Password side channel analysis method based on secondary start genetic algorithm
By using the method of secondary startup and dynamic reduction of population individuals in the genetic algorithm, the key recovery process is optimized, the problems of slow iteration speed and local optimality are solved, and efficient key recovery and improved success rate are achieved.
Patent Information
- Application Number
- CN202510282069.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-06-06
AI Technical Summary
The existing side channel analysis method based on genetic algorithms is slow to iterate, has high computational complexity, and is prone to fall into local optimization, resulting in a low success rate of key recovery.
A secondary startup genetic algorithm is used and the population number is dynamically reduced to speed up iteration and improve the success rate of key recovery. By constructing the corresponding formulas of the intermediate value of the cryptographic algorithm and the leaked waveform, and combining the offset calculation formula of the register Hamming weight and bit width, the fitness calculation of the genetic algorithm is optimized.
It significantly improves the success rate and speed of key recovery, reduces the computational complexity, and successfully breaks the protection of the first-order mask, achieving efficient key recovery.
Smart Images

Figure CN120110658A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a cryptographic side channel analysis method based on a secondary start genetic algorithm, and in particular to a genetic algorithm side channel analysis method capable of improving a key recovery success rate and accelerating a key recovery speed, and belongs to the technical field of information security cryptography. Background Art
[0002] With the development of IoT applications, IoT devices are deployed in a large number of actual production and life scenarios. Lightweight cryptographic algorithms are designed to solve problems in the IoT field with limited computing resources. At the same time, the nonlinear operations of cryptographic algorithms often require pre-calculated lookup tables to be stored in the device memory for accelerated implementation.
[0003] In 1996, Kocher et al. proposed the side channel analysis technology, which uses the energy side information leaked by the device to build a corresponding relationship with the intermediate value bits of the cryptographic algorithm to recover the key of the cryptographic algorithm being executed. Brier et al. improved the key recovery method based on differential energy analysis and combined the Hamming weight model, constructed the correlation relationship between the Hamming weight model of the intermediate value and the leaked energy side information, and proposed the Correlation Power Analysis (CPA), which improved the key recovery efficiency.
[0004] In 2006, Herbst et al. proposed a first-order masking scheme to protect the intermediate value side information during the execution of the cryptographic algorithm to counter the correlation energy analysis method. In the masking scheme, in order to balance the additional computing cost and security, Herbst et al. designed a masking scheme in the form of first-order mask byte reuse for each byte of the Advanced Encryption Standard (AES). This classic scheme has also been used as a design template by later generations and is the most commonly used protection method for the implementation of cryptographic products.
[0005] In 2019, Jia Keting and others from Tsinghua University proposed the block cipher algorithm FESH. Compared with AES, FESH uses an S-box with a shorter bit width, which reduces the memory resources required to store pre-calculated S-box values. It also has multiple versions to facilitate software and hardware implementation.
[0006] As an artificial intelligence method, heuristic algorithm can significantly reduce the complexity of search space. Genetic algorithm is a heuristic search algorithm. Inspired by the idea of "evolution" in the biological world, it simulates the evolution process of species to find the optimal solution to the problem, and has a good effect in performing key recovery search. In 2015, Zhang et al. proposed a related energy analysis method based on genetic algorithm, analyzed the parallel DES (Data Encryption Standard) algorithm, and recovered the complete key with less energy waveform than the traditional CPA, which significantly improved the analysis efficiency. In the side channel analysis method based on genetic algorithm, the number of individuals in the population is constant. When the number of individuals in the initial population is large, the iterative evolution speed is slow, which requires a lot of computing cost.
[0007] Current cryptographic algorithms will add protection countermeasures during the design of physical implementations. Bit slicing technology is currently the mainstream technology for lightweight cryptographic algorithms and is widely used. In order to accelerate the implementation of nonlinear layers, a new S-box lookup table with a pre-calculated mask is often used. Due to limited memory resources, IoT devices often use a new S-box lookup table reuse implementation method. The pre-calculated new S-box lookup table is completed before the formal encryption begins. For attackers, the energy waveform in the pre-calculation stage is often difficult to obtain. The number of individuals in the existing genetic algorithm-based side channel analysis remains constant. When the first part of the individuals is selected for crossover and mutation operations, the latter part of the individuals do not participate in this round of iteration, which increases the computational overhead of the fitness of this iteration.
[0008] The termination condition of current genetic algorithms is often set to reach the maximum number of iterations. Since the initialization and operators of the heuristic algorithm are random, the evolution of the population is not fixed and the emergence of individuals is also random, it often falls into a local optimum and cannot recover the correct key. Summary of the invention
[0009] The purpose of the present invention is to propose a method for accelerating the iteration speed and improving the success rate of recovering the correct key for a genetic algorithm side channel analysis method with a constant number of individuals in the population. This method can accelerate the evolution speed and reduce the computational complexity by dynamically reducing the number of individuals in the population during iterative evolution. Restarting and discarding the previous local optimal population can improve the success rate of recovering the correct key and reduce the uncertainty caused by the randomly generated population. Under the premise of using a lookup table to implement the nonlinear layer and multiplexing the mask lookup table, the protection of the first-order mask can be broken and the key can be recovered efficiently.
[0010] The present invention is implemented by adopting the following technical solutions.
[0011] A cryptographic side channel analysis method based on a secondary start genetic algorithm comprises the following steps:
[0012] Step 1: For the first-order mask protection scheme implemented by nonlinear layer lookup table, determine the second-order leakage caused by mask multiplexing in the case of parallel implementation, and construct the corresponding formula between the intermediate value of the cryptographic algorithm and the leakage waveform for the second-order leakage;
[0013] Step 2: For the generated second-order leakage, a calculation formula for the offset between the register Hamming weight and the typical value of the register bit width Hamming weight for calculating the nonlinear layer result in the form of a lookup table is constructed;
[0014] Step 3: Construct a genetic algorithm fitness calculation formula for the algorithm intermediate value offset;
[0015] Step 4: Use a genetic algorithm with secondary startup and dynamic population reduction combined with the formulas in steps 2 and 3 to recover the key.
[0016] Beneficial Effects
[0017] 1. The present invention implements a mask lookup table and reuses the FESH cryptographic algorithm of the lookup table. For the energy trace generated by the flipping of a 16-bit width register, a genetic algorithm can be used to break through the mask protection and realize efficient key recovery. Under the experimental conditions of implementing a 16-bit storage Hamming weight simulation wave with 800 plaintext parallel lookup tables with a Gaussian noise standard deviation of 3, the experimental success rate of the genetic algorithm in completely recovering the correct key after a second start is increased from 25% of a single start to 55%, which proves that a second start and discarding the population that has evolved to the local optimum has the effect of reducing the impact of random numbers and improving the experimental success rate.
[0018] 2. The time required for the genetic algorithm with dynamic population reduction to successfully recover the complete key is 54 seconds, which is 6.8 times faster than the 370 seconds when the initial number of individuals remains constant. This proves that dynamic population reduction can effectively accelerate the population iteration speed and reduce computing costs.
[0019] 3. The present invention only requires the algorithm to execute the first round of encryption of the nonlinear layer position leakage waveform. Compared with the traditional second-order attack method, there is no need to pre-calculate the stage leakage waveform, which reduces the difficulty of obtaining the leakage waveform. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 is a flow chart of the method of the present invention;
[0021] Figure 2 is a schematic diagram of nonlinear layer mask transformation in an embodiment of the method of the present invention;
[0022] Figure 3 Schematic diagram of mask multiplexing in an embodiment of the method of the present invention;
[0023] Figure 4 Schematic diagram of the mask form in a 32-bit register in an embodiment of the method of the present invention;
[0024] Figure 5 Schematic diagram of the form of selecting the intermediate value in the embodiment of the method of the present invention;
[0025] Figure 6 is a flow chart of a genetic algorithm for secondary activation in an embodiment of the method of the present invention;
[0026] Figure 7 Schematic diagram of dynamic reduction of the number of individuals in a population in an embodiment of the method of the present invention; DETAILED DESCRIPTION
[0027] The detailed steps of the method of the present invention are described below in conjunction with the accompanying drawings and embodiments.
[0028] Example
[0029] Taking the FESH algorithm as an example, the energy consumption generated by the first round of nonlinear layer register flipping is simulated, and the method of the present invention is used to recover the key on the simulated energy trace. The nonlinear layer of the FESH algorithm is implemented by pre-calculating the lookup table, and the first-order Boolean mask pair 4-bit lookup table is pre-calculated and stored before the first round of use. The simulated energy consumption is taken as an example of the Hamming weight model of the 4 32-bit wide registers of the FESH algorithm and the Gaussian noise standard deviation of 3.
[0030] like Figure 1 As shown, a password side channel analysis method based on a secondary start genetic algorithm comprises the following steps:
[0031] Step 1: For the first-order mask protection scheme implemented by nonlinear layer lookup table, determine the second-order leakage caused by mask multiplexing in the case of parallel implementation, and construct the corresponding formula between the intermediate value of the cryptographic algorithm and the leakage waveform for the second-order leakage;
[0032] Specifically, the first-order mask protection scheme adopts the nonlinear layer lookup table implementation after pre-calculating the mask, such as Figure 2 , Figure 3 As shown, each 32-bit wide register uses a Boolean mask in a form perpendicular to the storage direction, that is, the four registers in the vertical direction are protected by a 4-bit mask, and the 32 groups in the horizontal direction all use the same 4-bit mask. Lookup table implementation refers to pre-calculating all possible values for the 4-bit mask of the input and output of the nonlinear layer in the pre-calculation stage, and directly taking the pre-calculated value as the result when the algorithm executes the nonlinear layer transformation. The nonlinear layer of the cryptographic algorithm is implemented in parallel using a lookup table. After implementation, the Boolean mask is changed compared to the nonlinear layer, but the vertical multiplexing form is not affected. Second-order leakage refers to the fact that due to the use of a lookup table, the mask between the bits of each register is the same, which is bit 0 or bit 1, resulting in the correlation relationship between the intermediate value and the value before mask protection is not used, which remains the same or is bit-inverted;
[0033] Step 2: For the generated second-order leakage, a calculation formula for the offset between the register Hamming weight and the typical value of the register bit width Hamming weight for calculating the nonlinear layer result in the form of a lookup table is constructed;
[0034] Specifically, Figure 4 As shown, the extraction method is calculated in units of each 32-bit register. Taking the FESH algorithm as an example, there are 4 32-bit registers in total. Since the nonlinear layer is pre-calculated in the form of a lookup table, the mask of the output result of the nonlinear layer is the same, and the lightweight cryptographic algorithm often uses bit slicing technology, so that different bits of the output result are stored in different registers respectively. For different bits stored in the same register, the masks of the corresponding bits are exactly the same; for a register storing a certain bit slice bit, the mask of the register has only two possibilities: all "1" and all "0"; and using the all "1" mask and the algorithm intermediate value for an XOR operation is to invert the algorithm intermediate value, and using the all "0" mask and the algorithm intermediate value for an XOR operation is to keep the algorithm intermediate value unchanged. In these two cases, the Hamming distance between the algorithm intermediate value and the typical value of the Hamming weight of the corresponding bit number is the same, that is, the offset from the typical value is the same, so the influence of the first-order mask can be ignored; the typical value of the Hamming weight of the corresponding bit number refers to, for example, the typical value of the Hamming weight of 32 bits is 16, and the typical value is the maximum probability of the Hamming weight distribution of the corresponding bit number;
[0035] Step 3: Construct the genetic algorithm fitness calculation formula for the algorithm intermediate value offset: Where HW(y i ) refers to the Hamming weight of the intermediate value of each bit slice register, HW(y i * ) refers to the typical value of the Hamming weight of the corresponding register bit width; T refers to the energy consumption amplitude of the leakage position of the register of the target device in the energy trace, Refers to the average value of the energy consumption amplitude of the leakage position of multiple energy traces; there is a correlation between the offset of the Hamming weight and the offset of the leakage waveform energy amplitude, and this correlation coefficient is used as the fitness in the genetic algorithm;
[0036] Specifically, Figure 5 As shown, after extracting the specific bits in step 2 and accumulating their Hamming weights, the correlation coefficients are calculated with the energy consumption simulated by the corresponding registers, and the four correlation coefficients are taken logarithmically and accumulated as the fitness of the individual sorting in the genetic algorithm. In particular, compared with the traditional second-order attack method, the energy consumption waveform simulated by this method does not require the waveform generated by the flip register in the pre-calculation stage mask storage, and only the energy waveform leaked by the intermediate value of the first round of nonlinear layer operation can be attacked;
[0037] Step 4: Use a genetic algorithm with secondary startup and dynamic population reduction combined with the formulas in steps 2 and 3 to recover the key;
[0038] Specifically, Figure 6 As shown, step 4 includes the following steps:
[0039] Step 4.1: The random number generator randomly generates the initial key, that is, the individuals of the population, and the randomly generated individuals are used as the initial population for evolution;
[0040] Specifically, an individual refers to a complete guessed key; the number of individuals in the initial population is set to 500;
[0041] Step 4.2: Calculate the fitness of individuals in the population;
[0042] Step 4.3: Perform selection, crossover and mutation operations on the individuals in the population to obtain the next generation population;
[0043] Specifically, selection refers to selecting the top 70% of individuals in the population in terms of fitness as parents; the fitness calculation formula refers to step 3;
[0044] Specifically, crossover refers to randomly selecting specific bits of specific bytes of different registers on an individual, exchanging all specific bits of the two guessed keys after the crossover point, and the crossover rate is set to 0.3; specific bytes refer to selecting the same byte of all registers; specific bits refer to the same bit in the same byte;
[0045] Specifically, mutation refers to traversing the specific bits of the specific bytes of the guessed key represented by the individual, selecting the candidate individual with the highest fitness as the mutation result, and setting the mutation rate to 0.1; in this example, the mutation position is each bit of each byte, that is, 32 candidate mutation positions; traversal refers to generating candidate individuals with all possible values of the specific bit position under the premise that the other bits remain the same, calculating their fitness and sorting them;
[0046] Step 4.4: Reduce the number of individuals in the population to speed up its evolution;
[0047] Specifically, Figure 7 As shown, the method of reducing the number of individuals is to reduce the number of individuals in the population to one-fifth of the original number every two iterations, and take the top one-fifth of the fitness ranking in the population as the reduced new population; the lower limit of the reduction is 20 individuals;
[0048] Step 4.5: Repeat steps 4.2 to 4.4 until the iteration limit is reached or the correct key is evolved;
[0049] Step 4.6: When the iteration limit is reached and the correct key has not been evolved, all individuals in the population are discarded, a new population with the same number of individuals is randomly generated, and the process returns to step 4.2. After the second restart, the process ends after executing step 4.5.
[0050] Specifically, the upper limit of iteration is set to 20 generations in this example.
[0051] In this embodiment, 800 randomly generated simulated energy waveforms are analyzed, and the experimental success rate of the genetic algorithm with secondary activation to completely recover the correct key is increased from 25% of a single activation to 55%, proving that secondary activation and abandoning the population that has evolved to the local optimum has the effect of reducing the impact of random numbers and improving the experimental success rate. The time required for the genetic algorithm with dynamically reduced population to successfully recover the complete key is 54 seconds, which is 6.8 times faster than the 370 seconds when the initial number of individuals remains constant. The traditional second-order CPA cannot recover the key when only the first round of parallel table lookup leakage waveforms are collected. This method can successfully recover the waveforms without leakage at other locations of the encryption algorithm.
Claims
1. A cryptographic side channel analysis method based on a secondary start genetic algorithm, characterized in that: The following steps are involved: Step 1: For the first-order mask protection scheme implemented by nonlinear layer lookup table, determine the second-order leakage caused by mask multiplexing in the case of parallel implementation, and construct the corresponding formula between the intermediate value of the cryptographic algorithm and the leakage waveform for the second-order leakage; Among them, the first-order mask protection scheme adopts the nonlinear layer lookup table implementation method after pre-calculating the mask. The bit slicing technology uses the same lookup table when the corresponding bit is transformed through the nonlinear layer. The lookup table implementation refers to pre-calculating all possible values for the 4-bit mask of the nonlinear layer input and output in the pre-calculation stage, and directly taking the pre-calculated value as the result when the algorithm executes the nonlinear layer transformation. The nonlinear layer of the cryptographic algorithm is implemented in parallel using the lookup table method. After implementation, the Boolean mask is changed compared to the nonlinear layer, but the vertical multiplexing form is not affected. The second-order leakage refers to the fact that due to the use of the lookup table form, the mask between the bits of each register is the same, which is bit 0 or bit 1, resulting in the correlation relationship between the intermediate value and the value before the mask protection is not adopted, which remains the same or is bit-inverted. Step 2: For the generated second-order leakage, a calculation formula for the offset between the register Hamming weight and the typical value of the register bit width Hamming weight for calculating the nonlinear layer result in the form of a lookup table is constructed; Among them, since the nonlinear layer is pre-calculated in the form of a lookup table, the mask of the output result of the nonlinear layer is the same, and the lightweight cryptographic algorithm often uses the bit slicing technology, so that different bits of the output result are stored in different registers respectively. For different bits stored in the same register, the masks of the corresponding bits are exactly the same; for a register storing a certain bit slice bit, the mask of the register has only two possibilities: all "1" and all "0"; and using the all "1" mask and the algorithm intermediate value to perform an XOR operation, that is, to invert the algorithm intermediate value, and using the all "0" mask and the algorithm intermediate value to perform an XOR operation, that is, to keep the algorithm intermediate value unchanged, in these two cases, the Hamming distance between the algorithm intermediate value and the typical value of the Hamming weight of the corresponding bit number is the same, that is, the offset from the typical value is the same, so the influence of the first-order mask can be ignored; the typical value of the Hamming weight of the corresponding bit number refers to, for example, the typical value of the Hamming weight of 32 bits is 16, and the typical value is the maximum probability of the Hamming weight distribution of the corresponding bit number; Step 3: Construct the genetic algorithm fitness calculation formula for the algorithm intermediate value offset: Where HW(y i ) refers to the Hamming weight of the intermediate value of each bit slice register, HW(y i * ) refers to the typical value of the Hamming weight of the corresponding register bit width; T refers to the energy consumption amplitude of the leakage position of the register of the target device in the energy trace, Refers to the average value of the energy consumption amplitude of the leakage position of multiple energy traces; there is a correlation between the offset of the Hamming weight and the offset of the leakage waveform energy amplitude, and this correlation coefficient is used as the fitness in the genetic algorithm; Step 4: Use a genetic algorithm with secondary startup and dynamic population reduction combined with the formulas in steps 2 and 3 to recover the key.
2. A cryptographic side channel analysis method based on a secondary start genetic algorithm as claimed in claim 1, characterized in that: Step 4 includes the following steps: Step 4.1: The random number generator randomly generates the initial key, that is, the individuals of the population, and the randomly generated individuals are used as the initial population for evolution; Here, individual refers to a complete guess key; Step 4.2: Calculate the fitness of individuals in the population; Step 4.3: Perform selection, crossover and mutation operations on the individuals in the population to obtain the next generation population; Among them, selection refers to selecting the top 70% of individuals in the population as parents; the fitness calculation formula refers to step 3; Among them, crossover refers to randomly selecting specific bits of specific bytes of different registers on an individual, and exchanging all specific bits of the two guessed keys after the crossover point; specific bytes refer to selecting the same byte of all registers; specific bits refer to the same bit in the same byte; Among them, mutation refers to traversing the specific bits of the specific bytes of the guessed key represented by the individual, and selecting the candidate individual with the highest fitness as the mutation result; traversal refers to generating candidate individuals with all possible values of the specific bit under the premise that the other bits remain the same, calculating their fitness and sorting them; Step 4.4: Reduce the number of individuals in the population to speed up its evolution; The method of reducing the number of individuals is to reduce the number of individuals in the population to one-fifth of the original number after two iterations, and take the top one-fifth of the fitness ranking in the population as the new population after reduction; the lower limit of the reduction is 20 individuals; Step 4.5: Repeat steps 4.2 to 4.4 until the iteration limit is reached or the correct key is evolved; Step 4.6: When the iteration limit is reached and the correct key has not been evolved, all individuals in the population are discarded, a new population with the same number of individuals is randomly generated and the process returns to step 4.
2. After the second restart, the process ends at step 4.
5. Among them, re-random generation means that the number of individuals in the population is the same as the initial number of individuals before reduction, and the relevant parameters of the genetic algorithm operator remain consistent; in order to avoid the impact caused by the failure of the previous evolution, the last optimal individual is discarded and does not participate in the evolution of the new population.
3. As described in claim 1, the present method only requires the energy consumption amplitude caused by the storage register flip after the nonlinear layer parallel table lookup. Compared with the previous second-order attack, in the case of parallel implementation, the energy consumption amplitude generated by the first-order mask pre-calculation is not required.
Citation Information
Cited By
Method for generating optimal wide-interval frequency hopping sequence based on genetic algorithm
CN120880489A