Micro-architecture side-channel leakage protection method and apparatus

By measuring and generating instruction scheduling words to regulate the encryption and decryption operations of the dedicated cryptographic processor, the problem of side-channel leakage is solved, and higher information transmission security is achieved.

CN120110636BActive Publication Date: 2026-02-24INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510212538.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2026-02-24
Estimated Expiration
2045-02-25

AI Technical Summary

Technical Problem

Cryptographic processors are vulnerable to side-channel leakage, which reduces the security of information transmission.

Method used

By measuring the actual execution time and energy consumption of encryption and decryption operations, an instruction scheduling word is generated to adjust the execution of each instruction in the next encryption and decryption operation, balancing time, energy, and electromagnetic side-channel leakage to prevent information leakage.

Benefits of technology

It improves the security of information transmission and reduces the risk of sensitive information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110636B_ABST
    Figure CN120110636B_ABST
Patent Text Reader

Abstract

The present application provides a kind of micro-architecture side channel leakage protection method and device, method includes: the actual execution duration and actual energy consumption of current encryption and decryption operation are measured;Based on the actual execution duration and the actual energy consumption, the instruction scheduling word of next encryption and decryption operation is obtained;Based on the instruction scheduling word, the execution of each instruction in next encryption and decryption operation is adjusted.The method and device provided by the present application, by measuring the actual execution duration and actual energy consumption of current encryption and decryption operation;Based on the actual execution duration and the actual energy consumption, the instruction scheduling word of next encryption and decryption operation is obtained;Based on the instruction scheduling word, the execution of each instruction in next encryption and decryption operation is adjusted, the time, energy, electromagnetic side channel leakage generated by balanced password special processor is realized, to avoid based on side channel information leakage, to reduce the risk of sensitive information leakage in information transmission process, and then the security of data transmission is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of electronic technology, and in particular to a method and apparatus for protecting against side-channel leakage in a microarchitecture. Background Technology

[0002] In recent years, with the continuous advancement of cryptographic technology and the development of the industry, various cryptographic algorithms have been widely applied. For example, my country's commercial cryptographic algorithms include SM2 / 3 / 4 / 7 / 9. This requires cryptographic chips to provide flexible and scalable encryption and decryption functions while meeting power consumption and cost constraints. As a result, dedicated cryptographic processors have become the mainstream technology in recent years.

[0003] However, side-channel information leakage is a significant factor that compromises the security of cryptographic chips, such as time, power consumption, and energy side-channels. The configurable, reconfigurable, and programmable nature of dedicated cryptographic processors makes them more susceptible to side-channel leakage, leading to reduced security in information transmission. Summary of the Invention

[0004] This invention provides a side-channel leakage protection method and apparatus for microarchitecture, which addresses the shortcomings of existing technologies where dedicated cryptographic processors are more susceptible to side-channel leakage, leading to reduced information transmission security.

[0005] This invention provides a side-channel leakage protection method for microarchitecture, comprising:

[0006] Measure the actual execution time and energy consumption of the current encryption / decryption operation;

[0007] Based on the actual execution time and the actual energy consumption, the instruction scheduling word for the next encryption / decryption operation is obtained;

[0008] Based on the instruction scheduling word, the execution of each instruction in the next encryption / decryption operation is adjusted.

[0009] According to a side-channel leakage protection method for a microarchitecture provided by the present invention, the step of obtaining the instruction scheduling word for the next encryption / decryption operation based on the actual execution time and the actual energy consumption includes:

[0010] Based on the actual execution time and the actual energy consumption, the side-channel risk status of the next encryption / decryption operation is calculated;

[0011] Based on the side channel risk state, the instruction scheduling word is obtained.

[0012] According to a side-channel leakage protection method for a microarchitecture provided by the present invention, the step of adjusting the execution of each instruction in the next encryption / decryption operation based on the instruction scheduling word includes:

[0013] The instruction scheduling word is analyzed to adjust the execution of the instruction fetching instruction in the next encryption / decryption operation;

[0014] Based on the instruction scheduling word, execution time analysis and energy consumption analysis are performed respectively to adjust the transmission of the instruction to be transmitted in the next encryption / decryption operation.

[0015] According to a side-channel leakage protection method for a microarchitecture provided by the present invention, the measurement of the actual execution time and actual energy consumption of the current encryption / decryption operation includes:

[0016] Obtain the activation state of each operation unit in the current encryption / decryption operation;

[0017] The actual execution time is determined based on the activation state of each computing unit;

[0018] Based on the activation status of each computing unit, the processor microarchitecture configuration table is queried to obtain the actual energy consumption.

[0019] According to a side-channel leakage protection method for a microarchitecture provided by the present invention, the processor microarchitecture configuration table is used to store the circuit power consumption corresponding to each arithmetic unit.

[0020] According to the side-channel leakage protection method of a microarchitecture provided by the present invention, the activation state of each arithmetic unit is obtained based on a counter; the counter corresponds one-to-one with each arithmetic unit.

[0021] The present invention also provides a side-channel leakage protection device for a microarchitecture, comprising:

[0022] The measurement unit measures the actual execution time and energy consumption of the current encryption / decryption operation.

[0023] The decision-making unit obtains the instruction scheduling word for the next encryption / decryption operation based on the actual execution time and the actual energy consumption.

[0024] The scheduling execution unit, based on the instruction scheduling word, adjusts the execution of each instruction in the next encryption / decryption operation.

[0025] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements a side-channel leakage protection method for any of the microarchitectures described above.

[0026] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a side-channel leakage protection method for any of the microarchitectures described above.

[0027] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements a side-channel leakage protection method for any of the microarchitectures described above.

[0028] The present invention provides a side-channel leakage protection method and apparatus for microarchitecture, which measures the actual execution time and actual energy consumption of the current encryption / decryption operation; based on the actual execution time and actual energy consumption, obtains the instruction scheduling word for the next encryption / decryption operation; based on the instruction scheduling word, adjusts the execution of each instruction in the next encryption / decryption operation, thereby balancing the time, energy, and electromagnetic side-channel leakage generated by the dedicated cryptographic processor, avoiding side-channel information leakage, reducing the risk of sensitive information leakage during information transmission, and thus improving the security of data transmission. Attached Figure Description

[0029] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0030] Figure 1 This is a flowchart illustrating the side-channel leakage protection method for microarchitecture provided by the present invention.

[0031] Figure 2 This is a schematic diagram of the structure of an encryption / decryption system provided by existing technology;

[0032] Figure 3 This is a flowchart illustrating the instruction scheduling word determination method provided by the present invention;

[0033] Figure 4 This is a schematic diagram of the operational framework of the secure instruction fetching module provided by the present invention;

[0034] Figure 5 This is a schematic diagram of the operational framework of the secure decoding and transmission module provided by the present invention;

[0035] Figure 6 This is a schematic diagram of the encryption / decryption execution module provided by the present invention;

[0036] Figure 7 This is a schematic diagram of the encryption and decryption operation system of the microarchitecture provided by the present invention;

[0037] Figure 8 This is a schematic diagram of the side-channel leakage protection device of the microarchitecture provided by the present invention.

[0038] Figure 9This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0039] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0040] Information security is becoming increasingly important, and cryptography is a core technology and fundamental support for ensuring network and information security. Cryptographic processors are a secure and efficient technical approach to encryption and decryption calculations. Cryptographic processors are typically implemented in two ways: Application-Specific Integrated Circuits (ASICs) and Application-Specific Processors (ASICs) with dedicated instruction sets and microarchitectures. ASICs are implemented using hardwired sequential and combinational logic circuits with relatively fixed functions. They are characterized by high performance and high security, but poor flexibility and scalability. ASICs are interconnected through programmable and reconfigurable modules, allowing for reconfiguration of functions through programmability at different granularities. They are characterized by high flexibility and scalability, but slightly lower performance. In terms of security, each has its advantages and disadvantages compared to ASIC circuits.

[0041] It is understandable that programmable encryption and decryption operations implemented using dedicated cryptographic processors often have a more significant risk of side-channel leakage, thus reducing information security. To address this issue, this invention provides a microarchitecture-based side-channel leakage protection method, enabling encryption and decryption methods applied to dedicated cryptographic processors that effectively prevent side-channel information leakage, thereby significantly improving the security of information transmission. Figure 1 This is a flowchart illustrating the side-channel leakage protection method for microarchitecture provided by the present invention, as shown below. Figure 1 As shown, the method includes:

[0042] Step 110: Measure the actual execution time and actual energy consumption of the current encryption / decryption operation;

[0043] Here, the current encryption / decryption operation refers to the process by which the execution module of the dedicated cryptographic processor executes the corresponding encryption or decryption operation according to the currently fetched instruction. This operation can be implemented through multiple arithmetic units, such as adders, multipliers, shifters, logic units, shufflers, and modular exponentiation units. Furthermore, the actual execution time here refers to the sum of the activation and operation times of all arithmetic units within the execution module during the current encryption / decryption operation. The actual energy consumption here refers to the circuit power consumption generated by the activation and operation of all arithmetic units within the execution module during the current encryption / decryption operation.

[0044] Specifically, at least one counter can be set in the execution module to obtain the activation status of the main computing unit in the execution module, thereby obtaining the actual execution time of the current encryption / decryption operation. Additionally, the actual energy consumption of the current encryption / decryption operation can be obtained by querying the activation status of the main computing unit in the execution module and a pre-stored processor microarchitecture configuration table. It should be noted that the measured actual execution time and energy consumption are positively correlated with the time, energy, and electromagnetic side-channel information generated during the operation of the cryptographic processor in the microarchitecture. Attackers can analyze the time, energy, and electromagnetic side-channel information generated by the current encryption / decryption operation to infer sensitive information such as the key or cipher. Therefore, based on the actual execution time and energy consumption of the current encryption / decryption operation, the actual execution time and energy consumption of the next encryption / decryption operation can be balanced to mitigate the time, energy, and electromagnetic side-channel leakage generated by the cryptographic processor, thereby increasing the risk of side-channel leakage and achieving side-channel leakage protection of the microarchitecture.

[0045] In one embodiment, Figure 2 This is a schematic diagram of the structure of an encryption / decryption system provided by existing technology, such as... Figure 2 As shown, the encryption / decryption system includes modules for instruction fetching, decoding and issuing, execution, memory access, and write-back, as well as memory and a register file. Specifically, during operation, the encryption / decryption system first fetches the instruction from memory and sends it to the decoding unit for decoding. During decoding, the processor identifies the operation to be performed by the instruction, generating an operation control signal, which is then passed to the execution module for the corresponding encryption / decryption calculations. In the execution module, the register file is accessed based on the operand's location index number. The corresponding operand is read and input to the appropriate functional unit to execute the operation specified by the encryption / decryption algorithm, or to perform memory address generation operations, etc. The memory access module writes the calculation result to memory. The write-back module writes the calculation result back to the register file.

[0046] Step 120: Based on the actual execution time and the actual energy consumed, obtain the instruction scheduling word for the next encryption / decryption operation;

[0047] Here, the instruction scheduling word refers to the scheduling instruction used to schedule the next encryption / decryption operation. For example, it can be used to schedule the execution of instruction fetch, decoding, and transmission instructions in the next encryption / decryption operation.

[0048] Specifically, the current side-channel risk status can be calculated based on the actual execution time and actual energy consumption. Then, based on the current side-channel risk status, the instruction scheduling word for the next encryption / decryption operation can be determined.

[0049] It should be noted that during encryption and decryption operations, the more complex the operation performed by the processing unit, the longer the execution time and the greater the energy consumption; conversely, the simpler the operation performed by the processing unit, the shorter the execution time and the less energy consumption. Therefore, if the processing unit performing a complex operation in the current encryption / decryption process can generate an instruction scheduling word to schedule the simpler operation in the next encryption / decryption operation, thus preventing a significant increase in the instantaneous energy consumption of the encryption / decryption operation and balancing the actual execution time.

[0050] It is understandable that the generated instruction schedule contains key information such as the execution order and execution time of instructions in the next encryption / decryption operation, and is used to control the instruction execution time and order of the instruction fetch module, decoding and transmission module and execution module in the next encryption / decryption operation.

[0051] Step 130: Based on the instruction scheduling word, adjust the execution of each instruction in the next encryption / decryption operation.

[0052] Specifically, the generated instruction scheduling word can be sent to the instruction fetching module, decoding module, and transmission module. Then, the instruction fetching module, decoding module, and transmission module receive and analyze the instruction scheduling word, and control the next transmission and instruction fetching instructions according to the instruction scheduling word, so as to balance the time, energy, and electromagnetic side-channel leakage generated by the dedicated cryptographic processor and increase the security of information transmission.

[0053] The method provided in this invention measures the actual execution time and energy consumption of the current encryption / decryption operation; based on the actual execution time and energy consumption, it obtains the instruction scheduling word for the next encryption / decryption operation; based on the instruction scheduling word, it adjusts the execution of each instruction in the next encryption / decryption operation, thereby balancing the time, energy, and electromagnetic side-channel leakage generated by the dedicated cryptographic processor, avoiding side-channel information leakage, reducing the risk of sensitive information leakage during information transmission, and thus improving the security of data transmission.

[0054] Based on any of the above embodiments, step 120 includes:

[0055] Based on the actual execution time and the actual energy consumption, the side channel risk status is calculated.

[0056] Based on the side-channel risk state, the instruction scheduling word for the next encryption / decryption operation is determined.

[0057] In detail, the side-channel risk status, including time, energy, and electromagnetic parameters, corresponding to the actual execution time and energy consumption can be calculated. Then, targeting the side-channel leakage caused by the equalization cryptographic processor (time, energy, and electromagnetic parameters), a side-channel security-oriented instruction scheduling word is generated to control the instruction fetching, decoding, and transmission in the next encryption / decryption operation.

[0058] In one embodiment, Figure 3 This is a flowchart illustrating the instruction scheduling word determination method provided by the present invention, as shown below. Figure 3 As shown, the method includes: First, by setting a counter in the execution module of the encryption / decryption system, the execution status of the current encryption / decryption operation is obtained, and the execution time of the current encryption / decryption operation is measured to obtain the actual execution duration of the current encryption / decryption operation. Second, by obtaining the energy consumption corresponding to the activated operation unit from the processor microarchitecture configuration table, the energy consumption is measured to obtain the actual energy consumption. Then, the actual execution duration and actual energy consumption of the current encryption / decryption operation are used to make instruction scheduling decisions to determine the side-channel security instruction scheduling word, thereby achieving security protection against side-channel information leakage during the encryption / decryption process.

[0059] Based on any of the above embodiments, step 130 includes:

[0060] The instruction scheduling word is analyzed to adjust the execution of the instruction fetching instruction in the next encryption / decryption operation;

[0061] Based on the instruction scheduling word, execution time and energy consumption are analyzed to adjust the execution of the instruction to be transmitted in the next encryption / decryption operation.

[0062] Specifically, the instruction dispatch word can be used to control the next instruction to be issued and fetched, thereby controlling the execution order of the arithmetic units in the next encryption / decryption operation. It should be noted that the typical operation of an existing instruction fetch module is as follows: the program memory storing instructions uses the PCR (Program Counter Register) as an address index to generate program instructions. The main control logic is the next address logic, which mainly consists of instruction fetch prediction and jump prediction functions. The former is used for instruction prefetching, and the latter is used to predict the target jump address during program jumps. The goal of both prediction functions is to improve program execution efficiency.

[0063] In this embodiment of the invention, to mitigate the side-channel security risk of the cryptographic processor, side-channel attenuation prediction is added to the existing subsequent address logic. In one embodiment, Figure 4 This is a schematic diagram of the operational framework of the secure instruction fetching module provided by the present invention, as shown below. Figure 4 As shown, the instruction fetch module includes a Program Control Register (PCR), side-channel attenuation prediction, instruction fetch prediction, and jump prediction. The program memory storing instructions uses the PCR as an address index to generate program instructions. The main control logic is the NextAddress Logic, which mainly consists of instruction fetch prediction and jump prediction functions. The former is used for instruction prefetching, and the latter is used to predict the target jump address during program jumps.

[0064] It should be noted that before instruction fetch prediction, the received side-channel security instruction scheduling word is analyzed by the side-channel attenuation prediction module. Specifically, the side-channel attenuation prediction logic, through analysis of the side-channel security instruction scheduling word, can obtain the latency and power consumption information generated during the current processor execution. Then, with the goal of side-channel information leakage security, it optimizes the acquisition of subsequent instructions to be executed. That is, through the subsequent instruction fetch prediction and jump prediction processes, it optimizes the acquisition of subsequent instructions to be executed.

[0065] Next, based on the instruction scheduling word, execution time and energy consumption are analyzed to adjust the execution of the instructions to be transmitted in the next encryption / decryption operation. In one embodiment, Figure 5 This is a schematic diagram of the operational framework of the secure decoding and transmission module provided by the present invention, as shown below. Figure 5 As shown, the decoding and transmission module receives program instructions from the instruction fetch module, decodes and renames the program instructions, and then obtains an instruction queue. At this point, the instruction queue and the side-channel security instruction scheduling word are input into the instruction transmission decision unit. In the instruction transmission decision unit, execution component port occupancy analysis is performed. Through the scheduling decision word, execution time and execution energy analysis are conducted. The instruction scheduling word controls the timing of instruction transmission or submission during the next encryption / decryption operation, thereby controlling the execution of the ALU (Arithmetic Logic Unit), FPU (Float Point Unit), and LSU (Load Store Unit) in the next encryption / decryption operation. This achieves the goal of minimizing side-channel information leakage while considering the occupancy of execution components.

[0066] It should be noted that current instruction issuance processes only consider the dependencies of the execution sequence and the resource occupancy of the execution components, aiming at optimal program performance in instruction decoding and issuance, while ignoring the security risk of side-channel information leakage. The operational framework provided in this invention, however, comprehensively analyzes execution time, execution energy, and component occupancy to complete the instruction queue submission, thus not only achieving protection against side-channel leakage but also improving processor performance.

[0067] Based on any of the above embodiments, step 110 includes:

[0068] Obtain the activation state of each operation unit in the current encryption / decryption operation;

[0069] The actual execution time is determined based on the activation state of each computing unit;

[0070] Based on the activation status of each computing unit, the processor microarchitecture configuration table is queried to obtain the actual energy consumption.

[0071] Here, the processor microarchitecture configuration table is used to store the circuit power consumption corresponding to each arithmetic unit.

[0072] Specifically, during encryption and decryption operations, the activation status of each arithmetic unit can be obtained. Then, by analyzing the execution status counter, the execution time of the arithmetic unit participating in the current encryption and decryption operation can be reflected in its activation status, thus calculating the overall actual execution time of the current encryption and decryption operation. Additionally, the energy consumption corresponding to the activated arithmetic unit can be retrieved from the processor microarchitecture configuration table using the activation status of each arithmetic unit, and the execution energy can be measured to obtain the actual energy consumption.

[0073] In one embodiment, Figure 6 This is a schematic diagram of the encryption / decryption execution module provided by the present invention, as shown below. Figure 6 As shown, the encryption / decryption execution module can contain multiple operation units such as adders, multipliers, shifters, logic operators, shufflers, and modular exponentiation operators. Each operation unit corresponds to a counter, and these multiple operation units constitute the secure execution module. During a single encryption or decryption operation, the number to be operated on can be divided into multiple operands, such as operand 1 and operand 2. The operands and opcodes are input into the encryption / decryption execution module. The operation units, as indicated by the opcodes, perform operations on the operands to obtain the final execution result. The execution status of each operation unit is output through each counter, thus determining the actual execution time of the current encryption / decryption operation.

[0074] Based on any of the above embodiments, the processor microarchitecture configuration table is used to store the circuit power consumption corresponding to each arithmetic unit.

[0075] Based on any of the above embodiments, the activation state of each arithmetic unit is obtained based on a counter; the counter corresponds one-to-one with each arithmetic unit.

[0076] Here, a counter can be configured for each arithmetic unit, establishing a one-to-one correspondence between the counter and each arithmetic unit, thereby more accurately obtaining the activation status of the arithmetic unit. This activation status can reflect the duration of the corresponding arithmetic unit's execution.

[0077] Based on any of the above embodiments Figure 7 This is a schematic diagram of the encryption / decryption operation system of the microarchitecture provided by the present invention, as shown below. Figure 7 As shown, the system includes a side-channel security protection module, a secure instruction fetch module, a secure decoding and transmission module, a secure execution module, a memory access module, a write-back module, a memory, and a register file. The side-channel security protection module measures the actual execution time and energy consumption of the current encryption / decryption operation. Based on the actual execution time and energy consumption, it determines the instruction scheduling word for the next encryption / decryption operation.

[0078] Then, the instruction scheduling word can be transmitted to the secure instruction fetching module, secure decoding and transmission module via the side-channel security protection module to control the instruction scheduling of each module in the next encryption / decryption operation according to the instruction scheduling word. It should be noted that the actual execution time of the current encryption / decryption operation is obtained by configuring corresponding counters in each operation unit of the secure execution module.

[0079] The encryption / decryption system provided in this invention uses a side-channel security protection module to determine the instruction scheduling word for the next encryption / decryption operation based on the actual execution time, actual energy consumption, and electromagnetic side-channel risk status of the current encryption / decryption operation. This balances the time, energy, and electromagnetic side-channel leakage generated by the dedicated cryptographic processor, thereby achieving encryption / decryption operation with side-channel leakage protection and greatly improving the security of information transmission.

[0080] It should also be noted that the encryption / decryption system provided in this embodiment of the invention adds a "side-channel security protection module" to the existing typical processor pipeline structure; improves the "instruction fetch" module of the existing typical processor by adding side-channel attenuation prediction logic, thus becoming a "secure instruction fetch" module; further improves the "decoding and transmission" module of the existing typical processor by adding execution time analysis and execution energy analysis logic, thus becoming a "secure decoding and transmission" module; and improves the "execution" module of the existing typical processor by adding execution state counter logic, thus becoming a "secure execution" module. Therefore, based on the above-mentioned "side-channel security protection," "secure instruction fetch," "secure decoding and transmission," and "secure execution," a cryptographic dedicated processor microstructure that is beneficial for side-channel leakage protection is formed, greatly improving the security of information transmission.

[0081] Based on any of the above embodiments Figure 8 This is a schematic diagram of the side-channel leakage protection device of the microarchitecture provided by the present invention, as shown below. Figure 8 As shown, the device includes:

[0082] Measurement unit 810 measures the actual execution time and actual energy consumption of the current encryption / decryption operation;

[0083] Decision unit 820 obtains the instruction scheduling word for the next encryption / decryption operation based on the actual execution time and the actual energy consumption;

[0084] The scheduling execution unit 830, based on the instruction scheduling word, adjusts the execution of each instruction in the next encryption / decryption operation.

[0085] The apparatus provided in this invention measures the actual execution time and energy consumption of the current encryption / decryption operation; based on the actual execution time and energy consumption, it obtains the instruction scheduling word for the next encryption / decryption operation; based on the instruction scheduling word, it adjusts the execution of each instruction in the next encryption / decryption operation, thereby balancing the time, energy, and electromagnetic side-channel leakage generated by the dedicated cryptographic processor, avoiding side-channel information leakage, reducing the risk of sensitive information leakage during information transmission, and thus improving the security of data transmission.

[0086] Based on any of the above embodiments, the decision unit is specifically used for:

[0087] Based on the actual execution time and the actual energy consumption, the side channel risk status is calculated.

[0088] Based on the side-channel risk state, the instruction scheduling word for the next encryption / decryption operation is determined.

[0089] Based on any of the above embodiments, the scheduling execution unit is used for:

[0090] The instruction scheduling word is analyzed to adjust the execution of the instruction fetching instruction in the next encryption / decryption operation;

[0091] Based on the instruction scheduling word, execution time and energy consumption are analyzed to adjust the execution of the instruction to be transmitted in the next encryption / decryption operation.

[0092] Based on any of the above embodiments, the measuring unit is specifically used for:

[0093] Obtain the activation state of each operation unit in the current encryption / decryption operation;

[0094] The actual execution time is determined based on the activation state of each computing unit;

[0095] Based on the activation status of each computing unit, the processor microarchitecture configuration table is queried to obtain the actual energy consumption.

[0096] Based on any of the above embodiments, the processor microarchitecture configuration table is used to store the circuit power consumption corresponding to each arithmetic unit.

[0097] Based on any of the above embodiments, the activation state of each arithmetic unit is obtained based on a counter; the counter corresponds one-to-one with each arithmetic unit.

[0098] Figure 9 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 9 As shown, the electronic device may include a processor 910, a communications interface 920, a memory 930, and a communication bus 940. The processor 910, communications interface 920, and memory 930 communicate with each other via the communication bus 940. The processor 910 can call logical instructions from the memory 930 to execute a side-channel leakage protection method for the microarchitecture. This method includes: measuring the actual execution time and actual energy consumption of the current encryption / decryption operation; obtaining an instruction schedule word for the next encryption / decryption operation based on the actual execution time and actual energy consumption; and adjusting the execution of each instruction in the next encryption / decryption operation based on the instruction schedule word.

[0099] Furthermore, the logical instructions in the aforementioned memory 930 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0100] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the microarchitecture side-channel leakage protection method provided by the above methods. The method includes: measuring the actual execution time and actual energy consumption of the current encryption / decryption operation; obtaining the instruction schedule word for the next encryption / decryption operation based on the actual execution time and the actual energy consumption; and adjusting the execution of each instruction in the next encryption / decryption operation based on the instruction schedule word.

[0101] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a side-channel leakage protection method for a microarchitecture provided by the methods described above. The method includes: measuring the actual execution time and actual energy consumption of the current encryption / decryption operation; obtaining an instruction schedule word for the next encryption / decryption operation based on the actual execution time and the actual energy consumption; and adjusting the execution of each instruction in the next encryption / decryption operation based on the instruction schedule word.

[0102] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0103] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0104] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A side-channel leakage protection method for a microarchitecture, characterized in that, include: Measure the actual execution time and energy consumption of the current encryption / decryption operation; Based on the actual execution time and the actual energy consumption, the instruction scheduling word for the next encryption / decryption operation is obtained; The instruction scheduling word includes the execution order and execution time of each instruction in the next encryption / decryption operation; Based on the instruction scheduling word, the execution of each instruction in the next encryption / decryption operation is adjusted, including: analyzing the instruction scheduling word and adjusting the execution of the instruction fetch instruction in the next encryption / decryption operation; Based on the instruction scheduling word, execution time and energy consumption are analyzed respectively, and the execution of the instruction to be transmitted in the next encryption / decryption operation is adjusted. The step of obtaining the instruction schedule word for the next encryption / decryption operation based on the actual execution time and the actual energy consumption includes: Based on the actual execution time and the actual energy consumption, the side channel risk status is calculated. Based on the side channel risk state, the instruction scheduling word for the next encryption / decryption operation is determined. The measurement of the actual execution time and actual energy consumption of the current encryption / decryption operation includes: Obtain the activation state of each operation unit in the current encryption / decryption operation; The actual execution time is determined based on the activation state of each computing unit; Based on the activation status of each computing unit, the processor microarchitecture configuration table is queried to obtain the actual energy consumption; The processor microarchitecture configuration table is used to store the circuit power consumption corresponding to each arithmetic unit; the activation state of each arithmetic unit is obtained based on a counter; the counter corresponds one-to-one with each arithmetic unit.

2. A side-channel leakage protection device for a microarchitecture, characterized in that, The device performs the side-channel leakage protection method for the microarchitecture as described in claim 1, comprising: The measurement unit measures the actual execution time and energy consumption of the current encryption / decryption operation. The decision-making unit obtains the instruction scheduling word for the next encryption / decryption operation based on the actual execution time and the actual energy consumption. The scheduling execution unit, based on the instruction scheduling word, adjusts the execution of each instruction in the next encryption / decryption operation.

3. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the side-channel leakage protection method of the microarchitecture as described in claim 1.

4. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the side-channel leakage protection method of the microarchitecture as described in claim 1.

5. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the side-channel leakage protection method of the microarchitecture as described in claim 1.

Citation Information

Patent Citations

  • Side channel attack detection method and system based on deep learning

    CN118337494A