Side channel analysis method, device, equipment, storage medium and program product
By predicting the Hamming weight of the Kyber algorithm through a machine learning model and leveraging the mask algebraic properties, a set of candidate values is generated. This solves the data volume and computational complexity issues of high-order analysis in existing technologies, and achieves efficient detection of side channel leaks in the mask-protected Kyber algorithm.
Patent Information
- Application Number
- CN202511024443.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-07-24
AI Technical Summary
When performing side-channel analysis on the masked Kyber algorithm, the existing technology increases the data volume and computational complexity of high-order correlation energy analysis exponentially, and places high demands on the quality of the collected data, making it difficult to conduct efficient security analysis.
A machine learning model is used to predict the Hamming weight of polynomial multiplication operations, and the mask algebra characteristics are used to generate a set of candidate values. By screening the target key coefficients, the side channel vulnerability of the Kyber algorithm is detected, reducing the amount of data and computational complexity.
It improves the accuracy and robustness of detection, reduces the dependence on real labeled data, and improves the efficiency and accuracy of detection.
Smart Images

Figure CN120546853B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to, but is not limited to, the field of data security technology, and in particular to a side channel analysis method, apparatus, device, storage medium, and program product. Background Art
[0002] With the advancement of quantum computing, the security of post-quantum cryptographic algorithms (such as Kyber) has become a research focus. Side-channel analysis (SCA), which extracts secret keys through physical leakage information (such as power consumption and electromagnetic radiation), poses a significant threat to hardware implementations. To mitigate SCA, masking techniques are widely used. Its core approach is to split the secret value into random shares, making the leakage of a single operation independent of the full key. However, high-order masking is complex to implement and may still have potential leakage.
[0003] Related technologies usually use high-order correlation energy analysis to eliminate the mask effect by combining leakage signals at multiple time points. However, the amount of data to be processed and the computational complexity of this analysis method will increase exponentially with the mask order, and the quality requirements of the collected data are high, making it difficult to efficiently analyze the data security of the mask-protected side channel. Summary of the Invention
[0004] In view of this, embodiments of the present application provide at least one side channel analysis method, apparatus, device, storage medium, and program product.
[0005] The technical solution of the embodiment of the present application is implemented as follows:
[0006] On the one hand, an embodiment of the present application provides a side channel analysis method, the method comprising: obtaining a side channel fragment involving a polynomial multiplication operation of a key in masked Kyber algorithm side channel data, and inputting the side channel fragment into a Hamming weight classification model to obtain a Hamming weight prediction value of the output result of the polynomial multiplication operation; based on the Hamming weight prediction value, generating a set of candidate values involving different mask shares of the same key coefficient; screening a target key coefficient from the candidate value set; when the target key coefficient successfully matches the real key, the masked Kyber algorithm implementation has a side channel vulnerability in which the key is stolen.
[0007] On the other hand, an embodiment of the present application provides a side channel analysis device, the device comprising:
[0008] A prediction module is configured to obtain side channel segments of the masked Kyber algorithm side channel data that involve polynomial multiplication operations with a key, and input the side channel segments into a Hamming weight classification model to obtain a Hamming weight prediction value for the output of the polynomial multiplication operation, wherein the Hamming weight classification model is trained using the public phase data of the masked Kyber algorithm side channel data;
[0009] a processing module, configured to generate a set of candidate values for different mask shares related to the same key coefficient based on the Hamming weight prediction value; and select a target key coefficient from the set of candidate values;
[0010] An analysis module is configured to detect, when the target key coefficient successfully matches the real key, that the masked Kyber algorithm implementation has a side channel vulnerability in which the key can be stolen.
[0011] On the other hand, an embodiment of the present application provides a computer device, including a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor executes the program, it implements some or all of the steps in the above-mentioned side channel analysis method.
[0012] On the other hand, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements some or all of the steps in the above-mentioned side channel analysis method.
[0013] On the other hand, an embodiment of the present application provides a computer program, including computer-readable code. When the computer-readable code is executed in a computer device, a processor in the computer device executes some or all of the steps in the side channel analysis method.
[0014] On the other hand, an embodiment of the present application provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and when the computer program is read and executed by a computer, implements some or all of the steps in the above-mentioned side channel analysis method.
[0015] In an embodiment of the present application, the predicted Hamming weight of the collected side channel fragments is obtained by using a Hamming weight classification model pre-trained with public stage data, and the predicted Hamming weight is fused with the mask signal by using the mask algebraic characteristics to generate a candidate set. The key coefficients screened from the candidate set are used to achieve efficient detection of side channel leakage of the mask-protected Kyber algorithm. In this way, the machine learning model and the mask algebraic characteristics are utilized to reduce the data volume and computational complexity of high-order analysis, improve the accuracy of detection, and because the Hamming weight model takes into account the mask characteristics, the model's dependence on real labeled data is avoided, thereby improving the robustness of detection.
[0016] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the technical solutions of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings herein are incorporated into and constitute a part of the specification. These drawings illustrate embodiments consistent with the present application and, together with the specification, are used to illustrate the technical solutions of the present application.
[0018] Figure 1 This is a schematic diagram of the implementation flow of a side channel analysis method according to an embodiment of the present application;
[0019] Figure 2 This is a system architecture diagram of a side channel analysis method according to an embodiment of the present application;
[0020] Figure 3 This is one of the implementation flow diagrams of another side channel analysis method according to an embodiment of the present application;
[0021] Figure 4 This is a second schematic diagram of the implementation flow of another side channel analysis method according to an embodiment of the present application;
[0022] Figure 5 This is the third flowchart of another side channel analysis method according to an embodiment of the present application;
[0023] Figure 6 This is a schematic diagram of the structure of a side channel analysis device according to an embodiment of the present application;
[0024] Figure 7 This is a hardware entity diagram of a computer device according to an embodiment of the present application. DETAILED DESCRIPTION
[0025] In order to make the purpose, technical solutions and advantages of this application clearer, the technical solutions of this application are further elaborated in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0026] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0027] The terms "first / second / third" involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. It is understandable that "first / second / third" can be interchanged with a specific order or sequence where permitted so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing this application only and are not intended to limit this application.
[0029] Masking adds randomness to secret information during execution, eliminating the statistical information generated by a fixed key. During each run, the secret information is split into multiple mask shares, so the value actually participating in subsequent algorithm calculations changes each time, effectively defending against statistical side-channel attacks. Common masking methods, based on how the shares are generated, include arithmetic masking and Boolean masking. Data protected by an N-order mask is divided into N+1 shares. The original key value can only be recovered if all N+1 secret values are obtained simultaneously.
[0030] For arithmetic masking, shares are restored to their original values through addition, i.e., x = x_1 + ... + x_n. Values with arithmetic masks are convenient for linear calculations such as addition, subtraction, and multiplication. In Kyber's masking scheme, polynomial multiplication is typically protected by arithmetic masking. That is, for a single key coefficient value s, a mask protection s = s_1 + s_2 is added to each operation, and the actual calculation is the value of two shares s_1 and s_2. This effectively protects against side-channel attacks of the same order and below.
[0031] Traditional side channel analysis methods (such as DPA and CPA): These are classic side channel attack methods that statistically analyze the correlation between a large number of side channel traces and assumed intermediate values (usually based on key assumptions) to recover the key. To implement mask protection, higher-order side channel analysis (HO-SCA), such as second-order or higher-order CPA, is required. By combining side channel information at different time points or different computation processes, it can eliminate the influence of the mask and recover the key or intermediate value.
[0032] Implementation: Collect a large number of power consumption or electromagnetic traces. For each key hypothesis, calculate a mask-independent predicted value (e.g., by combining different shares of the hypothesis values). Then, calculate the correlation between the predicted value and the actual side channel signal (or a combination of them). Select the key hypothesis with the highest correlation.
[0033] Machine Learning-Based Side Channel Analysis (ML-SCA): In recent years, machine learning (especially deep learning, such as MLP and CNN) has been widely used in side channel analysis. The basic idea is:
[0034] Profiling: Using a fully controllable device (with known secret keys) that is identical or similar to the target device, side channel data is collected and the corresponding true intermediate value (or its Hamming weight, bit position, etc.) is calculated. This data (side channel fragments, labels) is used to train a machine learning model to predict a certain attribute of the intermediate value based on the side channel fragments.
[0035] Attack phase: Side-channel data is collected on the target device and fed into a trained model to obtain the model's predictions for unknown intermediate attributes. These predictions are then used to recover the key, typically by predicting and analyzing the output of a single basic operation.
[0036] Application to Masking: ML-SCA has also been used to attack masking implementations. A common approach is to train a model to predict the Hamming weight of a single share, or the Hamming weight of an intermediate value after masking (if there is a first-order leakage point), or to directly try to distinguish side channel patterns under different key assumptions.
[0037] The above prior art, when applied to detecting mask-protected Kyber implementations (especially polynomial multiplication), suffers from the following drawbacks:
[0038] High Cost (Traditional HO-SCA): The data volume and computational complexity required for traditional high-order attacks (such as HO-CPA) increase exponentially with the mask order. Furthermore, precise selection of combination points is required, placing high demands on signal alignment.
[0039] This application addresses the following issues: This application utilizes an ML model that can better handle noise and capture complex leakage patterns. This model may require fewer traces or have slightly lower signal quality requirements than traditional HO-SCA. More importantly, this application does not rely on the traditional HO-SCA combination approach, but instead utilizes multi-share information through prediction and subsequent logical inference.
[0040] Difficulty obtaining labels for ML-SCA training (for masked key operations): When training an ML model, ideally, one needs to know the true intermediate value labels corresponding to the side channel fragments. However, for operations involving secret keys under masked protection, the true intermediate values (the values of individual shares or combined values) are often difficult to obtain or calculate directly unless the secret key is known or specific first-order leakage exists. This makes it difficult to directly train high-precision models for the target key operations.
[0041] This application solves the problem of obtaining training labels directly on the target key operation. It trains the model on public information operations (NTT of ciphertext u), where intermediate values are known and labels are easily accessible. This trained model is then transferred and applied to side-channel analysis of the target key operation (polynomial multiplication), assuming that the leakage characteristics of similar operations share certain commonalities. This significantly reduces the feasibility threshold for model training.
[0042] Attacks based on traditional templates or machine learning models typically require high classification accuracy and have poor error tolerance: Machine learning-based profiling attacks (such as template attacks) typically rely on the model to accurately classify side channel fragments (for example, accurately predicting the Hamming weight). The success of such attacks often requires very high classification accuracy. A single misclassification of a key position can cause the screening of key candidates to fail, rendering the entire key recovery process ineffective. The attack process is highly sensitive to the "hard decision" results (i.e., the most likely classification) predicted by the model.
[0043] This application solves the following problem: The method proposed in this application has a higher error tolerance. First, due to the use of mask characteristics for cross-share information fusion (as described in point 3), even if there are errors in the Hamming weight predictions of some basic operations, as long as most of the predictions are correct or close to correct, by statistically accumulating multiple calculation results involving the same key coefficient, the correct key value still has a high probability of standing out in the final score / count. The impact of incorrect predictions is statistically diluted. Secondly, the method of this application is not limited to counting using hard-decision classification results. The classification probability output of the machine learning model (i.e., the model's confidence in each possible Hamming weight) can be converted into probability-based scoring (Scoring).
[0044] For example, the expected score or weighted count of each key candidate value is calculated based on the predicted Hamming weight probability distribution. This soft decision approach can more fully utilize the model output information, accumulating advantages for the correct key hypothesis even when the classification confidence is low or there is ambiguity, further enhancing the method's robustness to model prediction errors.
[0045] This application proposes a side channel analysis method based on machine learning to detect potential leakage of multiplication operations in masked Kyber algorithm implementations.
[0046] The core of this method is to first use the calculation process of known intermediate values (such as the multiplication when performing the NTT transformation on the ciphertext polynomial vector u) and its corresponding side channel information to train a machine learning classification model that can predict the Hamming weight of the multiplication result based on the side channel data; then, apply this model to the polynomial multiplication operations involving secret keys in Kyber decapsulation, and predict the Hamming weights of these key multiplication (masked share operations) results based on the collected side channel data; then, combine the predicted Hamming weight information, known ciphertext information, and the algebraic properties of arithmetic masks (or similar masking schemes) to infer and screen candidate key values by combinatorially analyzing different masked share information involving the same key coefficients: finally, by evaluating whether the key coefficients can be successfully recovered using this method, it is determined whether the tested hardware implementation has the detected multiplication operation side channel leakage.
[0047] This application provides a concrete, attack-based verification approach for evaluating the effectiveness of mask protection.
[0048] The present invention provides a side channel analysis method that can be executed by a processor of a computer device. The computer device may include a server, laptop, tablet, desktop computer, smart TV, set-top box, mobile device (e.g., mobile phone, portable video player, personal digital assistant, dedicated messaging device, portable gaming device), or other device capable of side channel analysis. Figure 1 This is a schematic diagram of the implementation flow of a side channel analysis method according to an embodiment of the present application, as shown in FIG. Figure 1 As shown, the method includes:
[0049] Step 101: Obtain a side channel segment of a polynomial multiplication operation involving a key from the masked Kyber algorithm side channel data, and input the side channel segment into a Hamming weight classification model to obtain a Hamming weight prediction value of the output result of the polynomial multiplication operation, wherein the Hamming weight classification model is trained using the public phase data of the masked Kyber algorithm side channel data.
[0050] In the embodiments of this application, the Kyber algorithm is a lattice-theory-based encryption algorithm used to implement a post-quantum secure key encapsulation mechanism. Side-channel data is physical information leaked by the device under test when performing cryptographic operations, such as power consumption and electromagnetic radiation. Polynomial multiplication is the core operation in the Kyber algorithm, involving multiplication of polynomial coefficients. The Hamming weight classification model is a machine learning model used to predict the Hamming weight of data (i.e., the number of 1s in a binary system). The public phase is the operation phase in the encryption and decryption process that does not involve secret keys, and its input and output are both accessible to observers.
[0051] The system collects side channel snippets from the side channel data of the device under test that involve polynomial multiplication of a key. These snippets correspond to individual primitive operations of the polynomial multiplication (e.g., multiplication of a coefficient). The system feeds these snippets into a pre-trained Hamming weight classification model. Based on the snippet features, the model predicts the Hamming weight of the corresponding multiplication output and outputs the predicted Hamming weight. This Hamming weight classification model is trained on publicly available masked Kyber algorithm side channel data, without relying on the corresponding real intermediate data in the Kyber algorithm side channel data as labels.
[0052] Step 102: Generate a set of candidate values for different mask shares related to the same key coefficient based on the Hamming weight prediction value.
[0053] In this embodiment of the present application, the Hamming weight prediction value is the model's prediction of the number of "1"s in the binary intermediate value. The key coefficient is the individual coefficient value of the private key polynomial. The masked share is the random component obtained by splitting the key coefficient using masking techniques. The candidate value set is a set of possible key coefficient or share values generated based on the constraints.
[0054] Based on the predicted Hamming weights and known ciphertext coefficient information, the system establishes constraint equations for the key coefficients or their mask shares. The system then iterates over all possible key share values, calculates the corresponding intermediate Hamming weights, and selects those that match the predicted values to generate a set of candidate values. This process is repeated for different mask shares involving the same key coefficient, generating multiple sets of candidate values.
[0055] Step 103: Filter out the target key coefficient from the candidate value set.
[0056] In this embodiment of the present application, the system uses the algebraic rules of masking schemes (e.g., additive combinations of arithmetic masks) to combine candidate value sets for different mask shares. Through cross-validation and statistical accumulation, the system calculates a score or count for each key coefficient hypothesis. The system selects the candidate with the highest score as the target key coefficient.
[0057] In step 104, if the target key coefficient successfully matches the real key, the masked Kyber algorithm implementation has a side channel vulnerability that allows the key to be stolen.
[0058] In this embodiment of the present application, the system calculates the success rate of recovering the target key coefficient and compares it to a preset threshold. If the success rate exceeds the threshold, the system determines that a roadway vulnerability exists in the masked Kyber algorithm implementation, and the data leaked by this side channel vulnerability can be used to recover the key coefficient. Otherwise, the system determines that there is no side channel vulnerability that could allow the key to be stolen in the Kyber algorithm implementation. The system generates a report containing the results of this determination.
[0059] The embodiments of the present application utilize a pre-trained classification model to obtain the predicted Hamming weight of the collected side channel data, and utilize the mask algebraic properties to fuse the predicted Hamming weight with the mask signal to generate a candidate set. Based on the key coefficients screened from the candidate set, efficient detection of side channel leaks of the masked Kyber algorithm is achieved. This utilizes machine learning models and mask algebraic properties to reduce the data requirements for high-level analysis and improve the accuracy and robustness of detection.
[0060] In some embodiments of the present application, step 102 includes:
[0061] Step 1021, traverse the key share values corresponding to the Hamming weight prediction values, and screen candidate values that meet the arithmetic addition rule of mask protection.
[0062] In this embodiment of the present application, the Hamming weight prediction value is the machine learning model's prediction of the number of binary "1s" in the intermediate value of the polynomial multiplication operation. The key share value is the random component obtained by splitting the original key coefficients through masking techniques, which is used to protect the key from side-channel attacks. The masked arithmetic addition rule is the mathematical rule used in the masking scheme to recover the original key. For example, in arithmetic masking, the original key is equal to the sum modulo the operation of each share value.
[0063] The system iterates over all possible key share values corresponding to the Hamming weights predicted by the machine learning model. For each candidate key share value, the system calculates the multiplication result of the value with the known ciphertext coefficient and verifies whether the resulting Hamming weight matches the predicted value. Simultaneously, based on the predicted Hamming weight and the known ciphertext coefficient, the system obtains the corresponding candidate key share value for that Hamming weight, forming a preliminary candidate set.
[0064] Step 1022: Combine candidate values of different mask shares according to the arithmetic addition rule, assign a confidence weight to each candidate value based on the probability distribution of the combination result, and obtain a set of candidate values of different mask shares involving the same key coefficient.
[0065] In the embodiment of the present application, the probability distribution of the combination result is that each time a single curve is analyzed, a probability value is obtained for all possible key coefficients. In extreme cases, only the hard classification results of the model are taken (that is, the predicted classification is 1, and the others are 0). If a guessed key coefficient is in the key set after the candidate set in the multi-share is calculated according to the mask rule, the probability of the key coefficient is 1; if it is not in the set, it is 0. For a more general probability-based situation, during the calculation, each set corresponding to the multi-share prediction classification will obtain a set of corresponding key coefficients and their corresponding probabilities. Since there are multiple sets of multi-share prediction classifications, there are repeated elements. At this time, the probability value assigned to each key coefficient is the largest of all corresponding probabilities of the value. The confidence weight is a score assigned to each candidate key coefficient based on the probability distribution, reflecting its credibility.
[0066] The system combines candidate values for different mask shares according to arithmetic addition rules. The system calculates the probability distribution of each combination result, which is determined by the prediction confidence output by the machine learning model. The system calculates a confidence weight for each candidate key coefficient, such as a product or weighted sum based on the predicted probabilities. Ultimately, the system outputs an optimized set of candidate values, each with an accompanying confidence score for subsequent key recovery analysis.
[0067] The embodiment of the present application obtains the predicted Hamming weight of the collected side channel fragments by using a Hamming weight classification model pre-trained with public stage data, and uses the mask algebraic characteristics to fuse the predicted Hamming weight with the mask signal to generate a candidate set. Based on the key coefficients screened from the candidate set, efficient detection of side channel leakage of the mask-protected Kyber algorithm is achieved. In this way, the machine learning model and the mask algebraic characteristics are utilized to reduce the data volume and computational complexity of high-order analysis, improve the accuracy of detection, and because the Hamming weight model takes into account the mask characteristics, the model avoids the dependence of the model on real labeled data, thereby improving the robustness of detection.
[0068] In some embodiments of the present application, step 103 includes:
[0069] Step 1031 : Accumulate and score the candidate values according to the confidence weight corresponding to each candidate value in the candidate value set.
[0070] In this embodiment, the confidence weight is a credibility score assigned by the system to each candidate key value, reflecting the probability that the candidate value is correct. Accumulated scoring is a statistical method used by the system to accumulate scores for candidate values, enhancing the discrimination of correct candidate values through multiple observations.
[0071] The system maintains a scorer for each candidate key value. When processing a new side channel fragment, the system increments the candidate's score based on its corresponding confidence weight. Candidates with higher confidence weights receive larger score increments. The system continuously scores different candidate values for the same key modulus independently, ensuring that the scoring process reflects the overall performance of each candidate across all observations. This cumulative mechanism allows the scores of correct candidates to steadily increase, while the scores of incorrect candidates remain relatively low.
[0072] Step 1032: After processing a predetermined number of side channel segments, select the candidate value with the highest score as the key coefficient.
[0073] In the embodiment of the present application, the preset number of side channel segments is a sample size threshold for statistical analysis set by the system to ensure that the statistical results have sufficient reliability. The candidate value with the highest score is the key coefficient hypothesis with the highest cumulative score among all candidate values.
[0074] After processing a preset number of side channel fragments, the system compares the cumulative scores of all candidate key values. The system selects the candidate with the highest score as the most likely key coefficient. This selection is based on statistical significance, ensuring that the final result is determined only when supported by a sufficient number of observations. By setting a reasonable threshold for the number of side channel fragments, the system strikes a balance between analysis efficiency and result reliability, avoiding premature or late decisions.
[0075] Step 1033: Use the key coefficient that matches the known ciphertext information as the target key coefficient.
[0076] In the embodiment of the present application, the known ciphertext information is public information used in the decryption process that is known to the attacker. The target key coefficient is the correct key polynomial coefficient value finally determined through analysis.
[0077] The system verifies the candidate with the highest score against known ciphertext. It then performs a simulated decryption operation using the candidate to verify its ability to correctly interpret the known ciphertext. Candidates that pass the ciphertext match test are confirmed as the target key coefficients. The system records these verified key coefficients for subsequent full key recovery and leak analysis.
[0078] In some embodiments, when only normal interactive verification is considered, after all keys are completely recovered, legal ciphertext can be generated using known public key information, and then the recovered key can be used for decapsulation, and the validity of the key can be verified based on the decapsulation result.
[0079] This embodiment of the application achieves efficient recovery of masked secret keys through a three-stage process involving confidence-weighted statistical accumulation, a decision-making mechanism based on a preset sample size, and ciphertext verification. The system utilizes statistical methods to enhance the reliability of analysis results and ensures the correctness of the recovered key through multi-stage verification.
[0080] In some embodiments of the present application, before step 104, the method further includes:
[0081] Step 1041: Obtain the matching ratio between the target key coefficient and the real key.
[0082] In this embodiment of the present application, the target key coefficients are the key polynomial coefficients recovered by the system through side-channel analysis. The true key is the correct key value actually used by the device under test. The match ratio is the percentage of the total key coefficients for which the recovered key coefficients match the true key coefficients.
[0083] The system compares the recovered target key coefficients against the known authentic key, item by item. It counts the number of coefficients that match perfectly and calculates that percentage of the total number of coefficients in the key. The system uses an exact matching algorithm to ensure the accuracy of the comparison results, avoiding misjudgments due to approximate values. The calculated matching percentage reflects the overall accuracy of key recovery and provides a quantitative basis for subsequent leak determination.
[0084] Step 1042: When the matching ratio is greater than or equal to a preset threshold, it is determined that the target key coefficient matches the real key successfully.
[0085] In the embodiments of the present application, the preset threshold is a pre-set critical value for determining whether a side channel leak exists, typically determined based on security standards or experimental data. A side channel leak refers to a security vulnerability in which an encryption device leaks key-related information through physical channels such as power consumption and electromagnetic radiation during operation.
[0086] The system compares the calculated match ratio against a preset threshold. If the match ratio is greater than or equal to the threshold, the system determines that the device under test's Kyber algorithm implementation has an exploitable side channel leak. The system records the result of this determination and generates a security alert, while also saving the specific key recovery data for subsequent analysis. This determination is based on statistical significance, ensuring the reliability of the conclusion.
[0087] Step 1043: When the matching ratio is less than the preset threshold, it is determined that the target key coefficient fails to match the real key.
[0088] In this embodiment, when the match ratio is less than a preset threshold, the system performs two determinations: if the match ratio is close to random guessing, then no side channel leak is detected; if the match ratio is slightly higher than random guessing but below the threshold, then a leak is detected but not sufficiently exploitable. The system distinguishes between these two situations and generates corresponding assessment reports, providing a reference for subsequent security improvements.
[0089] This embodiment of the present application achieves an objective assessment of side-channel leaks in masked Kyber implementations by quantifying and analyzing key recovery accuracy. The system employs a threshold comparison mechanism to ensure uniformity in determination criteria, clearly distinguishing between secure and vulnerable implementations. This method provides a quantifiable basis for hardware security assessments and effectively supports the verification of side-channel security in cryptographic devices.
[0090] In some embodiments of the present application, the Hamming weight classification model is obtained by the following steps:
[0091] Step 201: Collect public phase data from the masked Kyber algorithm side channel data.
[0092] In this embodiment, the system controls data acquisition equipment to monitor target devices running the Kyber algorithm. During the algorithm's public phase (e.g., NTT transformation), the system simultaneously records side-channel signals during that phase. The system ensures that the collected side-channel data is strictly aligned with specific computational operations, providing the raw data foundation for subsequent analysis. High-precision sampling equipment is used during the acquisition process to ensure that the signal quality meets the training requirements of machine learning models.
[0093] Step 202: extract side channel segments corresponding to known intermediate values from the public phase data, and obtain the Hamming weight of the known intermediate values as labels.
[0094] In this embodiment of the present application, the system time-aligns and segments the collected public-phase data. Based on the algorithm execution process, the system segments the side-channel data into segments corresponding to basic computational units (e.g., single modular multiplications). The system synchronously calculates the intermediate values corresponding to each computational unit and determines their Hamming weights. The system then establishes a mapping between side-channel segments and Hamming weights, forming a labeled training dataset in preparation for model training.
[0095] Step 203: Use the side channel segments and the labels to train a machine learning model to obtain the Hamming weight classification model.
[0096] In the embodiments of the present application, the machine learning model is a computing model that obtains prediction capabilities through data training, such as a CNN or MLP. The Hamming weight classification model is a specialized classifier that can predict the Hamming weight of the median value based on the side channel features.
[0097] The system inputs the prepared training dataset into the machine learning framework. It configures the model structure and hyperparameters, selecting a network architecture suitable for side-channel analysis (e.g., a hybrid model with convolutional and fully connected layers). The system then performs supervised learning training, optimizing model parameters through backpropagation to minimize the discrepancy between the predicted Hamming weights and the true labels. After training, the system verifies the model's classification accuracy on the test set to ensure reliable predictions, ultimately outputting a trained Hamming weight classification model.
[0098] This embodiment of the present application implements machine learning modeling of encryption device side-channel characteristics by collecting public-stage data, extracting feature labels, and training a prediction model. This method effectively addresses the difficulty of obtaining labels in traditional analysis and provides high-precision Hamming weight prediction capabilities for subsequent key recovery attacks. The systematic training process ensures that the model accurately captures the leakage characteristics of the target device, significantly improving the efficiency and success rate of side-channel analysis.
[0099] In some embodiments of the present application, step 202 includes:
[0100] Step 2021: Collect the side channel traces of the number theory transformation phase of the ciphertext polynomial vector in the public phase data.
[0101] In the embodiments of this application, public-phase data refers to data generated during observable computations that do not involve secret keys during the execution of the Kyber algorithm. The decapsulation process is the core operational flow in the Kyber algorithm where the recipient uses the private key to decrypt the ciphertext. The ciphertext polynomial vector is a polynomial representation of the ciphertext information generated during the encryption process. The number theoretic transformation phase is a key computational phase in the Kyber algorithm that uses number theoretic transformations (NTTs) to perform polynomial multiplication. Side channel traces are continuous records of physical signals generated by cryptographic devices while performing computations, such as power consumption or electromagnetic radiation profiles.
[0102] The system precisely triggers side-channel acquisition devices during the Kyber algorithm's decapsulation operation. The system uses high-sampling equipment to capture complete side-channel traces during the Number Theoretic Transform (NTT) calculation phase of the ciphertext polynomial vector. Hardware synchronization signals ensure that the acquired traces are strictly aligned with the NTT calculation process, while also recording the corresponding algorithm status information and input parameters. Anti-interference measures are implemented during the acquisition process to ensure trace quality, providing a reliable data source for subsequent analysis.
[0103] Step 2022: Segment the side channel trace into side channel segments corresponding to a single modular multiplication operation according to the acquisition unit of the number theoretic transformation node.
[0104] In the embodiment of the present application, the computing unit is the smallest divisible computing unit during the execution of the algorithm.
[0105] A single modular multiplication operation is the fundamental finite field multiplication operation in the NTT transform and constitutes the basic unit of NTT calculation. A side channel segment is a signal segment corresponding to a specific calculation operation extracted from a continuous trace.
[0106] The system analyzes the algorithmic structure of the NTT transform and determines the timing locations of individual modular multiplication operations. Based on the computational steps specified in the algorithm specification, the system precisely segments the continuous side channel traces according to modular multiplication cycles. The system uses signal alignment algorithms such as Dynamic Time Warping (DTW) to ensure that each segment strictly matches the corresponding modular multiplication operation. The segmented side channel segments maintain a fixed length and a unified time alignment reference, forming a standardized feature input sequence.
[0107] Step 2023: Record the output value of the single modular multiplication operation, and use the obtained Hamming weight of the output value as a label of the side channel segment.
[0108] In this embodiment of the present application, the system calculates the theoretical output value of each modular multiplication operation based on the known ciphertext input and NTT algorithm parameters. The system converts the output value into binary representation and counts the number of "1" bits as the Hamming weight. The system then establishes a mapping relationship between side channel segments and corresponding Hamming weight labels, forming structured training data pairs. The system verifies the accuracy of the label calculations, ensuring that each side channel segment is labeled with the correct Hamming weight value, providing a reliable supervision signal for model training.
[0109] The embodiments of the present application provide high-quality supervised learning data for the machine learning model by accurately collecting the side channel traces of the NTT stage, dividing the signal by modular multiplication operation, and calculating the corresponding Hamming weight labels.
[0110] In some embodiments of the present application, step 2021 includes:
[0111] Step 20211, controlling the hardware device under test to load multiple sets of known ciphertexts.
[0112] In an embodiment of the present application, multiple groups of known ciphertexts are predefined sets of encrypted data with public content, which are used as test inputs to trigger specific computing processes of the device under test.
[0113] The control computer sends a load instruction containing multiple sets of known ciphertext data to the hardware device under test. Upon receiving the instruction, the hardware device under test loads the ciphertext data into its memory or registers, completing data initialization. This ensures reproducible input conditions for subsequent computations, providing a benchmark dataset for side-channel analysis.
[0114] Step 20212: trigger the hardware device under test to execute the decapsulation process of the Kyber algorithm.
[0115] In the embodiment of the present application, the decapsulation process is a standardized process for decryption operations in the Kyber algorithm, involving polynomial operations and key processing to generate the original plaintext or verification message.
[0116] The control computer sends an execution instruction to the hardware device under test, triggering it to run the Kyber decapsulation process. Based on the loaded known ciphertext, the hardware device under test performs a series of calculations according to the algorithm specification, including polynomial multiplication, modular reduction, and key participation. This step activates the target operation module, allowing the side-channel acquisition device to synchronously capture the physical signals during the calculation process.
[0117] In step 20213, during the public phase, the hardware device under test collects the Kyber algorithm decapsulation process, calculates the number-theoretic transformation of the ciphertext polynomial vector corresponding to the known ciphertext, and captures the side channel traces through the side channel acquisition device.
[0118] In an embodiment of the present application, when the hardware device under test performs a number-theoretic transformation calculation on a ciphertext polynomial vector, a control computer sends a synchronous acquisition instruction to a side-channel acquisition device. The side-channel acquisition device connects to the device under test via a probe, capturing the physical signals during the calculation in real time and converting them into digitized side-channel trace data. The control computer stores the trace data, ensuring it is precisely aligned with the time of the calculation operation, providing the original signal input for subsequent analysis.
[0119] The embodiments of the present application support the subsequent model prediction of Hamming weight, integration of mask characteristics and leakage detection processes, and ultimately achieve effective evaluation of the security of mask protection hardware.
[0120] In some embodiments of the present application, step 203 includes:
[0121] Step 2031, select convolutional neural network as the architecture to build a machine learning model.
[0122] In an embodiment of the present application, a convolutional neural network is a deep learning model that includes convolution operations, has local perception and weight sharing characteristics, and is suitable for processing time series signal data. The system selects a convolutional neural network as the basic architecture based on the time series characteristics of the side channel signal. The system configuration network includes an input layer, multiple convolution layers, a pooling layer, and a fully connected layer. The convolution layer design uses a one-dimensional convolution kernel, which is specifically designed to process time series side channel data. The system sets appropriate convolution kernel size and step size parameters to ensure that the network can effectively extract local features and global patterns in the side channel segments. The network output layer uses a softmax activation function, which corresponds to the classification task of Hamming weight.
[0123] Step 2032: Use the side channel segment as an input feature vector and the Hamming weight as an output label to construct a training dataset.
[0124] In the present embodiment, the input feature vector is a numerical representation of data that has been preprocessed and can be directly processed by the model. The output label is the correct answer or target value corresponding to the sample in supervised learning. The training dataset is the collection of labeled samples used for model training.
[0125] The system normalizes the preprocessed side channel segments and converts them into fixed-dimensional feature vectors. Each feature vector is paired with a corresponding Hamming weight label to construct a structured dataset. The dataset is partitioned into training and validation sets according to a preset ratio. The feature vectors are normalized to ensure consistent numerical ranges across dimensions. The dataset construction process includes integrity checks to ensure that each sample has the correct feature-label mapping.
[0126] Step 2033: Use the training data set to train the machine learning model, where the machine learning model is constructed by selecting a convolutional neural network as the architecture.
[0127] In this embodiment of the present application, the system inputs a prepared training dataset into a convolutional neural network. The system initializes the model parameters and sets training parameters including the learning rate, batch size, and number of training rounds. The system uses a mini-batch gradient descent strategy to feed the training data into the network in batches. The system calculates forward propagation results on each batch of data, providing a foundation for subsequent backpropagation. The system monitors key indicators during training to ensure stable training.
[0128] Step 2034: Obtain a cross entropy loss value between the predicted Hamming weight and the label.
[0129] In the embodiment of the present application, the cross entropy loss value is a metric that measures the difference between the model's predicted probability distribution and the true distribution. After the system completes the forward propagation of each batch of data, it calculates the cross entropy loss between the model's predicted results and the true labels. The system models the Hamming weight classification problem as a multi-class classification task and uses classification cross entropy as the loss function. The system calculates the difference between the predicted probability distribution and the true one-hot encoded label. The loss value calculation process includes numerical stability processing to prevent calculation overflow problems. The system records the loss value of each training step to monitor the training convergence.
[0130] Step 2035: Optimize the parameters of the machine learning model using a back-propagation algorithm until the cross-entropy loss value is minimized to obtain a Hamming weight classification model.
[0131] In the implementation of this application, the backpropagation algorithm is an optimization method that calculates gradients and updates model parameters using the chain rule. The Hamming weight classification model is a specialized model that is trained to predict Hamming weights based on side channel fragments.
[0132] After calculating the loss value, the system executes a backpropagation algorithm to calculate the gradients of the parameters at each layer. The system uses an optimizer (such as Adam) to update the network weight parameters based on the gradients. The system repeats the forward propagation, loss calculation, and backpropagation process until the loss function converges to a stable level. The system regularly evaluates model performance on a validation set to prevent overfitting. After training is complete, the system saves the optimal model parameters to obtain the final Hamming weight classification model.
[0133] The embodiments of this application effectively capture key features of side channel signals through convolutional neural networks and use supervised learning mechanisms to establish a mapping relationship between signal patterns and Hamming weights. The systematic training process and optimization strategy ensure the accuracy and generalization ability of the model, providing a reliable prediction tool for subsequent side channel analysis. In addition, the standardized model development process ensures the repeatability and verifiability of the results.
[0134] This embodiment of the present application utilizes an ML model, which can better handle noise and capture complex leakage patterns. This model may require fewer traces or have slightly lower signal quality requirements than traditional HO-SCA. More importantly, this embodiment of the present application does not rely on the traditional HO-SCA combination method, but instead utilizes multi-share information through prediction and subsequent logical deduction.
[0135] In related technologies, obtaining labels for ML-SCA training (for masked key operations) is difficult: ideally, when training an ML model, it's necessary to know the true intermediate value labels corresponding to the side channel fragments. However, for operations involving secret keys under mask protection, the true intermediate values (the values of individual shares or combined values) are often difficult to directly obtain or calculate unless the secret key is known or specific first-order leakage exists. This makes it difficult to directly train high-precision models for the target secret key operations.
[0136] This embodiment cleverly circumvents the difficulty of obtaining training labels directly on the target key operation. In the technical solution of this embodiment, the model is first trained on public information operations (NTT of ciphertext u). The intermediate values at this stage are known, and the labels are easily obtained. This trained model is then transferred and applied to side-channel analysis of the target key operation (polynomial multiplication), assuming that the leakage characteristics of similar operations have certain commonalities. This significantly reduces the feasibility threshold of model training.
[0137] In related technologies, attacks based on traditional templates or machine learning models typically require high classification accuracy and have poor error tolerance. Machine learning-based profiling attacks (such as template attacks) typically rely on the model to accurately classify side channel fragments (for example, accurately predicting the Hamming weight). The success of such attacks often requires very high classification accuracy. A misclassification of a single key position can cause the key candidate screening to fail, ultimately crippling the entire key recovery process. The attack process is highly sensitive to the "hard decision" results (i.e., the most likely classification) predicted by the model.
[0138] The side channel analysis method proposed in the embodiments of this application has a higher error tolerance. First, because it utilizes the masking feature to fuse information across shares, even if the Hamming weight predictions of some basic operations are incorrect, as long as the majority of predictions are correct or nearly correct, the correct key value still has a high probability of standing out in the final score / count by statistically accumulating the results of multiple calculations involving the same key coefficient. This statistically dilutes the impact of incorrect predictions. Second, the side channel analysis method in the embodiments of this application is not limited to counting using hard-decision classification results. The classification probability output of the machine learning model (i.e., the model's confidence in each possible Hamming weight) can be converted into a probability-based score. For example, the expected score or weighted count of each key candidate value can be calculated based on the predicted Hamming weight probability distribution. This soft decision approach can more fully utilize the model output information, accumulating advantages for the correct key hypothesis even when the classification confidence is low or there is ambiguity, further enhancing the method's robustness to model prediction errors.
[0139] The embodiments of this application propose a side-channel analysis method. This application is not a standalone hardware product, but rather a technical solution, primarily in the form of a software tool or integrated module, for use in specific security assessment and testing scenarios. The product embodiment of this application can be implemented as a side-channel security assessment software tool or as a functional module within an existing hardware security testing platform (such as a side-channel analysis workstation).
[0140] The main application scenarios of the embodiments of this application include the following categories:
[0141] 1) Verification at the Chip / Hardware Design Stage: Chip design companies or security IP core providers, when designing and implementing hardware modules (such as security processors, cryptographic coprocessors, and FPGA implementations) that utilize masked Kyber algorithms, should use this application to conduct early side-channel security assessments to identify and address potential vulnerabilities and reduce subsequent remediation costs.
[0142] 2) Third-party security assessment and certification: Independent security assessment laboratories (e.g., FIPS and Common Criteria certified laboratories) use this application as part of their assessment toolset to conduct side-channel vulnerability analysis on hardware products (e.g., smart cards, HSMs, secure elements) that include Kyber implementations, to assess whether they meet the required security level.
[0143] 3) Pre-production Quality Assurance (QA): Hardware manufacturers use this application to perform rapid side-channel scanning before mass production or during random inspections of their products (e.g., SoCs with Kyber integrated) to ensure that the produced batches meet the expected security standards.
[0144] 4) Academic Research and Teaching: Universities or research institutions may use this application as a research tool to analyze side-channel characteristics under different masking schemes and hardware architectures, or for security teaching demonstrations.
[0145] Implementing the side channel analysis methods of some embodiments of the present application generally requires the following hardware and software environments, including:
[0146] The hardware environment includes the device under test (DUT), side-channel acquisition equipment, probes, signal amplifiers (if required), a control computer, and synchronization trigger equipment. The DUT is the hardware used to implement the mask-protected Kyber algorithm, such as an FPGA development board, ASIC chip, smart card, or embedded device. The side-channel acquisition equipment is used to acquire side-channel signals during DUT operation, such as a high-bandwidth oscilloscope or a dedicated data acquisition (DAQ) card. Appropriate probes are also required (such as current probes / differential probes and low-resistance sampling resistors for power consumption analysis, or near-field / far-field EM probes for electromagnetic analysis). The control computer is used to send instructions to the DUT (such as executing Kyber decapsulation), control the acquisition equipment, store acquired data, and run the analysis software described in this application. The synchronization trigger ensures that side-channel acquisition is precisely synchronized with specific computational operations on the DUT (such as the start of NTT or polynomial multiplication).
[0147] The software environment includes the DUT control program, data acquisition control software, and the core analysis software / modules of this application, including:
[0148] DUT control program: used to communicate with the DUT, send specified ciphertext input, and trigger the target computing process.
[0149] Data acquisition control software: controls the oscilloscope / DAQ card to acquire data, set parameters, and save waveform data.
[0150] The core analysis software / module of this application: This is the key part of implementing the method of this application. Its functions include data preprocessing module, model training module, prediction and analysis module, and result determination and reporting module, among which:
[0151] The data preprocessing module performs filtering, alignment, and segmentation (slicing) on the collected raw side channel traces. The model training module loads the side channel segments and corresponding intermediate values (or their HW) from the NTT phase, selects and trains a machine learning model. The prediction and analysis module loads the side channel segments from the polynomial multiplication phase, uses the trained model to predict HW, generates and fuses key candidate sets based on the prediction results and masking rules, and performs scoring / counting. The result determination and reporting module outputs a leak determination conclusion ("target leak detected" / "target leak not detected") based on the results of the key recovery attempt, and may provide detailed information such as the confidence level and the recovered key coefficient (if successful). Data includes the following three categories: the first category is the known ciphertext set used for training and attack; the second category is the collected side channel trace data files; and the third category is the known intermediate values or their attributes (such as HW) calculated by the NTT.
[0152] By deploying and running the software tools / modules of this application in the above environment, the following functions and effects can be achieved: 1) Automated detection: Automated completion of the process from data collection (some of which require manual setup), model training, attack analysis to result determination; 2) Targeted evaluation: Accurately detect side channel leaks in the key link of Kyber polynomial multiplication under mask protection; 3) Enhanced detection capabilities: By utilizing the fusion of machine learning and mask features, leaks that are difficult to detect with traditional methods or that require more data to detect may be detected; 4) Clear risk indication: Using the success or failure of key recovery as the determination standard, it directly indicates whether the hardware implementation has side channel risks that can be actually exploited; 5) Design / evaluation guidance: The detection results can be fed back to designers for improving hardware implementations or serve as an important basis for security assessment / certification.
[0153] The embodiments of the present application propose a side channel analysis method. The core of the method is to use a machine learning model to predict the properties (such as Hamming weight) of the intermediate values of the Kyber polynomial multiplication operation under mask protection, and combine the algebraic properties of the masking scheme to fuse information from different calculation instances (involving different shares of the same key coefficient) to improve the efficiency and accuracy of key recovery attempts and ultimately determine whether a leak exists.
[0154] The hardware environment and system architecture involved in the embodiments of this application are explained below:
[0155] The implementation of this application relies on a standard side channel analysis hardware environment, the system architecture of which is as follows: Figure 2, the architecture includes the device under test (DUT) A1, the side channel acquisition system A2 and the control computer A3, where:
[0156] Device Under Test (DUT) A1: A hardware device used to implement the Kyber algorithm with mask protection, such as an ASIC, FPGA, or embedded system containing a secure element.
[0157] Side-channel acquisition system A2: This system is used to capture side-channel signals generated during DUT operation. It includes a high-bandwidth oscilloscope or data acquisition (DAQ) card, probes suitable for the target signal (such as current probes and EM probes), a signal amplifier, and filters.
[0158] Control Computer A3: Used to run the DUT control program, send instructions (such as performing decapsulation) and input data (known ciphertext) to the DUT; also used to run the data acquisition control software, configure acquisition parameters and store acquired side channel traces; and used to run the core analysis software module of this application to perform data processing, model training, predictive analysis and leakage determination.
[0159] The implementation logic and data processing flow of the embodiment of the present application are explained below:
[0160] Step 1: Profiling Phase:
[0161] Input and Operation: On the Kyber hardware implementation under test, the Kyber decapsulation algorithm is executed using one or more known ciphertexts as input.
[0162] Data Collection: During the decapsulation process, when performing a Number Theoretic Transform (NTT) on the public ciphertext polynomial vector u, the side channel information generated by this process (e.g., power consumption curves, electromagnetic radiation signals, etc.) is collected simultaneously. Furthermore, the known intermediate calculation results (e.g., the output value of the NTT butterfly operation) that precisely correspond to the collected side channel information during the NTT calculation process are recorded or calculated.
[0163] Data segmentation and labeling: Split the continuous side channel information into computational units (e.g., corresponding to single modular multiplications or basic operations in NTT) to generate side channel trace segments. Calculate the Hamming weight (HW) or other selected leakage-sensitive attributes (such as bit values) for each segment corresponding to a known intermediate value. Develop the side channel segments as feature vectors (Features) for machine learning, and use the corresponding Hamming weights (or other attributes) as labels (Labels).
[0164] Step 2: Machine Learning Model Training:
[0165] The training of machine learning models includes two sub-steps: model selection and model training.
[0166] Model selection: Based on the side channel signal characteristics and prediction objectives, select an appropriate machine learning model, such as support vector machine (SVM), multilayer perceptron (MLP), convolutional neural network (CNN), or other deep learning models.
[0167] Model training: Using the feature and labeled dataset, the selected machine learning model is trained. The goal is to enable the model to accurately classify or predict the Hamming weight (or other selected attribute) of the corresponding basic operation results based on the input side channel fragments.
[0168] Step 3: Target attack data collection and prediction (Exploitation / Detection Phase):
[0169] Input and Operation: Also on the hardware implementation under test, the Kyber decapsulation algorithm is executed using the known (or sometimes unknown, depending on the attack model) ciphertext as input.
[0170] Data Collection: Focus on collecting side channel information when performing polynomial multiplication involving keys during the decapsulation process (for example, calculating sk_u or sk_v, where sk is the private key polynomial).
[0171] Data Segmentation and Prediction: The collected side channel information from the polynomial multiplication process is segmented into corresponding individual basic multiplication operations (e.g., multiplication of a single coefficient). These segmented side channel fragments are fed into a trained machine learning model to obtain the model's predicted Hamming weight (or other attributes) for each basic multiplication output (i.e., key coefficient share, ciphertext coefficient share, or intermediate value after masking).
[0172] Step 4: Key Recovery Attempt Leveraging Maskingroperties:
[0173] Single-multiplication candidate set generation: For a single basic operation in polynomial multiplication (involving the multiplication of a share s_i,j of a key coefficient s_i by a share c_k,1 of a known ciphertext coefficient c_k, or similar operations), based on the known ciphertext coefficient information (the value of c_k is usually known) and the Hamming weight (or other properties) of the output of the operation predicted in step 3, a constraint equation or condition can be established regarding the key coefficient share involved in the operation: s_i,j or the key coefficient s_i itself (depending on the specific attack point and model prediction target). Solving this constraint yields a set of candidate values for the key coefficient (or its share).
[0174] Cross-share information fusion and candidate set refinement: Using Kyber to implement the algebraic structure of the arithmetic masking scheme used. Identify the coefficients of the same original key that occur at different computation times or locations.
[0175] Multiple basic operations are performed on different shares of si (e.g., s_i, 1, s_i, 2, ...). The candidate sets of key coefficients (or their shares) generated by these operations are combined and cross-validated according to the mask combination rules (e.g., s_i = s_i, 1 + s_i, 2, ... mod q in arithmetic masking). For example, if candidate sets of s_1, 1 and s_1, 2 are obtained respectively, a more accurate candidate set of s_i can be derived using s_i = s_i, 1 + s_1, 2 mod q, or a hypothesized value of s_i can be verified.
[0176] Candidate key coefficient scoring / accumulation: A counter or score is maintained for each possible key coefficient value s_i. For each candidate set derived using the prediction results, the counter or score is incremented for each possible s_i value included in the set. Theoretically, if the model prediction is sufficiently accurate, the correct key coefficient value s_i will fall into the candidate set (or fall into it with high probability) in each relevant calculation, resulting in its cumulative count or score being significantly higher than the error value.
[0177] Key coefficient recovery: After processing a sufficient number of side channel fragments (corresponding to a sufficient number of basic multiplication operations), for each key coefficient s_i, the candidate value with the highest cumulative count or score is selected as the recovered key coefficient value.
[0178] Step 5: Side channel leakage determination:
[0179] Evaluate the recovery results: Check all (or some) key coefficients that were attempted to be recovered. Evaluate the success rate of the recovery, for example, the number of coefficients successfully recovered, the confidence level of the recovered value (difference from the next highest count), etc.
[0180] The determination process is as follows: If all or most of the key coefficients can be successfully recovered, or the recovery success rate is significantly higher than random guessing (for example, determined by statistical tests), then it is determined that the hardware implementation under test has the side channel leakage targeted by this application in its polynomial multiplication calculation link; if: the key cannot be recovered, or the recovery result is not significantly different from random guessing, then it is determined that the hardware implementation under test has not detected (or has sufficient resistance to) the specific side channel leakage path targeted by this application.
[0181] The detailed process of the embodiment of this application is as follows:
[0182] Phase 1: Reference Figure 3 , Model Training (Profiling Phase)
[0183] Step S1, data preparation: input a set of known ciphertext c.
[0184] In step S2, the Kyber decapsulation operation is performed on the DUT to calculate the public ciphertext.
[0185] In step S3, during the NTT transformation of the polynomial u, the side channel trace T_NTT of the NTT(u) phase is synchronously collected.
[0186] Step S4, intermediate value acquisition: Since u is public, all intermediate values IV (eg, outputs of butterfly operations) in its NTT calculation process can be accurately calculated or recorded.
[0187] Step S5, preprocessing: perform necessary preprocessing on the collected T_NTT, such as filtering and noise reduction, trace alignment using a reference signal or pattern matching, and then divide it into fragments T_NTT according to the calculation unit (such as single modular multiplication).
[0188] Step S6, label generation: Calculate the Hamming weight HW_IV of each intermediate value IV as the label l of the corresponding side channel segment T_NTT.
[0189] Step S7, model training: Use the preprocessed side channel segment T_NTT as a feature and HW_IV as a label to train a machine learning model M.
[0190] The corresponding input of step S7 is: {(T_NTT_1, 1_1), (T_NTT_2, 1_2), ...};
[0191] Model M, for example, can be a CNN, and consists of an input layer, convolutional / pooling layers, fully connected layers, and an output layer. The input layer receives the side channel segment T_NTT. The convolutional / pooling layers extract time-domain and frequency-domain features. The fully connected layers perform feature combination and classification. The output layer outputs the probability (Softmax) of each possible Hamming weight category or directly predicts the most likely Hamming weight.
[0192] Training process: Use the standard backpropagation algorithm and optimizer (such as Adam) to minimize the loss function (such as cross entropy loss L=-∑l_ilog(p_i), where p_i is the probability predicted by the model as category i and l_i is the one-hot encoding of the true label).
[0193] The output corresponding to step S7 is: the trained model M, which can predict the Hamming weight of the corresponding calculation result based on the input side channel fragment.
[0194] In this embodiment, the model is trained on a public computation (NTT(u)) where labels are easily available, rather than directly training on a difficult target key computation.
[0195] Phase 2: Reference Figure 4 , data preparation and prediction stage:
[0196] Step P1, input a known ciphertext set: use a known ciphertext (either one in the training set or a new one).
[0197] In step P2, Kyber decapsulation is performed on the DUT. The focus is on collecting the side channel trace T_Mul during the polynomial multiplication of the private key sk (e.g., sku or sk v).
[0198] Step P3, collect the side channel traces of the polynomial multiplication stage: perform preprocessing similar to step E on T_Mul, and split it into side channel segments T_mul corresponding to a single basic multiplication operation (for example, s_{i, j}u_{k, l}, where s_(i, j) is the jth share of the key coefficient s_i, and u_{k, l} is the 1st share of the ciphertext coefficient u_k).
[0199] P4, data preprocessing, segmentation T_Mul;
[0200] Step P5, Hamming Weight Prediction (M): Input t-mul into the trained model M to obtain the model's predicted Hamming Weight value HW_pred for the output of the basic multiplication operation (denoted by z). This can be the most likely HW value (hard decision) or a probability distribution P(HW(z) = h | t_mul) (soft decision).
[0201] In step P6, the model M predicts HW_pred and applies a different calculation (polynomial multiplication) than in the training phase, leveraging its generalization ability to predict the attributes of unknown intermediate values.
[0202] Phase 3, reference Figure 5 ,Key recovery and leakage determination phase:
[0203] Step M1, Single Multiplication Constraint: For a single basic multiplication z = s_{i, j}u_{k, l} (or other similar forms, depending on the specific masking scheme and multiplication implementation), the system can establish constraints on the unknown key share s_{i, j} on the word multiplication operation based on the known u_k above (from the input ciphertext) and the predicted HW_pred(z). For example, iterate over all possible s_{i, j} values and calculate z'. If HW(z') = HW _pred(z) (hard decision) or P(HW(z') | tmul) is higher (soft decision), then the s_{i, j} value belongs to the candidate set Cand(s_{i, j}).
[0204] Step M2: using mask rules to fuse cross-share candidate sets;
[0205] Step M2 includes two sub-steps: identification association operation and candidate set fusion, where:
[0206] Identify associated operations: Identify multiple basic operations at different time points or involving different ciphertext coefficients that are ultimately associated with the same original key coefficient 3. For example, operations involving s_{i,1}, s_{i,2}, ..., s_{i,d} (where d is the mask order).
[0207] Candidate set fusion: The candidate sets Cand(s_{i,1}, Cand(s_{i,2}), ... obtained from different share operations are combined according to the algebraic rules of the masking scheme used by the Kyber implementation (usually arithmetic mask s_i=∑s_{i,j}modq or Boolean mask s_i=XORs_{i,j}).
[0208] Example (arithmetic mask, d=2): If Cand(s_{i,1})=a, b} and Cand(s_{i,2})={c,d}, the fused candidate set for s_i can be obtained by calculating {(a+c) mod q, (a+d) mod q, (b+c) mod q, (b+d mod q}, or by using the cross-positive hypothesis for s_i.
[0209] Effect: This step greatly narrows the possible range of s_i, effectively utilizes redundant information distributed in different calculations, and improves the accuracy and efficiency of recovery.
[0210] Step M3, cumulative key coefficient score / count Score(s_i): For each possible key coefficient value, s_i, maintain a score or counter Score(s_i). For each candidate set of s_i obtained after each fusion, increase the score for each candidate value.
[0211] Hard counting: If a certain s_i value is in the fused candidate set, the count is increased by 1.
[0212] Step M4, recovering the key and selecting the highest score s_i_rec: the probability distribution output by the model can be used.
[0213] For example, the increment of Score(s_i) can be some combination (such as product or weighted sum) of the probabilities of all paths (involving predictions of different shares) under the conditions of satisfying the mask rules and the prediction HW. This makes the method less sensitive to single prediction errors.
[0214] Key recovery: After processing a sufficient number of trace segments, for each key coefficient s_i, the candidate value with the highest Score(s_i) is selected as the recovered key coefficient value s_i_rec.
[0215] Step M5: Evaluate the success of key recovery:
[0216] In this embodiment of the present application, step M5 is used to determine leakage (whether key recovery is successful) and evaluate the success rate of key recovery. For example, the success rate of the recovered s_i_rec is compared with the success rate of random guessing, or the recovered s_i_rec is checked to see whether it can correctly decrypt the corresponding ciphertext.
[0217] If the key coefficients can be successfully recovered with a probability significantly higher than random guessing, it is determined that the DUT has a target side channel leakage in the polynomial multiplication link.
[0218] If: the key cannot be effectively recovered, it is determined that the DUT has not detected the target side channel leakage, or the leakage is not severe enough to be exploited by this method.
[0219] Step M6, output leakage assessment report: generate an assessment report including leakage determination results, confidence level, possible recovery key information, etc.
[0220] The embodiments of the present application can achieve the following technical effects: 1) Decoupling the training and attack stages: The model is trained on public calculations where labels are easy to obtain, and then applied to confidential calculations where labels are difficult to obtain, solving the label acquisition problem of ML-SCA in masked scenarios; 2) Cross-share information fusion based on mask algebraic structure: Instead of relying solely on single-point predictions, the inherent connections of the masking scheme are systematically combined to constrain the information about different shares of the same key coefficient obtained at different times / locations, significantly improving the effectiveness of the analysis and robustness to noise / errors; 3) Support for probability-based soft scoring: The confidence information output by the model can be utilized, making the embodiments of the present application more tolerant to individual prediction errors of the ML model, which is superior to traditional template attacks that rely on high-precision hard decisions.
[0221] The machine learning-based masked Kyber side channel detection method proposed in this application has the following advantages over existing technologies in scenarios with medium and low-order masks (e.g., d = 1, 2, 3):
[0222] The embodiments of this application offer enhanced detection capabilities in low- and medium-order masks or specific leakage scenarios: Compared to traditional high-order side channel analysis (HO-SCA) methods, this application utilizes machine learning models to more effectively capture complex leakage patterns. For first- and second-order masks, or even higher-order masks, where implementation flaws such as cross-share operations reduce the leakage dimension, this application may be more sensitive or require less data than traditional methods.
[0223] The embodiments of the present application improve the feasibility and practicality of the method (for specific scenarios): by training the model in the public phase, the difficulty of directly obtaining labels on confidential operations is avoided. This provides a more feasible analysis path when rapid evaluation is required or when it is impossible to fully control the device for analysis, and is particularly suitable for evaluating the implementation of first-order or second-order protection.
[0224] This embodiment of the present invention improves accuracy and robustness through mask-aware information fusion. The core mechanism of this application is to fuse information obtained from different share operations (via ML prediction) using the algebraic structure of the mask (s_i = ∑s_{i, j}). Within the range of its ability to effectively predict information about a single or a small number of share combinations (typically more effective for low- and medium-order masks), it can effectively aggregate information and eliminate false assumptions, thereby improving the accuracy of key recovery attempts and robustness to noise and prediction errors.
[0225] The embodiments of the present application can perform risk assessment more directly: in scenarios where the method can be successfully implemented and attempts to recover the key (mainly medium and low-order masks), the success or failure of key recovery is used as the determination standard, providing a more specific risk indication than methods such as TVLA.
[0226] This embodiment of the present invention has a certain tolerance for model prediction errors: within the applicable order range of the method, due to information fusion and statistical accumulation, compared with template attacks that rely on single-point high-precision predictions, this application is less sensitive to partial prediction errors of the model. Support for soft scoring mechanisms can further utilize model information.
[0227] Figure 6 This is a schematic diagram of the structure of a side channel analysis device according to an embodiment of the present application. Figure 6 As shown, the side channel analysis device 30 includes:
[0228] Prediction module 301 is configured to obtain side channel segments involving polynomial multiplication operations of secret keys from masked Kyber algorithm side channel data, and input the side channel segments into a Hamming weight classification model to obtain a Hamming weight prediction value for the output result of the polynomial multiplication operation;
[0229] The processing module 302 is configured to generate a set of candidate values for different mask shares related to the same key coefficient based on the Hamming weight prediction value; and select a target key coefficient from the set of candidate values;
[0230] The analysis module 303 is configured to detect, if the target key coefficient successfully matches the real key, that the masked Kyber algorithm implementation has a side channel vulnerability that allows the key to be stolen.
[0231] In some embodiments of the present application, the apparatus further includes: a training module configured to: collect public phase data from masked Kyber algorithm side channel data; extract side channel segments corresponding to known intermediate values from the public phase data, and obtain the Hamming weights of the known intermediate values as labels; and train a machine learning model using the side channel segments and the labels to obtain the Hamming weight classification model.
[0232] In some embodiments of the present application, the training module is further used to: collect side channel traces of the number theoretic transformation stage of the ciphertext polynomial vector in the public stage data; divide the side channel traces into side channel segments corresponding to a single modular multiplication operation according to the acquisition unit of the number theoretic transformation node; record the output value of the single modular multiplication operation, and use the Hamming weight of the obtained output value as a label of the side channel segment.
[0233] In some embodiments of the present application, the training module is further used to: construct a training data set using the side channel segment as an input feature vector and the Hamming weight as an output label; use the training data set to train the machine learning model, wherein the machine learning model is constructed by selecting a convolutional neural network as the architecture; obtain the cross-entropy loss value between the predicted Hamming weight and the label; and use the back-propagation algorithm to optimize the parameters of the machine learning model until the cross-entropy loss value tends to be minimized to obtain a Hamming weight classification model.
[0234] In some embodiments of the present application, the training module is further used to: control the hardware device under test to load multiple sets of known ciphertexts; trigger the hardware device under test to execute the decapsulation process of the Kyber algorithm; during the public phase, when collecting the decapsulation process of the Kyber algorithm, the hardware device under test calculates the number theoretic transformation of the ciphertext polynomial vector corresponding to the known ciphertext, and captures the side channel traces through the side channel acquisition device.
[0235] In some embodiments of the present application, the processing module 302 is also used to: traverse the key share values corresponding to the Hamming weight prediction values, and screen candidate values that meet the arithmetic addition rules of mask protection; combine the candidate values of different mask shares according to the arithmetic addition rules, and assign a confidence weight to each candidate value based on the probability distribution of the combination result, so as to obtain a set of candidate values of different mask shares involving the same key coefficient.
[0236] In some embodiments of the present application, the processing module 302 is further used to: accumulate and score the candidate values according to the confidence weights corresponding to each candidate value in the candidate value set; after processing a preset number of side channel fragments, select the candidate value with the highest score as the key coefficient; and use the key coefficient that matches the known ciphertext information as the target key coefficient.
[0237] In some embodiments of the present application, the analysis module 303 is also used to: obtain the matching ratio between the target key coefficient and the real key; when the matching ratio is greater than or equal to a preset threshold, determine that the target key coefficient and the real key are successfully matched; when the matching ratio is less than the preset threshold, determine that the target key coefficient and the real key fail to match.
[0238] The embodiment of the present application obtains the predicted Hamming weight of the collected side channel fragments by using the Hamming weight classification model pre-trained with the public stage data, and uses the mask algebraic characteristics to fuse the predicted Hamming weight with the mask signal to generate a candidate set. The mask protection Kyber algorithm side channel leakage is efficiently detected based on the key coefficients screened from the candidate set, thereby utilizing the machine learning model and the mask algebraic characteristics to reduce the data volume and computational complexity of high-order analysis and improve the accuracy of detection. In addition, because the Hamming weight model takes into account the mask characteristics, it avoids the model's dependence on real labeled data, thereby improving the robustness of detection.
[0239] The description of the above device embodiment is similar to the description of the above method embodiment and has similar beneficial effects as the method embodiment. In some embodiments, the functions or modules included in the device provided in the embodiments of the present application can be used to perform the methods described in the above method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0240] If the technical solution of this application involves personal information, the product that applies the technical solution of this application has clearly informed the personal information processing rules and obtained the individual's voluntary consent before processing personal information. If the technical solution of this application involves sensitive personal information, the product that applies the technical solution of this application has obtained the individual's separate consent before processing sensitive personal information, and at the same time meets the "explicit consent" requirement. For example, on personal information collection devices such as cameras, a clear and prominent sign is set to inform that the personal information collection scope has been entered and personal information will be collected. If the individual voluntarily enters the collection scope, it is deemed that they agree to the collection of their personal information; or on the personal information processing device, when the personal information processing rules are notified by obvious signs / information, the individual's authorization is obtained through pop-up information or by asking the individual to upload their personal information; among which, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the type of personal information processed.
[0241] It should be noted that in the embodiments of the present application, if the side channel analysis method described above is implemented in the form of a software functional module and sold or used as a standalone product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, or the portion that contributes to the relevant technology, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of the present application. The aforementioned storage medium includes various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), magnetic disks, or optical disks. Thus, the embodiments of the present application are not limited to any specific hardware, software, or firmware, or any combination of hardware, software, and firmware.
[0242] An embodiment of the present application provides a computer device, including a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor executes the program, some or all of the steps in the above method are implemented.
[0243] The present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements some or all of the steps in the above method. The computer-readable storage medium may be transient or non-transient.
[0244] An embodiment of the present application provides a computer program, including computer-readable code. When the computer-readable code is run in a computer device, a processor in the computer device executes some or all of the steps for implementing the above method.
[0245] An embodiment of the present application provides a computer program product, comprising a non-transitory computer-readable storage medium storing a computer program. When the computer program is read and executed by a computer, the computer program implements some or all of the steps of the above-described method. The computer program product can be implemented in hardware, software, or a combination thereof. In some embodiments, the computer program product is embodied as a computer storage medium. In other embodiments, the computer program product is embodied as a software product, such as a software development kit (SDK).
[0246] It should be noted that the descriptions of the various embodiments above tend to emphasize the differences between the various embodiments, and their similarities or similarities can be referenced to each other. The descriptions of the above device, storage medium, computer program, and computer program product embodiments are similar to the descriptions of the above method embodiments and have similar beneficial effects as the method embodiments. For technical details not disclosed in the embodiments of the device, storage medium, computer program, and computer program product of this application, please refer to the description of the method embodiments of this application for understanding.
[0247] It should be noted that Figure 7 A schematic diagram of a hardware entity of a computer device in an embodiment of the present application is shown in FIG. Figure 7 As shown, the hardware entity of the computer device 700 includes: one or more processors 701, a communication interface 702 and a memory 703, wherein:
[0248] Processor 701 generally controls the overall operation of computer device 700 .
[0249] The communication interface 702 enables the computer device to communicate with other terminals or servers through a network.
[0250] Memory 703 is configured to store instructions and applications executable by processor 701. It can also cache data to be processed or processed by processor 701 and various modules in computer device 700 (e.g., image data, audio data, voice communication data, and video communication data). This can be implemented using flash memory (FLASH) or random access memory (RAM). Data can be transmitted between processor 701, communication interface 702, and memory 703 via bus 704. While only one processor is shown in the figure, each processor 701 includes one or more cores.
[0251] It should be noted that the computer device may include multiple processors 701, and each processor 701 can exchange data with each other through aggregate communication methods such as all-to-all, allgather, or allreduce. The processor 701 may be a central processing unit (CPU), a graphics processing unit (GPU), an embedded neural network processing unit (NPU), a tensor processing unit (TPU), a data processing unit (DPU), an accelerated processing unit (APU), a floating-point processing unit (FPU), or an application-specific integrated circuit (ASIC). The processor may also be a single-core processor or a multi-core processor. The processor may be a combination of a CPU and a hardware chip. The hardware chip may be an ASIC, a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), an FPGA, a generic array logic (GAL), or any combination thereof. The processor may also be implemented solely using a logic device with built-in processing logic, such as an FPGA or a digital signal processor (DSP).
[0252] The communication interface 702 may be a wired interface or a wireless interface for communicating with other modules or devices. The wired interface may be an Ethernet interface, a local interconnect network (LIN), etc. The wireless interface may be a cellular network interface or a wireless local area network interface, etc.
[0253] Memory 703 may be a non-volatile memory, such as read-only memory (ROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Memory 703 may also be a volatile memory, such as random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synclink DRAM (SLDRAM), direct rambus RAM (DRRAM), direct rambus DRAM (DRDRAM), and rambus DRAM.
[0254] The bus 704 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc.
[0255] It should be understood that "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned steps / processes does not mean the order of execution, and the execution order of each step / process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The above-mentioned serial numbers of the embodiments of the present application are for description only and do not represent the advantages and disadvantages of the embodiments.
[0256] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.
[0257] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.
[0258] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units; they may be located in one place or distributed across multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the scheme of this embodiment.
[0259] In addition, all functional units in the embodiments of the present application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the above-mentioned integrated units can be implemented in the form of hardware or in the form of hardware plus software functional units.
[0260] Those skilled in the art will understand that all or part of the steps of the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: mobile storage devices, read-only memories (ROM), magnetic disks or optical disks, and other media that can store program codes.
[0261] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the relevant technology, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.
[0262] The above is only an implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the scope of protection of the present application.
Claims
1. A side channel analysis method, characterized in that: The method comprises: Obtaining a side channel segment involving a polynomial multiplication of a key from the masked Kyber algorithm side channel data, and inputting the side channel segment into a Hamming weight classification model trained on the public phase data of the masked Kyber algorithm side channel data to obtain a Hamming weight prediction for the output of the polynomial multiplication; generating a set of candidate values for different mask shares related to the same key coefficient based on the Hamming weight prediction value; Filtering a target key coefficient from the candidate value set; If the target key coefficient matches the real key, the masked Kyber algorithm implementation has a side-channel vulnerability that allows the key to be stolen. The Hamming weight classification model is obtained by the following steps: Collect public phase data from masked Kyber algorithm side channel data; In the public phase data, side channel traces of the number theory transformation phase of the ciphertext polynomial vector are collected; According to the acquisition unit of the number theoretic transformation stage, the side channel trace is divided into side channel segments corresponding to a single modular multiplication operation; Recording an output value of the single modular multiplication operation, and using a Hamming weight of the output value as a label of the side channel segment; The side channel segments and labels are used to train a machine learning model to obtain the Hamming weight classification model.
2. The method according to claim 1, characterized in that The method of training a machine learning model using the side channel segments and labels to obtain the Hamming weight classification model includes: Using the side channel segment as an input feature vector and the Hamming weight as an output label, a training dataset is constructed; Using the training data set to train the machine learning model, the machine learning model is constructed by selecting a convolutional neural network as an architecture; Obtaining a cross entropy loss value between the predicted Hamming weight and the label; The back propagation algorithm is used to optimize the parameters of the machine learning model until the cross entropy loss value is minimized to obtain a Hamming weight classification model.
3. The method according to claim 2, characterized in that The side channel traces of the number theory transformation phase of the ciphertext polynomial vector are collected in the public phase data, including: Control the hardware device under test to load multiple sets of known ciphertexts; Trigger the hardware device under test to execute the Kyber algorithm decapsulation process; During the public phase of collecting the decapsulation process of the Kyber algorithm, the hardware device under test obtains the number-theoretic transformation of the ciphertext polynomial vector corresponding to the known ciphertext, and captures the side channel traces through the side channel collection device.
4. The method according to any one of claims 3, characterized in that Generating a set of candidate values for different mask shares related to the same key coefficient according to the Hamming weight prediction value includes: Traversing the key share values corresponding to the Hamming weight prediction values, and screening candidate values that meet the arithmetic addition rule of mask protection; The candidate values of different mask shares are combined according to the arithmetic addition rule, and a confidence weight is assigned to each candidate value based on the probability distribution of the combination result to obtain a set of candidate values of different mask shares involving the same key coefficient.
5. The method according to claim 4, characterized in that The step of selecting a target key coefficient from the candidate value set includes: Accumulating and scoring the candidate values according to the confidence weight corresponding to each candidate value in the candidate value set; After processing a predetermined number of side channel segments, the candidate with the highest score is selected as the key coefficient; The key coefficient that matches the known ciphertext information is used as the target key coefficient.
6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Obtaining a matching ratio between the target key coefficient and the real key; If the matching ratio is greater than or equal to a preset threshold, it is determined that the target key coefficient matches the real key successfully; When the matching ratio is less than the preset threshold, it is determined that the target key coefficient fails to match the real key.
7. A side channel analysis device, characterized in that: include: A prediction module is configured to obtain side channel segments of the masked Kyber algorithm side channel data that involve polynomial multiplication operations with a key, and input the side channel segments into a Hamming weight classification model to obtain a Hamming weight prediction value for the output of the polynomial multiplication operation, wherein the Hamming weight classification model is trained using the public phase data of the masked Kyber algorithm side channel data; a processing module, configured to generate a set of candidate values for different mask shares related to the same key coefficient based on the Hamming weight prediction value; and select a target key coefficient from the set of candidate values; An analysis module configured to determine, if the target key coefficient successfully matches the real key, that the masked Kyber algorithm implementation has a side-channel vulnerability that allows the key to be stolen; The device further includes: a training module, configured to: collect public phase data from masked Kyber algorithm side channel data; collect side channel traces of a number theoretic transformation phase of a ciphertext polynomial vector from the public phase data; segment the side channel traces into side channel segments corresponding to a single modular multiplication operation according to an acquisition unit of the number theoretic transformation phase; record an output value of the single modular multiplication operation, and use the Hamming weight of the output value as a label of the side channel segment; and train a machine learning model using the side channel segment and the label to obtain the Hamming weight classification model.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, characterized in that: When the processor executes the program, the steps of the side channel analysis method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the side channel analysis method according to any one of claims 1 to 6 are implemented.
10. A computer program product comprising a non-transitory computer-readable storage medium storing a computer program, characterized in that: When the computer program is read and executed by a computer, the steps of the side channel analysis method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Combined high-order side channel attack method and device for SM4, equipment and medium
CN112134679A
Hybrid side channel attack method for affine mask protection scheme
CN116055028A