A security assessment method and device based on side channel analysis
By combining PC-oracle's side channel analysis and grid-base subtraction algorithm, the perfect prompt threshold is optimized, and the inefficiency problem of side channel analysis under the limitation of query resources in the prior art is solved, achieving more efficient security assessment and attack capabilities.
Patent Information
- Application Number
- CN202510907373.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2045-07-02
AI Technical Summary
The existing side channel analysis method based on plaintext inspection oracle is inefficient in attacks when querying resources are limited, and fails to effectively optimize the perfect prompt threshold, affecting the success rate of the criterion and the accuracy of security assessment.
An accurate success rate evaluation model was constructed, combining PC-oracle-based side channel analysis with grid-based subtraction algorithm. By reasonably setting perfect prompt thresholds, the complexity of grid-based subtraction algorithm is optimized, and the attack with the minimum trace amount is achieved, and the efficiency of security evaluation is improved.
It improves the adaptability and efficiency of side channel attacks, especially when the number of queries is limited, maximizes the use of information, enhances the attack capabilities of G-key cryptographic schemes, and reasonably evaluates security.
Smart Images

Figure CN120415914B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cyberspace security technology, and in particular to a security assessment method and device based on side channel analysis. Background Art
[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.
[0003] Side-channel analysis is a method of attacking cryptographic implementations (including cryptographic chips, modules, and systems) to ultimately extract cryptographic keys. With the advancement of integrated circuit technology, cryptographic algorithms are now implemented in hardware circuits within cryptographic devices. In practice, these hardware devices leak various types of physical information, such as energy and electromagnetic fields, known as side information. Side-channel analysis leverages this information to directly or indirectly obtain intermediate values during the cryptographic algorithm's operation, enabling segmented recovery of longer cryptographic keys. Side-channel analysis is an effective method for assessing chip security.
[0004] A plaintext check oracle (PC-oracle) is an attacker capability assumption in a security model and an important tool for evaluating the security of cryptographic CCA schemes. Side-channel analysis of the PC-oracle poses a significant threat to the security of lattice-based key encapsulation mechanisms (KEMs).
[0005] However, existing methods for side-channel security assessment based on plaintext inspection oracles often have some significant limitations. First, they typically use a fixed query strategy, dividing the side-channel attack and lattice reduction process into two independent stages. They lack a dynamic adjustment mechanism, which results in an inability to fully exploit the attack effect when query resources are limited. Second, when exploiting leaked information, these methods often only consider the existence of hints, while ignoring the statistical accuracy and confidence of the hints. This makes it easy to misuse low-quality hint information, affecting the success rate of subsequent lattice reduction. In addition, traditional methods do not optimize the judgment threshold for "perfect hints," and the attack efficiency decreases significantly when faced with a limited number of queries. Summary of the Invention
[0006] In order to solve the above problems, the present invention proposes a security assessment method and device based on side channel analysis, constructs an accurate success rate assessment model, combines the side channel analysis based on PC-oracle with the lattice basis reduction algorithm, and reduces the complexity of the lattice basis reduction algorithm to a level that the system can execute by reasonably setting the perfect prompt threshold, thereby achieving the maximum attack based on the minimum amount of traces, thereby improving the efficiency of security assessment and enhancing the security of the system in the face of potential attack threats.
[0007] In some embodiments, the following technical solutions are adopted:
[0008] A security assessment method based on side channel analysis, comprising:
[0009] constructing a ciphertext in such a way that the decrypted message bits m are only related to certain coefficients of the target key;
[0010] Collect L side channel leakage traces of cryptographic devices, calculate the probability distribution of key guessing, and obtain the mean and variance of the probability distribution;
[0011] Calculate the optimal variance threshold, and use the variance threshold to divide the probability of key guessing into perfect hints and approximate hints; integrate the divided perfect hints and approximate hints into the DBDD instance through the DDGR framework, convert the DBDD instance into a USVP instance, perform BKZ-β lattice reduction on the USVP instance, and calculate the security parameter β;
[0012] A security assessment based on side channel analysis is implemented based on the security parameter β.
[0013] As a further solution, the constructed ciphertext is specifically:
[0014] ct = (u,v)∈( R q × R q );
[0015] in, , , , j∈[0,n−1], n represents the number of coefficients; R q represents the set of real numbers in the range [0,q), represents the set of integers in the range [0,q); and are all constructed ciphertexts, 、 are all unit vectors, and the superscript represents the position of 1 in the unit vector.
[0016] As a further solution, the relationship between the message bit m and the specific coefficient of the target key is specifically:
[0017] ;
[0018] in, Indicates the specific formula for calculating m in the Kyber algorithm, which is related to the current s[0]; Indicates the 0th bit of the secret key; Indicates the position of m.
[0019] As a further approach, collect L side channel traces t1,…,t L , use the mean vector to represent the leaked signal component, use the covariance matrix to represent the leaked noise component, construct templates (w0, c0) and (w1, c1), and obtain the leakage features corresponding to messages m = (0, 0, ..., 0) and m = (1, … , 0); where (w0, c0) represents the mean vector and covariance matrix of the 0th group of traces, and (w1, c1) represents the mean vector and covariance matrix of the 1st group of traces.
[0020] As a further solution, by leaking the trace t i With the jth template (w j , c j ) to determine the message bit, specifically:
[0021] ;
[0022] in, represents the matching probability between the i-th trace and the j-th template, j ∈ {0, 1}.
[0023] As a further solution, the probability distribution of key guessing is calculated as follows:
[0024] Assume that j1,…, j |S| is the key guess of the key coefficient other than the key s;
[0025] The probability of guessing the key is:
[0026] ;
[0027] in, Indicates arbitrary key guessing The distinguisher, Indicates arbitrary key guessing Differentiators and other guesses The difference between the differentiators; Indicates arbitrary key guessing The probability density function of represents the variable in the integral, o=1,…, .
[0028] As a further solution, the optimal variance threshold is calculated. The specific process is:
[0029] Calculate the required safety parameter β0 without any prompts as a penalty for solution failure;
[0030] Assume that t is the amount of traces required to achieve perfect prompting, t∈[1, ], is the upper limit value;
[0031] Traverse all t, calculate the number of perfect hints and approximate hints under different t, integrate them into DBDD to calculate the expected value of the security parameter β;
[0032] Select t corresponding to the lowest expected value of β to determine the optimal variance threshold.
[0033] Among them, the expected value of the security parameter β is Specifically:
[0034] ;
[0035] in, Indicates the corresponding security parameter when the prediction is successful, Indicates the success rate of key s.
[0036] The success rate of key s Specifically:
[0037] ;
[0038] Among them, j1,…,j |S| is the key guess of the key coefficient other than the key s, a discriminator representing a correct key guess, ,…, are the distinguishers of wrong key guesses, express The probability density function of Respectively The probability density function of 、 represents the variable in the integral.
[0039] In other embodiments, the following technical solutions are adopted:
[0040] A terminal device includes a processor and a memory, wherein the processor is used to implement instructions; the memory is used to store multiple instructions, and the instructions are suitable for being loaded by the processor and executing the above-mentioned security assessment method based on side channel analysis.
[0041] Compared with the prior art, the present invention has the following beneficial effects:
[0042] (1) The present invention proposes a method for calculating the theoretical success rate of side-channel attacks based on plaintext check oracles, which can theoretically determine the number of queries required for each coefficient without the need to actually execute the attack multiple times. The method for calculating the theoretical success rate of the present invention covers multiple types of PC oracle side-channel attacks, thereby improving the adaptability and efficiency of the attack strategy.
[0043] (2) This paper introduces a perfect hint threshold optimization method, which can dynamically judge the hint quality based on statistical characteristics, thereby reasonably allocating the amount of curves required for each secret key and improving the overall attack efficiency; especially in scenarios where the number of queries is limited, this method can maximize the use of available information and effectively improve the attack capability against lattice-based cryptographic schemes such as ML-KEM.
[0044] (3) The present invention combines the estimation of the theoretical success rate of side channel attacks based on the plaintext check oracle with the lattice reduction algorithm, and uses the adaptive threshold algorithm to obtain a more dangerous attack setting, revealing hidden security risks and enabling a more reasonable security assessment.
[0045] Other features and advantages of additional aspects of the present invention will be given in part in the following description and in part will become obvious from the following description or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 Flowchart of a security assessment method based on side channel analysis in an embodiment of the present invention;
[0047] Figure 2 The comparison results of the predicted success rate and the actual success rate of the attack based on PC Oracle when the signal-to-noise ratio is 0.12 in the embodiment of the present invention;
[0048] Figure 3 The comparison results of the predicted success rate and the actual success rate of the attack based on PC Oracle when the signal-to-noise ratio is 0.06 in the embodiment of the present invention;
[0049] Figure 4 The comparison results of the predicted success rate and the actual success rate of the attack based on PC Oracle when the signal-to-noise ratio is 0.03 in the embodiment of the present invention;
[0050] Figure 5 The comparison results of the predicted variance and the actual variance of the attack based on PC Oracle when the signal-to-noise ratio is 0.12 in the embodiment of the present invention;
[0051] Figure 6 The comparison results of the predicted variance and the actual variance of the attack based on PC Oracle when the signal-to-noise ratio is 0.06 in the embodiment of the present invention;
[0052] Figure 7 1 is a comparison result between the predicted variance and the actual variance of the attack based on PC Oracle when the signal-to-noise ratio is 0.03 in an embodiment of the present invention. DETAILED DESCRIPTION
[0053] It should be noted that the following detailed description is illustrative and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used in the present invention have the same meaning as commonly understood by those skilled in the art to which the present invention belongs.
[0054] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or combinations thereof.
[0055] Example 1
[0056] In one or more embodiments, a security assessment method based on side channel analysis is disclosed, combined with Figure 1 , specifically including the following steps:
[0057] S101: Construct a ciphertext in such a way that the decrypted message bit m is only related to a specific coefficient of the target key.
[0058] In Kyber KEM (Post-Quantum Key Encapsulation Mechanism), plaintext check oracle (PC-oracle)-based analysis constrains the dependencies of message bits during decryption by constructing specific ciphertexts.
[0059] Specifically, the ciphertext constructed in this embodiment is:
[0060] ct = (u,v)∈( R q × R q );
[0061] in, , , , j∈[0,n−1], n represents the number of coefficients in Kyber KEM; R q represents the set of real numbers in the range [0,q), represents the set of integers in the range [0,q); and are all constructed ciphertexts, 、 are all unit vectors, and the superscript represents the position of 1 in the unit vector. For example, the vector (1,0,0,0,0) is , the vector (0,0,1,0,0) is .
[0062] u and v are constructed in such a way that the decrypted message bit m is only related to certain coefficients of the target key, and this relationship can be expressed by the function F:
[0063] ;
[0064] in, Indicates the specific formula for calculating m in the Kyber algorithm, which is related to the current s[0]; Indicates the 0th bit of the secret key; Indicates the position of m.
[0065] Therefore, by selecting the ciphertext, different message bits m can be generated under possible key values s, as shown in Table 1. Using the four bits m, a single bit of the secret key s[i] can be determined, thus eliminating interference from other bits. In this embodiment, the value of m is 0 or 1.
[0066] Table 1 Kyber’s selected ciphertext table
[0067]
[0068] S102: Perform a side channel attack based on plaintext inspection (PC-oracle), collect L side channel leakage traces of the cryptographic device, calculate the probability distribution of key guessing, and obtain the mean and variance of the probability distribution.
[0069] In this embodiment, the side channel analysis based on plaintext inspection (PC-oracle) mainly consists of two stages.
[0070] In the first phase, the leakage associated with the message bit m is analyzed.
[0071] Collect L side channel traces t1,…,t L , such as power consumption or electromagnetic radiation, the corresponding device processing ciphertext is ct1,…,ct L The mean vector is used to represent the leaked signal component, and the covariance matrix is used to represent the leaked noise component.
[0072] By analyzing these traces, we can construct templates (w0, c0) and (w1, c1) to obtain the leakage signatures corresponding to message bits m = (0, 0, ..., 0) (i.e., m=0) and m = (1, ..., 0) (i.e., m=1):
[0073] ;
[0074] ;
[0075] Among them, w j , c j Represent the mean vector and covariance matrix of the jth group of traces, n j represents the number of traces in the jth group, j ∈ {0, 1}.
[0076] In the second stage, there are n selected ciphertexts ct1,…,ct n Used to perform decapsulation operations.
[0077] Assume that the key coefficient of the target device is s, whose value is unknown. The corresponding decrypted message is expressed as m1,…,m n , the power trace is represented by t1,…,t n Assuming that the leakage roughly follows a multivariate normal distribution, the leakage trace t i With the jth template (w j , c j ) to determine the message bit m (i.e., the leakage trace t i corresponds to m=0 or m=1):
[0078] ;
[0079] in, is the matching probability between the i-th trace and the j-th template, Indicates the calculation of the determinant of the matrix, is the i-th trace.
[0080] In actual analysis, the logarithm can be used instead of the matching probability to minimize the approximation error. The covariance matrix C can be obtained by averaging the covariance matrices of different templates to accurately represent the noise.
[0081] Distance is always used as the statistic:
[0082] ;
[0083] in, Represents the i-th trace The distance from the jth template. The closer the distance, the closer it is to the template and the higher the matching probability.
[0084] The message leak allows the analyst to construct a plaintext inspection oracle (PC-oracle) with a side-channel distinguisher. .
[0085] Based on the results of PC-oracle, we can distinguish which category the leakage trace belongs to:
[0086] ;
[0087] in, represents the matching probability between the i-th trace and the 0-th template, represents the matching probability between the i-th trace and the first template.
[0088] By querying PC-oracle multiple times using the ciphertext selected in Table 1 , the key s can be determined.
[0089] In actual analysis scenarios, noise from the environment or target equipment can affect This means that It is not perfect and cannot always output the correct result. Therefore, multiple tracking is required to obtain the probability of Bayes' theorem.
[0090] In this embodiment, the relationship between the analysis success rate based on PC-oracle and different parameters is theoretically analyzed, and a theoretical calculation formula for the success rate is obtained. This eliminates the need for multiple actual attack executions, thereby improving the attack efficiency.
[0091] Specifically, assume that j1,…,j |S| is the key guess of the key coefficient other than key s, key s is regarded as the correct key coefficient here, j s is a key guess for the correct key s; let is the difference between the distance results of the correct key and the incorrect key. Represents the i-th trace The distance from the jth template, Represents the distance between the i-th trace and the s-th template.
[0092] There are n ciphertexts ct1,…,ct n Used to perform decapsulation during the key recovery phase. Random variable ,…, Independent and identically distributed; According to the central limit theorem, if ,…, are independent and identically distributed variables. When n approaches infinity, Obey Gaussian distribution.
[0093] Let S be the set of key coefficients, the eigenvalue of the jth key coefficient can be expressed as: , and D s The eigenvalues corresponding to the correct key coefficient s. The difference between them can be expressed as:
[0094] ;
[0095] During the decapsulation process, the side channel traces are measured through the selected ciphertext. c There are several types of ciphertexts to choose from to obtain side channel information.
[0096] For each key coefficient s , under the selected ciphertext, the value of the message bit m is expressed as c ( s ). The values of the two message bits c ( s 1) and c ( s 2) The Hamming distance between d ( c ( s 1), c ( s 2)). For example, if c (-2)=1100 and c (1)=0010, then the Hamming distance d ( c (-2), c (1))=3.
[0097] For message bit m =(0,0,...,0) and m =(1,0,...,0), analyze the leakage. Assume that the correct message bit is m s , the wrong message bit is m o . Correct template and the ith power trace t i The distance between . Error template and the ith power trace t i The distance between .
[0098] make is the difference between the distance results of the correct key and the incorrect key, then:
[0099] ;
[0100] The expectation and variance of can be obtained as follows:
[0101] ;
[0102] Among them, var represents the variance function, Obeys normal distribution.
[0103] The difference between the discriminators under the correct key assumption and the incorrect key assumption can be simplified to:
[0104] ;
[0105] in, Indicates the number of ciphertext types, Indicates the number of analysis queries, 、 They all represent the value of the message bit m. Different selected ciphertexts and different s will correspond to different m.
[0106] Therefore, D can be deduced under the theoretical model. s -D j distribution.
[0107] ;
[0108] Because D s -D j represents the variance of the discriminator and therefore also follows a normal distribution: .
[0109] D s -D j The probability density function (PDF) of a probability distribution is expressed as :
[0110] ;
[0111] The theoretical calculation formula for the final success rate is:
[0112] .
[0113] Based on the above analysis, the success rate can be theoretically estimated SR Theoretical analysis results show that the success rate SR The number of main queries n a and the difference between the differentiators, that is, affected by The impact of accuracy.
[0114] In this embodiment, the probability distribution of key guessing is calculated to obtain the mean and variance of the probability distribution. The specific process is as follows:
[0115] Assume that j1,…, j |S| Indicates the key guess of the key coefficient other than key s. Key s is regarded as any current key coefficient here. s is a key guess for any key s.
[0116] variable ,…, Represents arbitrary key guesses and the difference between the differentiators for other key guesses.
[0117] The probability distribution of key guesses can be calculated as follows:
[0118] ;
[0119] Among them, any guess Differentiators and other key guesses The difference between can be expressed as:
[0120] ;
[0121] in, represents j1,…, j |S| ; Indicates the number of ciphertext types, Indicates the number of analysis queries, express and The Hamming distance between Indicates the current key guess The corresponding m value is, Indicates the m value corresponding to other key guesses; Indicates the distance between the i-th trace and the template corresponding to the current secret key guess m value, Represents the distance between the i-th trace and the template corresponding to other key guess m values; Indicates the current key guess With other key guesses the difference between distance results; express expectations, express The variance of .
[0122] Then the probability of key guessing can be expressed as:
[0123] ;
[0124] in, Indicates the current key guess The probability density function of represents the variable in the integral.
[0125] Based on the above method, the probability distribution of other key guesses can be obtained ,…, .
[0126] Based on the prediction of the above posterior probability, the key guess can be obtained Mean of a probability distribution and variance :
[0127] .
[0128] S103: Calculate the optimal variance threshold, and use the variance threshold to divide the probability of key guessing into perfect hints and approximate hints; integrate the divided perfect hints and approximate hints into the DBDD instance through the DDGR framework, convert the DBDD instance into a USVP instance, perform BKZ-β lattice reduction on the USVP instance, and calculate the security parameter β.
[0129] Specifically, the DDGR framework can get the mean value in S102 and variance It is integrated into the DBDD instance as a specific hint, and then the lattice basis reduction is performed through the USVP instance. ,average value and covariance matrix Composition, called .
[0130] Side channel analysis based on PC-oracle usually relies on a predefined number of queries to measure and analyze the leakage information of each coefficient. This information is converted into a probability distribution through a side channel discriminator and further converted into a perfect hint or an approximate hint.
[0131] Specifically, the number of analysis queries t affects the mean of the posterior probability and variance For simplicity, the calculation process is expressed as function:
[0132] ;
[0133] Given , , where A is sampled uniformly at random, and s, e are sampled with independent and distributed coefficients; 、 They represent integer sets respectively, and A is The matrix, is a vector of length m, and q represents the modulus (mod).
[0134] The initial security of the DBDD instance of LWE is denoted as β0. In the DDGR framework, the posterior mean and variance Considered as an approximate hint or a perfect hint integrated into the DBDD instance as follows:
[0135] ;
[0136] in, The variance is , the mean is , the volume is DBDD instance, represents the operation of integrating perfect prompts in the DDGR framework, represents the operation of integrating approximate hints in the DDGR framework, represents the variance threshold for distinguishing perfect cues from approximate cues, The variance is , the mean is , the volume is DBDD instance.
[0137] The integration process is performed for each prompt, and after each prompt is integrated, the DBDD instance is updated accordingly. Based on the above formula, The converted USVP instances obtain a block size β. This process can be expressed as a τ function:
[0138] .
[0139] in, is a security parameter, This is an algorithm for predicting security parameters. This algorithm is easy to implement in the prior art and will not be further described.
[0140] The setting of the variance threshold directly affects the number of queries, which in turn affects the mean and variance of the probability distribution, and thus affects the properties and volume of the grid, thereby affecting the security parameter β. λ Significant impact on the number of analytical queries and success rate: smaller threshold λ This means that fewer queries are required and the analysis results can be considered as perfect hints. However, the coefficient values of the analysis may be inaccurate, which in turn affects the update of the DBDD instance and causes the solution to fail. On the contrary, a larger threshold λ This will cause the analysis to perform more redundant queries, which may result in higher β value.
[0141] Existing techniques typically predefine a variance threshold to distinguish perfect cues from approximate ones. However, in practical analysis, the appropriate variance threshold is often unknown. The DDGR framework assumes a variance of zero to integrate perfect cues. However, in practice, variance is rarely zero, or requires a large number of queries to approach zero, which can affect the accuracy of the evaluation results.
[0142] This embodiment provides a method for calculating an optimal variance threshold, which can obtain a more dangerous attack setting, reveal hidden security risks, and enable a more reasonable security assessment.
[0143] The method for calculating the optimal variance threshold is as follows:
[0144] First, we calculate the β0 required without any hints as a penalty for solution failure; t represents the amount of curve required to achieve perfect hints, and the larger t is, the higher the corresponding success rate.
[0145] Assume that t is the amount of traces required to achieve perfect prompting, t∈[1, ], is the upper limit, that is, the number of queries used when the success rate SR is 1.
[0146] We then calculate the number of perfect and approximate hints at different t values and integrate them into DBDD to obtain the probability of successful solution β. However, because the threshold for perfect hints is lowered, perfect hints may be incorrect, leading to solution failure. Therefore, this implementation comprehensively considers both successful and failed solutions to obtain the final expected value of β:
[0147] ;
[0148] in, is the key coefficient s The success rate can be calculated according to the theoretical calculation formula of the success rate in S102.
[0149] Traverse all t and select The lowest value corresponds to , thereby determining the optimal variance threshold: , that is, select the query quantity The corresponding posterior variance as the optimal variance threshold.
[0150] It should be noted that in this embodiment, the perfect hints and approximate hints of the division are integrated into the DBDD instance through the DDGR framework, the DBDD instance is converted into a USVP instance, the BKZ-β lattice reduction is performed on the USVP instance, and the security parameter β is calculated; this process can be implemented using existing technology, so a detailed analysis and description will not be given.
[0151] S104: Implementing a security assessment based on side-channel analysis based on the security parameter β.
[0152] In the Lattice Basis Reduction (BKZ) algorithm, the security parameter β is a key indicator for measuring security. A larger β value usually means stronger anti-analysis capability, that is, the larger the security parameter β, the higher the security. The security parameter β can be used to achieve security assessment based on side-channel analysis.
[0153] Experimental results
[0154] The ciphertexts selected from Table 1 control the decrypted messages m0 = (0, 0, .., 0) and m1 = (1,0, .., 0). Leakage traces are generated during the re-encryption process using the Fujisaki-Okamoto transform (FO transform). Noise can affect the effectiveness of side-channel analysis, so this example evaluates the success rate (SR) estimation under different noise levels. The noise is parameterized by the standard deviation of the side-channel noise, set to 50, 70, and 100, respectively, corresponding to signal-to-noise ratios (SNRs) of 0.12, 0.06, and 0.03.
[0155] Figure 2-Figure 4 The comparison between the predicted success rate and the actual success rate of PC-oracle-based analysis at different noise levels is shown. As the number of analysis queries increases, the gap between the predicted success rate and the actual success rate gradually decreases, which verifies the accuracy of the theoretical model proposed in this example.
[0156] When the signal-to-noise ratio (SNR) is 0.12, the analysis success rate can reach 100% after more than 50 queries; when the SNR is 0.06 and 0.03, more than 100 and 200 queries are required respectively to achieve the same success rate.
[0157] Figure 5-Figure 7 The figure shows the comparison of the predicted variance of the PC-oracle-based analysis with the actual variance for different noise levels. As the number of analyzed queries increases, the predicted variance gradually approaches the actual value. When the number of queries is small, the predicted variance is lower than the actual value. This is mainly because the distribution of the discriminator is not accurate when the number of queries is small.
[0158] This example experiments all Kyber768 coefficients under different noise levels. An optimized threshold is selected for a given total number of queries. To verify the effectiveness of the adaptive threshold optimization scheme, this example performs side-channel analysis based on the selected threshold using a PC oracle and obtains the β value after integrating the analysis results. The final β values under different noise levels are listed in Table 2.
[0159] Table 2 Efficiency of adaptive threshold optimization analysis (β value)
[0160]
[0161] For comparison, this embodiment also performed analysis using the DDGR framework using the same trajectory data. First, when the signal-to-noise ratio (SNR) was 0.12 and the total number of queries was 1,000, the traditional analysis achieved a β of 602.8, while the optimized threshold analysis achieved a β of 538.7, a 10.6% improvement. When the total number of queries increased to 15,000, the traditional analysis achieved a final β of 322.0, while the optimized threshold analysis achieved a β of 127.2, an improvement of 60.5%. Compared to the traditional method, the adaptive threshold method of this embodiment can achieve lower β values at different noise levels with the same number of queries.
[0162] Example 2
[0163] In one or more embodiments, a terminal device is disclosed, which includes a processor and a memory, wherein the processor is used to implement instructions; the memory is used to store multiple instructions, and the instructions are suitable for being loaded by the processor and executing the security assessment method based on side channel analysis described in Example 1.
[0164] It should be understood that in this embodiment, the processor may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), off-the-shelf field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0165] The memory may include a read-only memory and a random access memory, and provides instructions and data to the processor. A portion of the memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.
[0166] During implementation, each step of the above method may be completed by an integrated logic circuit of hardware in a processor or by instructions in the form of software.
[0167] Although the above describes the specific embodiments of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without any creative work are still within the scope of protection of the present invention.
Claims
1. A security assessment method based on side channel analysis, characterized in that: include: constructing a ciphertext in such a way that the decrypted message bits m are only related to certain coefficients of the target key; Collect L side channel leakage traces of cryptographic devices, calculate the probability distribution of key guessing, and obtain the mean and variance of the probability distribution; Calculate the optimal variance threshold, and use the variance threshold to divide the probability of key guessing into perfect hints and approximate hints; integrate the divided perfect hints and approximate hints into the DBDD instance through the DDGR framework, convert the DBDD instance into a USVP instance, perform BKZ-β lattice reduction on the USVP instance, and calculate the security parameter β; Calculate the optimal variance threshold. The specific process is: Calculate the required safety parameter β0 without any prompts as a penalty for solution failure; Assume that t is the amount of traces required to achieve perfect prompting, t∈[1, ], is the upper limit value; Traverse all t, calculate the number of perfect hints and approximate hints under different t, integrate them into DBDD to calculate the expected value of the security parameter β; Select t corresponding to the lowest expected value of β to determine the optimal variance threshold; The expected value of the security parameter β Specifically: ; in, represents the corresponding security parameter when the prediction is successful, τ represents the τ function, The variance is , the mean is , the volume is DBDD instance, represents the success rate of key s; A security assessment based on side channel analysis is implemented based on the security parameter β.
2. A security assessment method based on side channel analysis according to claim 1, characterized in that: The constructed ciphertext is: ct = (u,v) ∈ ( R q × R q ); in, , , , j∈[0,n-1], n represents the number of coefficients; R q represents the set of real numbers in the range [0,q), represents the set of integers in the range [0,q); and are all constructed ciphertexts, 、 are all unit vectors, and the superscript represents the position of 1 in the unit vector.
3. A security assessment method based on side channel analysis according to claim 1, characterized in that: The relationship between the message bit m and the specific coefficient of the target key is specifically: ; in, Indicates the specific formula for calculating m in the Kyber algorithm, which is related to the current s[0]; Indicates the 0th bit of the secret key; Indicates the position of m.
4. A security assessment method based on side channel analysis according to claim 1, characterized in that: Collect L side channel traces t1,…,t L , use the mean vector to represent the leaked signal component, use the covariance matrix to represent the leaked noise component, construct templates (w0, c0) and (w1, c1), and obtain the leakage features corresponding to messages m = (0, 0, ..., 0) and m = (1,… , 0); where (w0, c0) represents the mean vector and covariance matrix of the 0th group of traces, and (w1, c1) represents the mean vector and covariance matrix of the 1st group of traces.
5. A security assessment method based on side channel analysis according to claim 4, characterized in that: Through the leakage trace t i With the jth template (w j , c j ) to determine the message bit, specifically: ; in, represents the matching probability between the i-th trace and the j-th template, j ∈ {0, 1}.
6. A security assessment method based on side channel analysis according to claim 1, characterized in that: Calculate the probability distribution of key guessing, specifically: Assume that j1,…, j |S| is the key guess of the key coefficient other than the key s; The probability of guessing the key is: ; in, Indicates arbitrary key guessing The distinguisher, Indicates arbitrary key guessing Differentiators and other guesses The difference between the differentiators; Indicates arbitrary key guessing The probability density function of represents the variable in the integral, o=1,…, .
7. A security assessment method based on side channel analysis according to claim 1, characterized in that: The success rate of key s Specifically: ; Among them, j1,…,j |S| is the key guess of the key coefficient other than the key s, a discriminator representing a correct key guess, ,…, are the distinguishers of wrong key guesses, express The probability density function of Respectively The probability density function of 、 represents the variable in the integral.
8. A terminal device comprising a processor and a memory, wherein the processor is used to implement instructions; the memory is used to store multiple instructions, characterized in that: The instructions are suitable for being loaded by a processor and executing the security assessment method based on side channel analysis described in any one of claims 1-7.
Citation Information
Patent Citations
Power consumption side channel analysis method and system based on cryptographic algorithm collision attack
CN118631419A
Secret key estimation methods and devices
EP3226460A1