Construction and application method of cross-device side channel attack model based on domain adaptation
By introducing a domain adaptive autoencoder into the side channel attack model, and using MMD loss and reconstruction loss functions to regulate the feature differences between devices, the application problem of the side channel attack model in the prior art is solved, and stronger generalization capabilities and key recovery effects are achieved.
Patent Information
- Application Number
- CN202510473772.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-06-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing side channel attack model based on deep learning is difficult to adapt to the differences between different devices, resulting in weak generalization capabilities and unable to effectively implement side channel analysis in scenarios with high device differences.
The domain adaptation-based autoencoder is used to domain adapt the side channel attack feature data of different devices. Through the maximum mean difference (MMD) loss and reconstruction loss function, the feature distribution difference between the source device and the target device is narrowed, thereby building a cross-device side channel attack model.
It significantly improves the generalization ability of deep learning models among different devices, enhances the scope of application of side channel attack models, and realizes efficient key recovery capabilities under the situation of high device differences.
Smart Images

Figure CN120223547A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of side-channel attacks, and particularly to the construction and application method of a cross-device side-channel attack model based on domain adaptation. Background Art
[0002] With the rapid development of computing power and the increasing attention to the security of Internet of Things hardware, side-channel attack (SCA), as a technology that exploits the physical characteristics of hardware to leak information, has become an important threat in the field of information security. Such attacks bypass traditional encryption protection measures and directly target the implementation of encryption algorithms, bringing huge risks to device and data security. By analyzing power consumption, electromagnetic radiation, or timing information during the encryption process, an attacker can infer encryption keys or other sensitive data. This attack method has been widely verified on various devices, from smart cards to complex embedded systems.
[0003] Among various types of side-channel attacks, Profiled SCA plays a crucial role. With the introduction of machine learning and deep learning, the ability of Profiled SCA has been further enhanced. The SCA community emphasizes the following advantages of deep learning-based SCA: (1) It can process higher-dimensional inputs compared to traditional template attacks; (2) It can naturally adapt to and cope with masking strategies, which enables it to maintain high accuracy when facing signals with noise or masking; (3) It can exhibit stronger generalization ability.
[0004] The Chinese invention patent CN202111598760.3 in the prior art proposes a side-channel attack method based on a convolutional neural network. It collects the power consumption traces of a cryptographic device, extracts relevant feature points, constructs a data set for training a convolutional neural network model, and finally uses the trained model to attack the power consumption traces in the test set to recover key information. The Chinese invention patent CN202311127739.4 designs a model that extracts features at different scales using different-sized convolutional kernels, aiming to improve the model performance through the internal architecture design of the network. However, although these deep learning technologies perform well in Profiled SCA, the existing deep learning-based side-channel attack (DL-SCA) studies as described above do not fully consider the differences between devices and can only achieve attack analysis on a single device. The differences between different devices come from different hardware platforms, measurement technology differences, real-time device random variations, and possible protection measures implemented by the target device. These factors make the attack models trained based on one device in the prior art unable to be effectively applied to other devices, thus reducing the generalization ability of the model and the success rate of the attack.
[0005] In addition, in recent years, some researchers have begun to focus on the impact of device differences on the attack effect. For example, Chinese invention patent CN201911012806.1 proposes an unsupervised domain adaptation method based on an adversarial learning loss function. It generates high-level features from source domain images through a feature extraction network and calculates the cross-entropy loss, thereby adjusting the feature extraction network without target domain labels to make the extracted features have better adaptability between the source domain and the target domain and improve the performance of the model on the target domain. Chinese invention patent CN202310124377.7 proposes a cross-device side-channel analysis method based on a variational autoencoder (VAE) model. In the offline stage, it trains by constructing a VAE model with a single encoder and multiple decoders; in the online stage, it uses the trained encoder to extract latent space features from the power consumption traces of the target device and combines a support vector machine classifier to infer the key. This method can achieve general feature extraction among multiple devices and effectively cope with the distribution differences of side-channel curves between different devices. However, at present, in the case of large device differences, the attack success rate will be significantly reduced, and existing research often fails to fully capture the common features between different devices, resulting in poor performance of the model on new devices.
[0006] In summary, there is currently no solution on the market that can well implement side-channel attacks across devices with large device differences. Summary of the Invention
[0007] The embodiments of the present application provide a method for constructing and applying a cross-device side-channel attack model based on domain adaptation. The domain adaptation is realized for the collected data set based on the loss function regulation mechanism of the maximum mean discrepancy to narrow the feature distribution difference between the source device data set and the target device data set, thereby realizing the distribution alignment between the source device data set and the target device data set, and further enabling the cross-device side-channel attack model to be widely applied to devices with large device differences to implement side-channel analysis.
[0008] In a first aspect, the embodiments of the present application provide a method for constructing a cross-device side-channel attack model based on domain adaptation, including the following steps: S1: Obtain side-channel data of the same encryption algorithm running on different cryptographic devices as the initial data set, and extract side-channel attack feature data from the initial data set; S2: Use an autoencoder to perform domain adaptation on the side-channel attack feature data from different cryptographic devices to obtain an aligned data set. The autoencoder is trained with unlabeled side-channel attack feature data, and the loss function of the autoencoder includes the MMD loss function and the reconstruction loss function; S3: Input the aligned data set into the cross-device side-channel attack framework for training until the training conditions are met to obtain a cross-device side-channel attack model.
[0009] In a second aspect, an application method of a cross-device side-channel attack model based on domain adaptation provided by an embodiment of the present application includes: Obtain side-channel data when an encryption algorithm runs on a cryptographic device to be analyzed, and extract side-channel attack feature data from the side-channel data; Input the side-channel attack feature data of the cryptographic device to be analyzed into the cross-device side-channel attack model obtained by constructing the above-mentioned cross-device side-channel attack model based on domain adaptation to output a prediction result.
[0010] In a third aspect, an electronic device provided by an embodiment of the present application includes a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the method for constructing the cross-device side-channel attack model based on domain adaptation.
[0011] In a fourth aspect, a readable storage medium provided by an embodiment of the present application stores a computer program. The computer program includes program code for controlling a process to execute the process, and the process includes the method for constructing the cross-device side-channel attack model based on domain adaptation.
[0012] The main contributions and innovations of the present invention are as follows: Enhance the generalization ability of the deep learning model: Design a domain adaptation autoencoder as a preprocessing step. This innovative measure significantly reduces the data distribution difference between the source device and the target device. Traditional deep learning-based side-channel attack models can often only perform attack analysis on a single device and are difficult to adapt to the differences between different devices, resulting in weak generalization ability. However, through the processing of the autoencoder in the present application, this problem is effectively overcome. It allows the deep learning model to better learn the common features in the data of different cryptographic devices, enabling the trained cross-device side-channel attack model to be widely applied to scenarios with large device differences, significantly improving the generalization ability of the model between different devices, and greatly expanding the applicable range of the side-channel attack model. In addition, the autoencoder adopts an unsupervised learning method and does not rely on target labels during the training process, avoiding the complex process of obtaining labels and the problems caused by inaccurate labels, further enhancing the practicality and versatility of the model.
[0013] Achieve data feature balance optimization: Creatively introduce the Maximum Mean Discrepancy (MMD) loss and reconstruction loss in the autoencoder, and through adjusting the penalty parameter, achieve a delicate balance between reducing inter-domain differences and preserving data structure features. The MMD loss function can accurately quantify and reduce the potential feature differences of side-channel attack feature data from different sources, making the datasets of different cryptographic devices tend to be consistent in feature distribution, thus narrowing the gap between the source device dataset and the target device dataset, and making the performance of the model more stable on different devices. At the same time, the reconstruction loss function uses the mean square error, which can retain the feature information of the original data to the greatest extent, ensuring that the key features of the data are not lost during the process of reducing inter-domain differences, providing a high-quality data basis for the subsequent training of the attack model, and effectively improving the performance and accuracy of the attack model.
[0014] Efficient key recovery ability: This application has conducted comprehensive experimental verification on a variety of microprocessors, covering various types of cryptographic devices such as STM32F0, STM32F1, STM32F2, STM32F3, STM32F4, and XMEGA. The experimental results strongly prove that the framework of this attack model can still achieve efficient key recovery in the case of large device differences. This means that in actual application scenarios, whether facing different hardware platforms, different measurement technologies, real-time random changes in devices, or the implementation of protection measures, the technical solution of this application can demonstrate strong attack capabilities, posing a severe challenge to the security of the encryption system, and also providing important research references and technical warnings for the information security field in dealing with side-channel attacks.
[0015] The details of one or more embodiments of this application are presented in the following drawings and descriptions to make other features, purposes, and advantages of this application more concise and understandable. Brief Description of the Drawings
[0016] The drawings described herein are used to provide a further understanding of this application, form a part of this application, and the schematic embodiments and descriptions thereof are used to explain this application and do not constitute an improper limitation of this application. In the drawings: Figure 1 is a flowchart of a method for constructing a cross-device side-channel attack model based on domain adaptation according to an embodiment of this application; Figure 2 is a structural diagram of an autoencoder according to an embodiment of this application; Figure 3 is a flowchart of a method for applying a cross-device side-channel attack model based on domain adaptation according to an embodiment of this application; Figure 4 is a schematic diagram of the hardware structure of an electronic device according to an embodiment of this application. Detailed Embodiments
[0017] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements.
[0018] It should be noted that: In other embodiments, the steps of the corresponding method are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.
[0019] Embodiment 1 As Figure 1 shown, this solution provides a method for constructing a cross-device side-channel attack model based on domain adaptation. By performing domain adaptation on the collected side-channel data of different devices, the constructed cross-device side-channel attack model has strong cross-device generalization ability.
[0020] Specifically, the method for constructing a cross-device side-channel attack model based on domain adaptation provided by this solution includes the following steps: S1: Obtain the side-channel data of the same encryption algorithm running on different cryptographic devices as the initial data set, and extract side-channel attack feature data from the initial data set; S2: Use an autoencoder to perform domain adaptation on the side-channel attack feature data from different cryptographic devices to obtain an aligned data set. The autoencoder is trained with unlabeled side-channel attack feature data, and the loss function of the autoencoder includes the MMD loss function and the reconstruction loss function; S3: Input the aligned data set into the cross-device side-channel attack framework and train until the training conditions are met to obtain a cross-device side-channel attack model.
[0021] It should be emphasized that since this solution uses the aligned data set after domain adaptation to train the cross-device side-channel attack framework, the cross-device side-channel attack model trained by this solution has strong cross-device generalization ability, and realizes the side-channel attack analysis of cryptographic devices of different chips.
[0022] Regarding step S1 of this solution: The cryptographic device in this solution refers to a hardware device that can perform cryptographic operations of encryption algorithms and process data such as encryption and decryption. It includes, but is not limited to, chips such as STM32F0, STM32F1, STM32F2, STM32F3, STM32F4, XMEGA and their related hardware systems, where the encryption keys of different cryptographic devices are different.
[0023] The encryption algorithms in this solution include symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms, etc., including but not limited to DES, 3DES, AES, RC4, RSA, ECC, MD5, SHA, etc.
[0024] The side-channel data in this solution refers to the information related to the device operation obtained through the means of non-direct access to the encryption algorithm or key when the cryptographic device executes operations such as encryption algorithms, mainly including the following categories: power consumption data, electromagnetic data, time data, and sound data.
[0025] In a specific embodiment, this solution preferably runs the AES encryption algorithm on the cryptographic devices of STM32F0, STM32F1, STM32F2, STM32F3, STM32F4, XMEGA, and real-time collects and saves the side-channel data generated when the cryptographic device is running.
[0026] In addition, after obtaining the initial data set, this solution needs to extract side-channel attack feature data from it. Specifically, in the step of "extracting side-channel attack feature data from the initial data set", the feature data related to side-channel attacks is extracted from the initial data set according to the leakage of intermediate states, and the feature data is preprocessed by standardization operations and constructed into side-channel attack feature data.
[0027] It should be noted that the side-channel attack feature data in this solution is side-channel leakage, that is, traces.
[0028] During the process of the cryptographic device executing the encryption algorithm, it will go through multiple intermediate calculation steps, and each step will generate some intermediate results or intermediate states. These intermediate states should be confidential and only used for internal calculations of the encryption algorithm. However, since the cryptographic device will leak some information through side channels (such as power consumption, electromagnetic, etc.) during actual operation, it is possible for attackers to obtain clues related to these intermediate states, and this solution precisely extracts the feature data related to side-channel attacks from the initial data set based on the leakage of these intermediate states.
[0029] The feature data constructed in this solution includes traces, corresponding keys, and plaintext. Furthermore, in the step of "performing standardized preprocessing operations on the feature data and constructing it into side-channel attack feature data", labels for each piece of feature data are made based on the corresponding keys of the feature data, and feature data with high correlation to the same label is screened and constructed into side-channel attack feature data.
[0030] Specifically, when the encryption algorithm is the AES encryption algorithm, the formula for making labels for each piece of feature data based on the key is as follows: ; where Sbox represents the S-box operation in the AES encryption algorithm, represents the exclusive OR operation, p represents the plaintext, k represents the key.
[0031] In the step of "screening feature data with high correlation to the same label", the Pearson correlation coefficient is used to calculate the correlation between the feature data and the label, and feature data with high correlation to the same label is retained. The purpose of doing this in this solution is to reduce the amount of data used in subsequent training of the model.
[0032] Specifically, the formula for the Pearson correlation coefficient is:
[0033] where is the Pearson correlation coefficient between the data at the i th byte and the j th time point and the label, represents the feature value of the d th sample at the j th time point, represents the label of the d th label sample at the j th time point, represents the mean of the feature values on the i th byte, represents the mean of the label values on the i th byte, represents the number of samples, 1 ≤ i ≤ N p .
[0034] Regarding step S2 of this solution: The autoencoder designed in this solution for domain adaptation uses an unsupervised learning method and does not require the use of labels when training the autoencoder, and is used to learn an efficient representation of the input data.
[0035] Specifically, the structure of the autoencoder in this solution is as Figure 2As shown, the autoencoder includes a plurality of convolutional blocks and a plurality of deconvolutional blocks connected in sequence, where the number of convolutional blocks and deconvolutional blocks is the same. Each convolutional block includes a one-dimensional convolutional layer, an activation function layer, and a one-dimensional max pooling layer. Each deconvolutional block includes a corresponding one-dimensional deconvolutional layer and an activation function layer. The purpose of the convolutional blocks in the autoencoder of this solution is to extract features from the input data and map the high-dimensional features to the latent space. The purpose of the deconvolutional blocks is to map the data in the latent space back to the original data space to complete data reconstruction, which results in data that is still similar to the input data (the size, structure are the same as the input data).
[0036] In a specific embodiment, the convolutional kernels in the one-dimensional convolutional layer of the sequentially connected convolutional blocks are (1, 64, 2), (64, 32, 2), (32, 16, 2), and (16, 8, 2) in sequence. The convolutional kernels in the one-dimensional deconvolutional layer of the sequentially connected deconvolutional blocks are (8, 16, 3), (16, 32, 4), (32, 64, 4), and (64, 1, 2) in sequence.
[0037] The multiple convolutional blocks in this solution form the encoder in the autoencoder, and the multiple deconvolutional blocks form the decoder in the autoencoder. The encoder maps the high-dimensional input side-channel attack feature data to the latent space and converts it into a hidden representation , with the purpose of enabling the encoder to extract the most informative features. The conversion process can be represented by a mathematical formula:
[0038] where x represents the input side-channel attack feature data, σ represents the network parameters of the encoder, W 1 and b 1 represent the weight and bias of the encoder respectively; the decoder is to remap the hidden representation h back to the original data space to complete data reconstruction and obtain an aligned dataset. Similarly, this conversion process can be represented by a mathematical formula: ; where h represents the hidden representation, σ represents the network parameters of the decoder, W 2 and b 2 represent the weight and bias of the decoder respectively, represents the converted side-channel attack feature data.
[0039] Once again, it is emphasized that regarding the training method of the autoencoder in this solution: the autoencoder in this solution is constructed through unsupervised learning using the side-channel attack feature data of different cryptographic devices, that is, the side-channel attack feature data from different cryptographic devices are input into the autoencoder for training until the loss function is minimized. Generally, the side-channel attack feature data of two cryptographic devices are taken and input into the autoencoder for training.
[0040] The loss function of the autoencoder consists of the MMD loss function and the reconstruction loss function, and is expressed as: ; where Loss is the loss function of the autoencoder, L Recons is the total reconstruction loss function, L MMD is the MMD loss function, is the penalty parameter. In this solution, when training the autoencoder, the balance between reducing the differences between datasets from different sources and retaining the data structure features can be achieved by adjusting the penalty parameter.
[0041] In some embodiments, the loss function of the autoencoder is composed of the combined reconstruction loss functions of two cryptographic devices respectively. As Figure 2 shown, the side-channel attack feature data of two different cryptographic devices are respectively input into the autoencoder. The weights are shared between the encoders of the two autoencoders. The MMD loss function is constructed based on the latent representations output by the encoders of the two autoencoders, and then the reconstruction loss functions corresponding to the respective cryptographic devices are constructed based on the output data of the decoders of the two autoencoders. The two reconstruction loss functions and the MMD loss function are aggregated as the loss function of the autoencoder.
[0042] Regarding the reconstruction loss function of each cryptographic device, the mean square error is adopted to retain as much original feature information of the input data as possible, and is expressed as: ; where MSE corresponds to the reconstruction loss function of the side-channel feature data of the current source, n is the total number of data points in the side-channel feature data of the current source, is the actual value of the i-th data point, is the predicted value of the i-th data point, 1 ≤ i ≤ n。
[0043] The MMD loss function of the autoencoder in this solution uses the Maximum Mean Discrepancy (MMD) to quantify and reduce the differences between the potential features of side-channel attack feature data from different sources, making the feature distributions of two side-channel attack feature data from different sources tend to be consistent.
[0044] The MMD loss function of this solution is expressed as: ; ; ; .
[0045] Where n and m respectively represent the data sizes of the side-channel attack feature data from two sources, and represent the samples of the source dataset, and represent the samples of the target dataset, represents the inner product of the u th and th data points of the side-channel attack feature data from the same source and in the latent space after being transformed by the mapping function , which can be represented by the kernel function ; represents the inner product of the th and u th data points of the side-channel attack feature data from different sources v and i in the latent space after being transformed by the mapping function and , which can be represented by ; represents the inner product of the th and th data points of the side-channel attack feature data from the same source v in the latent space after being transformed by the mapping function j and and j’ , which can be represented by the kernel function after being transformed by the mapping function , and can be represented by the kernel function .
[0046] It should be noted that the method of using the kernel function to replace the inner product in this solution can calculate the MMD without explicit calculation of the high-dimensional feature space, avoiding the need to directly process high-dimensional features. The calculation formula of the kernel function is as follows: 。
[0047] Among them represents the width parameter of the Gaussian kernel, represents the norm of the vector, u and v correspond to two data points, and exp() represents the exponential operation around the natural constant.
[0048] Similarly, for the corresponding 、 and the calculation only needs to replace the data points with the corresponding data points.
[0049] It should be emphasized again that the reason for choosing the MMD loss function as part of the loss function of the autoencoder in this solution is that the MMD loss can be used to reduce the difference in feature distributions between datasets from different sources, for example, alignment between STM32F1 and STM32F2. If it is a comparison between STM32F1 and STM32F1, the MMD value will be very small. The purpose of using MMD as the loss function is to reduce the difference between these two datasets, so that the classifier trained on the source device dataset can still achieve effective performance when attacking the target device dataset.
[0050] Regarding step S3 of this solution: The cross-device side-channel attack framework provided by this solution consists of three consecutive convolutional blocks, one flattening layer, and four fully connected layers. Each convolutional block consists of a one-dimensional convolutional layer, a one-dimensional batch normalization layer, and a one-dimensional max pooling layer.
[0051] It should be noted that this solution uses aligned datasets from two sources as input to the cross-device side-channel attack framework for training. The datasets include corresponding labels, and the cross-entropy loss is used for the classifier in the training of the side-channel attack. The formula for the cross-entropy loss is as follows:
[0052] Among them, C represents the number of label categories, y i is the true label of category i , p i is the predicted probability of the model for category i , 1 ≤ i ≤ C , and log() represents taking the logarithm.
[0053] It should be noted that the cross-entropy loss is usually the loss function of the classifier. In deep learning side-channel analysis, a classifier needs to be trained finally to match the traces with the labels. The smaller the cross-entropy loss, the higher the accuracy of the matching between the traces and the labels.
[0054] Of course, after the cross-device side-channel attack model is constructed using the above solution in this scheme, the cross-device side-channel attack model is used to make predictions on the target data set to evaluate the accuracy of the cross-device side-channel attack model. The construction of the target data set is the same as that of the alignment data set. The specific formula for evaluating the accuracy is as follows; ; ; where Acc is the accuracy, n represents the total number of samples in the target data set used for testing, represents the th predicted value of the sample, represents the th actual value of the sample, I() represents a judgment function, 1 ≤ i ≤ n.
[0055] At the same time, the guessing entropy is used to evaluate the attack effect. The guessing entropy is defined as the number of traces required to make the correct key rank zero in Key guess , that is, the number of samples required to recover the key. In the attack stage, the attacker uses N attack traces to construct a key guessing vector , where represents the size of the key space, K k represents the kth key in the key space. The main body K represents the key, and the subscript k represents the kth key. When the number of traces used for the attack increases, the rank of the correct key Key true will gradually decrease. In other words, first, the guesses of each key in a trace are sorted in descending order of probability. At this time, the probability of the correct key is not the highest. Then, the number of traces is increased. At this time, the rank of the correct key in the key space will decrease. The lower the rank, the higher the accuracy. When the correct key ranks 0th, it means that no more traces need to be added to accurately recover the key. The number of traces used is defined as the guessing entropy.
[0056] Embodiment 2 Based on the same concept, as Figure 3 shown, this application also proposes an application method of a cross-device side-channel attack model based on domain adaptation, including: Obtain the side-channel data of the encryption algorithm running on the cryptographic device to be analyzed, and extract the side-channel attack feature data from the side-channel data; Input the side-channel attack feature data of the cryptographic device to be analyzed into the autoencoder mentioned in Embodiment 1 to obtain the traces after domain adaptation, and input the traces after domain adaptation into the cross-device side-channel attack model obtained in Embodiment 1 to output the prediction result.
[0057] It should be noted that while the traces after domain adaptation retain the original side-channel leakage characteristics, they are aligned with the characteristics of the cryptographic devices that have been analyzed to achieve the mutual approximation of the feature dimensions. Then, the traces after domain adaptation are input into the cross-device side-channel attack model for analysis to obtain the corresponding recovered key, that is, the key corresponding to the cryptographic device to be analyzed is output in the cross-device side-channel attack model.
[0058] The same content as in Embodiment 1 in Embodiment 2 will not be repeated.
[0059] Embodiment 3 This embodiment also provides an electronic device, refer to Figure 4 , including a memory 404 and a processor 402. A computer program is stored in the memory 404, and the processor 402 is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0060] Specifically, the above-mentioned processor 402 may include a central processing unit (CPU), or a specific integrated circuit (Application Specific Integrated Circuit, abbreviated as ASIC), or may be configured as one or more integrated circuits implementing the embodiments of the present application.
[0061] Among them, the memory 404 may include a mass storage 404 for data or instructions. By way of example and not limitation, the memory 404 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disc, a magneto-optical disc, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In appropriate cases, the memory 404 may include removable or non-removable (or fixed) media. In appropriate cases, the memory 404 may be internal or external to the data processing device. In a particular embodiment, the memory 404 is non-volatile memory. In a particular embodiment, the memory 404 includes a read-only memory (ROM) and a random access memory (RAM). In appropriate cases, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these. In appropriate cases, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended data out dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0062] The memory 404 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 402.
[0063] By reading and executing the computer program instructions stored in the memory 404, the processor 402 implements any one of the construction methods or application methods of the cross-device side-channel attack model based on domain adaptation in the above embodiments.
[0064] Optionally, the above electronic device may further include a transmission device 406 and an input / output device 408. Among them, the transmission device 406 is connected to the above processor 402, and the input / output device 408 is connected to the above processor 402.
[0065] The transmission device 406 can be used to receive or send data via a network. Specific examples of the above network may include wired or wireless networks provided by a communication provider of the electronic device. In one example, the transmission device includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one example, the transmission device 406 can be a radio frequency (Radio Frequency, abbreviated as RF) module, which is used to communicate with the Internet wirelessly.
[0066] The input / output device 408 is used to input or output information. In this embodiment, the input information can be side-channel attack feature data of a password device, etc., and the output information can be the correct key, etc.
[0067] Optionally, in this embodiment, the above processor 402 can be set to execute the following steps through a computer program: S1: Obtain side-channel data of the same encryption algorithm running on different password devices as an initial data set, and extract side-channel attack feature data from the initial data set; S2: Use an autoencoder to perform domain adaptation on the side-channel attack feature data from different password devices to obtain an aligned data set, where the autoencoder is trained using unlabeled side-channel attack feature data, and the loss function of the autoencoder includes the MMD loss function and the reconstruction loss function; S3: Input the aligned data set into the cross-device side-channel attack framework for training until the training conditions are met to obtain a cross-device side-channel attack model.
[0068] It should be noted that specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, and will not be repeated here.
[0069] In general, various embodiments can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects of the present invention can be implemented in hardware, while other aspects can be implemented by firmware or software executed by a controller, microprocessor, or other computing device, but the present invention is not limited thereto. Although various aspects of the present invention may be shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, by way of non-limiting example, the blocks, devices, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuits or logic, general hardware or a controller or other computing device, or some combination thereof.
[0070] Embodiments of the present invention can be implemented by computer software that is executable by a data processor of a mobile device, such as in a processor entity, or by hardware, or by a combination of software and hardware. A computer software or program (also referred to as a program product), including software routines, applets, and / or macros, can be stored in any device-readable data storage medium, and they include program instructions for performing specific tasks. The computer program product can include one or more computer-executable components that are configured to perform the embodiments when the program runs. One or more computer-executable components can be at least one software code or a part thereof. Additionally, in this regard, it should be noted that any block in the logical flow as shown in the figure can represent a program step, or interconnected logical circuits, blocks, and functions, or a combination of program steps and logical circuits, blocks, and functions. The software can be stored on physical media such as memory chips or storage blocks implemented within the processor, magnetic media such as hard disks or floppy disks, and optical media such as, for example, DVDs and their data variants, CDs. The physical media is a non-transitory medium.
[0071] Those skilled in the art should understand that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.
[0072] The above embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application.
Claims
1. A method for constructing a cross-device side channel attack model based on domain adaptation, characterized in that: The following steps are involved: S1: Obtain side channel data of the same encryption algorithm running on different cryptographic devices as an initial data set, and extract side channel attack feature data from the initial data set; S2: Use an autoencoder to perform domain adaptation on the side channel attack feature data from different cryptographic devices to obtain an aligned dataset, where the autoencoder is trained using unlabeled side channel attack feature data, and the loss function of the autoencoder includes an MMD loss function and a reconstruction loss function; S3: Input the aligned dataset into the cross-device side-channel attack framework for training until the training conditions are met to obtain a cross-device side-channel attack model.
2. The method for constructing a cross-device side channel attack model based on domain adaptation according to claim 1, characterized in that: In the step of "extracting side channel attack feature data from the initial data set", feature data related to the side channel attack is extracted from the initial data set according to the intermediate state leakage, and a standardized preprocessing operation is performed on the feature data to construct the side channel attack feature data.
3. The method for constructing a cross-device side channel attack model based on domain adaptation according to claim 2, characterized in that: In the step of "applying standardized preprocessing operations to the feature data and constructing it into side-channel attack feature data", a label for each feature data is produced based on the key of the corresponding feature data, and feature data with high correlation with the label is selected and constructed into side-channel attack feature data.
4. The method for constructing a cross-device side channel attack model based on domain adaptation according to claim 1, characterized in that: The autoencoder includes a plurality of convolution blocks and a plurality of deconvolution blocks connected in sequence, wherein the number of convolution blocks and deconvolution blocks is the same, each convolution block includes a one-dimensional convolution layer, an activation function layer and a one-dimensional maximum pooling layer, and each deconvolution block includes a corresponding one-dimensional deconvolution layer and an activation function layer.
5. The method for constructing a cross-device side channel attack model based on domain adaptation according to claim 1, characterized in that: The loss function of the autoencoder includes the MMD loss function and the reconstruction loss function, which is expressed as: ; in Loss is the loss function of the autoencoder, L Recons is the total reconstruction loss function, L MMD is the MMD loss function, is the penalty parameter.
6. The method for constructing a cross-device side channel attack model based on domain adaptation according to claim 5, characterized in that: ; ; ; ; in n and m Represents the data size of the side channel attack feature data from two sources, and represents a sample of the source dataset, and represents a sample of the target dataset, represents the same source in the latent space u The side channel attack feature data i Data points and i’ Data points After mapping function The inner product after conversion can be obtained by using the kernel function express; Representing different sources in the latent space u and v The side channel attack feature data i Data points and j Data points After mapping function The inner product after conversion can be used express; Represents the same source in the latent space v The side channel attack feature data j Data points and j’ Data points After mapping function The inner product after conversion can be obtained by using the kernel function express.
7. The method for constructing a cross-device side channel attack model based on domain adaptation according to claim 5, characterized in that: The side channel attack feature data of two different cryptographic devices are respectively input into the autoencoder. The encoders of the two autoencoders share weights. The MMD loss function is constructed based on the invisible representation output by the encoders of the two autoencoders. Then, the reconstruction loss function corresponding to each cryptographic device is constructed based on the output data of the decoders of the two autoencoders. The reconstruction loss function and MMD loss function of the two cryptographic devices are summarized as the loss function of the autoencoder.
8. An application method of a cross-device side channel attack model based on domain adaptation, characterized in that: include: Obtaining side channel data of an encryption algorithm running on a cryptographic device to be analyzed, and extracting side channel attack feature data from the side channel data; Inputting the side channel attack feature data of the cryptographic device to be analyzed into the autoencoder mentioned in the method for constructing a cross-device side channel attack model according to any one of claims 1 to 7 to obtain a trace after domain adaptation, wherein the autoencoder is trained using unlabeled side channel attack feature data, and the loss function of the autoencoder includes an MMD loss function and a reconstruction loss function; The domain-adapted trace is input into the cross-device side-channel attack model described in any one of claims 1 to 7 to output a prediction result.
9. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to execute the method for constructing a cross-device side channel attack model based on domain adaptation as described in any one of claims 1 to 7.
10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, which includes a program code for controlling a process to execute a process, and the process includes a method for constructing a cross-device side-channel attack model based on domain adaptation according to any one of claims 1 to 7.
Citation Information
Patent Citations
Side channel analysis method based on deep learning
CN111565189A
Different device side channel analysis method based on multi-label learning
CN116366229A
Method and device for constructing side channel attack model and side channel attack method and device
CN117081722A
Method and apparatus for side channel analysis
CN117353896A
Grid password side channel analysis method based on transfer learning
CN117499035A