Mobile phone USIM (Universal Subscriber Identity Module) side channel analysis method based on outlier
By combining relevant energy analysis and local outlier factor algorithm, the misjudgment problem of key recovery in USIM card high protection environment is solved, accurate key recognition in complex scenarios is achieved, and the security and attack efficiency of USIM card are improved.
Patent Information
- Application Number
- CN202510524274.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-07-25
AI Technical Summary
The existing side channel attack methods are difficult to accurately recover AES keys in a high protection environment of USIM cards, especially in low signal-to-noise ratio and complex interference scenarios. Traditional CPA methods are prone to misjudgment or inability to judge key bytes, resulting in failure of key recovery.
Combining the correlation energy analysis and local outlier factor algorithm, by collecting the power consumption signals in the process of executing the AES algorithm of the USIM card, filtering and aligning, standardized side channel curve data is constructed, and the correlation analysis of candidate key values is performed for the first round of AES key byte positions is derived, the second round of diffusion path is derived, and the local outlier factor algorithm is used to identify the outlier as the final key byte.
In a high protection and low signal-to-noise ratio environment, the accuracy and completeness of key recovery are significantly improved, the risk of misjudgment is reduced, and the actual power consumption signals under various protection mechanisms are adapted to the stability and discrimination capabilities of USIM card key recovery.
Smart Images

Figure CN120378084A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to a method for analyzing the mobile phone USIM side channel based on outliers. Background Art
[0002] A USIM (Universal Subscriber Identity Module) card is a key security component in a mobile communication system and is widely used in 3G, 4G, and 5G network environments. It is not only used to store user identity information such as IMSI (International Mobile Subscriber Identity) and authentication keys, but also undertakes core security tasks such as encryption and authentication. Since the USIM card is usually constructed based on Smart Card technology and integrates a dedicated hardware security chip internally, its overall security plays a decisive role in the credibility of the mobile communication system. Although various cryptographic protection mechanisms have been adopted in the design of the USIM card, it still faces the potential threat of side-channel attacks (SCA) in practical applications.
[0003] Side-channel attack is a type of non-traditional cryptographic attack method. It does not directly target the mathematical structure of the algorithm itself, but uses non-functional information leaked during the execution of the encryption operation by the device, such as power consumption, electromagnetic radiation, execution time, noise fluctuation, etc., to infer the internal processed key or other sensitive data. Compared with classical methods such as brute-force cracking or algebraic cryptanalysis, side-channel attacks are more concealed and efficient, especially showing strong adaptability when attacking embedded devices in a restricted environment. Currently, the mainstream energy side-channel analysis methods include differential power analysis (DPA) and correlation power analysis (CPA), among which CPA has become an important means when attacking symmetric encryption algorithms (such as AES) due to its simple modeling and high computational efficiency.
[0004] However, with the continuous progress of chip manufacturing technology, modern USIM cards widely adopt advanced processes with low power consumption and low noise, which significantly reduces the amplitude of the energy signal leaked during the encryption process and significantly increases the difficulty of side-channel attacks. In addition, various active or passive protection mechanisms have been introduced inside the USIM card, such as data masking, operation scrambling, pseudo-operation insertion, power consumption balancing, etc. These technologies effectively disrupt the corresponding relationship between the side-channel signal and the plaintext and the key, thereby weakening the accuracy of the attack model.
[0005] Taking the AES algorithm as an example, to recover the internal key of the USIM card, an attacker usually needs to perform energy analysis such as CPA on the first-round S-box operation of the encryption process. In theory, by calculating the correlation between each candidate key byte and the sampled power consumption, the key value can be recovered. However, in actual attacks, due to the reduced signal-to-noise ratio caused by advanced manufacturing processes, as well as the interference of protection means such as out-of-order execution and dummy operations, the correlation values of some key bytes may be very close, making it difficult to clearly determine which one is the correct key byte. This will lead to errors in the first-round key recovery result, which in turn affects the second-round state matrix derived from the first-round result, causing the overall analysis chain to break and the attack to fail. Especially in authentication algorithms based on AES such as MILENAGE, an attacker usually cannot directly obtain the encryption output result, further limiting the possibility of using key enumeration and verification mechanisms to debug errors.
[0006] Therefore, how to provide a side-channel analysis method for mobile phone USIM based on outliers is an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0007] An object of the present invention is to propose a side-channel analysis method for mobile phone USIM based on outliers. The present invention aims at the encryption process of the AES algorithm in the USIM card. By combining relevant energy analysis and local outlier factor algorithm, a key recovery mechanism for two-round analysis and fusion decision is established, and it is described in detail how to construct feature vectors using the diffusion path and introduce outlier measurement to complete key identification in the case of large power consumption signal noise and inability to directly determine some key bytes. This method fully combines technologies such as power consumption signal processing, AES structure analysis, and statistical anomaly detection, and has the advantages of adapting to a strong interference environment, not requiring decryption result verification, and having the ability to discriminate uncertain key bytes.
[0008] The side-channel analysis method for mobile phone USIM based on outliers according to an embodiment of the present invention includes the following steps:
[0009] S1. Collect the power consumption signal generated by the USIM card during the execution of the AES algorithm;
[0010] S2. Filter and align the collected power consumption signal to generate standardized side-channel curve data;
[0011] S3. For each key byte position participating in the S-box operation in the first round of AES, construct candidate key byte values, and calculate the S-box output values in combination with the plaintext input;
[0012] S4. Adopt the relevant energy analysis method to calculate the correlation between the S-box output value of each candidate key byte value and the standardized side-channel curve data, select the one with the largest correlation as the recovered key byte, and select those with a correlation lower than the preset threshold as uncertain key bytes;
[0013] S5. For all candidate key byte values corresponding to each uncertain key byte, deduce the positions of the S-box output bytes affected in the second round;
[0014] S6. Taking the positions of the S-box output bytes as the target, calculate the correlation of each candidate key byte value in the second round to generate a correlation feature vector;
[0015] S7. Organize the correlation feature vectors corresponding to all candidate key byte values into a vector set, which is used as the input of the local outlier factor algorithm to calculate the outlier value of each candidate key byte value;
[0016] S8. For each uncertain key byte, select the one with the largest outlier value as the final key byte, and combine it with all the recovered key bytes to form a key byte set, which is used as the input data for authentication key calculation.
[0017] Optionally, the candidate key byte values are all possible values between 0 and 255.
[0018] Optionally, the S-box is a non-linear transformation module that implements byte substitution operations in the AES algorithm, and the S-box output value is obtained by performing a non-linear transformation on the result of the exclusive OR of each candidate key byte value and the plaintext.
[0019] Optionally, the specific steps of S1 include:
[0020] S11. During the execution of the AES algorithm in the USIM card, start the power consumption signal acquisition process;
[0021] S12. Set the sampling trigger conditions, including the sampling frequency, sampling window duration, and clock synchronization signal;
[0022] S13. Detect the current change at the external power supply terminal of the USIM card through the power consumption acquisition module to obtain continuous power consumption signals;
[0023] S14. Synchronously sample the power consumption signals according to the set sampling frequency and record them as time-series sampling data;
[0024] S15. Number and store the sampling data in the sampling order to form an original power consumption signal set.
[0025] Optionally, the specific steps of S2 include:
[0026] S21. Perform moving average filtering on each group of sampling data in the original power consumption signal set, and smooth the original signal using a fixed window length and a sliding step size;
[0027] S22. Select a reference trigger template, calculate the Euclidean distance sequence for each group of sampling data, and locate the starting time point of the AES operation;
[0028] S23. Align all the sampling data according to the starting time point to form a set of aligned side-channel curves;
[0029] S24. Apply weighted normalization processing to each group of aligned sampling sequences:
[0030] z k = α·(x k - μ k ) / σ k + β·(x k - b k ) / r k ;
[0031] where z k is the normalized output value of the k-th sampling point, x k is the original power consumption value of the k-th sampling point, μ k is the mean value of the power consumption values within the sliding window centered on the k-th point, σ k is the standard deviation of the power consumption values within the sliding window, b k is the baseline estimated value within the sliding window, r k is the range difference within the window, and α and β are weighting coefficients;
[0032] S25. Store all the normalized sampling data in chronological order to generate a set of standardized side-channel curve data.
[0033] Optionally, the specific steps of S3 include:
[0034] S31. For each key byte position participating in the S-box operation in the first round of AES, construct a set of candidate key byte values, and the range of candidate values is all integers from 0 to 255;
[0035] S32. Extract the plaintext byte sequence corresponding to each sampled power consumption signal, and combine each plaintext byte with the candidate key byte values one by one to generate candidate input pairs;
[0036] S33. Perform an XOR operation on each group of candidate input pairs to obtain the S-box input value, and input the S-box input value into the S-box lookup table of AES to obtain the corresponding S-box output value;
[0037] S34. Construct intermediate variables based on each S-box output value:
[0038]
[0039] Wherein, Ψ1 is an intermediate variable, s is the output value of the S-box, p is the plaintext byte, k is the candidate key byte value, α is a scaling parameter, δ is an offset parameter, β is a balance parameter, λ is a sine adjustment parameter, and π is the constant of the circumference ratio;
[0040] S35. Construct a combined intermediate variable for the output values of the S-box at multiple key byte positions:
[0041]
[0042] Wherein, Ψ2 is the combined intermediate variable, n is the number of key byte positions participating in the combined calculation, s i is the output value of the S-box at the i-th position, p i is the i-th plaintext byte, k i is the i-th candidate key byte value, θ i is the weighting parameter, ∈ is the offset constant, and η is the exponential adjustment parameter;
[0043] S36. Map each candidate key byte value to the corresponding S-box output value, record the corresponding intermediate variable result, and use it as the input data for step S4 in claim 1.
[0044] Optionally, the S4 specifically includes:
[0045] S41. Locate the estimated leakage position of the S-box output value in the first round of AES in the standardized side-channel curve data, and construct a time alignment window containing all sampled curves;
[0046] S42. For each candidate key byte value at each key byte position, extract the S-box output value calculated in step S3, and construct a reference sequence corresponding to the sampled power consumption curve;
[0047] S43. Adopt the correlation energy analysis method to calculate the correlation between the S-box output value of each candidate key byte value and the standardized side-channel curve data:
[0048]
[0049] Wherein, ρ is the weighted correlation coefficient, x t is the standardized power consumption value at the t-th sampling point, μ x is the mean value of the power consumption window, y t is the S-box output value corresponding to the t-th sampling point, μ y is the mean value of the S-box output sequence, w t is the weight coefficient at the t-th sampling point, and T is the length of the time window;
[0050] S44. Statistically analyze the correlation results of each candidate key byte value on all sampled curves, and construct an enhanced scoring function:
[0051]
[0052] Among them, Γ is the scoring value, ρ m is the correlation coefficient on the m-th sampling curve, N is the total number of sampling curves, ∈ is a constant offset factor, κ is a derivative weighting factor, is the change rate of correlation in the time dimension;
[0053] S45. Select the candidate key byte value with the largest scoring value as the recovered key byte;
[0054] S46. For the positions of the candidate key byte values with scoring values less than the preset threshold, mark them as uncertain key bytes, and retain all candidate key byte values and the corresponding scoring results.
[0055] Optionally, the S5 specifically includes:
[0056] S51. For each uncertain key byte, extract all corresponding candidate key byte values, and calculate the S-box output value at the key byte position in the first round in combination with the plaintext input;
[0057] S52. Map each S-box output value to the corresponding byte position in the first-round state matrix, and rearrange the row where the byte is located through the row shift operation;
[0058] S53. Perform a multiplication operation on the rearranged byte vector and the column mixing matrix to deduce the diffusion path of the first-round output in the second-round state matrix:
[0059]
[0060] Among them, Π i is the diffusion result of the i-th candidate key byte value in the second-round state matrix, M is the column mixing matrix, ShiftRows is the row shift operation, is the S-box output value, p i is the plaintext byte, k i is the candidate key byte value, e r,c is the corresponding unit vector position in the first-round state matrix;
[0061] S54. Output the positions of the S-box output bytes affected by each candidate key byte value in the second round.
[0062] Optionally, the S6 specifically includes:
[0063] S61. For all candidate key byte values of each uncertain key byte, extract the positions of the S-box output bytes affected in the second round;
[0064] S62. In the standardized side-channel curve data, locate the sampling regions corresponding to the output byte positions of each target S-box, and intercept the power consumption sampling window of a fixed length;
[0065] S63. Combine the candidate key byte values with the corresponding plaintext bytes in the second round, calculate the S-box output values at each target position, and construct a power consumption leakage model;
[0066] S64. Adopt the weighted correlation energy analysis method to calculate the correlation of each candidate key byte value at the corresponding output byte position of each S-box:
[0067] v i =[ρ i,1 ,ρ i,2 ,,ρ i,n ;
[0068]
[0069] where v i is the correlation feature vector of the i-th candidate key byte value, and ρ i,j represents the weighted correlation coefficient between the standardized power consumption curve at the output byte position of the j-th S-box, is the power consumption value at the j-th position at the t-th moment, is the mean value, is the reference value of the leakage model, is the mean value, is the sampling point weight, T is the number of window sampling points, and n is the number of S-box output byte positions affected by the candidate values;
[0070] S65. Output the correlation feature vectors of all candidate key byte values.
[0071] Optionally, the S7 specifically includes:
[0072] S71. For each uncertain key byte, extract the correlation feature vectors generated by all candidate key byte values in step S6;
[0073] S72. Centralize and normalize the correlation feature vectors of each candidate key byte value to construct a normalized feature matrix;
[0074] S73. Based on each pair of normalized feature vectors, calculate the weighted generalized distance:
[0075]
[0076] where D(i,j) is the weighted distance between the i-th and j-th candidate key byte values, v i,m is the component of the i-th vector in the m-th dimension, and ω mis the weight for the m-th dimension, and σ m is the standard deviation of the dimension, ∈ is a positive constant to prevent division by zero, β is the norm parameter, and n is the feature dimension;
[0077] S74. Construct the local reachability density function:
[0078]
[0079] where LRD i is the local reachability density of the i-th candidate key byte value, N k (i) is the set of indices of the first k nearest neighbors of the i-th vector, and D k (j) is the distance between the j-th vector and the k-th nearest neighbor;
[0080] S75. Construct the local outlier factor based on the local reachability density:
[0081]
[0082] where LOF i is the local outlier factor of the i-th candidate key byte value, and λ is the distance perturbation adjustment coefficient;
[0083] S76. Output the outlier value of each candidate key byte value.
[0084] The beneficial effects of the present invention are as follows:
[0085] Aiming at the key technical bottlenecks existing in the existing side-channel analysis methods in the high-security environment of USIM cards, the present invention proposes a multi-round key recovery method that combines correlation power analysis and outlier judgment, which can effectively improve the attack accuracy and integrity in complex scenarios such as noise enhancement, weak signals, and unverifiable outputs. In the traditional CPA method, the determination of candidate key byte values highly depends on the correlation extreme values. If some bytes are not obvious in the power consumption signal, it is easy to produce misjudgments or inability to judge, resulting in the interruption of the subsequent state derivation chain. After completing the first-round correlation calculation and identifying the uncertain key bytes, the present invention combines the data diffusion structure of the AES algorithm to further deduce the positions affected by the uncertain bytes in the second round and reconstruct the feature representation of the candidate values, thereby introducing the supplementary information in the second round to enhance the sufficiency of the judgment basis.
[0086] By generating a correlation feature vector for each candidate key byte value in the second round and introducing the Local Outlier Factor algorithm to model its statistical characteristics, the present invention realizes multi-level and multi-dimensional anomaly detection relying only on sampled power consumption data without the true encryption output result. Finally, the one with the largest outlier value is used as the judgment basis, effectively distinguishing the key bytes that are difficult to directly identify in the first round, and greatly reducing the risk of false judgment caused by insufficient correlation. Compared with the existing methods that rely on a large number of sampling times or construct complex training models, the method of the present invention has a clear structure and strong adaptability. Without relying on sample labels and prior verification, it has excellent discrimination ability and versatility, and can realize stable key recovery analysis in a variety of actual environments, providing a more robust and efficient technical means for USIM side-channel analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0087] The accompanying drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention, but do not constitute a limitation to the present invention. In the drawings:
[0088] Figure 1 is a flowchart of the method for mobile phone USIM side-channel analysis based on outlier value proposed by the present invention;
[0089] Figure 2 is a schematic diagram of the derivation structure of the S-box output byte diffusion path in the first and second rounds of AES in the present invention;
[0090] Figure 3 is a schematic diagram of the process of constructing the correlation feature vector of the candidate key byte value and calculating the Local Outlier Factor in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0091] Now, the present invention will be further described in detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only showing the basic structure of the present invention in a schematic way, so they only show the components related to the present invention.
[0092] Refer to Figures 1-3 , the method for mobile phone USIM side-channel analysis based on outlier value includes the following steps:
[0093] S1. Collect the power consumption signal generated by the USIM card during the execution of the AES algorithm;
[0094] S2. Filter and align the collected power consumption signal to generate standardized side-channel curve data;
[0095] S3. For each key byte position participating in the S-box operation in the first round of AES, construct a candidate key byte value, and calculate the S-box output value in combination with the plaintext input;
[0096] S4. Use the correlation energy analysis method to calculate the correlation between the S-box output value of each candidate key byte value and the normalized side-channel curve data, select the one with the largest correlation as the recovered key byte, and select those with a correlation lower than the preset threshold as the uncertain key bytes;
[0097] S5. For all candidate key byte values of each uncertain key byte, deduce the positions of the S-box output bytes affected in the second round;
[0098] S6. Taking the positions of the S-box output bytes as the targets, calculate the correlation of each candidate key byte value in the second round to generate a correlation feature vector;
[0099] S7. Organize the correlation feature vectors corresponding to all candidate key byte values into a vector set, which is used as the input of the local outlier factor algorithm to calculate the outlier value of each candidate key byte value;
[0100] S8. For each uncertain key byte, select the one with the largest outlier value as the final key byte, and combine it with all the recovered key bytes to form a key byte set, which is used as the input data for authentication key calculation.
[0101] The outlier-based side-channel analysis method for mobile phone USIM provided by the present invention can effectively improve the accuracy and integrity of key recovery in scenarios where the AES encryption signal noise is significant and the correlation of some key bytes is weak. By collecting high-precision power consumption signals during the execution of the AES algorithm on the USIM card, and performing normalization filtering and alignment processing, side-channel curve data with a clear structure is constructed, laying a foundation for subsequent analysis. The correlation energy analysis method is used to quantitatively evaluate the matching degree between each candidate key byte value and the power consumption signal, and a preliminary distinction between the recovered and uncertain key bytes is realized in the first round. For the uncertain bytes, the positions of the S-box output bytes affected in the second round are further deduced, and combined with the diffusion characteristics of the AES structure, a multi-target correlation feature vector is constructed to comprehensively characterize the performance differences of candidate values under different paths. Finally, the local outlier factor algorithm is introduced to accurately screen the credible key bytes from the perspective of statistical deviation, realizing the cross-round fusion judgment from the first round to the second round, and effectively alleviating the problem of insufficient recognition ability of traditional CPA methods in high-security environments. The present invention does not need to rely on the encryption output results or training data, can adapt to the actual power consumption signals under various protection mechanisms, and improves the stability and discrimination ability of USIM card key recovery attacks.
[0102] In this embodiment, the candidate key byte values are all possible values between 0 and 255.
[0103] In the present invention, the candidate key byte values are all possible values between 0 and 255, ensuring an exhaustive search coverage for each key byte and avoiding misjudgment or missed judgment problems caused by insufficient candidate ranges. By uniformly adopting the complete 256 candidate byte values during the analysis process, not only is the integrity of the key space guaranteed, but also a sufficient data basis is provided for subsequent correlation calculation, diffusion path derivation, and outlier analysis. This design avoids the deviation risks introduced by pre-screening or pruning the candidate set, enhances the objectivity and reliability of the key recovery process, and ensures a robust candidate discrimination ability even in high-security and strong-interference environments.
[0104] In this embodiment, the S-box is a non-linear transformation module that implements byte substitution operations in the AES algorithm. The output value of the S-box is obtained through non-linear transformation of the result of XORing each candidate key byte value with the plaintext.
[0105] In the present invention, the S-box, as the core non-linear transformation module that performs byte substitution operations in the AES algorithm, establishes a non-linear mapping relationship between the candidate key byte values and the plaintext input, constituting the key leakage modeling basis in side-channel analysis. By performing an XOR operation on each candidate key byte value and the corresponding plaintext byte, and inputting the result into the S-box lookup table, S-box output values with highly uneven distribution characteristics are obtained, thus effectively amplifying the distinguishability of different candidate values in power consumption characteristics. This non-linear mapping not only enhances the response intensity of the model to the key in correlation analysis, but also provides high-information-entropy basic variables for subsequent multi-round feature construction and outlier determination, improving the discrimination accuracy and applicable range of the entire key recovery process under complex encryption paths.
[0106] In this embodiment, the S1 specifically includes:
[0107] S11. During the execution of the AES algorithm by the USIM card, start the power consumption signal acquisition process;
[0108] S12. Set the sampling trigger conditions, including sampling frequency, sampling window duration, and clock synchronization signal;
[0109] S13. Detect the current change at the external power supply terminal of the USIM card through the power consumption acquisition module to obtain continuous power consumption signals;
[0110] S14. Synchronously sample the power consumption signals according to the set sampling frequency and record them as time-series sampling data;
[0111] S15. Number and store the sampling data in the sampling order to form a set of original power consumption signals.
[0112] In the present invention, during the execution of the AES algorithm in the USIM card, a power consumption signal acquisition process is actively initiated to ensure that the acquisition operation is strictly aligned with the key-related operation time period, effectively avoiding interference from non-related energy consumption. By setting fine sampling trigger conditions, including sampling frequency, window duration, and clock synchronization signal, high-resolution capture of power consumption changes is achieved. The acquisition module continuously detects the current fluctuation at the external power supply terminal of the USIM card, and converts the analog signal into time-series sampling data through synchronous sampling, and further numbers and stores them in the execution order to form a structured set of original power consumption signals. This processing flow ensures that the sampling signal has high time accuracy and power consumption integrity, providing a stable and high-quality data input basis for subsequent filtering alignment, correlation analysis, and key discrimination, effectively enhancing the recognition ability of the side-channel analysis model for weak leakage features.
[0113] In this embodiment, the S2 specifically includes:
[0114] S21. Perform moving average filtering on each group of sampling data in the set of original power consumption signals, and smooth the original signal using a fixed window length and a sliding step size;
[0115] S22. Select a reference trigger template, calculate the Euclidean distance sequence for each group of sampling data, and locate the starting time point of the AES operation;
[0116] S23. Align all sampling data in time sequence according to the starting time point to form a set of aligned side-channel curves;
[0117] S24. Apply weighted normalization processing to each group of aligned sampling sequences:
[0118] z k =α·(x k -μ k ) / σ k +β·(x k -b k ) / r k ;
[0119] where z k is the normalized output value of the kth sampling point, x k is the original power consumption value of the kth sampling point, μ k is the mean value of the power consumption values within the sliding window centered on the kth point, σ k is the standard deviation of the power consumption values within the sliding window, b k is the baseline estimated value within the sliding window, r k is the range value within the window, and α and β are weighting coefficients;
[0120] S25. Store all the normalized sampling data in chronological order to generate a set of standardized side-channel curve data.
[0121] In the preprocessing stage of the original power consumption signal set, the present invention introduces a structured filtering, alignment, and normalization process to significantly improve the analysis stability and comparability of side-channel data. By performing moving average filtering on each group of sampled data and smoothing it in combination with a fixed window length and a sliding step size, high-frequency noise and transient interference are significantly suppressed, and the continuity of the power consumption signal is enhanced. An Euclidean distance sequence is constructed using a reference trigger template to accurately locate the starting time point of the AES encryption operation, providing a unified anchor point for time alignment between different power consumption sequences. Further, time series alignment processing is implemented on this basis to ensure that the sampling points of each group of data correspond one by one during the key operation stage. Subsequently, the aligned sampling sequence is introduced into a weighted normalization mechanism to unify power consumption signals with different amplitude ranges to a standard scale, eliminate interference differences caused by power consumption fluctuations, and improve the quantization accuracy of subsequent correlation analysis. Finally, by storing the normalized curves in chronological order, a standardized side-channel curve data set is constructed, providing consistent, comparable, and well-structured input features for subsequent key-related operations, effectively laying the foundation for high-precision power consumption modeling and discrimination.
[0122] In this embodiment, S3 specifically includes:
[0123] S31. For each key byte position participating in the S-box operation in the first round of AES, construct a set of candidate key byte values, and the range of candidate values is all integers from 0 to 255;
[0124] S32. Extract the plaintext byte sequence corresponding to each sampled power consumption signal, and combine each plaintext byte with the candidate key byte values one by one to generate candidate input pairs;
[0125] S33. Perform an exclusive OR operation on each group of candidate input pairs to obtain the S-box input value, and input the S-box input value into the S-box lookup table of AES to obtain the corresponding S-box output value;
[0126] S34. Construct an intermediate variable based on each S-box output value:
[0127]
[0128] where Ψ1 is the intermediate variable, s is the S-box output value, p is the plaintext byte, k is the candidate key byte value, α is the proportional parameter, δ is the offset parameter, β is the balance parameter, λ is the sine adjustment parameter, and π is the constant of the circumference ratio;
[0129] S35. Construct a combined intermediate variable for the S-box output values of multiple key byte positions:
[0130]
[0131] Among them, Ψ2 is the combined intermediate variable, n is the number of key byte positions participating in the combined calculation, s i is the output value of the S-box at the i-th position, p i is the i-th plaintext byte, k i is the candidate key byte value at the i-th position, θ i is the weighting parameter, ∈ is the offset constant, and η is the exponential adjustment parameter;
[0132] S36. Map each candidate key byte value to the corresponding S-box output value, record the corresponding intermediate variable result, and use it as the input data for step S4 in claim 1.
[0133] In the first-round key byte analysis stage of AES, the present invention adopts a structured candidate construction and mapping modeling method to achieve a complete state modeling of each key byte position. By enumerating all possible values in the range of 0 to 255, a set of candidate key bytes is constructed to ensure the exhaustion of the key search space. Combining the plaintext byte sequence corresponding to the sampled power consumption data, candidate keys and plaintext are combined one by one to generate input pairs, and after performing the XOR operation, they are input into the S-box lookup table to obtain the corresponding S-box output values, and a mapping relationship between the candidate keys and the leakage characteristics is established. On this basis, parameters such as ratio, offset, balance, and period adjustment are introduced to construct a non-linear intermediate variable expression to further characterize the coupling strength between the S-box output and the power consumption characteristics. Subsequently, by combining the intermediate variables at multiple byte positions, a high-dimensional combined intermediate variable that integrates information from multiple key positions is constructed to enhance the model's ability to capture the collaborative characteristics of multi-point leakage. Finally, a mapping is established between the candidate keys and the intermediate variable results, providing a clear-structured and computationally consistent input basis for subsequent correlation analysis and score determination, effectively improving the controllability, scalability, and discriminant dimension expression ability of the analysis process.
[0134] In this embodiment, S4 specifically includes:
[0135] S41. Locate the estimated leakage position of the S-box output value in the first round of AES in the standardized side-channel curve data, and construct a time alignment window containing all sampled curves;
[0136] S42. For each candidate key byte value at each key byte position, extract the S-box output value calculated in step S3, and construct a reference sequence corresponding to the sampled power consumption curve;
[0137] S43. Adopt the correlation energy analysis method to calculate the correlation between the S-box output value of each candidate key byte value and the standardized side-channel curve data:
[0138]
[0139] Among them, ρ is the weighted correlation coefficient, and x t is the normalized power consumption value at the t-th sampling point, μ x is the mean value of the power consumption window, y t is the S-box output value corresponding to the t-th sampling point, μ y is the mean value of the S-box output sequence, w t is the weight coefficient of the t-th sampling point, and T is the time window length;
[0140] S44. Statistically analyze the correlation results of each candidate key byte value on all sampling curves, and construct an enhanced scoring function:
[0141]
[0142] Among them, Γ is the scoring value, and ρ m is the correlation coefficient on the m-th sampling curve, N is the total number of sampling curves, ∈ is a constant offset factor, κ is a derivative weighting factor, is the change rate of the correlation in the time dimension;
[0143] S45. Select the candidate key byte value with the largest scoring value as the recovered key byte;
[0144] S46. For the positions of the candidate key byte values with scoring values less than the preset threshold, mark them as uncertain key bytes, and retain all candidate key byte values and their corresponding scoring results.
[0145] In the first-round key determination stage of the AES, the present invention establishes a refined candidate key discrimination process through constructing a timing alignment window, correlation analysis, and a multi-dimensional scoring mechanism. First, in the standardized side-channel curve, locate the estimated leakage position of the S-box output value, and construct a unified time window in combination with all sampling curves to ensure the consistency and comparability in the time dimension during the analysis process. Subsequently, for each key byte position and its corresponding candidate value, based on the S-box output result calculated in S3, construct a reference sequence with the same length as the power consumption curve as the input of the theoretical leakage model. Adopt the weighted correlation energy analysis method, introduce factors such as power consumption value, mean value, standard deviation, and sampling point weight, calculate the matching degree between each candidate value and the power consumption curve, and further statistically analyze the results on multiple sampling curves to construct an enhanced scoring function containing multi-dimensional information such as offset and derivative, so as to enhance the sensitivity to signal fluctuations and trend changes. Finally, identify the most likely true key byte by comparing the scoring values, mark the candidate group with a score lower than the threshold as an uncertain area, and retain all candidate scoring information at the same time, providing complete data support for the subsequent steps. This method significantly enhances the key discrimination ability in the scenario of unstable signal-to-noise ratio, and effectively improves the robustness and accuracy of the overall side-channel analysis.
[0146] In this embodiment, S5 specifically includes:
[0147] S51. For each uncertain key byte, extract all corresponding candidate key byte values, and calculate the S-box output value at the key byte position in the first round in combination with the plaintext input;
[0148] S52. Map each S-box output value to the corresponding byte position in the first-round state matrix, and rearrange the rows where the bytes are located through the row shift operation;
[0149] S53. Perform a multiplication operation on the rearranged byte vector and the column confusion matrix to deduce the diffusion path of the first-round output in the second-round state matrix:
[0150]
[0151] where Π i is the diffusion result of the i-th candidate key byte value in the second-round state matrix, M is the column confusion matrix, ShiftRows is the row shift operation, is the S-box output value, p i is the plaintext byte, k i is the candidate key byte value, e r,c is the corresponding unit vector position in the first-round state matrix;
[0152] S54. Output the S-box output byte positions affected by each candidate key byte value in the second round.
[0153] In view of the uncertain key bytes caused by insufficient correlation in the first round, the present invention designs a cross-round path deduction mechanism based on the internal diffusion structure of AES, effectively enhancing the further recognition ability of the credibility of candidate keys. By re-extracting the candidate values corresponding to each uncertain key byte and calculating the S-box output value in combination with the plaintext input, the state bytes after the first-round key operation are accurately restored. On this basis, the S-box output value is mapped to the specific position in the AES state matrix, and the state matrix is rearranged by rows in combination with the row shift operation defined by the AES algorithm to reconstruct the intermediate state after the transformation. Further, a matrix multiplication operation is performed on the rearrangement result using the column confusion matrix to deduce the diffusion path of the first-round output in the second-round state matrix, so as to locate the S-box output byte positions that each candidate key value may affect in the second round. Finally, the diffusion positions corresponding to each candidate key value are used as the target areas for subsequent analysis, ensuring that the second-round analysis has a complete and clearly defined input basis. This design makes full use of the structural reversibility and diffusibility of the AES algorithm, maps the difficult-to-judge key influence in the first round to the second-round path, enhances the coherence and logic of the analysis chain from both the time sequence and the structure dimensions, and establishes a high-quality path basis for subsequent feature extraction and outlier determination.
[0154] In this embodiment, step S6 specifically includes:
[0155] S61. For all candidate key byte values of each uncertain key byte, extract the positions of the S-box output bytes affected in the second round;
[0156] S62. In the normalized side-channel curve data, locate the sampling regions corresponding to each target S-box output byte position, and intercept a power consumption sampling window of a fixed length;
[0157] S63. Combine the candidate key byte values with the corresponding plaintext bytes in the second round, calculate the S-box output values at each target position, and construct a power consumption leakage model;
[0158] S64. Adopt the weighted correlation energy analysis method to calculate the correlation of each candidate key byte value at each corresponding S-box output byte position:
[0159] v i =[ρ i,1 ,ρ i,2 ,,ρ i,n ;
[0160]
[0161] where v i is the correlation feature vector of the i-th candidate key byte value, and ρ i,j represents the weighted correlation coefficient between the normalized power consumption curve at the j-th S-box output byte position, is the power consumption value at the j-th position at the t-th moment, is the mean value, is the reference value of the leakage model, is the mean value, is the sampling point weight, T is the number of window sampling points, and n is the number of S-box output byte positions affected by the candidate values;
[0162] S65. Output the correlation feature vectors of all candidate key byte values.
[0163] In view of the problem of judging uncertain key bytes, a multi-point correlation feature extraction mechanism based on the diffusion path is constructed in the second round, effectively improving the discrimination ability between candidate values. First, extract the S-box output byte positions corresponding to all candidate values of each uncertain key byte in the second round, and establish a mapping relationship between the key influence range and the power consumption area. Subsequently, in the standardized side-channel curve data, accurately locate the sampling area corresponding to each target position, and intercept a power consumption sampling window of a fixed length to provide a unified analysis time period for different candidate values. On this basis, combine the candidate key value and the plaintext byte corresponding to the second round, calculate the S-box output value, and construct a leakage model for correlation analysis. Through the weighted correlation energy analysis method, calculate the correlation of candidate values at all target positions point by point, considering factors such as power consumption fluctuations, model mean, and sampling point weights within the time window, and construct a correlation feature vector with consistent dimensions and stable structure. Each finally output feature vector comprehensively reflects the statistical performance of the candidate key value under the diffusion path, provides high-resolution and multi-target input data support for subsequent outlier calculation, and significantly enhances the accuracy and reliability of discriminating uncertain keys.
[0164] In this embodiment, the S7 specifically includes:
[0165] S71. For each uncertain key byte, extract the correlation feature vectors generated by all candidate key byte values in step S6;
[0166] S72. Centralize and normalize the correlation feature vectors of each candidate key byte value to construct a normalized feature matrix;
[0167] S73. Based on each pair of normalized feature vectors, calculate the weighted generalized distance:
[0168]
[0169] where D(i,j) is the weighted distance between the i-th and j-th candidate key byte values, v i,m is the component of the i-th vector in the m-th dimension, ω m is the weight of the m-th dimension, σ m is the standard deviation of the dimension, ∈ is a positive constant to prevent division by zero, β is the norm parameter, and n is the feature dimension;
[0170] S74. Construct a local reachability density function:
[0171]
[0172] where LRD i is the local reachability density of the i-th candidate key byte value, N k(i) is the set of the first k nearest neighbor indices for the i-th vector, D k (j) is the distance between the j-th vector and the k-th nearest neighbor;
[0173] S75. Constructing the local outlier factor based on the local reachability density:
[0174]
[0175] where LOF i is the local outlier factor of the i-th candidate key byte value, and λ is the distance perturbation adjustment coefficient;
[0176] S76. Outputting the outlier values of each candidate key byte value.
[0177] By introducing the local outlier factor analysis method, the present invention performs high-dimensional statistical discrimination on the candidate values of the uncertain key bytes, and can identify the most credible key in the case where the correlation distributions are close and difficult to distinguish by traditional analysis. By normalizing the correlation feature vectors, constructing a generalized distance function and a local reachability density model, and calculating the outlier factor by combining the density differences between the candidate values, the abnormal degree of each candidate value in the feature space is effectively measured, so as to accurately identify the real key byte and improve the stability and accuracy of the key recovery process in a complex noise environment.
[0178] Example 1:
[0179] To verify the feasibility of the present invention in implementation, the present invention is deployed to the USIM card security evaluation experimental platform with side-channel protection characteristics to evaluate its ability to recover the AES key in a high-protection and high-noise environment. This experimental platform takes a 4G smart phone equipped with a domestic security chip as the test object, calls the AES encryption module inside the USIM card through real network authentication operations, and performs a full-process analysis on the power consumption data during its operation. The experiment was completed in the Beijing Information Science Laboratory in October 2024. The test lasted for 8 days, the total number of collected samples exceeded 100,000, the sampling frequency was 200MS / s, and a complete power consumption acquisition link and a clock synchronization system were built for high-precision recovery and discrimination of side-channel leakage.
[0180] As a key security element in mobile communication, the key protection mechanism of the AES algorithm inside the USIM card is extremely important. This test chip integrates multiple side-channel protection measures such as random delay, instruction pseudo-execution, and power consumption perturbation, resulting in a significant decrease in the key recovery accuracy of traditional side-channel analysis methods. At the initial stage of the experiment, the research team used the classical CPA method (correlation power analysis) to attack and verify the first-round S-box operation. Under the condition of collecting 5000 power consumption curves, it was found that a total of 5 key bytes could not be accurately determined, and their candidate values showed a high degree of similarity in terms of correlation, resulting in no significant difference in scores. Such fuzzy correlation problems are extremely likely to cause misjudgment or mislead the judgment path, thus affecting the entire key recovery link.
[0181] To solve this problem, the research team introduced the outlier-based USIM side-channel analysis method proposed in the present invention. This method first performs high-frequency and multi-point sampling during the power consumption signal acquisition stage, and then uses the moving average filter and time series alignment mechanism to standardize the signal. In the key modeling stage, for each byte position of the S-box operation in the first round of AES, a set of candidate key byte values from 0 to 255 is constructed, and combined with the plaintext byte in the sampled power consumption, the corresponding S-box output value is calculated.
[0182] In the first-round CPA analysis, a weighted correlation function is used to construct a scoring mechanism to preliminarily determine the credible key bytes, and those with scores lower than the threshold are marked as uncertain key bytes. For these positions, the present invention further deduces the positions of the S-box output bytes affected in the diffusion path of the second round of AES, and extracts the power consumption responses of the candidate values under the diffusion path based on the power consumption signal sampling window to construct a multi-dimensional correlation feature vector.
[0183] To achieve refined discrimination, the research team inputs these feature vectors into the Local Outlier Factor (LOF) algorithm, calculates the outlier value of each candidate value through the density anomaly recognition mechanism in the high-dimensional space, and finally selects the candidate value with the largest outlier value as the credible key. This mechanism effectively avoids the misjudgment problem caused by the unclear extreme values or the close distribution of traditional methods.
[0184] Table 1 Comparison of key recovery effects
[0185]
[0186]
[0187] As can be seen from Table 1, under the condition that the number of samplings is fixed at 5000, there are obvious blind spots in the key byte recovery of the traditional CPA method. However, by introducing the diffusion path feature construction and the outlier detection algorithm, the method of the present invention realizes the complete recovery of the key without increasing the number of samplings, and performs better in terms of false positive rate and computing time consumption. In addition, this method does not need to rely on the output result of the AES operation, is applicable to the encryption scenario where the output is unknown in the real USIM authentication process, has good versatility and practical deployment value, and is particularly suitable for key recovery and side-channel analysis tasks in high protection intensity and secure chip integration environments.
[0188] The above is only the preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, making equivalent replacements or changes, shall be covered by the protection scope of the present invention.
Claims
1. Method for analyzing side channels of mobile phone USIM based on outliers, characterized in that, It includes the following steps: S1. Collect the power consumption signals generated during the execution of the AES algorithm by the USIM card; S2. Filter and align the collected power consumption signals to generate standardized side-channel curve data; S3. For each key byte position participating in the S-box operation in the first round of AES, construct candidate key byte values, and calculate the S-box output values in combination with the plaintext input; S4. Adopt the correlation power analysis method to calculate the correlation between the S-box output values of each candidate key byte value and the standardized side-channel curve data, select the one with the maximum correlation as the recovered key byte, and select those with a correlation lower than the preset threshold as the uncertain key bytes; S5. For all candidate key byte values of each uncertain key byte, deduce the S-box output byte positions affected in the second round; S6. Take the S-box output byte positions as the targets, calculate the correlations of each candidate key byte value in the second round to generate a correlation feature vector; S7. Organize the correlation feature vectors corresponding to all candidate key byte values into a vector set, which is used as the input of the local outlier factor algorithm to calculate the outlier values of each candidate key byte value; S8. For each uncertain key byte, select the one with the maximum outlier value as the final key byte, and combine it with all the recovered key bytes to form a key byte set, which is used as the input data for authentication key calculation.
2. The method for analyzing the mobile phone USIM side channel based on outliers according to claim 1, wherein The candidate key byte values are all possible values between 0 and 255.
3. The method for analyzing the mobile phone USIM side channel based on outliers according to claim 1, wherein The S-box is a non-linear transformation module that implements byte substitution operations in the AES algorithm. The S-box output value is obtained by non-linearly transforming the result of the exclusive OR of each candidate key byte value and the plaintext.
4. The method for analyzing the mobile phone USIM side channel based on outliers according to claim 1, wherein The specific content of S1 includes: S11. During the execution of the AES algorithm by the USIM card, start the power consumption signal collection process; S12. Set the sampling trigger conditions, including the sampling frequency, sampling window duration, and clock synchronization signal; S13. Detect the current change at the external power supply terminal of the USIM card through the power consumption acquisition module to obtain continuous power consumption signals; S14. Synchronously sample the power consumption signals according to the set sampling frequency and record them as time-series sampling data; S15. Number and store the sampling data in the sampling order to form a set of original power consumption signals.
5. The method for analyzing the side channel of the mobile phone USIM based on outliers according to claim 1, wherein The specific content of S2 includes: S21. Perform moving average filtering on each set of sampling data in the set of original power consumption signals, and smooth the original signal using a fixed window length and a sliding step size; S22. Select a reference trigger template, calculate the Euclidean distance sequence for each set of sampling data, and locate the starting time point of the AES operation; S23. Align all the sampling data in time sequence according to the starting time point to form a set of aligned side-channel curves; S24. Apply weighted normalization processing to each set of aligned sampling sequences: z k = α·(x k - μ k ) / σ k + β·(x k - b k ) / r k ; where z k is the normalized output value of the k-th sampling point, x k is the original power consumption value of the k-th sampling point, μ k is the mean value of the power consumption values within the sliding window centered at the k-th point, σ k is the standard deviation of the power consumption values within the sliding window, b k is the baseline estimated value within the sliding window, r k is the range value within the window, and α and β are weighting coefficients; S25. Store all the normalized sampling data in time sequence to generate a set of standardized side-channel curve data.
6. The method for analyzing the mobile phone USIM side channel based on outliers according to claim 1, wherein The specific content of S3 includes: S31. For each key byte position participating in the S-box operation in the first round of AES, construct a set of candidate key byte values, and the range of candidate values is all integers from 0 to 255; S32. Extract the plaintext byte sequence corresponding to each sampled power consumption signal, and combine each plaintext byte with the candidate key byte values one by one to generate candidate input pairs; S33. Perform an XOR operation on each group of candidate input pairs to obtain the S-box input values, and input the S-box input values into the S-box lookup table of AES to obtain the corresponding S-box output values; S34. Construct intermediate variables based on each S-box output value: where Ψ1 is the intermediate variable, s is the S-box output value, p is the plaintext byte, k is the candidate key byte value, α is the proportionality parameter, δ is the offset parameter, β is the balance parameter, λ is the sine adjustment parameter, and π is the constant of pi; S35. Construct combined intermediate variables for the S-box output values at multiple key byte positions: Among them, Ψ2 is the combined intermediate variable, n is the number of key byte positions participating in the combined calculation, s i is the output value of the S-box at the i-th position, p i is the i-th plaintext byte, k i is the i-th candidate key byte value, θ i is the weighting parameter, ∈ is the offset constant, and η is the exponent adjustment parameter; S36. Map each candidate key byte value to the corresponding S-box output value, record the corresponding intermediate variable results, and use them as the input data for step S4 in claim 1.
7. The method for analyzing the mobile phone USIM side channel based on outliers according to claim 1, wherein The specific steps of S4 are as follows: S41. Locate the estimated leakage positions of the S-box output values in the first round of AES in the normalized side-channel curve data, and construct a time alignment window containing all sampled curves; S42. For each candidate key byte value at each key byte position, extract the S-box output values calculated in step S3, and construct a reference sequence corresponding to the sampled power consumption curve; S43. Use the correlation energy analysis method to calculate the correlation between the S-box output values of each candidate key byte value and the normalized side-channel curve data; Among them, ρ is the weighted correlation coefficient, x t is the normalized power consumption value at the t-th sampling point, μ x is the mean value of the power consumption window, y t is the output value of the S-box corresponding to the t-th sampling point, μ y is the mean value of the S-box output sequence, w t is the weight coefficient of the t-th sampling point, and T is the time window length; S44. Statistically analyze the correlation results of each candidate key byte value on all sampled curves, and construct an enhanced scoring function; where Γ is the scoring value, ρ m is the correlation coefficient on the m-th sampling curve, N is the total number of sampling curves, ∈ is the constant offset factor, κ is the derivative weighting factor, is the change rate of the correlation in the time dimension; S45. Select the candidate key byte value with the largest score value as the recovered key byte; S46. For the positions of the candidate key byte values with score values less than the preset threshold, mark them as uncertain key bytes, and retain all candidate key byte values and their corresponding score results.
8. The method for analyzing the side channel of the mobile phone USIM based on outliers according to claim 1, wherein The specific steps of S5 are as follows: S51. For each uncertain key byte, extract all the corresponding candidate key byte values, and calculate the S-box output values at the key byte positions in the first round in combination with the plaintext input; S52. Map each S-box output value to the corresponding byte position in the first-round state matrix, and rearrange the row where the byte is located through the row shift operation; S53. Perform a multiplication operation on the rearranged byte vector and the column confusion matrix to deduce the diffusion path of the first-round output in the second-round state matrix; Among them, Π i is the diffusion result of the i-th candidate key byte value in the state matrix of the second round, M is the column mixing matrix, and ShiftRows is the row shift operation. is the output value of the S-box, p i is the plaintext byte, k i is the candidate key byte value, e r,c is the position of the corresponding unit vector in the state matrix of the first round. S54. Output the S-box output byte positions affected by each candidate key byte value in the second round.
9. The method for analyzing the mobile phone USIM side channel based on outliers according to claim 1, wherein The specific steps of S6 are as follows: S61. For all candidate key byte values of each uncertain key byte, extract the S-box output byte positions affected in the second round; S62. In the normalized side-channel curve data, locate the sampling regions corresponding to each target S-box output byte position, and intercept a power consumption sampling window of a fixed length; S63. Combine the candidate key byte values with the corresponding plaintext bytes in the second round, calculate the S-box output values at each target position, and construct a power consumption leakage model; S64. Use the weighted correlation energy analysis method to calculate the correlation of each candidate key byte value at each corresponding S-box output byte position; v i = [ρ i,1 , ρ i,2 ,, ρ i,n ; Among them, v i is the correlation feature vector of the i-th candidate key byte value, and ρ i,j represents the weighted correlation coefficient between the output byte position of the j-th S-box and the normalized power consumption curve, is the power consumption value at the j-th position at the t-th moment, is the mean value, is the leakage model reference value, is the mean value, is the sampling point weight, T is the number of window sampling points, and n is the number of S-box output byte positions affected by the candidate value; S65. Output the correlation feature vectors of all candidate key byte values.
10. The method for analyzing the mobile phone USIM side channel based on outliers according to claim 1, wherein The specific steps of S7 are as follows: S71. For each uncertain key byte, extract the correlation feature vectors generated by all candidate key byte values in step S6; S72. Centralize and normalize the correlation feature vectors of each candidate key byte value to construct a normalized feature matrix; S73. Calculate the weighted generalized distance based on each pair of normalized feature vectors; Among them, D(i, j) is the weighted distance between the i-th and j-th candidate key byte values, v i,m is the component of the i-th vector in the m-th dimension, ω m is the weight of the m-th dimension, σ m is the standard deviation of the dimension, ∈ is a positive constant to prevent division by zero, β is the norm parameter, and n is the feature dimension; S74. Construct a local reachability density function; Among them, LRD i is the local reachability density of the i-th candidate key byte value, N k (i) is the set of the first k nearest neighbor indices of the i-th vector, D k (j) is the distance between the j-th vector and the k-th nearest neighbor; S75. Construct a local outlier factor based on the local reachability density; Among them, LOF i is the local outlier factor of the i-th candidate key byte value, and λ is the distance perturbation adjustment coefficient; S76. Output the outlier values of each candidate key byte value.
Citation Information
Cited By
Side channel characteristic analysis system and method based on interlayer correlation evaluation
CN121750191A