Side channel information processing method and device and computer equipment
By constructing a graph model and message delivery algorithm to process side channel information, the high computational complexity problem of LWE problems in post-quantum cryptography is solved, security and ability to defend against side channel attacks are improved, and efficient and accurate side channel information processing is achieved.
Patent Information
- Application Number
- CN202510361867.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-08
AI Technical Summary
In the existing post-quantum cryptography, the learning error problem (LWE) has high computational complexity and uncertainty when dealing with high-dimensional problems. The traditional method is costly or inefficient in practical applications, making it difficult to effectively prevent side channel information leakage.
By constructing a graph model, multiple target inequality corresponding to the side channel information are converted into the association structure of variable nodes and factor nodes, and the message delivery algorithm is used to iterate over and update information between nodes, combining clustering methods and mixed integer linear planning algorithms, and gradually converge to the optimal value to solve the side channel information.
It significantly reduces the computational complexity, improves the globality and accuracy of understanding, enhances the security of the post-quantum cryptography scheme, can better identify and defend side channel attacks, and protects the security of encrypted information.
Smart Images

Figure CN120281471A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cryptography technology, and particularly to a side-channel information processing method, apparatus, and computer device. Background Art
[0002] With the development of quantum computing, traditional number theory-based cryptography (such as RSA and ECC) faces the risk of being cracked. Therefore, researching post-quantum cryptography schemes has become an important field. The Learning With Errors (LWE) problem is a core mathematical problem in post-quantum cryptography. It involves recovering an unknown vector from a set of linear equations, but noise is added to these equations, making it very difficult to computationally recover the vector.
[0003] Currently, LWE is usually transformed into a short integer solution problem or into solving a non-linear equation. The former is to find a short vector in the dual lattice, but it requires allocating a large amount of memory space to store this data, and there are some uncertainties in complexity when dealing with high-dimensional problems; the latter's algebraic method can solve the LWE problem in sub-exponential time when the Gaussian distribution is narrow enough, but in practical cryptographic applications, its cost is much higher than other methods for the parameters usually considered. Summary of the Invention
[0004] Based on this, the purpose of this application is to provide a side-channel information processing method for solving inequalities, which is used to prevent side-channel information leakage and is of great significance for evaluating the security of post-quantum cryptographic schemes, and can solve the technical problems mentioned in the above background art.
[0005] In a first aspect, this application provides a side-channel information processing method. The method includes: Determine a plurality of target inequalities corresponding to the side-channel information; Construct a graph model according to the plurality of target inequalities; the graph model includes variable nodes associated with inequality unknowns and factor nodes associated with inequality coefficients; Perform message passing and update between the plurality of factor nodes and the plurality of variable nodes until an initial optimal value is obtained when a termination condition is reached; Solve the target inequalities according to the initial optimal value to obtain a target optimal value corresponding to the side-channel information.
[0006] In one embodiment, determining a plurality of target inequalities corresponding to the side-channel information includes: obtaining a plurality of initial inequalities corresponding to the side-channel information; the formats of each initial inequality are unified; constructing a feature space according to the plurality of initial inequalities; regarding each initial inequality as a feature data point; filtering the plurality of feature data points in the feature space through a clustering method to obtain a plurality of target inequalities.
[0007] In one embodiment, a plurality of feature data points in a feature space are filtered by a clustering method to obtain a plurality of target inequalities, including: for each feature data point, a neighborhood calculation is performed according to a preset domain radius, and a core point is identified according to a preset minimum number of samples; cluster expansion is performed on the identified core points, and the feature data points that are not assigned to any cluster are marked as noise points; the initial inequalities corresponding to the noise points are filtered to obtain the plurality of target inequalities corresponding to the side-channel information.
[0008] In one embodiment, the above method further includes: verifying the identified noise points, and when the verification fails, adjusting the domain radius and the minimum number of samples, so as to re-filter the plurality of feature data points in the feature space with the adjusted domain radius and minimum number of samples.
[0009] In one embodiment, message passing and updating are performed between the plurality of factor nodes and the plurality of variable nodes until an initial optimal value is obtained when a termination condition is reached, including: initializing the prior probability distribution of each variable node; for a factor node that receives an initial message, determining an initial probability distribution according to the initial message and the corresponding target inequality, and transmitting the initial probability distribution as a target message to the next variable node; for a variable node that receives a target message, determining a posterior probability distribution according to the target message and the corresponding prior probability distribution; transmitting the posterior probability distribution as a new initial message to the next factor node until an initial optimal value is obtained when a termination condition is reached.
[0010] In one embodiment, the target inequality is solved according to the initial optimal value to obtain a target optimal value corresponding to the side-channel information, including: substituting the variables that have been recovered into the target inequality according to the initial optimal value to obtain a reduced-dimensional target inequality group; solving the reduced-dimensional target inequality group by a target algorithm to obtain the target optimal value corresponding to the side-channel information.
[0011] In one embodiment, the target algorithm includes a mixed integer linear programming algorithm; the step of solving the reduced-dimensional target inequality group by the target algorithm to obtain the target optimal value corresponding to the side-channel information includes: converting the reduced-dimensional target inequality group into a linear programming model; the linear programming model includes multiple inequality constraints; based on the multiple inequality constraints, and solving the linear programming model by a solver to obtain the target optimal value corresponding to the side-channel information.
[0012] In a second aspect, the present application further provides a side-channel information processing device. The device includes: A graph model construction module, configured to determine a plurality of target inequalities corresponding to side-channel information, and construct a graph model according to the plurality of target inequalities; the graph model includes variable nodes associated with inequality unknowns and factor nodes associated with inequality coefficients.
[0013] A message passing and updating module, configured to perform message passing and updating between the plurality of factor nodes and the plurality of variable nodes until an initial optimal value is obtained when a termination condition is reached.
[0014] An optimal value solving module, configured to solve the target inequalities according to the initial optimal value to obtain a target optimal value corresponding to the side-channel information.
[0015] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above side-channel information processing are implemented.
[0016] In a fourth aspect, the present application further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the above side-channel information processing are implemented.
[0017] The above side-channel information processing method, device, computer device and readable storage medium transform a plurality of target inequalities into an association structure of variable nodes and factor nodes through a graph model, and use a message passing algorithm to iteratively update information between nodes, so that large-scale and high-complexity optimization problems can be efficiently processed, and the computational complexity is significantly reduced. After message passing and updating, it gradually converges to an initial optimal value, and then solves the target inequalities after dimensionality reduction processing to obtain a target optimal value corresponding to the side-channel information, improving the globality and accuracy of the solution. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 It is an application environment diagram of the side-channel information processing method in an embodiment; Figure 2 It is a flowchart of the side-channel information processing method in an embodiment; Figure 3 It is a schematic diagram of the graph model of a factor graph in an embodiment; Figure 4 It is a schematic diagram of the message passing principle in the belief propagation algorithm in an embodiment; Figure 5 It is a flowchart of the side-channel information processing method in another embodiment; Figure 6 It is an internal structure diagram of a computer device in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] In order to make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0020] The side-channel information processing method provided by the embodiments of the present application can be applied to an application environment as shown in Figure 1 and is implemented through the interaction between the terminal 102 and the server 104. Among them, the data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or can be placed on the cloud or other network servers. The terminal 102 can be different types of external encryption devices, providing side-channel information for the server 104; the server 104 is used to determine a plurality of target inequalities corresponding to the side-channel information, and construct a graph model according to the plurality of target inequalities. The server 104 is also used to perform message passing and update between a plurality of factor nodes and a plurality of variable nodes until an initial optimal value is obtained when a termination condition is reached, and solve the target inequality according to the initial optimal value to obtain the target optimal value corresponding to the side-channel information. Among them, the terminal 102 can be, but is not limited to, various personal computers, smart cards vulnerable to side-channel attacks, Internet of Things devices, etc. The server 104 is implemented by an independent server or a server cluster composed of multiple servers, and can also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0021] In one embodiment, as shown in Figure 2 a side-channel information processing method is provided. When this method is applied to the server in Figure 1 it includes the following steps: Step 202, determining a plurality of target inequalities corresponding to the side-channel information.
[0022] Among them, side-channel information refers to the information leaked through non-direct communication channels during the operation of different encryption devices, and these information may include physical characteristics such as power consumption, electromagnetic radiation, time delay, and sound.
[0023] Specifically, due to the learning error problem LWE, which is a mathematical problem in post - quantum cryptography, involving recovering an unknown vector from a set of linear equations with noise added. Specifically, given a matrix A and a vector b, where b is obtained by multiplying A with an unknown vector s and adding a small noise e, i.e., b = As + e. Therefore, when the server obtains various side - channel information during the operation of the encryption device, it converts it into multiple target inequality forms. For example, Ax <= b, including the elements of the coefficient matrix A and the vector b. Since A is an N 1024 matrix and b is an N1 vector, each inequality can be represented as a 1025 - dimensional vector.
[0024] Step 204, construct a graph model according to multiple target inequalities.
[0025] Among them, the graph model includes variable nodes associated with inequality unknowns and factor nodes associated with inequality coefficients. As Figure 3 shown, Figure 3 is a schematic diagram of a graph model created for a factor graph. The "check" in the figure can be understood as verifying the structural integrity of the factor graph, the rationality of the factor nodes, and the constraint conditions of the variable nodes.
[0026] Specifically, each factor node is connected to the relevant variable nodes. This graph model provides an intuitive way to distinguish the relationships between inequalities, making the constraint relationships clear at a glance. That is, variable nodes represent random variables, factor nodes represent functional relationships or probability distributions between variables, and edges are used to connect variable nodes and factor nodes, indicating their dependence relationships. After the server constructs the graph model, it can use algorithms and theories in graph theory for subsequent calculations and optimizations. For example, during the information - passing process, it can efficiently update the information between nodes according to the structure of the graph to find the optimal solution.
[0027] Step 206, perform message passing and updating between multiple factor nodes and multiple variable nodes until the termination condition is reached to obtain the initial optimal value.
[0028] Specifically, as Figure 4 shown, Figure 4It is a schematic diagram of the message passing principle in the belief propagation algorithm. The belief propagation algorithm includes the processes of message passing and belief updating. The server performs message passing between factor nodes and variable nodes through the belief propagation algorithm, and continuously updates the distribution of factor nodes and the beliefs (i.e., probability distributions) of variable nodes. By repeatedly executing the processes of message passing and belief updating, and the termination condition can be reaching a certain number of iterations, the change in belief updating is less than a certain threshold, etc. The algorithm can gradually collect and integrate the constraint information from different inequalities, making the beliefs of each variable node gradually converge near the optimal solution, thus gradually approaching the global optimal solution, that is, it can more accurately estimate the initial optimal value of the variable.
[0029] Step 208, solve the target inequality according to the initial optimal value to obtain the target optimal value corresponding to the side-channel information.
[0030] Specifically, the server performs dimensionality reduction processing on the target inequality according to the initial optimal value, including but not limited to linear discriminant analysis (LDA), feature selection and extraction methods, etc., to obtain the reduced-dimensional target inequality group. This is equivalent to decomposing the original problem into smaller sub-problems, reducing the complexity of the problem. The reduced-dimensional inequality group can be regarded as an optimization problem. The server solves the reduced-dimensional target inequality group through the target algorithm, and can effectively find the target optimal value that satisfies all inequality constraints, that is, the value of the unknown that satisfies all inequality constraints. This step is the ultimate goal of the entire solution process, providing specific numerical results for solving practical problems, enabling users to more accurately identify the information vulnerability points when facing side-channel attacks or understand the information loopholes that attackers may exploit based on the numerical results.
[0031] In the above side-channel information processing method, multiple target inequalities are transformed into the association structure of variable nodes and factor nodes through a graph model, and the message passing algorithm is used to iteratively update the information between nodes, enabling efficient processing of large-scale and high-complexity optimization problems and significantly reducing the computational complexity. After message passing and updating, it gradually converges to the initial optimal value, and then the target algorithm is used to solve the reduced-dimensional target inequality to obtain the target optimal value corresponding to the side-channel information, improving the globality and accuracy of the solution.
[0032] In addition, this solution not only shows high efficiency and accuracy when dealing with large-scale inequality groups, especially in the face of complex scenarios containing noise and error information, it can effectively improve the reliability and stability of the solution results. It can also effectively handle various complex situations in practical applications. For example, the structure of the graph model can be dynamically adjusted according to specific problems, and it is applicable to various side-channel analysis scenarios, with strong practicality and adaptability.
[0033] Therefore, the specific application scenarios of this solution include: Security Evaluation of Post-Quantum Cryptographic Algorithms: When designing and evaluating post-quantum cryptographic algorithms, this solution can help cryptographers more accurately identify vulnerable points in the face of side-channel attacks. By effectively processing inequality information with errors, it can more realistically simulate attack scenarios, thereby providing a basis for algorithm optimization and enhancing the overall security of the system. For example, in post-quantum cryptographic schemes such as Kyber, this method can be used to evaluate its security under side-channel attacks, timely discover potential security hazards, optimize algorithm design, and ensure the security of encrypted information in various attack scenarios.
[0034] Among them, the characterization of side-channel attacks is the process of using this unintentionally leaked information to infer sensitive data inside the system (such as keys, passwords, etc.).
[0035] Formulation of Side-Channel Attack Defense Strategies: This solution can provide strong support for formulating side-channel attack defense strategies. By deeply analyzing the inequality information in the LWE problem and understanding the vulnerabilities that attackers may exploit, targeted defense measures can be designed to improve the system's anti-attack ability. For example, in scenarios vulnerable to side-channel attacks such as smart cards and Internet of Things devices, applying this method can discover potential attack paths in advance and take corresponding protection measures, such as adding noise interference and optimizing algorithm implementation, to effectively resist side-channel attacks and protect users' sensitive information.
[0036] In one embodiment, determining multiple target inequalities corresponding to side-channel information includes: obtaining multiple initial inequalities corresponding to side-channel information; constructing a feature space based on the multiple initial inequalities; and filtering multiple feature data points in the feature space through a clustering method to obtain multiple target inequalities.
[0037] Among them, the format of each initial inequality is unified; each initial inequality is regarded as a feature data point.
[0038] Specifically, as Figure 5 shown, Figure 5 is a schematic flowchart of a side-channel information processing method in another embodiment. Usually, when the server obtains various side-channel information during the operation of the encryption device, the first thing generated is the original inequality group (such as bi <= Ax <= bu), and then all inequalities need to be converted into a unified format (such as Ax <= b), making all inequalities consistent in form by eliminating symbol differences.
[0039] The server constructs a feature space and regards each initial inequality as a feature data point, and its features include the elements of the coefficient matrix A and the vector b. Since A is N 1024For a matrix of, and b is a vector of N1, each initial inequality can be represented as a 1025-dimensional vector. After normalizing the eigenvectors, the dimensional influence between different features can be eliminated. Finally, the server uses a clustering method to filter multiple feature data points in the feature space to screen out some incorrect initial inequalities, and uses the inequalities corresponding to the finally unfiltered feature data points as the target inequalities.
[0040] In this embodiment, by constructing a feature space from multiple initial inequalities with a unified format, and then screening out some incorrect inequalities through a clustering method, the noise and incorrect information in the inequality group are reduced, which is equivalent to preprocessing and cleaning the data, removing the incorrect data that may interfere with the subsequent solution process, thereby improving the accuracy of the subsequently constructed graph model and message passing, and laying a foundation for the accuracy of the final solution result.
[0041] In one embodiment, multiple feature data points in the feature space are filtered through a clustering method to obtain multiple target inequalities, including: for each feature data point, neighborhood calculation is performed according to a preset neighborhood radius, and core point identification is performed according to a preset minimum number of samples; cluster expansion is performed on the identified core points, and the feature data points that are not assigned to any cluster are marked as noise points; the initial inequalities corresponding to the noise points are filtered to obtain multiple target inequalities corresponding to the side channel information.
[0042] Among them, the clustering method is such as the DBSCAN method, and its core idea is density-based clustering. Clusters are formed by identifying high-density regions, and points in low-density regions are marked as noise. The neighborhood radius (eps) defines the neighborhood range of each point, and the minimum number of samples (min_samples) defines the minimum number of neighborhood points required for a point to become a core point.
[0043] Specifically, the user will pre-select appropriate neighborhood radius and minimum number of samples. For each feature data point, the server calculates the points within its neighborhood with a radius equal to the neighborhood radius. If there are at least the minimum number of samples of points within the neighborhood of a point, then this point is marked as a core point. Then the server starts from the core point and groups the density-connected points into the same cluster. If a point is neither a core point nor belongs to any cluster, it is marked as a noise point, such as marking the noise point with the label -1. The server continues to find unvisited core points and repeats the process of expanding the cluster until all points have been visited. Then the initial inequalities corresponding to the noise points are filtered, and the remaining initial inequalities are used as the target inequalities.
[0044] In this embodiment, through the density-based clustering method, the core points in the feature data points can be effectively identified and the clusters can be expanded, while filtering the invalid information corresponding to the noise points, so as to accurately extract the target inequality corresponding to the side-channel information. This method not only improves the accuracy of information extraction, but also enhances the robustness of the model to noise, and improves the overall analysis efficiency and reliability.
[0045] In one embodiment, the above method further includes: verifying the identified noise points, and when the verification fails, adjusting the neighborhood radius and the minimum sample number, so as to re-filter the multiple feature data points in the feature space with the adjusted neighborhood radius and minimum sample number.
[0046] Among them, referring to Figure 5 As shown, the server verifies the identified outliers to ensure that they are indeed incorrect inequalities, and adjusts the neighborhood radius and the minimum sample number as needed when the verification fails, so as to improve the accuracy of outlier detection.
[0047] In one embodiment, message passing and updating are performed between multiple factor nodes and multiple variable nodes until an initial optimal value is obtained when a termination condition is reached, including: initializing the prior probability distribution of each variable node; for the factor node that receives the initial information, determining the initial probability distribution according to the initial information and the corresponding target inequality, and taking the initial probability distribution as the target message to be passed to the next variable node; for the variable node that receives the target message, determining the posterior probability distribution according to the target message and the corresponding prior probability distribution; taking the posterior probability distribution as the new initial message to be passed to the next factor node until an initial optimal value is obtained when a termination condition is reached.
[0048] Specifically, referring to Figure 5 As shown, the prior distribution P(xi) of the variable node xi is initialized using the probability distribution of the key, which is equivalent to integrating prior knowledge into the solution process, providing a reasonable starting point for subsequent message passing and belief updating, guiding the solution process in a more likely direction, and thus improving the solution efficiency and accuracy. For the factor node fj that receives the initial information, the server calculates an initial probability distribution P(fj|x) according to the initial information and the corresponding target inequality, and takes the initial probability distribution as the target message to be passed to the next variable node xi connected thereto. For the variable node xi that receives the target message, the server calculates the posterior probability distribution according to the target message P(fj|x) and its own prior probability distribution P(xi).
[0049] The server repeatedly checks whether the termination condition for convergence has been reached. If not, it passes the posterior probability distribution as the new initial message to the next factor node until the termination condition is met. If the termination condition is reached, this ensures that the algorithm can find the optimal solution as much as possible with limited computing resources. When the probability distribution is highly concentrated, it indicates that a very likely optimal solution has been found. At this point, the optimal value of the variable node can be estimated based on the probability distribution, such as selecting the initial optimal value with the highest probability as the solution to the unknown.
[0050] In this embodiment, message passing occurs between the factor nodes and the variable nodes, continuously updating the distribution of the factor nodes and the beliefs of the variable nodes. Through this process, the algorithm can gradually collect and integrate the constraint information from different inequalities, causing the beliefs of each variable node to gradually converge near the optimal solution, thus gradually approaching the global optimal solution, more accurately estimating the initial optimal value of the variable, reducing the impact of noise on the solution result, and enhancing the robustness of the system.
[0051] In one embodiment, solving the target inequality according to the initial optimal value to obtain the target optimal value corresponding to the side-channel information includes: substituting the recovered variables into the target inequality according to the initial optimal value to obtain a reduced-dimensional target inequality group; solving the reduced-dimensional target inequality group through a target algorithm to obtain the target optimal value corresponding to the side-channel information.
[0052] Specifically, as shown in Figure 5 By substituting the already recovered variable xi into the target inequality group, the server can eliminate the inequalities corresponding to these variables, thereby reducing the dimension of the inequalities. This step is equivalent to decomposing the original problem into smaller sub-problems, reducing the complexity of the problem and making subsequent solutions easier. The reduced-dimensional target inequality group is smaller in scale, requiring less computing resources and time to solve. When using the target algorithm to solve the reduced-dimensional target inequality group subsequently, the target optimal value corresponding to the side-channel information can be obtained more quickly, improving the efficiency of the overall solution process.
[0053] In one embodiment, solving the reduced-dimensional target inequality group through a target algorithm to obtain the target optimal value corresponding to the side-channel information includes: converting the reduced-dimensional target inequality group into a linear programming model; based on multiple inequality constraints, and using a solver to solve the linear programming model to obtain the target optimal value corresponding to the side-channel information.
[0054] Among them, the target algorithm includes the Mixed Integer Linear Programming (MILP) algorithm; the linear programming model includes multiple inequality constraints.
[0055] Specifically, the mixed-integer linear programming algorithm is an efficient method for solving linear programming problems that contain continuous variables and integer variables. Its solution process mainly includes the following key steps. Problem modeling: Abstract the actual problems such as the reduced-dimensional target inequality group into a linear programming model of a linear objective function and linear constraints, clarifying the variables (including continuous variables and integer variables), the objective function (minimization or maximization), and various inequality constraint conditions. Relaxation and initialization: First, relax the integer variables and treat them as continuous variables, solve the linear programming relaxation problem, and obtain the initial solution and upper and lower bounds. Branch and bound method: Gradually narrow the solution space through the branch and bound method. Select an integer variable for branching, divide it into two sub-problems and solve them separately, calculate the objective function value and upper and lower bounds in each branch, and prune the branches that do not satisfy the optimality conditions. Iterative solution: Continuously repeat the branching and bounding processes to gradually approach the optimal solution. During the solution process using the solver, techniques such as the duality theory of linear programming and the cutting plane method are used to further narrow the feasible solution space and improve the solution efficiency. Optimality test: When the objective function values of all branches satisfy the optimality conditions or the solution space is completely searched, the algorithm terminates and returns the optimal objective value.
[0056] In this embodiment, through the MILP algorithm specifically designed for solving optimization problems, the optimal solution that satisfies all inequality constraints can be effectively found. By using the MILP algorithm to solve the reduced-dimensional inequality group, the result can be obtained faster, further improving the solution efficiency.
[0057] In summary, an inequality solving method for preventing side-channel information leakage provided by this solution is specifically aimed at the side-channel information leakage problem. Through effective inequality solving and optimization, the security of the post-quantum cryptography scheme is improved, and it can better resist side-channel attacks and protect the security of encrypted information. In post-quantum cryptography, the difficulty of solving the LWE problem is one of the key factors for ensuring the security of the cryptography scheme. This solution enhances the robustness of the cryptography scheme against side-channel attacks by increasing the difficulty of solving the LWE problem. In addition, by integrating various technical means such as clustering methods, graph models, belief propagation algorithms, and MILP algorithms, this solution can process and optimize the problem from multiple perspectives, has strong comprehensiveness and adaptability, and is applicable to solving LWE problems of different scales and complexities.
[0058] It should be understood that although the steps in the flowcharts involved in the above embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0059] Based on the same inventive concept, an embodiment of the present application also provides a side-channel information processing device for implementing the side-channel information processing method described above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the side-channel information processing device provided below can refer to the limitations on the side-channel information processing method in the above text, and will not be repeated here.
[0060] In one embodiment, a side-channel information processing device is provided, including: a graph model construction module, a message passing and updating module, and an optimal value solving module, where: The graph model construction module is used to determine a plurality of target inequalities corresponding to the side-channel information; construct a graph model according to the plurality of target inequalities; the graph model includes variable nodes associated with inequality unknowns and factor nodes associated with inequality coefficients.
[0061] The message passing and updating module is used to perform message passing and updating between a plurality of factor nodes and a plurality of variable nodes until an initial optimal value is obtained when the termination condition is reached.
[0062] The optimal value solving module is used to solve the target inequality according to the initial optimal value to obtain the target optimal value corresponding to the side-channel information.
[0063] Each of the above modules in the side-channel information processing can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0064] In one embodiment, a computer device is provided. This computer device can be a server, and its internal structure diagram can be as Figure 6As shown in the figure. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the data after side-channel information processing. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a method for processing side-channel information.
[0065] Those skilled in the art can understand that Figure 6 the structure shown in the figure is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0066] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the steps in the above method embodiments are implemented.
[0067] In one embodiment, a computer-readable storage medium is provided, storing a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0068] In one embodiment, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the steps in the above method embodiments.
[0069] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., and are not limited thereto. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., and are not limited thereto.
[0070] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0071] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A side-channel information processing method, characterized in that, The method includes: Determining a plurality of target inequalities corresponding to side-channel information; Constructing a graph model according to the plurality of target inequalities; the graph model includes variable nodes associated with inequality unknowns and factor nodes associated with inequality coefficients; Performing message passing and updating between the plurality of factor nodes and the plurality of variable nodes until an initial optimal value is obtained when a termination condition is reached; Solving the target inequalities according to the initial optimal value to obtain a target optimal value corresponding to the side-channel information.
2. The method according to claim 1, characterized in that The determining a plurality of target inequalities corresponding to side-channel information includes: Obtaining a plurality of initial inequalities corresponding to side-channel information; the format of each initial inequality is unified; Constructing a feature space according to the plurality of initial inequalities; each of the initial inequalities is regarded as a feature data point; Filtering the plurality of feature data points in the feature space by a clustering method to obtain a plurality of target inequalities.
3. The method according to claim 2, wherein The filtering the plurality of feature data points in the feature space by a clustering method to obtain a plurality of target inequalities includes: For each of the feature data points, performing neighborhood calculation according to a preset domain radius and performing core point identification according to a preset minimum number of samples; Performing cluster expansion on the identified core points and marking the feature data points that are not assigned to any cluster as noise points; Filtering the initial inequalities corresponding to the noise points to obtain a plurality of target inequalities corresponding to the side-channel information.
4. The method according to claim 3, characterized in that, The method further includes: Verifying the identified noise points, and when the verification fails, adjusting the domain radius and the minimum number of samples, and re-filtering the plurality of feature data points in the feature space with the adjusted domain radius and minimum number of samples.
5. The method according to claim 1, wherein The performing message passing and updating between the plurality of factor nodes and the plurality of variable nodes until an initial optimal value is obtained when a termination condition is reached includes: Initializing the prior probability distribution of each variable node; For a factor node that receives initial information, determining an initial probability distribution according to the initial information and the corresponding target inequality, and transmitting the initial probability distribution as a target message to the next variable node; For a variable node that receives a target message, determining a posterior probability distribution according to the target message and the corresponding prior probability distribution; Transmitting the posterior probability distribution as a new initial message to the next factor node until an initial optimal value is obtained when a termination condition is reached.
6. The method according to claim 1, wherein The solving the target inequalities according to the initial optimal value to obtain a target optimal value corresponding to the side-channel information includes: Substituting the recovered variables into the target inequalities according to the initial optimal value to obtain a reduced-dimensional target inequality group; Solving the reduced-dimensional target inequality group by a target algorithm to obtain a target optimal value corresponding to the side-channel information.
7. The method according to claim 6, characterized in that, The target algorithm includes a mixed integer linear programming algorithm; the solving the reduced-dimensional target inequality group by a target algorithm to obtain a target optimal value corresponding to the side-channel information includes: Converting the reduced-dimensional target inequality group into a linear programming model; the linear programming model includes various inequality constraints; Based on multiple inequality constraints, the linear programming model is solved by a solver to obtain the target optimal value corresponding to the side-channel information.
8. A side-channel information processing device, characterized in that, The device includes: a graph model construction module, configured to determine a plurality of target inequalities corresponding to side-channel information, and construct a graph model according to the plurality of target inequalities; the graph model includes variable nodes associated with inequality unknowns and factor nodes associated with inequality coefficients; a message passing and updating module, configured to perform message passing and updating between the plurality of factor nodes and the plurality of variable nodes until an initial optimal value is obtained when a termination condition is reached; an optimal value solving module, configured to solve the target inequality according to the initial optimal value to obtain the target optimal value corresponding to the side-channel information.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.