Side channel security detection method, device, equipment, medium and program product
By collecting and analyzing the side-channel curve data of the Aigis-enc algorithm, establishing a leakage model and recovering the private key, the side-channel attack risk faced by the Aigis-enc algorithm in its physical implementation is resolved, thereby improving the product's security and anti-attack capabilities.
Patent Information
- Application Number
- CN202510952505.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-10
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-07-10
AI Technical Summary
The existing Aigis-enc algorithm faces the risk of side-channel physical attacks in its physical implementation and lacks effective security detection methods, making it impossible to evaluate its security in practical applications.
By collecting side channel curve data during the execution of the Aigis-enc algorithm and converting it into a polynomial vector, a leakage model is established, and the private key is recovered using correlation coefficient analysis to detect and evaluate the security of the algorithm.
The detection of side-channel physical attacks on the Aigis-enc algorithm has been achieved, potential vulnerabilities have been discovered and repaired, and the overall anti-attack capability of post-quantum cryptographic products has been improved.
Smart Images

Figure CN120528698B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to, but is not limited to, the field of data security technology, and in particular to a side channel security detection method, apparatus, device, medium, and program product. Background Art
[0002] The Aigis-enc algorithm is a lattice-based post-quantum cryptographic algorithm whose security relies on the asymmetric MLNE problem (Asynmetric MLWE, AMLWE) and the asymmetric MSIS problem (Asymmetzic MSIS, AMSIS).
[0003] Although the Aigis-enc algorithm has been proven to be secure at the mathematical and logical level, it still faces the risk of side-channel physical attacks in its actual physical implementation. Summary of the Invention
[0004] In view of this, embodiments of the present application at least provide a side channel security detection method, apparatus, device, medium, and program product.
[0005] The technical solution of the embodiment of the present application is implemented as follows:
[0006] In one aspect, an embodiment of the present application provides a side channel security detection method, the method comprising:
[0007] The side channel curve data during the execution of the Aigis-enc algorithm is collected to obtain a sampling data set;
[0008] Restoring the ciphertext in the sample data set into a polynomial vector;
[0009] Traversing the guessed private key range and the polynomial vector according to the parameter set of the Aigis-enc algorithm to obtain a set of intermediate values of the sample data set;
[0010] establishing a leakage model based on the intermediate value set, and generating a power consumption curve through the leakage model;
[0011] Based on the correlation coefficient analysis between the power consumption curve and the sampled data set, the private key of the Aigis-enc algorithm is recovered.
[0012] On the other hand, an embodiment of the present application provides a side channel security detection device, the device comprising:
[0013] The acquisition module is used to collect the side channel curve data during the execution of the Aigis-enc algorithm to obtain a sample data set;
[0014] A detection module is configured to restore the ciphertext in the sampled data set into a polynomial vector; traverse a guessed private key range and the polynomial vector based on a parameter set of the Aigis-enc algorithm to obtain a set of intermediate values of the sampled data set; establish a leakage model based on the set of intermediate values, and generate a power consumption curve using the leakage model; recover the private key of the Aigis-enc algorithm based on a correlation coefficient analysis between the power consumption curve and the sampled data set; and perform a security assessment of a side channel during the execution of the Aigis-enc algorithm based on the private key.
[0015] On the other hand, an embodiment of the present application provides a computer device, including a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor executes the program, some or all of the steps in the above method are implemented.
[0016] On the other hand, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which implements some or all of the steps in the above method when executed by a processor.
[0017] On the other hand, an embodiment of the present application provides a computer program, including computer-readable code. When the computer-readable code is executed in a computer device, a processor in the computer device executes some or all of the steps for implementing the above method.
[0018] On the other hand, an embodiment of the present application provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program. When the computer program is read and executed by a computer, some or all of the steps in the above method are implemented.
[0019] In the embodiment of the present application, the polynomial operation during the execution of the Aigis-enc algorithm is used as the attack point, the correlation characteristics of the private key and the intermediate value reflected by the polynomial vector obtained by converting the sample data set are mapped to the leakage model, and the key is recovered through analysis through the leakage model. This realizes the detection of side channel physical attacks during the execution of the Aigis-enc algorithm, allowing users to discover and repair vulnerabilities in the execution process of the Aigis-enc algorithm by analyzing the recovered key during the hardware design phase, thereby improving the overall anti-attack capability of post-quantum cryptographic products.
[0020] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the technical solutions of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The drawings herein are incorporated into and constitute a part of the specification. These drawings illustrate embodiments consistent with the present application and, together with the specification, are used to illustrate the technical solutions of the present application.
[0022] Figure 1 A schematic diagram of a side channel security detection method provided in an embodiment of the present application;
[0023] Figure 2 A schematic diagram of a side channel security detection method provided in an embodiment of the present application;
[0024] Figure 3 This is one of the collection diagrams of a side channel security detection method provided in an embodiment of the present application;
[0025] Figure 4 This is a second collection diagram of a side channel security detection method provided in an embodiment of the present application;
[0026] Figure 5 The third collection diagram of a side channel security detection method provided in an embodiment of the present application;
[0027] Figure 6 A schematic diagram of a flow chart of another side channel security detection method provided in an embodiment of the present application;
[0028] Figure 7 One of the pseudo code diagrams provided in the embodiment of the present application;
[0029] Figure 8 A second pseudo code diagram provided for an embodiment of the present application;
[0030] Figure 9 A third pseudo-code diagram provided for an embodiment of the present application;
[0031] Figure 10 A fourth pseudo code diagram provided in an embodiment of the present application;
[0032] Figure 11 A fifth pseudo code diagram provided in an embodiment of the present application;
[0033] Figure 12 A sixth pseudo-code diagram provided for an embodiment of the present application;
[0034] Figure 13 A schematic diagram of experimental results provided in an embodiment of the present application;
[0035] Figure 14 A schematic diagram of the structure of a side channel security detection device provided in an embodiment of the present application;
[0036] Figure 15 A hardware entity diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0037] In order to make the purpose, technical solutions and advantages of this application clearer, the technical solutions of this application are further elaborated in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0038] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0039] The terms "first / second / third" involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. It is understandable that "first / second / third" can be interchanged with a specific order or sequence where permitted so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0040] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing this application only and are not intended to limit this application.
[0041] The Aigis-enc algorithm, a domestically developed lattice-based post-quantum cryptographic algorithm, relies on the security of the asymmetric MLWE (AMLWE) problem and the asymmetric MSIS (AMSIS) problem. Although the Aigis-enc algorithm has been proven secure at the mathematical and logical level, its actual physical implementation remains vulnerable to side-channel attacks. Currently, there is a lack of effective side-channel security detection methods for the Aigis-enc algorithm. This application addresses this technical gap.
[0042] This application proposes a side-channel security detection method. Its core concept is to exploit the leakage of polynomial multiplication operations and combine them with the characteristics of the Aigis-enc algorithm to perform CPA analysis. This method can effectively recover the algorithm's private key, thereby efficiently and accurately evaluating the algorithm's security in practical applications.
[0043] The Kyber algorithm is also a lattice-based post-quantum cryptography algorithm, whose security is guaranteed by the difficulty of the MLWE problem. Existing technical solutions collect the energy consumption of the Kyber algorithm's decryption operations, use the output of the point multiplication operation during the Kyber algorithm's decryption process as an attack point, and map it to a leakage model. CPA analysis techniques are then used to recover the Kyber algorithm's private key.
[0044] With the continuous advancement of science and technology, post-quantum cryptography technology is gradually moving from theoretical exploration to practical application, and products such as chips based on post-quantum cryptography are beginning to appear. The security testing of post-quantum cryptographic chips is receiving increasing attention from researchers. However, in the field of domestically produced post-quantum cryptographic algorithms, there is currently a lack of relatively mature security testing methods in China, which means that it is impossible to evaluate the security of the Aigis-enc algorithm after it is actually applied. The method proposed in this application can effectively perform side-channel security assessments on the physical implementation of the Aigis-enc algorithm. Manufacturers can discover and repair potential security risks before the equipment leaves the factory, avoiding security vulnerabilities after the product is put into use, thereby improving the overall security of the equipment. In addition, this technology can effectively fill the gap in China's side-channel security detection technology for post-quantum cryptographic algorithms, and is also conducive to improving the security level of domestic post-quantum algorithm design and implementation.
[0045] The present invention provides a side channel security detection method that can be executed by a processor of a computer device. The computer device may include a server, laptop, tablet, desktop computer, smart TV, set-top box, mobile device (e.g., mobile phone, portable video player, personal digital assistant, dedicated messaging device, portable gaming device), or other device capable of side channel security detection. Figure 1 A schematic diagram of the implementation flow of a side channel security detection method provided in an embodiment of the present application is shown as follows: Figure 1 As shown, the method includes the following steps 101 to 105:
[0046] This algorithm has a specific technical connection with the internal structure of the computer system, and can solve the technical problem of how to improve the hardware computing efficiency or execution effect (including reducing the amount of data storage, reducing the amount of data transmission, increasing the hardware processing speed, etc.), thereby obtaining the technical effect of improving the internal performance of the computer system in accordance with the laws of nature.
[0047] Step 101: collect side channel curve data during the execution of the Aigis-enc algorithm to obtain a sample data set.
[0048] In the present embodiment, side-channel data refers to physical information leaked by hardware devices during the execution of the Aigis-enc algorithm, including power consumption fluctuations, changes in electromagnetic radiation, or differences in computation time. This data reflects the dynamic characteristics of the device's internal operations. The sampled data set is a collection of side-channel data collected during multiple executions of the Aigis-enc algorithm, along with its corresponding input ciphertext and output plaintext, for subsequent analysis.
[0049] The system uses hardware devices such as oscilloscopes, current probes, or electromagnetic probes to capture physical leakage signals from target hardware (such as cryptographic chips) in real time while executing the Aigis-enc algorithm. The system stores the collected power consumption, current, or electromagnetic radiation data in a time series as curves, with each curve corresponding to a decryption operation. The system also records the input ciphertext and output plaintext of each operation to ensure data integrity. After acquisition, the system preprocesses the raw data (such as filtering and noise reduction) to form a standardized sample data set, providing a foundation for subsequent analysis.
[0050] Step 102: Restore the ciphertext in the sample data set into a polynomial vector.
[0051] Step 103: traverse the guessed private key range and the polynomial vector according to the parameter set of the Aigis-enc algorithm to obtain a set of intermediate values of the sample data set.
[0052] In this embodiment of the present application, the intermediate value set refers to the set of temporary operation results calculated by the system based on the guessed private key and the known ciphertext during the Aigis-enc decryption process. These results are potentially correlated with the intermediate values of the actual private key. It is assumed that the intermediate values are simulated intermediate values generated by the system by traversing the range of possible private keys (such as 2^13 or 2^14 private key bits) for comparison with the actual leaked data.
[0053] The system first decodes the input ciphertext, converting it to a polynomial form (e.g., the polynomial vector u). The system then applies the fast number theoretic transform (NTT) to convert the polynomial to the frequency domain, optimizing computational efficiency based on Montgomery reduction or Barrett reduction. For each guessed private key (guess-sk), the system multiplies it with NTT(u) to generate a hypothetical intermediate value. Based on the parameters set for the Aigis-enc algorithm, the system dynamically adjusts the private key guess range to ensure coverage of all possible values. Finally, the system stores all hypothetical intermediate values as an intermediate value set.
[0054] Step 104: Establish a leakage model based on the intermediate value set, and generate a power consumption curve using the leakage model.
[0055] Step 105 : Recovering the private key of the Aigis-enc algorithm based on the correlation coefficient analysis between the power consumption curve and the sampled data set.
[0056] In the embodiments of this application, correlation coefficient analysis is a statistical method used to quantify the strength of the linear relationship between the power consumption curve of the hypothetical intermediate value mapping and the actual side channel curve collected. Private key recovery is the process of restoring the complete private key byte by byte by identifying the private key guess corresponding to the maximum correlation coefficient.
[0057] The system maps the set of intermediate values to a selected leakage model (such as the Hamming weight model) to generate power consumption curves. The system then calculates the Pearson correlation coefficient between each hypothesized curve and the true curves in the sampled data set. By comparing the correlation coefficients of all guessed private keys, the system determines the private key fragment corresponding to the maximum value and marks it as the correct private key portion. This process is repeated, gradually recovering all bytes of the private key until the complete private key is restored.
[0058] In this embodiment, the system integrates key data from the private key recovery process (such as peak correlation coefficient, estimated private key range, and recovery time) to analyze potential vulnerabilities in the Aigis-enc algorithm. The system automatically generates a report containing attack success rates, vulnerability locations, and improvement suggestions, providing manufacturers with actionable security reinforcement evidence.
[0059] Specifically, refer to Figure 2 ,in:
[0060] S1, using an oscilloscope to collect side information leaked by the encryption hardware device during the Aigis-enc algorithm decryption operation, such as power consumption fluctuations, electromagnetic radiation changes, and operation time differences.
[0061] S2, selects the output of the polynomial multiplication operation in the Aigis-enc algorithm as the attack point for data collection;
[0062] S3, and map it to a leakage model (e.g., Hamming weight model, Hamming distance model); S4, use the CPA analysis method to evaluate the security of the algorithm in the encryption hardware device.
[0063] This application detects whether there is a risk of key exposure or sensitive data leakage by analyzing the correlation between side information and keys or sensitive data.
[0064] The embodiment of the present application uses the polynomial operation during the execution of the Aigis-enc algorithm as an attack point, maps the correlation characteristics of the private key and the intermediate value reflected by the polynomial vector obtained by converting the sample data set into a leakage model, and recovers the key through analysis based on the leakage model. This enables the detection of side-channel physical attacks during the execution of the Aigis-enc algorithm, allowing users to discover and repair vulnerabilities in the execution process of the Aigis-enc algorithm by analyzing the recovered key during the hardware design phase, thereby improving the overall anti-attack capability of post-quantum cryptographic products.
[0065] In some embodiments, step 103 includes:
[0066] Step 1031: Perform number theory transformation on the polynomial vector to obtain a polynomial represented in the frequency domain.
[0067] In this embodiment, a polynomial vector refers to a set of polynomials obtained by decoding ciphertext. These polynomials are the basic units used for mathematical operations in the Aigis-enc algorithm. Ciphertext restoration involves decompressing compressed ciphertext data (such as a set of 8-bit unsigned integers) according to specific rules to restore it to its original polynomial form.
[0068] The system extracts ciphertext data from the sampled dataset, stored as a byte array. Using the decoding rules of the Aigis-enc algorithm, the system parses the ciphertext byte array bit by bit, converting it into a polynomial vector. This operation involves segmenting the byte array into fixed-length blocks, each corresponding to a coefficient of the polynomial, ultimately generating the complete polynomial vector u. This step provides input data for subsequent number-theoretic transformations.
[0069] In the embodiments of this application, the Number Theoretic Transform (NTT) is a fast algorithm based on modular arithmetic that is used to convert a polynomial from coefficient representation to point-value representation (frequency domain representation), similar to the Fast Fourier Transform (FFT). The frequency domain representation of a polynomial is its representation in the frequency domain, facilitating efficient operations such as multiplication.
[0070] The system applies a number theoretic transform (NTT) to the polynomial vector u, converting it from coefficient representation to frequency domain representation. This involves selecting a suitable large prime number p and primitive root g, and using butterfly operations to convert the polynomial coefficients to point values. The system optimizes modular arithmetic efficiency through Montgomery and Barrett reductions, ensuring a fast transformation. Finally, the system outputs the frequency domain representation of the polynomial NTT(u), facilitating subsequent private key guessing and product calculations.
[0071] Step 1032: traverse the range of guessed private keys according to the parameter set of the Aigis-enc algorithm, obtain the product result of each guessed private key and the polynomial represented in the frequency domain, and store the product result in an intermediate value set.
[0072] In this embodiment, the parameter set is the configuration parameter defined by the Aigis-enc algorithm, which determines the private key length and guess range. The guess range is the range of possible private key values that the system needs to traverse during the attack. For example, Params I and II are 2^13 bits, and Params III is 2^14 bits.
[0073] The system determines the private key guess range based on the parameter set (PARAMS I, PARAMS II, and PARAMS III) used by the Aigis-enc algorithm. For each possible private key value (guess-sk), the system multiplies it point-by-point by the frequency-domain polynomial NTT(u) to obtain the product. This step leverages the efficiency of frequency-domain multiplication to rapidly simulate a large number of private key guesses. The system ensures that all possible private key values are fully explored, covering the entire guess space.
[0074] In this embodiment, the intermediate value set stores the product of all guessed private keys and the frequency domain polynomial, which is used for subsequent correlation analysis. Associating guessed private keys maps each product result to its corresponding guessed private key value, facilitating subsequent identification of the correct private key.
[0075] The system stores each product result in an intermediate value set, along with the corresponding guessed private key value, guess-sk. This storage is performed in a structured format (such as a hash table or database) to ensure efficient data query and retrieval. This provides a complete intermediate value dataset for subsequent CPA analysis, ensuring the system can accurately recover the private key through correlation analysis.
[0076] The embodiments of the present application construct a complete set of intermediate values by restoring ciphertext, frequency domain transformation, private key traversal and result storage, providing a data basis for subsequent correlation analysis and private key recovery, improving the efficiency and accuracy of side-channel attacks, and being able to comprehensively evaluate the security of the physical implementation of the Aigis-enc algorithm.
[0077] In some embodiments, step 1032 includes:
[0078] Step 10321: When the Aigis-enc algorithm adopts the first parameter set or the second parameter set, traverse the guessed private key range of the first number of private key bits.
[0079] In this embodiment, the first parameter set (PARAMS I) and the second parameter set (PARAMS II) are two sets of configuration parameters defined in the Aigis-enc algorithm, corresponding to different quantum security strengths. PARAMS I targets 80 quantum secure bits, while PARAMS II targets 128 quantum secure bits. The first number refers to the number of private key bits that need to be traversed under PARAMS I and PARAMS II, specifically 2^13 bits.
[0080] The system first detects the parameter set type used by the Aigis-enc algorithm. If it is PARAMS I or PARAMS II, the system sets the private key guess range to 2^13 bits. The system then sequentially generates all possible private key values (guess-sk) within this range, ensuring coverage of the entire private key space. This step provides a complete set of private key guesses for subsequent intermediate value calculations, ensuring the comprehensiveness of the attack.
[0081] Step 10322: When the Aigis-enc algorithm adopts a third parameter set, traverse a second number of private key bits, where the second number is greater than the first number, the quantum security strength targeted by the first parameter set is smaller than the quantum security strength targeted by the second parameter set, and the quantum security strength targeted by the second parameter set is smaller than the quantum security strength targeted by the third parameter set.
[0082] In this embodiment, the third parameter set (PARAMS III) defines higher security configuration parameters for the Aigis-enc algorithm, targeting 192 quantum secure bits. The second number refers to the number of private key bits that need to be traversed under PARAMS III, specifically 2^14 bits, which is greater than the 2^13 bits for PARAMS I and PARAMS II.
[0083] When the system detects that the Aigis-enc algorithm uses PARAMS III, it sets the private key guess range to 2^14 bits. Due to the higher security strength of PARAMS III, the system needs to expand the private key guess range to ensure the effectiveness of the attack. The system then sequentially generates all possible private key values (guess-sk) within this range to ensure coverage of the entire PARAMS III private key space. This step demonstrates the system's adaptability to different security strength parameter sets.
[0084] For example, the three parameters may be shown in Table 1 below:
[0085] Table 1
[0086]
[0087] In the embodiments of the present application, Montgomery Reduction is an algorithm for quickly performing modular operations, optimizing the modular reduction of intermediate results by pre-calculating Montgomery inverses. Barrett Reduction is another modular operation optimization technique that accelerates modular division operations by pre-calculating approximate reciprocals.
[0088] When performing polynomial multiplication on each guessed private key (guess-sk), the system applies Montgomery and Barrett reduction techniques to optimize the computational process. Specifically, during multiplication, the system uses Montgomery reduction to quickly handle modular operations involving intermediate results; during modular division, the system uses Barrett reduction to accelerate computation. These optimization techniques significantly improve the efficiency of polynomial multiplication, enabling the system to quickly complete simulations of large numbers of guessed private keys.
[0089] In some embodiments, step 1031 includes: decoding the byte array of the ciphertext in the sample data set into a polynomial represented by coefficients, and reconstructing the polynomial represented by the coefficients into a polynomial vector through an inverse compression algorithm.
[0090] In the embodiment of the present application, byte array refers to the storage format of ciphertext in the Aigis-enc algorithm, which is a continuous data block composed of 8-bit unsigned integers and is used to compactly represent encrypted information.
[0091] The polynomial represented by coefficients is a form of polynomial expression. The polynomial is defined by directly listing the coefficients. The inverse compression algorithm is a specific decoding method defined in the Aigis-enc algorithm, which is used to restore the compressed ciphertext byte array to the original polynomial form.
[0092] The system first extracts a ciphertext byte array from the sampled data set, which stores the encrypted information in a compact format. Following the Aigis-enc algorithm specification, the system segments the byte array into fixed-length data blocks, each corresponding to a coefficient of the polynomial. Using an inverse compression algorithm, the system decodes each data block into the original values of the polynomial coefficients. The decoding process includes bitwise and modular operations to ensure accurate restoration of the coefficient values. After decoding all coefficients, the system arranges them in sequence to construct the polynomial represented by the coefficients. Finally, the system combines the individual polynomials into a polynomial vector structure according to the algorithm requirements, preparing for subsequent number-theoretic transformation processing. This process strictly adheres to the algorithm specifications to ensure the accuracy and consistency of data conversion.
[0093] In some embodiments, the side channel curve data includes at least one of the following: a power consumption curve, a current curve, and an electromagnetic radiation curve.
[0094] In some embodiments, step 101 includes:
[0095] Step 1011: collect side channel curve data of the Aigis-enc algorithm when the hardware device is running.
[0096] In the embodiments of this application, an oscilloscope is an electronic measuring instrument used to capture and display the waveform of an electrical signal over time, capable of accurately recording the instantaneous values of physical quantities such as voltage and current. A power consumption curve is waveform data showing the power consumption of a hardware device as it executes the Aigis-enc algorithm. A current curve is waveform data showing the power supply current as it executes the algorithm. An electromagnetic radiation curve is waveform data showing the electromagnetic field strength leaked by the hardware device as it executes the algorithm.
[0097] The system connects an oscilloscope to the target hardware device and uses power, current, or electromagnetic probes to collect physical leakage signals while the device is running the Aigis-enc algorithm. The power probe measures the voltage difference at the chip's power supply terminals and converts it into a power consumption curve; the current probe directly measures current fluctuations at the power supply terminals; and the electromagnetic probe captures changes in electromagnetic radiation around the chip. The system records these curves at a high sampling rate, ensuring that physical information is captured at all critical points during the computation process.
[0098] The first step in attack detection is to collect the Aigis-enc decryption algorithm curve. This is divided into power consumption curve collection, current curve collection, and electromagnetic curve collection. Hardware equipment such as acquisition probes and oscilloscopes are required during the collection process. Power consumption curve collection usually involves connecting a small resistor in series with the core power supply or ground terminal of the chip, and using an active differential probe to collect the voltage difference across the resistor, such as Figure 3 As shown in the figure, the current curve acquisition is to use the current probe to collect the current changes at the power supply end during the operation of the chip, such as Figure 4 As shown. Electromagnetic curve collection uses electromagnetic probes to collect electromagnetic radiation during chip operation, such as Figure 5 As shown, where Vcc represents the power supply voltage, I represents the power supply current, Indicates the chip voltage.
[0099] Step 1012: Record the ciphertext input and the plaintext output when the hardware device executes the Aigis-enc algorithm.
[0100] In this embodiment of the present application, the system synchronously records the ciphertext input and plaintext output of each decryption operation performed by the hardware device. The ciphertext and plaintext are transmitted via the device's communication interface (e.g., SPI or I2C), and the system uses a protocol analysis tool to capture and store this data. The recorded data strictly corresponds to the physical curve collected in step 1011, ensuring that each curve can be associated with a specific algorithm input and output.
[0101] Step 1013: pre-process the side channel curve data to obtain pre-processed side channel curve data.
[0102] In this embodiment, the system applies digital filtering algorithms (such as low-pass filtering) to the acquired raw curves to remove high-frequency noise. Time alignment eliminates phase deviations caused by acquisition delays. Amplitudes are normalized to ensure comparability between different probes. This preprocessed curve retains the true operational characteristics while significantly reducing the impact of irrelevant noise on subsequent analysis.
[0103] Step 1014 : Bind the pre-processed power consumption curve, current curve, and electromagnetic radiation curve with the corresponding ciphertext and plaintext and store them as a sample data set.
[0104] In this embodiment, the system creates a unique identifier for each decryption operation and stores preprocessed power consumption, current, and electromagnetic radiation profiles in association with the corresponding ciphertext and plaintext. Data is indexed by timestamp or event number and stored in a database or binary file format, ensuring fast retrieval and batch processing. Metadata (such as sampling rate and probe type) is fully preserved during storage, providing a comprehensive data foundation for side-channel attacks.
[0105] This embodiment of the application generates a high-quality sampled dataset through multi-dimensional physical signal acquisition, rigorous input and output recording, noise elimination, and structured storage. This dataset accurately reflects the physical characteristics of the Aigis-enc algorithm in hardware implementation, providing reliable data support for subsequent intermediate value calculation, correlation analysis, and private key recovery, a prerequisite for effective side-channel security detection.
[0106] In some embodiments, the preprocessing method includes at least one of mean filtering, Gaussian filtering, or wavelet denoising.
[0107] In the embodiments of this application, mean filtering is a linear filtering technique in which the system replaces the original pixel value by calculating the average value of the pixels in the neighborhood of the target pixel. This method is primarily used to eliminate random noise and smooth signal curves. The system first sets a sliding window (e.g., 3×3 or 5×5) and iterates over each data point in the side channel curve. For each point, the system calculates the arithmetic mean of all data points in its neighborhood window and uses this average as the new value for the current point. This process effectively suppresses high-frequency noise, but may slightly blur signal details.
[0108] Gaussian filtering is a nonlinear filtering method based on a weighted Gaussian function. The system calculates a weighted average by assigning different weights to neighboring pixels (the closer to the center, the higher the weight). The system predefines a Gaussian kernel (e.g., a standard deviation of σ = 1) and generates a weight matrix based on the Gaussian distribution formula. The system then convolves the weight matrix with the local data points of the side channel curve to produce a smoothed output. Gaussian filtering can better preserve signal edge features while reducing noise.
[0109] Wavelet denoising is a multiscale analysis method based on wavelet transforms. It separates noise by decomposing the signal into frequency bands and thresholding the high-frequency coefficients. The system first performs wavelet decomposition on the side channel curve (e.g., using the Daubechies wavelet basis) to obtain high- and low-frequency coefficients. Next, the system applies hard or soft thresholding (e.g., the Donoho-Johnstone criterion) to the high-frequency coefficients, eliminating noise by setting coefficients below the threshold to zero. Finally, the system uses wavelet reconstruction to generate the denoised signal.
[0110] The embodiments of the present application preprocess the side channel curves through mean filtering, Gaussian filtering, or wavelet noise reduction, which can significantly reduce the interference of environmental noise and hardware noise and improve the accuracy of subsequent CPA analysis. Mean filtering is suitable for fast smoothing, Gaussian filtering balances noise reduction and detail preservation, and wavelet noise reduction excels at processing non-stationary noise. The combination or individual application of these methods provides cleaner input data for key recovery, thereby enhancing the success rate and reliability of side channel attacks.
[0111] In some embodiments, step 105 includes:
[0112] Step 1052 : Calculate the Pearson correlation coefficient between the power consumption curve and the actual power consumption curve in the sampled data set.
[0113] In an embodiment of the present application, the leakage model may be a Hamming model. The Hamming model is a power consumption leakage model used for side-channel analysis. The system simulates the energy consumption characteristics of the chip when performing cryptographic operations based on Hamming weight or Hamming distance. Hamming weight refers to the number of "1"s in binary data, while Hamming distance refers to the number of bit differences between two binary data.
[0114] The system first extracts the intermediate value to be analyzed (such as the register data stored in a polynomial multiplication operation) from the intermediate value set and converts it into binary form. The system then calculates the Hamming weight (the number of "1s") of each intermediate value and generates a corresponding power consumption curve based on this value. For example, if the intermediate value stored in the register is 0x5A (binary 01011010, with a Hamming weight of 4), the system simulates the power consumption characteristics of this value during chip operation, generating a power consumption curve.
[0115] In the embodiments of the present application, the Pearson Correlation Coefficient is a statistical indicator that measures the degree of linear correlation between two curves, and its value range is [-1, 1]. The closer the value is to 1, the stronger the correlation between the two curves; the closer the value is to 0, the less correlation there is; and the closer the value is to -1, the less correlation there is.
[0116] The system compares the power consumption curve generated in step 1051 with the actual power consumption curve in the sampled data set point by point. The specific calculation process is as follows:
[0117] The system calculates the mean of the two curves and removes the mean for each data point. It also calculates the covariance (a measure of whether the two curves are trending in the same direction) and their respective standard deviations. It also calculates the correlation coefficient using the Pearson formula.
[0118] Step 1052: Select the guessed private key corresponding to the maximum value of the Pearson correlation coefficient as the correct private key fragment.
[0119] In an embodiment of the present application, guessed private key is a side-channel attack in which the system generates a power consumption curve by enumerating possible private key values (such as 2^13 or 2^14 possibilities) and calculates its correlation with the actual power consumption curve to infer the actual private key.
[0120] The system iterates through all power consumption curves generated by guessing the private key and records the Pearson correlation coefficient for each curve. The system then selects the private key fragment corresponding to the power consumption curve with the highest correlation coefficient as the correct private key fragment. For example, if the private key is 16 bits, the system might first recover the first 8 bits, then the last 8 bits.
[0121] Step 1053: Repeat the calculation and selection steps until all bytes of the private key are restored using the correct private key fragments.
[0122] In the embodiments of the present application, private key recovery refers to the system gradually recovering the fragments of the private key (such as byte by byte or bit by bit) and finally piecing together the complete private key.
[0123] The system can use a step-by-step recovery strategy, recovering only a portion of the private key (e.g., 2 bytes) at a time. For example, the system first recovers the first 2 bytes of the private key and fixes that portion; the system then continues to perform steps 1031-1033 on the subsequent bytes to recover the remaining portion; the system repeats this process until all private key bytes are recovered, ultimately constructing the complete private key.
[0124] This embodiment of the application establishes a Hamming model to generate a power consumption curve and uses the Pearson correlation coefficient to screen the most likely private key fragments, ultimately recovering the complete private key segment by segment. This method can efficiently and accurately crack the physical implementation of the Aigis-enc algorithm, providing an effective means for side-channel security detection of post-quantum cryptographic algorithms.
[0125] In some embodiments, step 104 includes:
[0126] Step 1041 : Map each of the multiplication results in the intermediate value set into a binary bit sequence, count the number of logic high levels in the binary bit sequence as a Hamming weight, and establish a leakage model based on the Hamming weight.
[0127] Step 1042: Map each of the multiplication results in the intermediate value set into a binary bit sequence, calculate the number of bit flips of the binary bit sequence in adjacent operation cycles as the Hamming distance, and establish a leakage model based on the Hamming distance.
[0128] In the embodiment of the present application, a binary bit sequence refers to converting numerical data into a binary representation consisting of "0" and "1" to facilitate the subsequent calculation of Hamming weight or Hamming distance.
[0129] The system extracts each product result from the set of intermediate values (e.g., values stored in registers) and converts it to a fixed-bit-width binary representation. For example, if the product result is a 32-bit integer, the system represents it as a 32-bit binary sequence. During this conversion, the system ensures that the binary representation of the value conforms to the hardware-implemented storage format (e.g., little-endian or big-endian) to ensure the accuracy of subsequent calculations.
[0130] In the embodiments of this application, a logic high level (Logic High Level) in digital circuits typically corresponds to a binary "1," indicating a high voltage state for the signal. Hamming weight (Hamming Weight) refers to the number of "1s" in a binary sequence and is used to measure data activity, often related to chip power leakage.
[0131] The system iterates over each bit in the binary sequence and counts the number of "1s" within it. For example, for the binary sequence 01011010, the system counts a Hamming weight of 4. This value is used to simulate the energy consumption characteristics of the chip when performing memory or arithmetic operations, because a higher Hamming weight generally indicates higher dynamic power consumption.
[0132] In the present application, a bit flip refers to a change in the state of a bit in binary data from "0" to "1" or from "1" to "0" at adjacent time points. The Hamming distance, which measures the degree of data change, refers to the number of differences in corresponding bits between two binary sequences of equal length.
[0133] The system compares binary bit sequences within adjacent operation cycles (for example, the previous register value and the current value), comparing each bit for differences. For example, if the previous sequence was 01011010 and the current sequence is 11010010, the system counts the number of bits that differ (the first and fifth bits) and obtains a Hamming distance of 2. This value is used to simulate chip power fluctuations caused by data changes and is suitable for dynamic power analysis scenarios.
[0134] In the embodiments of the present application, specifically, if the Hamming weight model is used, the system directly maps the Hamming weight of each intermediate value to a hypothetical power consumption value, forming a power consumption curve. If the Hamming distance model is used, the system calculates the Hamming distance between adjacent intermediate values and maps it to a hypothetical power consumption change to generate a power consumption curve. The system selects an appropriate model for subsequent correlation analysis based on the actual leakage characteristics of the target device (e.g., whether static power consumption or dynamic power consumption dominates).
[0135] This embodiment of the application constructs an accurate power leakage model by converting intermediate values into binary bit sequences and calculating their Hamming weight or Hamming distance. This model effectively simulates the energy consumption characteristics of the chip when executing the Aigis-enc algorithm, providing a reliable power consumption curve for subsequent correlation analysis (such as CPA), improving the accuracy and efficiency of private key recovery, and providing key technical support for side-channel security assessment of post-quantum cryptographic algorithms.
[0136] In some embodiments, the calculation process of the Pearson correlation coefficient uses a parallel acceleration algorithm to reduce the total time for private key recovery.
[0137] In the embodiments of the present application, the parallel acceleration algorithm is a technology that improves processing efficiency by executing multiple computing tasks simultaneously. It uses multi-core processors or distributed computing resources to decompose a task into multiple subtasks for parallel processing, thereby reducing the total computing time.
[0138] When calculating the Pearson correlation coefficient, the system uses a parallel acceleration algorithm to optimize computational efficiency. The specific process is as follows: First, the system divides the power consumption curve to be calculated and the actual power consumption curve data into multiple subsets, each assigned to a different computing core or processing unit. Each processing unit independently calculates the Pearson correlation coefficient for its assigned data subset, generating partial results. The system then aggregates all partial results, using weighted or aggregated operations to obtain the final correlation coefficient value. Through parallel processing, the system significantly reduces computation time, thereby shortening the overall time required to recover private keys.
[0139] In some embodiments, after step 105, the method further includes:
[0140] Step 1061: Compare the private key with the preset private key of the Aigis-enc algorithm to obtain a comparison result.
[0141] In the embodiment of the present application, the preset private key refers to the correct private key used by the Aigis-enc algorithm during normal operation, which is usually generated by the algorithm or pre-stored in a secure environment for encryption and decryption operations.
[0142] After recovering the private key, the system compares it bit-by-bit against the preset private key. First, the system reads the recovered private key data and loads the preset private key as a reference. Then, the system uses a byte-by-byte or bit-by-bit comparison to check the match. If the recovered private key is completely identical to the preset private key, the side-channel attack is successful. If there is a partial or complete mismatch, the attack's accuracy is inaccurate. This step is crucial for verifying the effectiveness of the side-channel attack.
[0143] Step 1062 : If the comparison result indicates that the hardware device has a side channel leakage risk, generate a security assessment report including a leakage risk level and repair suggestions based on the comparison result.
[0144] In this embodiment of the present application, a hardware device refers to the physical medium that runs the Aigis-enc algorithm, such as a cryptographic chip, encryption module, or embedded system. Side-channel leakage risk refers to the potential security risk of a private key being cracked due to the leakage of physical information such as power consumption, electromagnetic radiation, and timing when the hardware device performs cryptographic operations.
[0145] After confirming that the recovered private key matches the preset private key, the system determines that the target hardware device is at risk of side-channel leakage. This determination is based on the following logic: if an attacker can recover the private key through physical leakage of information, then the device's implementation is not effectively protected against side-channel attacks. The system records this determination and marks the hardware device as having a security vulnerability for subsequent security hardening or remediation.
[0146] In the embodiments of this application, the leakage risk level is a quantitative assessment of the severity of the side channel leakage of the hardware device, which is generally divided into three levels: high, medium, and low, based on the accuracy of private key recovery and the difficulty of attack. The remediation suggestions are improvement measures proposed for the discovered side channel leakage risk, which may include optimizing algorithm implementation, increasing noise interference, using masking technology and other protection measures. The security assessment report is a formal document generated by the system, summarizing test results, risk levels and remediation suggestions for reference by developers or security teams.
[0147] After completing the risk assessment, the system automatically generates a safety assessment report. The report contains the following:
[0148] Leakage Risk Level: Based on the success rate of private key recovery and the complexity of the attack, the system assesses and labels the risk level (e.g., high, medium, or low). Remediation Recommendations: Based on the implementation characteristics of the Aigis-enc algorithm, the system provides targeted protection solutions, such as recommending the use of randomized calculations, increasing noise injection, or improving hardware protection measures for NTT operations. Test Data Summary: The system summarizes key test data, such as attack success rates and power consumption curve characteristics, for further analysis. This report is output in a structured format for security teams to use for vulnerability remediation and product optimization.
[0149] This embodiment of the application verifies the effectiveness of the attack by comparing the recovered private key with the preset private key, and accordingly determines the risk of hardware leakage. The resulting security assessment report not only provides a risk level but also provides specific remediation suggestions to help manufacturers optimize the security of their cryptographic implementations.
[0150] In some embodiments, the leakage risk levels are divided according to the proportional relationship between the maximum value of the Pearson correlation coefficient and a preset threshold.
[0151] In an embodiment of the present application, the system first calculates the ratio of the maximum value of the Pearson correlation coefficient to a preset threshold value to obtain a ratio value R. When R ≥ the first threshold value, the system determines that the leakage risk level is high, indicating that the attack curve is highly matched with the actual power consumption curve, and the device is at serious risk of leakage. When the second threshold value ≤ R < the first threshold value, the system determines that the leakage risk level is medium, indicating that the attack curve is partially matched with the actual power consumption curve, and the device is at a risk of leakage that can be exploited. When R < the third threshold value, the system determines that the leakage risk level is low, indicating that the attack curve is less matched with the actual power consumption curve, and the device is more secure under the current attack method. The system records the determined risk level in the security assessment report as a basis for subsequent repair recommendations.
[0152] This application provides a side-channel security detection solution for the Aigis-enc algorithm. It can be integrated into a side-channel security detection platform to test the security of the Aigis-enc algorithm's physical implementation. In practical applications, the Aigis-enc algorithm is typically implemented on specific hardware platforms, forming cryptographic modules, chips, and systems to meet specific information security requirements. These cryptographic modules (chips, or systems) are collectively referred to as cryptographic implementations, and they are all implemented in a specific digital circuit environment. The security of a cryptographic system depends not only on the mathematical security of the Aigis-enc algorithm itself, but also on the physical security of the Aigis-enc algorithm implementation.
[0153] The application scenarios of this application on the product side are as follows Figure 2 As shown. An oscilloscope is used to collect side information leaked by the encryption hardware device during the decryption operation of the Aigis-enc algorithm, such as power consumption fluctuations, electromagnetic radiation changes, and operation time differences. In the embodiment of the present application, the output of the polynomial multiplication operation in the Aigis-enc algorithm is selected as the attack point, and it is mapped to the Hamming weight model, and the CPA analysis method is used to evaluate the security of the algorithm in the encryption hardware device. In the embodiment of the present application, by analyzing the correlation between the side information and the key or sensitive data, the risk of key leakage or sensitive data leakage is detected. The present application innovatively proposes a side channel analysis scheme for the Aigis-enc algorithm, which can restore the private key coefficients of the Aigis-enc algorithm item by item. In actual side channel security detection, if the side information can be successfully used to deduce the key or sensitive data, then the cryptographic implementation is considered to have security risks.
[0154] The goal of a side-channel attack is to recover the private key or sensitive data associated with it. Therefore, the chosen attack point must be related to the private key storage, calculation, or transmission process. For the Aigis-enc algorithm, its decryption process relies on the private key, so the decryption algorithm within the Aigis-enc public key cryptosystem (i.e., the attack point is the private key calculation process) is the focus of detection and analysis. The Aigis-enc algorithm parameter set is shown in Table 1, where the lengths of the public key pk, private key sk, ciphertext c, and session key ss are expressed in bytes. Based on the current state of solving difficult lattice problems and the demand for quantum-resistant key wrapping mechanisms in the coming years, the designers selected three parameter sets for the Aigis-enc key wrapping mechanism: PARAMS I, PARAMS II, and PARAMS III, targeting quantum security strengths of 80, 128, and 192, respectively (corresponding to conservatively estimated classical security strengths of approximately 111, 162, and 235, respectively). PARAMS II and PARAMS III meet the security strength requirement of greater than 128 quantum secure bits, with PARAMS II being the recommended parameter for 128 quantum secure bits. This means that the mathematical and logical security level of the Aigis-enc algorithm varies depending on its parameter configuration. The attack method proposed in this application covers and is applicable to all three parameter sets covered by the algorithm.
[0155] The implementation process of the solution proposed in this application is as follows Figure 6 As shown in the figure, it mainly covers three aspects: side channel curve collection, calculation of intermediate value set and CPA analysis.
[0156] The specific implementation of each link is as follows:
[0157] Step A1, Aigis-enc algorithm curve acquisition
[0158] Aigis-enc algorithm curve collection is the first step in attack detection. It is divided into power consumption curve collection, current curve collection, and electromagnetic curve collection. The collection process requires the use of acquisition probes, oscilloscopes and other hardware equipment. Power consumption curve collection usually connects a small resistor in series with the core power supply or ground terminal of the chip, and uses an active differential probe to collect the voltage difference between the two ends of the resistor, such as Figure 3 As shown in the figure, the current curve acquisition is to use the current probe to collect the current changes at the power supply end during the operation of the chip, such as Figure 4 As shown. Electromagnetic curve collection uses electromagnetic probes to collect electromagnetic radiation during chip operation, such as Figure 5 shown.
[0159] To ensure the effectiveness and accuracy of side-channel attacks against a specific device under test (DUT), an appropriate curve acquisition scheme must be selected based on the device's physical characteristics, leakage patterns, and the specific implementation details of the algorithm. Multiple sets of ciphertext data are generated and sent to the DUT using the characteristics of the Aigis-enc algorithm. An oscilloscope is used to capture the chip's energy consumption during the Aigis-enc algorithm execution. The captured energy consumption data should provide a detailed overview of how the chip's power consumption changes over time during the computation. Furthermore, the communication data corresponding to each plaintext input, such as the input ciphertext and output plaintext, must be recorded for subsequent analysis and comparison. Each time the chip executes the Aigis-enc algorithm decryption operation, a corresponding side-channel curve and communication data are generated. Together, these data constitute the sampled dataset, which serves as the foundation and key for subsequent steps such as intermediate value calculation and key guessing. When constructing the sampled dataset, care must be taken to ensure data diversity and representativeness. By collecting side-channel curves for a large number of different ciphertext inputs, a more comprehensive picture of the DUT's energy consumption characteristics can be captured, thereby increasing the attack's success rate. At the same time, in order to reduce the impact of noise and errors, it may be necessary to perform preprocessing and filtering on the collected side channel curves.
[0160] Step A2: Calculate the intermediate value set
[0161] In side-channel attacks, intermediate values typically refer to intermediate results or states generated during algorithm execution. These intermediate results often correlate with the side-channel curve of the device under test (DUT). Specifically, during the execution of a cryptographic algorithm, the DUT performs a series of operations based on the input data and key, generating a series of intermediate values. These intermediate values may include inputs, outputs, and internal states of encryption and decryption functions. Furthermore, the DUT consumes energy when processing these intermediate values. Therefore, intermediate values serve as a bridge in side-channel attacks. By analyzing the correlation between intermediate values and the side-channel curve, the key can be indirectly inferred, enabling attacks against the DUT.
[0162] The method proposed in this application analyzes the private key operation (attack point) of the Aigis-enc algorithm. During the attack, the intermediate value of the Aigis-enc algorithm needs to be calculated. For each ciphertext input and assumed key, the intermediate value during the decryption process needs to be calculated.
[0163] During the test, the ciphertext c is a known value passed in from the outside, and the guessed intermediate value is calculated by guessing different private keys sk. Figure 7, where sk represents the private key, c represents the ciphertext, and represents the plaintext message; Decode(c) is the decoding function used to decode the ciphertext c; Encode(c) is the encoding function used to encode the ciphertext c. NTT(u) represents the Fourier transform function used to perform the Fourier transform on u.
[0164] In this application, when decrypting, the Aigis-enc algorithm performs a polynomial multiplication on the decoded private key s and the decoded ciphertext u, that is, , at this time the calculation result will be stored in the register, and the intermediate value will be used as the leakage point. Since the Aigis-enc algorithm contains three different parameter sets, in order to improve the wide applicability of the attack scheme, the attack method designed in this application will flexibly adjust the scope of guessing each private key bit according to the specific differences in the various parameter settings in the algorithm. Specifically, for each guess of PARAMS I and PARAMS II bit private key; for each guess of PARAMS III bit's private key.
[0165] The pseudo code of the CPA-based Aigis-enc algorithm side channel attack method in this application is as follows Figure 8 , where PARAMS I represents parameter set 1; PARAMS II represents parameter set 2; PARAMS III represents parameter set 3; Guesslen represents the range of guessed keys; Guess_sk represents the guessed key; LeakageModel represents the leakage model function; Correlation represents the Pearson correlation calculation function; and Maxabs represents the maximum absolute value extraction function. To accelerate computation, the designers of the Aigis-enc algorithm employed the fast number theoretic transform (NTT) and its corresponding inverse number theoretic transform (INTT) to assist in the polynomial multiplication between parameters. NTT is essentially similar to the FFT: it combines the polynomial values in a finite field with specific twiddle factors, then iterates interactively with itself to convert them into a frequency domain representation. The multiplication of the two polynomials, u and s, is then converted to the frequency domain to reduce computational effort and increase speed. In the Aigis-enc algorithm, polynomial multiplication is essentially a point-by-point multiplication of the elements of the two polynomial vectors.
[0166] The specific intermediate value calculation process for the Aigis-enc algorithm is as follows:
[0167] Step P1, refer to Figure 9, where BytesToBit(c) represents a byte-to-bit function that converts byte c into multiple bit values; PARAMS_n-1 represents parameter set n-1. Given that the ciphertext c is a set of 8-bit unsigned integers (bytes), the length of the byte array is nl / 8. The ciphertext is decoded according to the number of bytes in the ciphertext and restored to its original polynomial form, that is, a single polynomial is decompressed from a compressed ciphertext. And the corresponding polynomial vector u (u is the set of elements of polynomial f).
[0168] Step P2, apply the NTT transformation independently to each polynomial in the polynomial vector or matrix, that is, calculate the number-theoretic transformation NTT(u) of u. The calculation method of NTT transformation can refer to Figure 12 The calculation logic of the pseudocode shown, where kk represents the iteration variable; NLOG represents the number of iterations; Montgomery_reduce represents the Montgomery reduction function; Barrett_reduce represents the Barrett reduction function. Specifically, a large prime number p and a primitive root g are selected to convert the polynomial from coefficient representation to point value representation in the modulo p sense, and the power of the primitive root g is used to replace the unit complex root for butterfly operation, and then point-by-point multiplication is performed, and finally the result is converted from point value representation back to coefficient representation through the inverse NTT transformation, thereby realizing fast multiplication of polynomials in the modulo p sense. The designers of the Aigis-enc algorithm optimized the efficiency of the NTT operation by using the Montgomery reduction montgomery_reduce and Barrett reduction barrett_reduce methods. Montgomery reduction uses a pre-calculated Montgomery inverse to quickly reduce the product to the modulo range. For details, refer to Figure 10 The calculation logic of the pseudo code shown here. In the NTT operation here, Montgomery reduction is used to optimize the modular operation of the intermediate result. Barrett reduction speeds up the modular division operation by using a pre-calculated approximate reciprocal. For details, refer to Figure 11 The calculation logic of the pseudo code shown.
[0169] Step P3, for the Aigis-enc algorithm, PARAMS I and PARAMS II need to be increased from 0 to 2. 13 Traverse and guess the private key; for PARAMS III, you need to guess from 0 to 2 14 Traverse the guessed private key. Remember the current guessed private key is guess_sk, and for each guess_sk calculate , and store each guess result in an intermediate value set, where “∘” represents the product operator.
[0170] Step A3, CPA Analysis
[0171] CPA analysis mainly uses the energy differences generated by the device under test when processing different data and operations to infer the key. The CPA analysis steps for the Aigis-enc algorithm in this application are as follows:
[0172] Step (1) Establishing an energy consumption model: Select a leakage model, such as a Hamming weight model or a Hamming distance model, based on the internal structure of the device under test and the working principle of the algorithm. Map the intermediate value set calculated in step (2) to a suitable leakage model based on the actual situation to obtain multiple hypothetical curves.
[0173] Step (2), calculate the correlation coefficient: For each guessed key, calculate the correlation coefficient between the hypothetical curve and the actual power consumption curve. That is, calculate the correlation between the intermediate value set after the energy consumption model is mapped and the collected side channel curve.
[0174] Step (3), correlation coefficient analysis: Analyze the correlation coefficients of all guessed private keys and find the guessed private key corresponding to the maximum correlation coefficient. Based on this analysis, it is assumed that the guessed private key is the correct private key, because the correct private key will make the correlation between the power consumption curve and the real power consumption curve the strongest.
[0175] Step (4), private key recovery: This method can recover 2 bytes of the private key each time, repeating steps (2) and (3) until all private key bytes are recovered.
[0176] Based on the foregoing embodiments, an embodiment of the present application provides a side channel security detection device, which includes the various units included and the various modules included in each unit, and can be implemented by a processor in a computer device; of course, it can also be implemented by a specific logic circuit; in the implementation process, the processor can be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP) or a field programmable gate array (FPGA), etc.
[0177] The actual test results of the steps of a side channel security detection method provided by some embodiments of the present application on a 32-bit ARM development board are as follows: Figure 13As shown, the parameters used in the development board project are the above-mentioned PARAMS II. The experimental results of attacking the first two bytes of the private key of the algorithm are shown in Figure 13. It can be seen from the figure that the actual correct key curve shown in curve 1 and the key recovered by the side channel security detection method provided by curve 2 are highly correlated, that is, the scheme proposed in this application can recover the private key of the Aigis-enc algorithm item by item.
[0178] The side channel security detection method provided in this application is not only applicable to the CPA method, but can also use Differential Power Analysis (DPA), Analysis of Variance (ANOVA), and Signal-to-Noise Ratio (SNR) methods to recover the private key of the algorithm item by item. The specific settings can be based on actual needs and are not limited here.
[0179] Figure 14 A schematic diagram of the structure of a side channel security detection device provided in an embodiment of the present application is shown in FIG. Figure 14 As shown, the side channel security detection device 20 includes: an acquisition module 201 and a detection module 202, wherein:
[0180] The acquisition module 201 is used to acquire the side channel curve data during the execution of the Aigis-enc algorithm to obtain a sample data set;
[0181] The detection module 202 is configured to restore the ciphertext in the sample data set into a polynomial vector; traverse the guessed private key range and the polynomial vector according to the parameter set of the Aigis-enc algorithm to obtain a set of intermediate values of the sample data set; establish a leakage model based on the set of intermediate values, and generate a power consumption curve using the leakage model; and recover the private key of the Aigis-enc algorithm based on a correlation coefficient analysis between the power consumption curve and the sample data set.
[0182] In some embodiments, the detection module 202 is further used to: perform number theory transformation on the polynomial vector to obtain a polynomial represented in the frequency domain; traverse the range of guessed private keys according to the parameter set of the Aigis-enc algorithm, obtain the product result of each guessed private key and the polynomial represented in the frequency domain, and store the product result in an intermediate value set.
[0183] In some embodiments, the detection module 202 is further configured to:
[0184] When the Aigis-enc algorithm adopts the first parameter set or the second parameter set, the guessed private key range of the first number of private key bits is traversed; when the Aigis-enc algorithm adopts the third parameter set, the second number of private key bits is traversed, wherein the second number is greater than the first number; wherein the quantum security strength targeted by the first parameter set is smaller than the quantum security strength targeted by the second parameter set, and the quantum security strength targeted by the second parameter set is smaller than the quantum security strength targeted by the third parameter set.
[0185] In some embodiments, the detection module 202 is further configured to: decode the byte array of the ciphertext in the sample data set into a polynomial represented by coefficients, and reconstruct the polynomial represented by the coefficients into a polynomial vector through an inverse compression algorithm.
[0186] In some embodiments, the detection module 202 is further used to: collect side channel curve data of the Aigis-enc algorithm when the hardware device is running; record the ciphertext input and the plaintext output when the hardware device executes the Aigis-enc algorithm; preprocess the side channel curve data to obtain preprocessed side channel curve data; and bind the preprocessed side channel curve data with the corresponding ciphertext and the plaintext and store them as the sample data set.
[0187] In some embodiments, the preprocessing method includes at least one of the following: mean filtering, Gaussian filtering, and wavelet denoising.
[0188] In some embodiments, the side channel curve data includes at least one of the following: a power consumption curve, a current curve, and an electromagnetic radiation curve.
[0189] In some embodiments, the detection module 202 is further used to: calculate the Pearson correlation coefficient between the power consumption curve and the actual power consumption curve in the sampled data set; select the guessed private key corresponding to the maximum value of the Pearson correlation coefficient as the correct private key fragment; repeat the calculation and selection steps until all bytes of the private key are restored using the obtained correct private key fragment.
[0190] In some embodiments, the detection module 202 is further used to: map each of the multiplication results in the intermediate value set into a binary bit sequence, count the number of logic high levels in the binary bit sequence as a Hamming weight, and establish a leakage model based on the Hamming weight.
[0191] In some embodiments, the detection module 202 is further used to: map each of the product results in the intermediate value set into a binary bit sequence, calculate the number of bit flips of the binary bit sequence in adjacent operation cycles as the Hamming distance, and establish a leakage model based on the Hamming distance.
[0192] In some embodiments, the detection module 202 is further used to: compare the private key with the preset private key of the Aigis-enc algorithm to obtain a comparison result; when the comparison result indicates that the hardware device has a side channel leakage risk, generate a security assessment report including a leakage risk level and repair suggestions based on the comparison result.
[0193] The embodiment of the present application uses the polynomial operation during the execution of the Aigis-enc algorithm as an attack point, maps the correlation characteristics of the private key and the intermediate value reflected by the polynomial vector obtained by converting the sample data set into a leakage model, and recovers the key through analysis based on the leakage model. This enables the detection of side-channel physical attacks during the execution of the Aigis-enc algorithm, allowing users to discover and repair vulnerabilities in the execution process of the Aigis-enc algorithm by analyzing the recovered key during the hardware design phase, thereby improving the overall anti-attack capability of post-quantum cryptographic products.
[0194] The description of the above device embodiment is similar to the description of the above method embodiment and has similar beneficial effects as the method embodiment. In some embodiments, the functions or modules included in the device provided in the embodiments of the present application can be used to perform the methods described in the above method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0195] It should be noted that in the embodiments of the present application, if the side channel security detection method described above is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, or the portion that contributes to the relevant technology, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a magnetic disk, or an optical disk. Thus, the embodiments of the present application are not limited to any specific hardware, software, or firmware, or any combination of hardware, software, and firmware.
[0196] An embodiment of the present application provides a computer device including a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor executes the program, some or all of the steps in the above method are implemented.
[0197] The present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements some or all of the steps in the above method. The computer-readable storage medium may be transient or non-transient.
[0198] An embodiment of the present application provides a computer program, including computer-readable code. When the computer-readable code runs in a computer device, a processor in the computer device executes some or all of the steps for implementing the above method.
[0199] Embodiments of the present application provide a computer program product comprising a non-transitory computer-readable storage medium storing a computer program. When the computer program is read and executed by a computer, it implements some or all of the steps of the above-described method. The computer program product may be implemented in hardware, software, or a combination thereof. In some embodiments, the computer program product is embodied as a computer storage medium. In other embodiments, the computer program product is embodied as a software product, such as a software development kit (SDK).
[0200] It should be noted that the descriptions of the various embodiments above tend to emphasize the differences between the various embodiments, and their similarities or similarities can be referenced to each other. The descriptions of the above device, storage medium, computer program, and computer program product embodiments are similar to the descriptions of the above method embodiments and have similar beneficial effects as the method embodiments. For technical details not disclosed in the embodiments of the device, storage medium, computer program, and computer program product of this application, please refer to the description of the method embodiments of this application for understanding.
[0201] It should be noted that Figure 15 A schematic diagram of a hardware entity of a computer device in an embodiment of the present application is shown in FIG. Figure 15 As shown, the hardware entity of the computer device 700 includes: one or more processors 701, a communication interface 702 and a memory 703, wherein:
[0202] Processor 701 generally controls the overall operation of computer device 700 .
[0203] The communication interface 702 enables the computer device to communicate with other terminals or servers through a network.
[0204] Memory 703 is configured to store instructions and applications executable by processor 701. It can also cache data to be processed or processed by processor 701 and various modules in computer device 700 (e.g., image data, audio data, voice communication data, and video communication data). This can be implemented using flash memory (FLASH) or random access memory (RAM). Data can be transmitted between processor 701, communication interface 702, and memory 703 via bus 704. While only one processor is shown in the figure, each processor 701 includes one or more cores.
[0205] It should be noted that the computer device may include multiple processors 701, and each processor 701 can exchange data with each other through aggregate communication methods such as all-to-all, allgather, or allreduce. The processor 701 may be a central processing unit (CPU), a graphics processing unit (GPU), an embedded neural network processing unit (NPU), a tensor processing unit (TPU), a side-channel security detection unit (DPU), an accelerated processing unit (APU), a floating-point processing unit (FPU), or an application-specific integrated circuit (ASIC). The processor may also be a single-core processor or a multi-core processor. The processor may be a combination of a CPU and a hardware chip. The hardware chip may be an ASIC, a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), an FPGA, a generic array logic (GAL), or any combination thereof. The processor may also be implemented solely using a logic device with built-in processing logic, such as an FPGA or a digital signal processor (DSP).
[0206] Communication interface 702 may be a wired interface or a wireless interface for communicating with other modules or devices. A wired interface may be an Ethernet interface, a local interconnect network (LIN), or the like, while a wireless interface may be a cellular network interface or a wireless local area network interface. In the embodiment of the present application, communication interface 702 may be used to perform operations such as obtaining XXX data sent by other computer devices.
[0207] Memory 703 may be a non-volatile memory, such as read-only memory (ROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Memory 703 may also be a volatile memory, such as random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synclink DRAM (SLDRAM), direct rambus RAM (DRRAM), direct rambus DRAM (DRDRAM), and rambus DRAM.
[0208] The bus 704 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. A bus may be classified into an address bus, a data bus, a control bus, etc.
[0209] In some embodiments, the computer device may further include an input / output interface connected to an input / output device for receiving information input by the user, such as the compression type and mantissa compression level input by the user.
[0210] The specific implementation of various operations performed by the above-mentioned computer device may refer to the specific operations of data compression and data decoding performed by the computer device in the above-mentioned method embodiment.
[0211] It should be understood that "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned steps / processes does not mean the order of execution, and the execution order of each step / process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The above-mentioned serial numbers of the embodiments of the present application are for description only and do not represent the advantages and disadvantages of the embodiments.
[0212] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.
[0213] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of units is merely a logical function division. In actual implementation, there may be other division methods, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical or other forms.
[0214] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units; they may be located in one place or distributed across multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the scheme of this embodiment.
[0215] In addition, all functional units in the embodiments of the present application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the above-mentioned integrated units can be implemented in the form of hardware or in the form of hardware plus software functional units.
[0216] Those skilled in the art will understand that all or part of the steps of the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: mobile storage devices, read-only memories (ROM), magnetic disks or optical disks, and other media that can store program codes.
[0217] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the relevant technology, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.
[0218] The above are only implementation methods of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the protection scope of the present application.
Claims
1. A side channel security detection method, characterized in that: The method comprises: The side channel curve data during the execution of the Aigis-enc algorithm is collected to obtain a sampling data set; Restoring the ciphertext in the sample data set into a polynomial vector; Performing number theory transformation on the polynomial vector to obtain a polynomial represented in the frequency domain; Traversing a range of guessed private keys according to the parameter set of the Aigis-enc algorithm, obtaining a product result of each guessed private key and the polynomial represented in the frequency domain, and storing the product result in an intermediate value set; establishing a leakage model based on the intermediate value set, and generating a power consumption curve through the leakage model; Based on the correlation coefficient analysis between the power consumption curve and the sampled data set, the private key of the Aigis-enc algorithm is recovered.
2. The method according to claim 1, characterized in that The traversal and guessing of the private key range according to the parameter set of the Aigis-enc algorithm includes: When the Aigis-enc algorithm adopts the first parameter set or the second parameter set, traversing a guessed private key range of a first number of private key bits; When the Aigis-enc algorithm adopts a third parameter set, traversing a second number of private key bits, wherein the second number is greater than the first number; The quantum security strength targeted by the first parameter set is smaller than the quantum security strength targeted by the second parameter set, and the quantum security strength targeted by the second parameter set is smaller than the quantum security strength targeted by the third parameter set.
3. The method according to claim 1, characterized in that The restoring the ciphertext in the sample data set into a polynomial vector includes: The byte array of the ciphertext in the sample data set is decoded into a polynomial represented by coefficients, and the polynomial represented by the coefficients is reconstructed into a polynomial vector through an inverse compression algorithm.
4. The method according to claim 1, wherein The side channel curve data during the execution of the Aigis-enc algorithm is collected to obtain a sample data set, including: Collect side channel curve data of the Aigis-enc algorithm when the hardware device is running; Record the ciphertext input and plaintext output when the hardware device executes the Aigis-enc algorithm; Preprocessing the side channel curve data to obtain preprocessed side channel curve data; The preprocessed side channel curve data is bound to the corresponding ciphertext and the plaintext and stored as the sample data set.
5. The method according to claim 1, wherein The recovering the private key of the Aigis-enc algorithm based on the correlation coefficient analysis between the power consumption curve and the sampled data set includes: Calculating a Pearson correlation coefficient between the power consumption curve and a true power consumption curve in the sampled data set; Selecting the guessed private key corresponding to the maximum value of the Pearson correlation coefficient as the correct private key fragment; The calculation and selection steps are repeated until all bytes of the private key are recovered using the obtained correct private key fragment.
6. The method according to claim 5, characterized in that Establishing a leakage model for the intermediate value set includes: Mapping each of the multiplication results in the intermediate value set into a binary bit sequence, counting the number of logic high levels in the binary bit sequence as a Hamming weight, and establishing a leakage model based on the Hamming weight; or, Each of the product results in the intermediate value set is mapped into a binary bit sequence, the number of bit flips of the binary bit sequence in adjacent operation cycles is calculated as the Hamming distance, and a leakage model is established based on the Hamming distance.
7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: Comparing the private key with a preset private key of the Aigis-enc algorithm to obtain a comparison result; In the case where the comparison result indicates that the hardware device has a side channel leakage risk, a security assessment report including a leakage risk level and repair suggestions is generated based on the comparison result.
8. A side channel security detection device, characterized in that: The side channel safety detection device comprises: The acquisition module is used to collect the side channel curve data during the execution of the Aigis-enc algorithm to obtain a sample data set; A detection module is configured to restore the ciphertext in the sampled data set into a polynomial vector; perform number theoretic transformation on the polynomial vector to obtain a polynomial represented in the frequency domain; traverse a range of guessed private keys according to a parameter set of the Aigis-enc algorithm, obtain a product result of each guessed private key and the polynomial represented in the frequency domain, and store the product result in an intermediate value set; establish a leakage model based on the intermediate value set, and generate a power consumption curve using the leakage model; and recover the private key of the Aigis-enc algorithm based on a correlation coefficient analysis between the power consumption curve and the sampled data set.
9. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the side channel security detection method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the side channel security detection method according to any one of claims 1 to 7 are implemented.
11. A computer program product, characterized in that The computer program product includes a non-transitory computer-readable storage medium storing a computer program. When the computer program is read and executed by a computer, the steps of the side channel security detection method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Method and device for determining security of side channel, equipment, chip and storage medium
CN117155540A
Diithium rapid side channel attack analysis method
CN119652565A