model according to the modeling set and the leakage model label value; predicting a probability distribution of an intermediate value leakage model value of each energy trace in the verification set through the target discriminator model, and obtaining a key guess score of each energy trace in the verification set according to the probability distribution, to calculate a leading degree index of the target discriminator model according to the key guess score, and determine a discrimination function evaluation result of the target discriminator model through the leading degree index.

[0007] Optionally, in an embodiment of the present application, the calculating of the leakage model label value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the preset leakage model comprises: calculating an intermediate value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and a corresponding plaintext and key pair of each energy trace in the modeling set; and performing leakage model mapping on the intermediate value to calculate the leakage model label value of each energy trace in the modeling set based on the preset leakage model.

[0008] Optionally, in an embodiment of the present application, the constructing of the target discriminator model according to the modeling set and the leakage model label value comprises: determining a target output category number of the target discriminator model according to a value number of the preset leakage model, so as to determine an original discriminator model according to the target output category number; and training the original discriminator model in combination with the modeling set and the leakage model label value to obtain new model parameters of a trained model, so as to determine the target discriminator model according to the new model parameters.

[0009] Optionally, in an embodiment of the present application, the obtaining of the key guess score of each energy trace in the verification set according to the probability distribution comprises: solving a key probability distribution of each energy trace in the verification set by using a target relationship formula of key guess and intermediate value based on the probability distribution; and determining the key guess score of each energy trace in the verification set according to the key probability distribution.

[0010] Optionally, in an embodiment of the present application, the calculating of the lead degree index of the target discriminator model according to the key guess score, so as to determine the evaluation result of the discrimination function of the target discriminator model through the lead degree index, comprises: calculating a mean value and a variance of the key guess score, and calculating a comprehensive statistic of key guess based on the mean value and the variance of the key guess score; arranging the key guess according to the comprehensive statistic to obtain an arrangement array of key possible values, and performing weighted summation on elements in the arrangement array that meet a preset condition to obtain the lead degree index.

[0011] Optionally, in an embodiment of the present application, a calculation formula of the lead degree index is as follows:

[0012]

[0013] wherein, LD is the lead degree index, n is a number of elements selected from the arrangement array, and C[i] is an element in the arrangement array.

[0014] The second aspect embodiment of the application provides a fast evaluation device of a modeling side channel attack discriminator, comprising: a collection module, configured to collect power consumption curves of a target cryptographic chip when executing a target algorithm, so as to establish a modeling set and a verification set according to energy trace data corresponding to the power consumption curves; a construction module, configured to calculate a leakage model label value of each energy trace in the modeling set based on an attacked intermediate value object of the target algorithm and a preset leakage model, so as to construct a target discriminator model according to the modeling set and the leakage model label value; and an evaluation module, configured to predict a probability distribution of an intermediate value leakage model value of each energy trace in the verification set through the target discriminator model, and obtain a key guess score of each energy trace in the verification set according to the probability distribution, so as to calculate a leading degree index of the target discriminator model according to the key guess score, and determine a discrimination function evaluation result of the target discriminator model through the leading degree index.

[0015] Optionally, in an embodiment of the application, the construction module comprises: a first calculation unit, configured to calculate an intermediate value value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and a plaintext and key pair corresponding to each energy trace in the modeling set; and a second calculation unit, configured to perform leakage model mapping on the intermediate value value based on the preset leakage model, so as to calculate the leakage model label value of each energy trace in the modeling set.

[0016] Optionally, in an embodiment of the application, the construction module comprises: a first determination unit, configured to determine a target output category number of the target discriminator model according to a value number of the preset leakage model, so as to determine an original discriminator model according to the target output category number; and an updating unit, configured to train the original discriminator model in combination with the modeling set and the leakage model label value, so as to obtain new model parameters of a trained model, and determine the target discriminator model according to the new model parameters.

[0017] Optionally, in an embodiment of the application, the evaluation module comprises: a solving unit, configured to solve a key probability distribution of each energy trace in the verification set by using a target relationship formula of key guess and intermediate value based on the probability distribution; and a second determination unit, configured to determine a key guess score of each energy trace in the verification set according to the key probability distribution.

[0018] Optionally, in an embodiment of the present application, the evaluation module comprises: a calculation unit configured to calculate the mean and variance of the key guess score, and calculate a comprehensive statistic of the key guess based on the mean and variance of the key guess score; and a processing unit configured to arrange the key guess according to the comprehensive statistic to obtain an arrangement array of key possible values, and perform weighted summation on elements in the arrangement array that satisfy a preset condition to obtain the lead degree indicator.

[0019] Optionally, in an embodiment of the present application, the calculation formula of the lead degree indicator is:

[0020]

[0021] wherein, LD is the lead degree indicator, n is the number of elements selected from the arrangement array, and C[i] is an element in the arrangement array.

[0022] The third aspect embodiment of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the fast evaluation method of the modeling side channel attack discriminator as described in the above embodiments.

[0023] The fourth aspect embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the fast evaluation method of the modeling side channel attack discriminator as described above.

[0024] The fifth aspect embodiment of the present application provides a computer program product, comprising a computer program, and the computer program is executed to implement the fast evaluation method of the modeling side channel attack discriminator as described above.

[0025] The embodiment of the application can construct a target discriminator model to predict the probability distribution of the value of the intermediate value leakage model of each energy trace, and obtain the key guess score of each energy trace in the verification set according to the probability distribution to calculate the leading degree index of the target discriminator model, so as to determine the discrimination function evaluation result of the target discriminator model. Therefore, the probability of the target discriminator model predicting the intermediate value of each energy trace in the verification set is mapped to the probability distribution of the key guess, the key guess score of the target prediction model is obtained, the leading degree index is obtained through multi-layer calculation according to the key guess score, and the discrimination effect of the target discriminator model is determined according to the leading degree index, so that the discrimination ability and the generalization of the discriminator can be measured in a short time while meeting the evaluation accuracy required in the actual scene, and the efficiency of the discrimination ability evaluation of the discriminator is greatly improved. Therefore, the problems in the related art that the evaluation method for the modeling type side channel attack discriminator is difficult to measure the discrimination ability and the generalization of the discriminator in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient are solved.

[0026] Additional aspects and advantages of the application will be made apparent by the following description and the appended claims. BRIEF DESCRIPTION OF DRAWINGS

[0027] The above and / or additional aspects and advantages of the application will become apparent and be readily understood by considering the following detailed description, including the accompanying drawings, in which:

[0028] Figure 1 A flowchart of a fast evaluation method of a modeling type side channel attack discriminator according to an embodiment of the application;

[0029] Figure 2 A network structure diagram of a target discriminator model of an embodiment of the application;

[0030] Figure 3 A flowchart of a fast evaluation method of a modeling type side channel attack discriminator according to an embodiment of the application;

[0031] Figure 4 A structure diagram of a fast evaluation device of a modeling type side channel attack discriminator according to an embodiment of the application;

[0032] Figure 5 A structure diagram of an electronic device according to an embodiment of the application.

[0033] REFERENCE NUMERALS

[0034] 10 - fast evaluation device of modeling side-channel attack distinguisher: 100 - acquisition module, 200 - construction module and 300 - evaluation module; 501 - memory, 502 - processor and 503 - communication interface. DETAILED DESCRIPTION

[0035] Embodiments of the present application are described below in detail, examples of which are shown in the drawings, in which the same or similar notations represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by reference to the drawings are exemplary and are intended to explain the present application, and cannot be understood as limiting the present application.

[0036] The fast evaluation method and device of modeling side-channel attack distinguisher of the embodiments of the present application are described below with reference to the drawings. In view of the problems in the related art mentioned in the background art that the evaluation method for the modeling side-channel attack distinguisher is often difficult to measure the distinguishing ability and generalization of the distinguisher in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient, the present application provides a fast evaluation method for the modeling side-channel attack distinguisher. In the method, a target distinguisher model can be constructed to predict the probability distribution of the value of the intermediate value leakage model in each energy trace, and the key guess score of each energy trace in the verification set can be obtained according to the probability distribution to calculate the lead index of the target distinguisher model, so as to determine the evaluation result of the distinguishing function of the target distinguisher model. Thus, the probability of predicting the intermediate value of each energy trace in the verification set by the target distinguisher model is mapped to the probability distribution of key guessing, and the key guess score of the target prediction model is obtained; and the lead index is obtained by multi-layer calculation according to the key guess score, and the distinguishing effect of the target distinguisher model is determined according to the lead index, so as to meet the evaluation accuracy required in the actual scene, and also measure the distinguishing ability and generalization of the distinguisher in a short time, greatly improving the efficiency of the evaluation of the distinguishing ability of the distinguisher. Thus, the problems in the related art that the evaluation method for the modeling side-channel attack distinguisher is often difficult to measure the distinguishing ability and generalization of the distinguisher in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient are solved.

[0037] Specifically, Figure 1 A flowchart of a fast evaluation method for a modeling side-channel attack distinguisher provided by an embodiment of the present application is shown in FIG. 1.

[0038] As shown in FIG. 1, the fast evaluation method for the modeling side-channel attack distinguisher includes the following steps: Figure 1

[0039] In step S101, the power consumption curve of the target cryptographic chip when executing the target algorithm is collected to establish a modeling set and a verification set according to the energy trace data corresponding to the power consumption curve.​

[0040] It is understood that the target cryptographic chip here refers to an integrated circuit chip that can perform cryptographic operations such as information encryption, decryption, and key management. The target algorithm here can be understood as the special calculation method used to encrypt or decrypt information in the target cryptographic chip.

[0041] Modeling-based side-channel attacks involve two phases: modeling and attacking. In the modeling phase, the attacker specifies plaintext and a key on the controlled device, collects the corresponding energy traces, and constructs a probabilistic mapping model from the energy traces to algorithmic sensitive information, known as a discriminator. In the attack phase, the attacker uses the established discriminator model to analyze the energy traces collected from the target device and infer the key information. The effectiveness of modeling-based side-channel attacks is highly dependent on the established discriminator, but it is often difficult for an attacker to quickly measure the discriminative power and generalizability of the discriminator.

[0042] In some embodiments, when evaluating the distinguishing function of the discriminator, the present application can first collect the power consumption curve of the target cryptographic chip when executing the target algorithm, and then establish a modeling set and a verification set based on the energy trace data corresponding to the power consumption curve, so as to use the modeling set and the verification set to build a discriminator model and perform a distinguishing evaluation.

[0043] Because cryptographic chips exhibit different power consumption when processing different data and performing different operations, a power consumption curve, as used here, refers to a time-varying power consumption curve obtained by measuring and recording the power consumption changes generated by a specific cryptographic chip running a target cryptographic algorithm in real time using a tool such as an oscilloscope. This curve can reflect the voltage or current changes in the cryptographic chip during the execution of the target cryptographic algorithm. Converting this curve into a time-varying energy consumption curve or trajectory is known as an energy trace. By extracting key-related features from the energy trace and separating them from irrelevant noise, cryptographic-related information, such as the key, can be extracted.

[0044] For example, the present application may first implement the target cryptographic algorithm to be attacked on the target cryptographic chip and connect it to an acquisition device such as an oscilloscope.

[0045] Then, the embodiment of the present application can be based on the different energy trace quantity requirements of the modeling set and the verification set, that is, the number of energy traces N in the modeling set that needs to be collected P , the number of energy traces in the verification trace set N V , randomly generate N P Group first plaintext and key pair Then randomly generate N V Second plaintext and a fixed key k *wherein the i th energy trace corresponds to the j th byte of the plaintext and the key respectively represented by d i,j and k i,j .

[0046] Next, the embodiment of the present application can control the target cryptographic chip to perform the encryption algorithm once for each first plaintext and key pair (d i ,k i ), 1≤i≤N P corresponding to the modeling set, and save the waveform collected by the oscilloscope, denoted as T i =(t i,1 ,t i,2 ,…,t i,m ), where m is the number of sample points on the energy trace, and then the energy trace of the modeling set can be denoted as the modeling set

[0047] Similarly, for each second plaintext d j ,N P +1≤j≤N P +N V corresponding to the verification set, the embodiment of the present application can set its key as a fixed key k * , and control the cryptographic chip to perform the encryption algorithm once, and save the waveform collected by the oscilloscope, denoted as T j =(t j,1 ,t j,2 ,…,t j,m ), and finally, the energy traces of all test sets can be denoted as the verification set

[0048] It should be noted that the modeling set finally obtained in the embodiment of the present application includes but is not limited to the first plaintext, the key pair and the power consumption curve corresponding thereto, and the verification set includes but is not limited to the second plaintext, the fixed key and the power consumption curve corresponding thereto, wherein the modeling set can be used to construct a discriminator model, and the verification set can be used to verify the discrimination effect of the discriminator model.

[0049] In step S102, based on the attacked intermediate value object of the target algorithm and the preset leakage model, the leakage model label value of each energy trace in the modeling set is calculated, so as to construct the target discriminator model according to the modeling set and the leakage model label value.

[0050] It can be understood by those skilled in the art that the energy trace can be analyzed by using the discriminator model, and then the key information can be inferred, and the modeling side channel attack effect is highly dependent on the established discriminator.

[0051] In some embodiments, after obtaining the modeling set, the application can calculate the intermediate value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the selected preset leakage model, and obtain the label value of the energy trace, i.e., the leakage model label value, through the leakage model mapping, so as to construct the target discriminator model according to the modeling set and the leakage model label value.

[0052] The preset leakage model here can be understood as a different leakage model selected for the attacked intermediate value object, which can be determined according to the needs of the person skilled in the art and the actual attacked intermediate value object. Here, only exemplary description is made, without specific limitation. The target discriminator model here can be understood as a discriminator model constructed according to the modeling set, which will be different according to the data in the modeling set and the training mode.

[0053] The leakage model here can be understood as a model established according to the way, law, approach and characteristics of the intermediate value object leaking various information during the running of the target algorithm. Through these leakage models, the leaked information of the intermediate value object can be effectively collected and utilized.

[0054] For example, in a side-channel attack based on power analysis, the leakage model can describe the relationship between the power consumption change corresponding to different operations during the execution of the algorithm and the intermediate value. The attacker can analyze the power consumption characteristics related to a specific intermediate value according to the leakage model by measuring the power consumption curve of the target device during the execution of the algorithm, and then infer the information of the intermediate value.

[0055] In addition, the intermediate value here refers to the intermediate calculation result generated during the running of the target algorithm. These intermediate values play a key role in the execution process of the algorithm, and they are the transition state from input to output of the algorithm. The intermediate value is the intermediate value selected from these intermediate values. The attacked intermediate value object can be understood as those most valuable intermediate values that are most likely to be attacked for the purpose of cracking the algorithm, obtaining sensitive information or interfering with the normal operation of the algorithm, which are selected from numerous intermediate values in the execution process of the algorithm.

[0056] After determining the attacked intermediate value object of the target algorithm and the corresponding leakage model, the embodiments of the application can calculate the intermediate value of each energy trace in the modeling set, calculate the leakage model mapping of the corresponding intermediate value of each energy trace in the modeling set according to the mapping relationship, take it as the label value of the sample, and then combine the energy trace data in the modeling set to construct the target discriminator model.

[0057] Optionally, in an embodiment of the present application, based on the attacked intermediate value object of the target algorithm and the preset leakage model, the leakage model label value of each energy trace in the modeling set is calculated, including: based on the attacked intermediate value object of the target algorithm and the plaintext and key pair corresponding to each energy trace in the modeling set, the intermediate value value of each energy trace in the modeling set is calculated; based on the preset leakage model, the intermediate value value is mapped to the leakage model to calculate the leakage model label value of each energy trace in the modeling set.

[0058] In actual execution, when calculating the leakage model label value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the preset leakage model, the present application mainly uses the known target algorithm, the attacked intermediate value object, and the plaintext and key pair corresponding to each energy trace in the modeling set to calculate the intermediate value value corresponding to each energy trace according to the operation rule of the encryption algorithm. For example, in the AES encryption algorithm, the intermediate value value output by a certain round function is calculated according to the given plaintext and key.

[0059] Then the embodiment of the present application can use the selected leakage model to map the intermediate value value to the leakage, thereby calculating the leakage model label value of each energy trace in the modeling set.

[0060] Taking the key in the verification set in the AES encryption algorithm and other embodiments as an example, assuming that the bth byte (0≤b≤15) of the key is attacked, the bth byte of the output of the first round S-box is selected as the intermediate value object; then, a suitable leakage model is selected The value domain is denoted as r represents the number of possible values of the leakage model, and if the Hamming weight is used as the leakage model, the leakage model mapping (label) of the i th energy trace can be represented as 1≤i≤N P , wherein HW(·) represents the Hamming weight function, Sbox(·) represents the S-box function, and i represents the energy trace index.

[0061] Optionally, in an embodiment of the present application, the target discriminator model is constructed according to the modeling set and the leakage model label value, including: determining the target output category number of the target discriminator model according to the value number of the preset leakage model, to determine the original discriminator model according to the target output category number; training the original discriminator model in combination with the modeling set and the leakage model label value to obtain the new model parameter of the trained model, to determine the target discriminator model according to the new model parameter.

[0062] In some embodiments, when constructing the discriminator model, the present application first needs to determine the target output category number of the target discriminator model, thereby determining the original discriminator model.

[0063] For example, the embodiments of the present application can, but are not limited to, selecting one original discriminator model of a plurality of Gaussian noise templates, neural networks or other discriminator types, and initializing the parameters of the original discriminator model to ensure that the number of discriminator output categories is the same as the number of possible values r of the leakage model. Taking a multi-layer perceptron neural network model as an example, the network structure can be as shown in the following table, which includes an input layer, three intermediate layers and an output layer. Figure 2

[0064] Then, the embodiments of the present application can train the original discriminator model based on the modeling set and the leakage model label value to obtain the new model parameters after training, and then determine the target discriminator model according to the new model parameters.

[0065] Taking a neural network model discriminator as an example, the present application can train the original discriminator model based on the target loss function, the target learning rate, the target iteration number, the modeling set and the leakage model label value to obtain the new model parameters after training, so as to determine the target discriminator model according to the new model parameters.

[0066] Wherein, the target loss function can be understood here as a function of measuring the difference between the prediction result of the target discriminator model and the true label (i.e. the leakage model mapping of the intermediate value corresponding to each energy trace in the modeling set). The target loss function can be used to quantify the performance of the target discriminator model under the current parameter setting, i.e. the degree of deviation of the prediction value of the target discriminator model from the true value. The target learning rate refers to a hyperparameter that controls the step size of model parameter update in the training process of the target discriminator model. When updating the model parameters, the learning rate determines the size of each parameter update. The target iteration number is the number of training rounds of the original discriminator model.

[0067] For example, the loss function of the training can be set as a cross-entropy loss function, the learning rate is 0.001, the number of training rounds is 100 rounds, and the energy trace and its label in the modeling set are used to update the discriminator parameters, so as to obtain the target discriminator model after training.

[0068] It should be noted that in the case of a statistical test or a probability distribution, etc. without the target loss function or the target learning rate or the target iteration number, etc., the original discriminator model can be updated only by using the modeling set and the leakage model label value to obtain the new model parameters after updating, and then determine the target discriminator model.

[0069] ​Step S103, predicting the probability distribution of the intermediate value leakage model value of each energy trace in the verification set by the target discriminator model, and obtaining the key guess score of each energy trace in the verification set according to the probability distribution, so as to calculate the leading degree index of the target discriminator model according to the key guess score, and determine the discrimination function evaluation result of the target discriminator model through the leading degree index.

[0070] As a possible implementation manner, after the target discriminator model is constructed, the embodiments of the present application can use the target discriminator model to predict the probability distribution of the intermediate value leakage model value of each energy trace in the verification set, wherein the leakage model here refers to the leakage model type set when the modeling set and the verification set are constructed.

[0071] Then, the embodiments of the present application can calculate the key guess score of each energy trace in the verification set according to the probability distribution of the intermediate value leakage model value of each energy trace predicted by the target discriminator model.

[0072] Wherein, the key guess score here can be understood as the corresponding score given to each key guess value, which is a quantitative index for measuring the reliability or possibility of key guess result, which helps to more intuitively evaluate the rationality and credibility of each key guess, and helps to determine the most possible key guess.

[0073] Further, in order to achieve more accurate and faster evaluation of the discrimination ability of the target discriminator model to the energy trace, the embodiments of the present application propose to evaluate the target discriminator model by the leading degree index. Specifically, the embodiments of the present application can calculate the leading degree index of the discriminator according to the key guess score, and determine the discrimination function evaluation result of the target discriminator model through the leading degree index.

[0074] Next, the process is further explained.

[0075] Optionally, in an embodiment of the present application, obtaining the key guess score of each energy trace in the verification set according to the probability distribution comprises: based on the probability distribution, solving the key probability distribution of each energy trace in the verification set by using the target relationship between the key guess and the intermediate value; and determining the key guess score of each energy trace in the verification set according to the key probability distribution.

[0076] Based on the related description of other embodiments, it can be understood that the present application can calculate the key guess score of each energy trace in the verification set according to the probability distribution of the intermediate value leakage model value of each energy trace predicted by the target discriminator model.

[0077] In actual implementation, the application embodiment can predict the probability distribution of the value of the intermediate value leakage model in each energy trace based on the target discriminator model, and solve the key probability distribution of each energy trace in the verification set by using the target relationship between the key guess and the intermediate value.

[0078] For example, the application can calculate the probability of the intermediate value leakage model of each energy trace T i in the verification set being l j (1≤j≤r) based on the target discriminator model, and then predict the probability of the intermediate value leakage model of the energy trace being l j . i .

[0079] Then, the application embodiment can obtain the key probability distribution of the energy trace T i by using the target relationship between the key guess and the intermediate value, and further obtain the key guess score. The target relationship between the key guess and the intermediate value is usually determined based on the internal structure and operation rules of the target cryptographic algorithm in the actual scenario. For example, the typical relationship of the AES algorithm involves round key addition, byte substitution, row shifting, column mixing and the like. Therefore, the specific target relationship between the key guess and the intermediate value can be determined by the person skilled in the art according to the actual situation, which is only exemplarily described herein and is not specifically limited.

[0080] For example, the probability value of the energy trace T i corresponding to the key guess k is The score of the key guess k on the energy trace T i can be set as the logarithmic form s i (k) of the above probability value. i,j i .

[0081] By repeating the above steps, the scores of the key guess on each energy trace in the verification set can be obtained, which can be represented as follows but are not limited thereto:

[0082]

[0083] Optionally, in an embodiment of the application, a leading degree index of the discriminator is calculated according to the key guess score, so as to determine the evaluation result of the discrimination function of the target discriminator model by the leading degree index, including: calculating the mean and variance of the key guess score, and calculating the comprehensive statistic of the key guess based on the mean and variance of the key guess score; arranging the key guess according to the comprehensive statistic to obtain an arrangement array of the possible values of the key, and performing weighted summation on the elements in the arrangement array that meet the preset condition to obtain the leading degree index. The calculation formula of the leading degree index can be represented as follows but is not limited thereto: ​

[0084]

[0085] Wherein, LD is the leading degree index, n is the number of elements selected from the array, and C[i] is the element in the array.

[0086] In some embodiments, after obtaining different key guess scores, the embodiments of the present application can calculate the leading degree index of the discriminator according to the key guess score, so as to determine the evaluation result of the distinguishing function of the target discriminator model through the leading degree index.

[0087] Firstly, the embodiments of the present application can calculate the mean and variance of the key guess score. Taking the following key guess score as an example:

[0088]

[0089] The calculation formula of the mean (μ0,..., μ 255 ) and variance (Var0,..., Var 255 ) of the key guess score can be but not limited to represented as follows:

[0090]

[0091] Then, the embodiments of the present application can calculate the comprehensive statistics of the key guess according to the mean and variance of the key guess score, so as to arrange the key guess according to the comprehensive statistics to obtain the array of the possible values of the key, and to obtain the leading degree index by weighted sum of the elements in the array that meet the preset condition. The preset condition can be understood as the condition of selecting elements from the arranged array, for example, the first 5 elements, the first 10 elements, etc.

[0092] Specifically, the embodiments of the present application can calculate the statistics * for all key guesses k∈{0,..., 255}\k * except the correct key k and arrange the statistics in ascending order to obtain the array C = sorted({c0,..., c 255}\c k* ).

[0093] Then, the first n elements of the array C are weighted summed to obtain the leading degree (Leading Degree) index, wherein the calculation result of the leading degree index can be but not limited to represented as:

[0094]

[0095] Wherein, n can be 5 in general.

[0096] Additionally, in order to further reduce the evaluation time, the embodiment of the present application may also calculate the mean of all key guess scores (μ0, ..., μ 255 ) after the correct key k * All key guesses k∈{0,…,255}\k * Arrange the mean of the key in descending order and get the n key guesses with the highest mean (k0,…,k n-1 ), usually n can be 5; the mean calculation formula of the key guessing score is also:

[0097]

[0098] Then, the embodiment of the present application can guess the key (k0, ..., k n-1 ), calculate the score variance and statistics arrays Among them, the variance and statistic arrays can be expressed as follows:

[0099]

[0100] Finally, a weighted sum is performed on the array C to obtain a simplified evaluation result of the Leading Degree indicator, which can be expressed as follows but is not limited to:

[0101]

[0102] According to the leading index, the embodiment of the present application can determine the evaluation result of the discrimination effect of the target discriminator model, that is, the higher the leading index, the better the discrimination effect of the target discriminator model.

[0103] The following is a specific example to further illustrate the rapid evaluation method of the modeling-based side channel attack distinguisher in the embodiment of the present application.

[0104] Figure 3 This is a flowchart of a rapid evaluation method for a modeling-like side channel attack distinguisher according to an embodiment of the present application. Figure 3 As shown:

[0105] Step S301: using an oscilloscope to collect the power consumption curve of the cryptographic chip when executing the target cryptographic algorithm, obtaining energy trace data, and dividing the data into a modeling set and a verification set, which are used to build a discriminator model and verify the discrimination effect of the discriminator model respectively;

[0106] Step S302: for the target cryptographic algorithm, determine the intermediate value object and leakage model to be attacked, and use the leakage model mapping of the intermediate value calculated according to each energy trace in the modeling set as the label value;

[0107] Step S303, in the case of ensuring that the input and output of the discriminator model are adapted to the prepared data, the original discriminator model parameters are updated using the modeling set to construct a target discriminator model.

[0108] Step S304, the energy trace prediction intermediate value probability on the verification trace set is predicted using the established target discriminator model, and is mapped to the key hypothesis score, so as to calculate the leading degree index to evaluate the discrimination effect of the discriminator model.

[0109] According to the fast evaluation method of the modeling type side channel attack discriminator proposed in the embodiments of the present application, the probability distribution of the value of the intermediate value leakage model of each energy trace predicted by the target discriminator model can be constructed, and the key guess score of each energy trace in the verification set is obtained according to the probability distribution to calculate the leading degree index of the target discriminator model, so as to determine the evaluation result of the discrimination function of the target discriminator model. Therefore, the probability of predicting the intermediate value of each energy trace in the verification set by the target prediction model is mapped to the probability distribution of the key guess, the key guess score of the target prediction model is obtained, and the leading degree index is calculated through multiple layers according to the key guess score. According to the leading degree index, the discrimination effect of the target discriminator model is determined, so that the evaluation accuracy required in the actual scene is met, and the discrimination ability and generalization of the discriminator can also be measured in a short time, greatly improving the efficiency of the discrimination ability evaluation of the discriminator. Therefore, the problems in the related art that the evaluation method for the modeling type side channel attack discriminator is difficult to measure the discrimination ability and generalization of the discriminator in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient are solved.

[0110] Secondly, the fast evaluation device of the modeling type side channel attack discriminator according to the embodiments of the present application is described with reference to the accompanying drawings.

[0111] Figure 4 is a structural schematic diagram of the fast evaluation device of the modeling type side channel attack discriminator according to the embodiments of the present application.

[0112] As shown in Figure 4 , the fast evaluation device of the modeling type side channel attack discriminator 10 comprises a collection module 100, a construction module 200 and an evaluation module 300.

[0113] The collection module 100 is configured to collect the power consumption curve of the target cryptographic chip when executing the target algorithm, so as to establish the modeling set and the verification set according to the energy trace data corresponding to the power consumption curve.

[0114] The construction module 200 is configured to calculate the leakage model label value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the preset leakage model, and to construct a target discriminator model according to the modeling set and the leakage model label value.

[0115] The evaluation module 300 is configured to predict a probability distribution of the value of the intermediate value leakage model in each energy trace in the verification set by using the target discriminator model, and obtain a key guess score of each energy trace in the verification set according to the probability distribution, so as to calculate a leading degree index of the target discriminator model according to the key guess score, and determine a discrimination function evaluation result of the target discriminator model by using the leading degree index.

[0116] Optionally, in an embodiment of the present application, the construction module 200 comprises a first calculation unit and a second calculation unit.

[0117] The first calculation unit is configured to calculate the value of the intermediate value of each energy trace in the modeling set based on the intermediate value object attacked by the target algorithm and the plaintext and key pair corresponding to each energy trace in the modeling set.

[0118] The second generation unit is configured to map the value of the intermediate value to the leakage model based on the preset leakage model, so as to calculate the leakage model label value of each energy trace in the modeling set.

[0119] Optionally, in an embodiment of the present application, the construction module 200 comprises a first determination unit and an update unit.

[0120] The first determination unit is configured to determine the number of target output categories of the target discriminator model according to the number of values of the leakage model, and determine the original discriminator model according to the number of target output categories.

[0121] The second determination unit is configured to train the original discriminator model in combination with the modeling set and the leakage model label value, to obtain new model parameters of the trained model, and determine the target discriminator model according to the new model parameters.

[0122] Optionally, in an embodiment of the present application, the evaluation module 300 comprises a solving unit and a second determination unit.

[0123] The solving unit is configured to solve the key probability distribution of each energy trace in the verification set by using the target relationship between the key guess and the intermediate value based on the probability distribution.

[0124] The second determination unit is configured to determine the key guess score of each energy trace in the verification set according to the key probability distribution.

[0125] Optionally, in an embodiment of the present application, the evaluation module 300 comprises a calculation unit and a processing unit.

[0126] The calculation unit is configured to calculate the mean and variance of the key guess score, and calculate a comprehensive statistic of the key guess based on the mean and variance of the key guess score.

[0127] The processing unit is configured to arrange the key guesses according to the comprehensive statistics to obtain an arrangement array of possible values of the key, and to perform weighted summation on elements in the arrangement array that meet preset conditions to obtain the leading degree index.

[0128] Optionally, in an embodiment of the present application, the calculation formula of the leading degree index can be, but is not limited to, expressed as:

[0129]

[0130] wherein, LD is the leading degree index, n is the number of elements selected from the arrangement array, and C[i] is an element in the arrangement array.

[0131] It should be noted that the foregoing explanation and description of the embodiment of the fast evaluation method of the modeling type side channel attack discriminator also applies to the fast evaluation device of the modeling type side channel attack discriminator of this embodiment, which will not be described here.

[0132] The fast evaluation device of the modeling type side channel attack discriminator according to the embodiment of the present application can construct a target discriminator model to predict the probability distribution of the value of the intermediate value leakage model in each energy trace, and obtain the key guess score of each energy trace in the verification set according to the probability distribution to calculate the leading degree index of the target discriminator model, so as to determine the evaluation result of the distinguishing function of the target discriminator model. Thus, the probability of predicting the intermediate value of each energy trace in the verification set by the target discriminator model is mapped to the probability distribution of the key guess, the key guess score of the target prediction model is obtained, the leading degree index is calculated through multiple layers according to the key guess score, and the distinguishing effect of the target discriminator model is determined according to the leading degree index, so that the evaluation accuracy required in the actual scene is met, and the distinguishing ability and generalization of the discriminator can also be measured in a short time, greatly improving the efficiency of the evaluation of the distinguishing ability of the discriminator. Thus, the problems in the related art that the evaluation method for the modeling type side channel attack discriminator is difficult to measure the distinguishing ability and generalization of the discriminator in a short time, and the evaluation time is long and the evaluation efficiency and accuracy are insufficient are solved.

[0133] Figure 5 The structure schematic diagram of the electronic device provided in the embodiment of the present application is shown. The electronic device can include:

[0134] The memory 501, the processor 502, and the computer program stored in the memory 501 and executable on the processor 502.

[0135] The processor 502 implements the fast evaluation method of the modeling type side channel attack discriminator provided in the above embodiments when executing the program.

[0136] Further, the electronic device further includes:

[0137] The communication interface 503 is configured to communicate between the memory 501 and the processor 502.

[0138] The memory 501 is configured to store a computer program executable in the processor 502.

[0139] The memory 501 can include a high-speed RAM memory, and can further include a non-volatile memory, for example, at least one disk memory.

[0140] If the memory 501, the processor 502 and the communication interface 503 are independently implemented, the communication interface 503, the memory 501 and the processor 502 can be connected through a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, Figure 5 In the figure, only one thick line is used to represent, but it does not mean that there is only one bus or only one type of bus.

[0141] Optionally, in a specific implementation, if the memory 501, the processor 502 and the communication interface 503 are integrated on a chip, the memory 501, the processor 502 and the communication interface 503 can communicate with each other through an internal interface.

[0142] The processor 502 can be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.

[0143] The embodiments of the present application further provide a computer readable storage medium, having stored thereon a computer program, which, when executed by a processor, implements the above modeling side channel attack discriminator fast evaluation method.

[0144] The embodiments of the present application further provide a computer program product, comprising a computer program, which can run computer instructions, and the computer instructions, when executed by a processor, implement the modeling side channel attack discriminator fast evaluation method provided by the embodiments of the present application.

[0145] In the description of the application, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the application. The illustrative description of the above terms in the specification does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in one or N embodiments or examples. In addition, the skilled person can combine and combine the different embodiments or examples described in the specification and the features of the different embodiments or examples, without contradiction.

[0146] In addition, the terms "first", "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include at least one of the features. In the description of the application, the meaning of "N" is at least two, for example, two, three, etc., unless otherwise specifically limited.

[0147] Any process or method descriptions in flow charts or otherwise described herein can be understood as representing code modules, segments, or portions of code that include one or more executable instructions for performing specific logic functions or steps in the process, and the preferred embodiments of the application include additional implementations that can not be described in detail in connection with the flow charts. It is understood that the order in which the operations appear in the flow charts is not necessarily the order in which the operations are performed. The skilled person in the art will understand that the functions can be performed in different orders or substantially simultaneously, and that the described embodiments can be combined with other embodiments in accordance with the application, which should be understood by those skilled in the art.

[0148] The logic and / or steps represented in the flowcharts and / or described herein, for example, can be considered as a sequence of executable instructions stored in a computer readable medium, which can be executed by an instruction execution system, apparatus or device, such as a computer-based system, a processor-based system, or other system that can fetch the instructions from the instruction execution system, apparatus or device and execute the instructions, or a combination of the above. For the purposes of this specification, a "computer readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus or device. The computer readable medium can be a computer readable storage medium or a computer readable signal medium. The computer readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or a propagation medium. The computer readable signal medium can include, but is not limited to, a computer readable medium that facilitates transfer of the program from one place to another. A specific example of a computer readable medium is a non-transitory computer-readable storage medium. A specific example of a computer readable signal medium is a source or destination of the computer readable medium. Another specific example of a computer readable signal medium is a computer readable signal travelling through space. Thus, a computer readable medium can take many forms of hardware to carry out the program for use by or in connection with the instruction execution system, apparatus or device.

[0149] It should be understood that aspects of the application can be implemented in hardware, software, firmware or a combination thereof. In the above embodiments, the N steps or methods can be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system. If implemented in hardware and in another embodiment, the hardware can be implemented using any or a combination of the following technologies, which are each well known in the art: a discrete logic circuit(s) having logic gates for implementing logic functions upon an application of data signals, an application specific integrated circuit having appropriate combinational logic gates, a programmable gate array(s) (PGA), a field programmable gate array (FPGA), etc.

[0150] Those of skill in the art would understand that the steps of the methods carried out above can be carried out wholly or partly by a program instructing relevant hardware, and the program can be stored in a computer readable storage medium, and when executed, includes one or a combination of the steps of the method embodiments.

[0151] In addition, each of the functional units in the various embodiments of the present application can be integrated in one processing module, or each of the units can be physically present separately, or two or more units can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software functional module. When the integrated module is realized in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer readable storage medium.

[0152] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it should be understood that the above embodiments are exemplary and should not be construed as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application.

Claims

1. A rapid evaluation method for modeling side-channel attack distinguishers, characterized by: The following steps are involved: Collecting a power consumption curve of a target cryptographic chip when executing a target algorithm, and establishing a modeling set and a verification set based on energy trace data corresponding to the power consumption curve; Based on the attacked intermediate value object of the target algorithm and the preset leakage model, calculating the leakage model label value of each energy trace in the modeling set, so as to construct a target discriminator model according to the modeling set and the leakage model label value; Predicting a probability distribution of the value of the median leakage model of each energy trace in the verification set by the target discriminator model, and obtaining a key guessing score for each energy trace in the verification set according to the probability distribution, calculating a leading index of the target discriminator model according to the key guessing score, and determining a discrimination function evaluation result of the target discriminator model by using the leading index; The step of obtaining a key guessing score for each energy trace in the verification set according to the probability distribution includes: solving the key probability distribution for each energy trace in the verification set using a target relationship between key guessing and intermediate values ​​based on the probability distribution; and determining a key guessing score for each energy trace in the verification set according to the key probability distribution. Among them, the leading index of the target discriminator model is calculated according to the key guessing score to determine the discrimination function evaluation result of the target discriminator model through the leading index, including: calculating the mean and variance of the key guessing score, and calculating the comprehensive statistics of the key guessing based on the mean and variance of the key guessing score; arranging the key guesses according to the comprehensive statistics to obtain a permutation array of possible key values, and performing weighted summation on the elements in the permutation array that meet preset conditions to obtain the leading index.

2. The method according to claim 1, characterized in that The step of calculating the leakage model label value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the preset leakage model includes: Calculate the intermediate value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and the plaintext and key pair corresponding to each energy trace in the modeling set; Based on the preset leakage model, the intermediate value is subjected to leakage model mapping to calculate the leakage model label value of each energy trace in the modeling set.

3. The method according to claim 1, characterized in that The constructing a target discriminator model according to the modeling set and the leakage model label value includes: Determining the number of target output categories of the target discriminator model according to the number of values ​​of the preset leakage model, so as to determine the original discriminator model according to the number of target output categories; The original discriminator model is trained in combination with the modeling set and the leakage model label value to obtain trained new model parameters, so as to determine the target discriminator model according to the new model parameters.

4. The method according to claim 1, wherein The calculation formula of the leading index is: , in, is the leading indicator, is the number of elements selected from the permutation array, To sort the elements in an array.

5. A rapid evaluation device for modeling side channel attack distinguishers, characterized in that: include: An acquisition module is used to acquire a power consumption curve of a target cryptographic chip when executing a target algorithm, so as to establish a modeling set and a verification set based on energy trace data corresponding to the power consumption curve; a construction module, configured to calculate a leakage model label value of each energy trace in the modeling set based on the attacked intermediate value object of the target algorithm and a preset leakage model, so as to construct a target discriminator model according to the modeling set and the leakage model label value; an evaluation module, configured to predict a probability distribution of a value of a median leakage model of each energy trace in the verification set using the target discriminator model, and obtain a key guessing score for each energy trace in the verification set based on the probability distribution, so as to calculate a leading index of the target discriminator model based on the key guessing score, and determine a discrimination function evaluation result of the target discriminator model using the leading index; The evaluation module includes: a solving unit for solving the key probability distribution of each energy trace in the verification set based on the probability distribution and using a target relationship between the key guess and the intermediate value; a second determining unit for determining the key guess score of each energy trace in the verification set according to the key probability distribution; The evaluation module includes: a calculation unit for calculating the mean and variance of the key guessing scores, and calculating the comprehensive statistics of the key guessing based on the mean and variance of the key guessing scores; a processing unit for arranging the key guessing according to the comprehensive statistics to obtain a permutation array of possible key values, and performing weighted summation on the elements in the permutation array that meet preset conditions to obtain the leading index.

6. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the rapid evaluation method for a modeling-like side-channel attack distinguisher according to any one of claims 1 to 4.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the rapid evaluation method of the modeling-like side-channel attack distinguisher according to any one of claims 1 to 4.

8. A computer program product comprising a computer program, characterized in that When the computer program is executed, it is used to implement the rapid evaluation method of the modeling-type side channel attack distinguisher according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Evaluation and training method of deep learning model for side channel attack

    CN113472515A

  • Calculation method of non-fixed-point scalar multiplication in national secret SM2 algorithm resisting SPA attack

    CN114527956A