Method and device for resisting side channel attack

By dynamically generating mask values ​​and introducing random disturbances and pseudo-operations in timing, the problem of low key security caused by random number fixation is solved, and the security of the key and the system's anti-side channel attack capabilities are improved.

CN120602071APending Publication Date: 2025-09-05SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510872812.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In the prior art, the key security is low due to the fixed random number, and the attacker can analyze the intermediate data through external observations of power consumption changes, making it difficult to improve the security of the key.

Method used

By obtaining the operands of the target segment, the target mask storage area and the target mask value are dynamically determined from multiple preset mask storage areas, and a dynamic mask is generated in combination with true random numbers, increasing the diversity and unpredictability of the mask value, and introducing timing random perturbations, pseudo-operations and redundant operations to improve key security.

Benefits of technology

The security of the key is enhanced, making it difficult for attackers to predict or obtain fixed mask values, reducing the effectiveness of side-channel attacks and improving the system's security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602071A_ABST
    Figure CN120602071A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of side channel attack resistance, and discloses a side channel attack resistance method and device. The method comprises the following steps: acquiring a first operand when a target fragment in a plurality of fragments to be acted acts; wherein the action comprises encryption or decryption, and the target fragment is any one of a plurality of fragments to be acted; according to the first operand, determining a target mask storage area corresponding to the first operand from a plurality of preset mask storage areas, and obtaining a target mask value in the target mask storage area; wherein the target mask value is generated according to a sampled random number before the target segment acts, and the target mask storage area comprises at least one of a plurality of preset mask storage areas; and determining output data corresponding to the target mask value according to the target mask value and the input data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of anti-side channel attack, and in particular to an anti-side channel attack method and device. Background Art

[0002] In related technologies, random numbers are used to process the input and output data of hardware. Since random numbers participate in cryptographic algorithm operations and mask the data related to the key, it is difficult for attackers to analyze intermediate data from the power consumption changes observed externally.

[0003] However, when random numbers are used to process input and output data of hardware, the security of the key is low because the random numbers are fixed.

[0004] Therefore, how to improve the security of keys becomes a technical problem that needs to be solved. Summary of the Invention

[0005] In view of this, the present invention provides a method and apparatus for resisting side-channel attacks.

[0006] In a first aspect, the present invention provides a method for resisting side-channel attacks. The method comprises: obtaining a first operand when a target segment among multiple segments to be acted upon performs an action; wherein the action includes encryption or decryption, and the target segment is any one of the multiple segments to be acted upon; based on the first operand, determining a target mask storage area corresponding to the first operand from multiple preset mask storage areas, and obtaining a target mask value from the target mask storage area; wherein the target mask value is generated based on a sampled random number before the target segment performs the action, and the target mask storage area includes at least one of the multiple preset mask storage areas; and determining output data corresponding to the target mask value based on the target mask value and input data.

[0007] In a second aspect, the present invention provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to thereby execute the anti-side channel attack method of the above-mentioned first aspect or any corresponding embodiment thereof.

[0008] In a third aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the anti-side channel attack method of the first aspect or any corresponding embodiment thereof.

[0009] In a fourth aspect, the present invention provides a computer program product comprising computer instructions, the computer instructions being used to enable a computer to execute the method for resisting side-channel attacks according to the first aspect or any corresponding embodiment thereof.

[0010] The anti-side channel attack method provided in this embodiment determines the target mask storage area corresponding to the first operand from multiple preset mask storage areas through the first operand when the target fragment performs an action, and obtains the target mask value in the target mask storage area, thereby increasing the diversity and unpredictability of the mask value. It is difficult for an attacker to know or guess in advance which mask storage area will be used and what the mask value stored therein is. In addition, each time the target fragment needs to be processed, a random number based on sampling is dynamically generated. This dynamic generation method makes it possible that the mask value used each time the target fragment is processed may be different, thereby increasing the difficulty for the attacker to obtain a fixed mask value, thereby improving the security of the key. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0012] Figure 1 2 is a schematic diagram of the structure of a system for resisting side channel attacks according to an embodiment of the present invention;

[0013] Figure 2 is a flow chart of a method for resisting side channel attacks according to an embodiment of the present invention;

[0014] Figure 3 2 is a schematic structural diagram of a dynamic mask generation unit provided according to an embodiment of the present invention;

[0015] Figure 4 2 is a schematic structural diagram of an adaptive multi-dimensional mask control unit provided according to an embodiment of the present invention;

[0016] Figure 5 is a schematic diagram of the control logic of an adaptive multi-dimensional mask control unit provided according to an embodiment of the present invention;

[0017] Figure 6 2 is a schematic structural diagram of an obfuscation operation generating unit provided by an embodiment of the present invention;

[0018] Figure 7 2 is a schematic diagram of the structure of an adaptive confusion control unit provided according to an embodiment of the present invention;

[0019] Figure 8 is a schematic diagram of the control logic of an adaptive confusion control unit provided according to an embodiment of the present invention;

[0020] Figure 92 is a schematic diagram of the structure of an environment perception and analysis unit provided according to an embodiment of the present invention;

[0021] Figure 10 1 is a schematic structural diagram of an example of an SM4 block cipher algorithm core unit provided according to an embodiment of the present invention;

[0022] Figure 11 1 is a schematic structural diagram of an example of an SM4 block cipher algorithm core unit provided according to an embodiment of the present invention;

[0023] Figure 12 1 is a schematic structural diagram of an example of an SM4 block cipher algorithm core unit provided according to an embodiment of the present invention;

[0024] Figure 13 1 is a schematic structural diagram of an example of an SM4 block cipher algorithm core unit provided according to an embodiment of the present invention;

[0025] Figure 14 Schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0026] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.

[0027] Please refer to Figure 1 , Figure 1 3 is a schematic diagram of the structure of a system for resisting side-channel attacks provided according to an embodiment of the present invention.

[0028] Combine Figure 1 As shown, the anti-side channel attack system may include: a true random number module, a dynamic mask generation unit, a confusion operation generation unit, an adaptive multi-dimensional mask control unit, an environment perception and analysis unit, an adaptive confusion control unit and an SM4 block cipher algorithm core unit.

[0029] The true random number module is used to generate true random numbers. The true random number module can be a module that generates true random numbers in real time.

[0030] The dynamic mask generation unit is communicatively connected to the adaptive multi-dimensional mask control unit and the true random number module, and is used to sample true random numbers through true random number slicing, and generate three-dimensional masks based on the true random numbers, which correspond to the round function mask, the key expansion mask, and the input and output data masks respectively.

[0031] An adaptive multi-dimensional mask control unit is used to store a round function mask, a key expansion mask, and an input / output data mask, and output at least one of the round function mask, the key expansion mask, and the input / output data mask according to a protection state of the system on chip and a mask operand generated by a random number slice.

[0032] The obfuscation operation generation unit is connected to the adaptive obfuscation control unit and the true random number module, and is used to generate true random number slices through the true random number generator. The time-sharing multiplexing technology is used to realize the coordinated operation of the three major protection mechanisms of timing perturbation, pseudo-operation injection and redundant calculation.

[0033] The adaptive obfuscation control unit is used to store random delay operands, pseudo operation operands, and redundant operation operands, and selects to store at least one of the random delay operands, pseudo operation operands, and redundant operation operands according to the protection status of the on-chip system.

[0034] The environment perception and analysis unit is communicatively connected to the adaptive multi-dimensional mask control unit and the adaptive confusion control unit, and is used to send protection status to the adaptive multi-dimensional mask control unit and the adaptive confusion control unit respectively.

[0035] The SM4 block cipher algorithm core unit is communicatively connected to the adaptive obfuscation control unit and the adaptive multi-dimensional mask control unit, and is used to receive the mask output by the adaptive multi-dimensional mask control unit and receive the random delay operand output by the adaptive obfuscation control unit. When the random delay operand output by the adaptive obfuscation control unit is received, the ciphertext after the plaintext is encrypted is randomly delayed.

[0036] According to an embodiment of the present invention, an embodiment of a method for resisting side-channel attacks is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0037] In this embodiment, a side channel attack resistance method is provided, which can be used in the above-mentioned side channel attack resistance system. Figure 2 FIG. 1 is a flow chart of a method for resisting side channel attacks according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:

[0038] Step S201 : obtaining a first operand when a target segment among multiple segments to be acted upon performs an action; wherein the action includes encryption or decryption, and the target segment is any one of the multiple segments to be acted upon.

[0039] The action-pending fragment may indicate a data fragment that needs to be encrypted or decrypted. In cryptographic processing, data is divided into multiple fragments (such as blocks in a block cipher) and processed piece by piece.

[0040] The target segment is the currently processed segment to be acted upon. It is any one of the multiple segments to be acted upon. The target segment is the segment to be executed among the multiple segments to be acted upon. Actions include encryption or decryption.

[0041] The first operand indicates an operand related to the target segment during the encryption or decryption process (such as key expansion, intermediate state, etc. during the encryption or decryption process). The first operand may indicate an operand for selecting a mask storage area.

[0042] In a specific implementation, a target segment (a segment currently to be processed) is selected from a plurality of data segments to be processed, and a first operand required for the target segment in an encryption or decryption operation is determined.

[0043] Step S202: Determine, based on the first operand, a target mask storage area corresponding to the first operand from a plurality of preset mask storage areas, and obtain a target mask value in the target mask storage area; wherein the target mask value is generated based on a sampled random number before the target fragment performs an action, and the target mask storage area includes at least one of the plurality of preset mask storage areas.

[0044] The preset mask storage area is a predefined storage area for storing mask values. The mask value is used to mask sensitive data (such as intermediate states or keys) to enhance resistance to side channel attacks (such as power analysis attacks). The target mask storage area can indicate a specific mask storage area determined according to the first operand, in which the mask value related to the target fragment is stored. The target mask value is the mask value stored in the target mask storage area. That is, before the target fragment is encrypted or decrypted, the mask value is generated according to the random number. This value is stored in the target mask storage area and is used to mask sensitive data.

[0045] A target mask storage area is selected from a plurality of preset mask storage areas based on the value or characteristic of the first operand, and a pre-stored target mask value is read from the target mask storage area. The mask value is generated based on a random number before the target segment is encrypted or decrypted.

[0046] Please refer to Figure 3 , Figure 3 FIG. 4 is a structural diagram of a dynamic mask generation unit provided according to an embodiment of the present invention.

[0047] In a specific implementation, combined with Figure 3As shown, the dynamic mask generation unit is used to generate a three-dimensional mask, which corresponds to the round function mask value, the key expansion mask value, and the input and output data mask value. This three-dimensional mask covers a full range of mask coverage from input data, intermediate data, to output data.

[0048] S-box mask: msbox = S(r1)⊕S(r1⊕r2)msbox = S(r1)⊕S(r1⊕r2).

[0049] Linear transformation mask: mmix = L(r3)⊕r4 = L(r3)⊕r4; where r1, r2, r3, and r4 are data sampled by random value slices, and L(.) is the SM4 linear transformation function.

[0050] Input and output data masking: Take 32 bits from the random number slice and perform XOR on the 128-bit input data (X0, X1, X2, X3) and output data (Y0, Y1, Y2, Y3) to obtain the corresponding masked data. This operation is enabled by the adaptive multi-dimensional mask control unit.

[0051] Please refer to Figure 4 and Figure 5 , Figure 4 is a schematic structural diagram of an adaptive multi-dimensional mask control unit provided according to an embodiment of the present invention. Figure 5 4 is a schematic diagram of the control logic of an adaptive multi-dimensional mask control unit provided according to an embodiment of the present invention.

[0052] In a specific implementation, combined with Figure 4 As shown, the adaptive multi-dimensional mask control unit includes mask 1 storage, mask 2 storage, and mask 3 storage, which respectively store the round function mask value, key expansion mask value, and input and output data mask value. The mask operand is generated based on random number slices and serves as the basis for randomly selecting masks 1-3. When the protection level is in the low-effective state, the system performs a random mask output operation, outputting only a one-dimensional mask. This approach effectively reduces system power consumption while ensuring a certain level of security, making it suitable for scenarios with relatively low security requirements. When the protection level is high-effective, the system performs a three-dimensional mask output, fully applying the round function mask value, key expansion mask value, and input and output data mask value, significantly improving the system's security protection capabilities to cope with high-risk security threats. This design achieves dynamic and flexible adjustment of the masking strategy based on actual security requirements while effectively balancing overall power consumption.

[0053] In a specific implementation, combined with Figure 5 As shown, IDLE: initial state, check the empty signals of the three mask buffers. If Mask 1 Buffer || Mask 2 Buffer || Mask 3 Buffer ! = non-empty, jump to CHK state, otherwise maintain IDLE state.

[0054] CHK: Checks the empty signals of the three mask buffers. If Mask 1 Buffer || Mask 2 Buffer || Mask 3 Buffer ! = Empty, jump to IDLE state. Otherwise, check the current security level requirement. If it is at a low level, split the random number slices and jump to GET state after completion. Otherwise, jump to ALL_TRANS state.

[0055] GET: Gets the random mask operand based on the split random number slices, and jumps to the RD state after completion.

[0056] RD: Read the data in the corresponding mask storage area according to the operand, and jump to TRANS after completion.

[0057] TRANS: Sends masked data to the SM4 block cipher algorithm core unit and jumps to the CHK state after completion.

[0058] ALL_TRANS: The system is in a state with high security requirements. In this state, the data of masks 1-3 are sent in sequence. After the sending is completed, it jumps to the CHK state.

[0059] Step S203: determining output data corresponding to the target mask value according to the target mask value and the input data.

[0060] The input data may indicate the input to an encryption or decryption operation, which may be plaintext (when encrypting) or ciphertext (when decrypting), or an intermediate state.

[0061] The input data is masked using the target mask value (e.g., XOR operation) to hide sensitive information. The masked data is then encrypted or decrypted to generate the final target output data (which may be ciphertext or plaintext).

[0062] As an example, the target mask value is the round function mask value, and the input data can be processed by the SM4 block cipher algorithm, wherein, during the iterative processing, the output data corresponding to the number of iterations and the round function mask value can be XORed to determine the output data corresponding to the target mask value.

[0063] The anti-side channel attack method provided in this embodiment determines the target mask storage area corresponding to the first operand from multiple preset mask storage areas through the first operand when the target fragment performs an action, and obtains the target mask value in the target mask storage area, thereby increasing the diversity and unpredictability of the mask value. It is difficult for an attacker to know or guess in advance which mask storage area will be used and what the mask value stored therein is. In addition, each time the target fragment needs to be processed, a random number based on sampling is dynamically generated. This dynamic generation method makes it possible that the mask value used each time the target fragment is processed may be different, thereby increasing the difficulty for the attacker to obtain a fixed mask value, thereby improving the security of the key.

[0064] In one possible implementation, the method further includes:

[0065] Step S201 , obtaining a second operand; wherein the second operand is used to select a target operation from obfuscation operations, and the obfuscation operations include: a timing random perturbation operation.

[0066] The second operand can indicate a value used to select a target operation from the obfuscation operations, determining which obfuscation operation is performed. Obfuscation operations include random timing perturbations. These random timing perturbations are used to increase the difficulty for attackers to obtain information by randomly changing the timing of operation execution.

[0067] During specific implementation, a second operand is obtained, and the second operand is used to select a target operation from the obfuscation operations.

[0068] As an example, the second operand may be generated by random number slicing.

[0069] Step S202: acquiring target bit data, and determining a random delay of a target number of clock cycles according to the target bit data.

[0070] The target bit data is used to determine the basic data of the random delay, which can be one or more bits of data. A random delay time is generated based on the target bit data, and this delay time will be used for subsequent processing of the output data.

[0071] As an example, a true random number generation model is used to generate random delays based on target bit data.

[0072] As an example, a table lookup method is used to look up the corresponding random delay in a preset delay table according to the target bit data.

[0073] Step S203 , delaying the output data according to a random delay of a target number of clock cycles to obtain target output data.

[0074] By adding random delays, the timing of the output data becomes unpredictable, making it more difficult for attackers to obtain information through timing analysis. The output data can be the result of processing the input data using the SM4 block cipher algorithm. After determining the output data, the output data can be delayed by a random delay of a target number of clock cycles to obtain the target output data.

[0075] This embodiment introduces randomness in the timing to obfuscate the timing characteristics of the operation, making it difficult for attackers to infer keys or sensitive information through timing analysis. Furthermore, the random delay generated based on the target bit data further increases the uncertainty of the timing. Even if an attacker can monitor the occurrence of the operation, it is difficult to accurately predict the specific duration of the delay, thereby reducing the effectiveness of timing analysis.

[0076] In one possible implementation, the obfuscation operation further includes: a random pseudo operation and a redundant operation; and the method further includes:

[0077] Step S301: When the target operation is a random pseudo operation, a target random number is sampled.

[0078] A random pseudo operation can indicate a random operation that simulates a real operation but does not produce any actual valid results. The target bit random number is used to generate the random number required for the pseudo operation.

[0079] In a specific implementation, when the target operation is a random pseudo operation, a random number of target bits is sampled.

[0080] As an example, the target random number may be generated by a true random number and collected by random number slicing.

[0081] Step S302, processing the target bit random number to obtain first bit data and second bit data; wherein, the last data in the first bit data is before the first data in the second bit data, and the number of bits of the random numbers in the first bit data and the second bit data are the same.

[0082] The first bit data and the second bit data may indicate two sets of data obtained by processing the target bit random number, which are used for subsequent operations such as XOR and S-box table query. The preset data indicates known data used in the obfuscation operation, wherein the preset data is pre-set.

[0083] The last data in the first bit of data precedes the first data in the second bit of data, and the number of random numbers in the first bit of data and the second bit of data is the same. For example, for 16-bit data, the upper eight bits can be selected as the first bit of data and the lower eight bits can be selected as the second bit of data.

[0084] As an example, the target random number is evenly divided into two groups of data, and the number of bits in each group of data is the same.

[0085] As an example, the target bit random number is mapped into two sets of data according to a specific rule or algorithm (such as a hash function, an encryption algorithm, etc.).

[0086] Step S303, performing an XOR operation on the preset data and the first bit data to obtain first target data;

[0087] After determining the preset data and the first bit data, the preset data and the first bit data may be XORed to obtain first target data, wherein the first target data is data obtained by XORing the preset data and the first bit data.

[0088] As an example, the XOR operation may be implemented by a table lookup method, and all possible XOR results may be pre-calculated and stored.

[0089] As an example, an XOR operation may be performed using an XOR circuit or function implemented in hardware or software.

[0090] Step S304: Determine the second target data from a preset S-box table according to the first target data.

[0091] By utilizing the nonlinear replacement characteristics of the S-box table, the first target data is mapped to the second target data, further increasing the complexity and randomness of the data. The second target data is the data determined from the preset S-box table based on the first target data.

[0092] As an example, an S-box table implemented in hardware or software may be used to perform the query operation.

[0093] As an example, security can be increased by dynamically generating an S-box table (eg, based on a key or a random number) for query operations.

[0094] Step S305 , performing an XOR operation on the second target data and the second bit data to obtain third target data.

[0095] After determining the second target data and the second bit data, performing an XOR operation on the second target data and the second bit data to obtain the third target data.

[0096] As an example, a T-transformation circuit or function implemented in hardware or software may be used to perform the T-transformation process.

[0097] As an example, multiple transformation operations (such as replacement, permutation, combination, etc.) can be combined to implement T transformation processing to increase complexity and randomness.

[0098] Step S306: Perform T transformation on the third target data to obtain first pseudo data.

[0099] The first dummy data may be dummy data obtained through a random dummy operation. The first dummy data may be used as dummy data for output data obtained through an SM4 block cipher algorithm. In a specific implementation, the third target data is subjected to a T transformation to obtain the first dummy data.

[0100] As an example, a T-transformation circuit or function implemented in hardware or software is used to perform the T-transformation process.

[0101] As an example, T-transformation processing is implemented by combining multiple transformation operations (such as replacement, permutation, combination, etc.), which increases complexity and randomness.

[0102] Step S307 : When the target operation is a redundant operation, performing at least one of modular addition, modular subtraction, modular multiplication, and cyclic shift on the preset data to obtain second dummy data.

[0103] The redundant operation indicates an additional operation inserted into the cryptographic algorithm. The redundant operation does not change the final result of the SM4 block cipher algorithm, but may add a false result corresponding to the output result of the SM4 block cipher algorithm.

[0104] Modular Addition can indicate that a modular addition operation is performed on the preset data and a random number or a fixed value, and the result is used as the intermediate data. Preset data: 0x12; random number: 0x34; intermediate data: (0x12+0x34) mod 256 = 0x46.

[0105] Modular Subtraction: Performs a modular subtraction on the preset data, ensuring the result is non-negative and within the modulus range. For example: Preset data: 0x50; Random number: 0x20; Modular subtraction result: (0x50 - 0x20) mod 256 = 0x30.

[0106] Modular Multiplication: Multiplies the preset data by a random number and then takes the modulus. This is suitable for scenarios that require nonlinear transformations. For example: Preset data: 0x07; Random number: 0x0F; Modular multiplication result: (0x07 * 0x0F) mod 256 = 0x69.

[0107] Circular Shift: Shifts the binary representation of the preset data left or right, and backfills the shifted bits. For example: Preset data (8 bits): 0b10110011; circular right shift 2 bits: 0b11010110 (i.e., 0xD6).

[0108] When the target operation is a redundant operation, at least one of modular addition, modular subtraction, modular multiplication and cyclic shift is performed on the preset data to obtain second dummy data.

[0109] In a realistic scenario, please refer to Figure 6 , Figure 6 2 is a schematic diagram of the structure of an obfuscation operation generation unit provided according to an embodiment of the present invention.

[0110] Combine Figure 6 As shown in the figure, the obfuscation operation generation unit uses a dynamic defense mechanism and a triple-layer protection system to build a defense network against side-channel attacks. Driven by a true random number generation module, it generates true random number slices and uses time-sharing multiplexing technology to achieve the coordinated operation of the three major protection mechanisms: timing perturbation, pseudo-operation injection, and redundant calculation.

[0111] Figure 6 The timing perturbation operation in the algorithm is a random delay of 0-7 clock cycles. This random delay will be inserted into the running stage of the SM4 block cipher algorithm. The random delay of the clock cycle is randomly generated by random number slicing. The phase interpolation technology is used to achieve precise clock delay control. 3 bits of data are taken from the random number slice and expanded to a 0-7 cycle delay value through a probability weighted algorithm. The specific implementation can be achieved using the following formula:

[0112] delay = ∑(rng_bit[i] × 2^i) × T_clk, i = 0→2; where delay is the random delay in clock cycles, T_clk is the system clock cycle, and i is an index variable used to traverse each bit of the random number (rng_bit).

[0113] The random delay insertion strategy of the clock cycle can adopt the Markov chain model and be dynamically inserted in the 32 key stages of the SM4 block cipher algorithm execution (including round operation gaps, bus transmission period, and key scheduling window) to ensure that the timing characteristics are non-stationary.

[0114] The pseudo operation implements the S-box mapping, T transformation, and round key addition in the SM4 block cipher algorithm. The S-box mapping samples random number slices of 16-bit data and performs double S-box mapping transformation. The mapping enable comes from the obfuscation operation control unit; the T transformation consists of a nonlinear transformation τ and a linear transformation L, namely:

[0115] T(x)=L(τ(x)); where T(x) represents a transformation T, which is composed of a nonlinear transformation τ and a linear transformation L, i.e., T(x)=L(τ(x)). The nonlinear transformation is composed of four parallel 8-bit input and output S-boxes, represented by Sbox(x). Suppose the input x is The output is A is the preset input data, then:

[0116] (b0, b1, b2, b3) = τ(A) = (Sbox(a0), Sbox(a1), Sbox(a2), Sbox(a3)); where the output of the nonlinear transformation τ is the input of the linear transformation L. Let the input Output

[0117] It can represent an 8-bit binary number, modulo 2 operation. B is the input of the linear transformation L, which is composed of the output of τ (i.e., B = b0||b1||b2||b3, a total of 32 bits). C is the output of the linear transformation L and the final output of T.

[0118] Round key addition uses an XOR gate structure, where one path is derived from sampled data from a true random slice and randomly XORed with the input data. Redundant operations include modular addition, modular subtraction, modular multiplication, and circular shift.

[0119] Please refer to Figure 7 and Figure 8 , Figure 7 2 is a schematic diagram of the structure of an adaptive confusion control unit provided according to an embodiment of the present invention. Figure 8 2 is a schematic diagram of the control logic of an adaptive confusion control unit provided according to an embodiment of the present invention.

[0120] Combine Figure 7 As shown, the adaptive obfuscation control unit integrates random delay operands, pseudo-operation operands, redundant operation operands, adaptive obfuscation control, and obfuscation operation outputs. The three operands are randomly obtained after random number slicing. The adaptive obfuscation control dominates and controls the overall data flow. To balance security and power consumption, the random delay operands, pseudo-operation operands, and redundant operation operands are transmitted in a targeted manner based on the system protection level. Specifically, when the protection level is judged to be low, one of the three operands is randomly output; when the protection level is judged to be high, all three operands are output simultaneously. This design achieves the goal of effectively balancing overall power consumption while dynamically and flexibly adjusting the mask strategy according to actual security needs.

[0121] Combine Figure 8As shown, IDLE is the initial state. The protection level is checked. If the protection level is high, the state jumps to ALL_TRANS. If the protection level is low, a random number slice is obtained and segmented to obtain operands. The operands serve as the limit for the number of times timing delays, pseudo operations, and redundant operations are executed. The operands are generated according to the formula R(i) = P(i-1)||Q(i-2)||K(i-3), where || represents the concatenation operation, and P, Q, and K represent timing delays, pseudo operations, and redundant operations. After the operands are segmented, the state jumps to GET; otherwise, the IDLE state remains. GET indicates the acquisition of the operands for the obfuscation operation and jumps to TRANS. TRANS indicates the transmission of the operands to the SM4 block cipher algorithm core unit and the obfuscation operation generation unit. After the obfuscation operations are completed, the state jumps to CHK. ALL_TRANS is the state in which the system is under high security requirements. In this state, the operands of the three types of obfuscation operations are all set to 1 and sent. If the system detects that it is under low security requirements, the state jumps to IDLE; otherwise, the state remains.

[0122] The anti-side channel attack method provided in this embodiment introduces randomness in timing and power consumption by sampling the target bit random number and performing a series of processing (such as XOR, S-box table query, T transformation, etc.). This makes it difficult for attackers to infer keys or sensitive information through timing analysis or power analysis. In addition, redundant operations increase the complexity of calculations through operations such as modular addition, modular subtraction, modular multiplication, and circular shift. These operations themselves do not change the final result of the algorithm, but make it difficult for attackers to infer the true key or sensitive information through simple analysis.

[0123] In one possible implementation, step S103 includes:

[0124] Step S1031 : When the target mask value includes the input data mask value and the output data mask value, perform an XOR operation on the input data and the input data mask value to obtain input data to be processed.

[0125] Step S1032: Using the SM4 block cipher algorithm, the input data to be processed is processed to obtain output data to be processed.

[0126] Step S1033 , performing an XOR operation on the output data to be processed and the data mask value to obtain output data.

[0127] The SM4 block cipher algorithm integrates a round function, key expansion, subkey locking, and a round function, T transformation, and key expansion implementation. In the SM4 block cipher algorithm, the input data and the input data mask value can be XORed to obtain the processed input data. Using the SM4 block cipher algorithm, the processing of the processed input data can be performed by applying a round function to the processed input data to obtain the processed output data. The processed output data is then XORed with the data mask value to obtain the output data.

[0128] Step S1034, when the target mask value is a round function mask value, the SM4 block cipher algorithm is used to perform round function processing on the input data to obtain multiple intermediate data; wherein, the multiple intermediate data are iteratively generated by the input data, and the number of round function mask values, the number of intermediate data and the number of iterations are the same.

[0129] Step S1035 , performing an XOR operation on the round function mask value and the intermediate data corresponding to the round function mask value to obtain output data.

[0130] The round function mask value indicates the specific mask value associated with the round function processing of the SM4 block cipher algorithm, used to identify the current processing stage or control the specific behavior of the round function. The round function processing can indicate the core operations in the SM4 block cipher algorithm, including nonlinear transformations, linear transformations, round key additions, and other steps used to iterate the input data over multiple rounds. Intermediate data can indicate the data generated by the input data during multiple rounds of round function processing. Each round of iteration generates new intermediate data.

[0131] When the target mask value is the round function mask value, the SM4 block cipher algorithm is used to perform round function processing on the input data to obtain multiple intermediate data. The multiple intermediate data are generated by iteratively performing round function mask value processing on the input data, and the number of round function mask values, the number of intermediate data, and the number of iterations are equal. The round function mask value and the intermediate data corresponding to the round function mask value are XORed to obtain the output data.

[0132] As an example, the round function processing of the SM4 block cipher algorithm is implemented using hardware. A specialized hardware circuit (such as ASIC, FPGA, etc.) performs multiple rounds of iterative processing on the input data to generate intermediate data.

[0133] As an example, the round function processing of the SM4 block cipher algorithm is implemented using software. By writing program code, the round function processing of the SM4 block cipher algorithm is simulated on a general-purpose processor to generate intermediate data.

[0134] Step S1036: When the target mask value is a key expansion mask value, the SM4 block cipher algorithm is used to perform key expansion on the input data to obtain key-expanded data.

[0135] Step S1037: XOR the key expansion mask value and the key expanded data to obtain output data.

[0136] Key expansion is a key step in the SM4 block cipher algorithm. Through a series of nonlinear and linear transformations, the round keys required for multiple rounds of encryption are generated from the initial key. The key-expanded data can indicate the set of round keys generated by the key expansion process. The output data can indicate the resultant data after key expansion and the XOR operation.

[0137] When the target mask value is the key expansion mask value, the SM4 block cipher algorithm is used to perform key expansion on the input data to obtain the key-expanded data. The key expansion mask value and the key-expanded data are then XORed together to obtain the output data. This XOR operation mixes the key expansion mask value with the key-expanded data, potentially for further data obfuscation or to achieve specific security goals.

[0138] In this embodiment, the method for selecting the target mask value can be determined by the first operand. Specifically, when the first operand indicates selection of a key expansion mask value, a round function mask value, or input and output data mask values, the key expansion mask value, the round function mask value, and the input and output data mask values ​​can be processed with different processes of the SM4 block cipher algorithm to obtain output data. For example, the input data mask value can be XORed with the input data in the SM4 block cipher algorithm to obtain the data to be processed.

[0139] This embodiment provides a method for combating side-channel attacks, employing three-dimensional masked output. This method comprehensively applies round function mask values, key expansion mask values, and input and output data mask values, significantly enhancing the system's security capabilities to address high-risk security threats. This design allows for dynamic and flexible adjustment of masking strategies based on actual security requirements while effectively balancing overall power consumption.

[0140] In one possible implementation, the method further includes:

[0141] Step S401 , obtaining voltage, temperature, and power consumption values ​​of the system on chip.

[0142] Among the voltage, temperature and power consumption values ​​of the system on chip, the voltage of the system on chip can be collected by the voltage collection submodule, the temperature can be collected by the temperature collection submodule, and the power consumption value can be collected by the power consumption submodule.

[0143] The voltage may indicate the potential difference when the system-on-chip is operating. The temperature may indicate the ambient temperature or chip surface temperature when the system-on-chip is operating. The power consumption value may indicate the electrical energy consumed by the system-on-chip during operation.

[0144] Step S402: Compare the voltage with the voltage threshold to obtain a first comparison result.

[0145] The voltage threshold may be a pre-set value. The voltage threshold may be pre-selected. The voltage threshold may be determined by a default partition or a user-defined partition. When the default partition is selected, the voltage threshold may indicate a threshold standard value set by the chip design manufacturer. When a user-defined partition is selected, the voltage threshold may be user-defined.

[0146] In a specific implementation, the voltage is compared with a voltage threshold to obtain a first comparison result, which indicates whether the voltage is less than the voltage threshold.

[0147] Step S403: compare the temperature with the temperature threshold to obtain a second comparison result.

[0148] The temperature threshold may be a pre-set value. The temperature threshold may be pre-selected. The temperature threshold may be determined by a default partition or a user-defined partition. When the default partition is selected, the temperature threshold may indicate a threshold standard value set by the chip design manufacturer. When a user-defined partition is selected, the temperature threshold may be user-defined.

[0149] In a specific implementation, the temperature is compared with the temperature threshold to obtain a second comparison result, which indicates whether the temperature is less than the temperature threshold.

[0150] Step S404: compare the power consumption value with the power consumption threshold to obtain a third comparison result.

[0151] The power consumption threshold may be a pre-set value. The power consumption threshold may be pre-selected. The power consumption threshold may be determined by a default partition or a user-defined partition. When the default partition is selected, the power consumption threshold may indicate a threshold standard value set by the chip design manufacturer. When a user-defined partition is selected, the power consumption threshold may be user-defined.

[0152] In a specific implementation, the power consumption value is compared with the power consumption threshold to obtain a third comparison result. The second comparison result indicates whether the power consumption value is less than the power consumption threshold.

[0153] Step S405 , determining a first operand according to the first comparison result, the second comparison result, and the third comparison result.

[0154] After determining the first comparison result, the second comparison result, and the third comparison result, a first operand may be determined according to the first comparison result, the second comparison result, and the third comparison result to select a target mask value.

[0155] As an example, when the first comparison result indicates that the voltage is greater than the voltage threshold, the second comparison result indicates that the temperature is greater than the temperature threshold, and the third comparison result indicates that the power consumption value is greater than the power consumption threshold, it is determined that the protection level is high, then all masks need to be selected, that is, the round function mask value, key expansion mask value, and input and output data mask value are fully applied.

[0156] Step S406 , determining a second operand according to the first comparison result, the second comparison result, and the third comparison result.

[0157] After determining the second comparison result, the second comparison result, and the third comparison result, a second operand may be determined according to the first comparison result, the second comparison result, and the third comparison result to select an obfuscation operation.

[0158] As an example, when the second comparison result indicates that the voltage is greater than the voltage threshold, the second comparison result indicates that the temperature is greater than the temperature threshold, and the third comparison result indicates that the power consumption value is greater than the power consumption threshold, it is determined that the protection level is high, then all obfuscation operations need to be selected, that is, timing random perturbation operations, random pseudo operations and redundant operations are fully applied.

[0159] In a possible implementation, for each action segment in the to-be-action segments, when the action segment is used as a target segment, the protection level needs to be re-determined.

[0160] In a specific implementation, please refer to Figure 9 , Figure 9 2 is a schematic diagram of the structure of an environment perception and analysis unit provided according to an embodiment of the present invention.

[0161] Combine Figure 9As shown in the figure, the environmental perception and analysis unit generates a two-level digital risk identification (0-Low / 1-High) through multi-dimensional environmental parameter fusion analysis and real-time threat quantification assessment, driving the downstream obfuscation control and mask protection system to perform dynamic security policy adjustment. Among them, the environmental perception and analysis unit integrates the voltage / temperature / power consumption acquisition submodule, ADC analog-to-digital conversion submodule, threshold efuse module, and threshold judgment module. It completes voltage / temperature / power consumption acquisition and performs threshold judgment after analog-to-digital conversion. The threshold efuse module integrates efuse partitioning and efuse control for burning system risk thresholds and time parameters. The efuse partition consists of two parts: the default partition and the user-defined partition. The default partition is burned by the chip design manufacturer according to the threshold standard value, and the user-defined partition is burned by the user. The efuse control is used to control the efuse burning process and control which partition the threshold is output from. The threshold judgment submodule maintains a risk decision model.

[0162] Please refer to Table 1, which shows the relationship between the risk decision model, the threshold source, the time parameter T and the adaptation scenario.

[0163] model Threshold Source Time parameter T Applicable Scenarios Standard Mode Default partition 10ms Low-risk routine User Mode User partition Adjustable (5ms-50ms) High security requirements Emergency Mode One of the two 1ms Attack response status

[0164] The dynamic threshold comparison is based on the following formula:

[0165]

[0166] Among them, S sen (t) is the real-time data sampled by ADC; V th is the effective threshold (default / user); T is the effective time parameter.

[0167] To balance security and power consumption, the side-channel attack resistance method provided in this embodiment selectively transmits random delay operands, pseudo-operation operands, and redundant operands based on the system risk level. Specifically, when the system risk level is determined to be low, one of the three types of operands is randomly output; when the risk level is determined to be high, all three types of operands are output simultaneously. This design effectively balances overall power consumption while dynamically and flexibly adjusting the masking strategy based on actual security requirements.

[0168] In one possible implementation, the method further includes:

[0169] Step a1, when any one of the first comparison result indicating that the voltage is less than the voltage threshold, the second comparison result indicating that the temperature is less than the temperature threshold, and the third comparison result indicating that the power consumption value is less than the power consumption threshold is not true, obtain the associated data of the invalid comparison result; wherein the associated data includes the voltage change rate, the temperature change rate, and the power consumption change rate.

[0170] Step a2: Check whether the associated data of the invalid comparison result meets the preset conditions.

[0171] If any of the following conditions are not met: the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, the protection level is characterized as a high protection level. However, at this point, further determination can be made as to whether the associated data of the failed comparison result meets a preset condition. For example, if the failed comparison result indicates that the voltage is not less than the voltage threshold, further determination can be made as to whether the voltage change rate meets a preset condition. The preset condition can indicate a change rate threshold. The change rate threshold is a pre-set value used to indicate the threshold at which the voltage threshold needs to be adjusted.

[0172] Step a3: When the associated data of the unsatisfactory comparison result meets the preset condition, the threshold corresponding to the associated data of the unsatisfactory comparison result is adjusted to determine a successful comparison result based on the adjusted threshold.

[0173] When the associated data of the failed comparison result meets the preset condition, the method of adjusting the threshold corresponding to the associated data of the failed comparison result may indicate increasing the threshold corresponding to the associated data of the failed comparison result so that the voltage is less than the voltage threshold.

[0174] For example, if the voltage is not less than the voltage threshold and the voltage change rate meets the preset conditions, the voltage threshold is adjusted. This adjustment can be based on a specific algorithm or rule, such as increasing the voltage threshold by a certain percentage (e.g., 5%) so that the comparison result is valid when the voltage is compared again based on the adjusted threshold. This is done to make the threshold more adaptable to the actual current operating conditions of the SoC, avoiding frequent and unnecessary triggering of protection mechanisms due to normal fluctuations, while ensuring the safe and stable operation of the SoC.

[0175] In one possible implementation, the plurality of preset mask storage areas include a round function mask value storage area, a key expansion mask value storage area, and a data mask value storage area; and the above step S405 includes:

[0176] Step S4051, when any one of the first comparison result indicating that the voltage is less than the voltage threshold, the second comparison result indicating that the temperature is less than the temperature threshold, and the third comparison result indicating that the power consumption value is less than the power consumption threshold is not true, a first target operand is generated, and the first target operand is used as the first operand; wherein the first target operand indicates that the selected target mask storage area includes: a round function mask value storage area, a key expansion mask value storage area, and a data mask value storage area.

[0177] If any of the following conditions is not met: the voltage is less than the voltage threshold, the temperature is less than the temperature threshold, and the power consumption is less than the power consumption threshold, the protection level is high. When the protection level is high, it is necessary to extract corresponding mask values ​​from each of the round function mask value storage area, the key expansion mask value storage area, and the data mask value storage area. Specifically, the round function mask value is extracted from the round function mask value storage area, the key expansion mask value is extracted from the key expansion mask value storage area, and the input and output data mask values ​​are extracted from the data mask value storage area. The input data is then processed based on the round function mask value, the key expansion mask value, and the input and output data mask values ​​to obtain output data.

[0178] Step S4052: when the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, a second target operand is generated, and the second target operand is used as the first operand; wherein the second target operand indicates that the selected target mask storage area includes: any one of the round function mask value storage area, the key extension mask value storage area, and the data mask value storage area, or any two of the round function mask value storage area, the key extension mask value storage area, and the data mask value storage area.

[0179] When the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, it is characterized that the protection level is a low protection level. When the protection level is a low protection level, it is necessary to extract the corresponding mask value from any one or any two storage areas of the round function mask value storage area, the key expansion mask value storage area, and the data mask value storage area.

[0180] The specific storage area to be extracted may be determined by the first operand. For example, when the first operand indicates (0, 0, 1), a key expansion mask value may be selected. When the first operand indicates (1, 0, 1), a key expansion mask value and a round function mask value may be selected.

[0181] The anti-side channel attack method provided in this embodiment selects all mask storage areas (round function mask value storage area, key expansion mask value storage area, and data mask value storage area) when the system detects that any one of the voltage, temperature, or power consumption values ​​exceeds a threshold. This strategy provides the highest level of security protection when the system operating environment is unstable or there are potential security threats, ensuring that data is fully masked during encryption and decryption. When the system operating parameters are all within a safe range, the mask storage areas (any one or two) can be selectively used. This flexibility enables the system to reduce unnecessary computing overhead and improve performance while ensuring basic security.

[0182] In one possible implementation, step S406 includes:

[0183] Step S4061, when any one of the first comparison result indicating that the voltage is less than the voltage threshold, the second comparison result indicating that the temperature is less than the temperature threshold, and the third comparison result indicating that the power consumption value is less than the power consumption threshold is not true, a third target operand is generated, and the third target operand is used as the second operand; wherein the third target operand indicates that the target operation determined from the confusion operation includes: a timing random perturbation operation, a random pseudo operation, and a redundant operation.

[0184] When any one of the following conditions is not true: the voltage is less than the voltage threshold, the temperature is less than the temperature threshold, and the power consumption value is less than the power consumption threshold, the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, then the protection level is characterized as a low protection level. When the protection level is a low protection level, all obfuscation operations need to be selected, that is, the third target operand indicates that the target operation determined from the obfuscation operation includes: timing random perturbation operation, random pseudo operation, and redundant operation.

[0185] Step S4062, when the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, all of which are true, a fourth target operand is generated, and the fourth target operand is used as the second operand; wherein the fourth target operand indicates that the target operation determined from the confusion operation includes: any one of a timing random perturbation operation, a random pseudo operation, and a redundant operation, or any two of the timing random perturbation operation, the random pseudo operation, and the redundant operation.

[0186] When the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, any one of the following is not true, then the protection level is characterized as a low protection level. When the protection level is a low protection level, it is necessary to select one or two of the obfuscation operations, that is, the fourth target operand indicates that the target operation determined from the obfuscation operation includes: any one of a timing random perturbation operation, a random pseudo operation, and a redundant operation, or any two of a timing random perturbation operation, a random pseudo operation, and a redundant operation.

[0187] The anti-side channel attack method provided in this embodiment selects all obfuscation operations (timing random perturbation operations, random pseudo operations, and redundant operations) when the system detects that any one of the voltage, temperature, or power consumption values ​​exceeds a threshold. This strategy increases the difficulty of analysis for attackers through a variety of obfuscation methods when the system operating environment is unstable or there are potential security threats, providing the highest level of security protection. When the system operating parameters are all within a safe range, obfuscation operations (any one or two) can be selectively used. This flexibility enables the system to reduce unnecessary performance overhead and improve execution efficiency while ensuring basic security.

[0188] Please refer to Figure 10-14 , Figure 10 1 is a schematic structural diagram of an example of an SM4 block cipher algorithm core unit provided according to an embodiment of the present invention; Figure 11 1 is a schematic structural diagram of an example of an SM4 block cipher algorithm core unit provided according to an embodiment of the present invention; Figure 12 1 is a schematic structural diagram of an example of an SM4 block cipher algorithm core unit provided according to an embodiment of the present invention; Figure 13 1 is a schematic structural diagram of an example of an SM4 block cipher algorithm core unit provided according to an embodiment of the present invention.

[0189] In one possible implementation, the SM4 block cipher algorithm core integrates round functions, key expansion, subkey latching, round functions, T transformation, and key expansion implementation architecture.

[0190] The timing perturbation, round function mask, input and output data mask, and key expansion mask insertion are shown in the small dashed box. The timing perturbation is inserted in any cycle of the 32-round round function, and the mask insertion adopts the exclusive OR operation, which is expressed by the formula:

[0191] Combine Figure 10 As shown, the input data mask is inserted: Among them, input is input data, MASK input MASK_input is the input data mask value. ′ Indicates input data mask insertion.

[0192] Output data mask insertion: Among them, output is the output data. MASK output is the output data mask value, MASK_input′ indicates the output data mask insertion.

[0193] Combine Figure 11 As shown, the key expansion mask is inserted:

[0194] Among them, S box (Substitution box), a nonlinear substitution function, is used to increase the complexity of the password. MASK Sbox The mask value applied to the S-box. L(·) is a linear transformation. MASK_Sbox ′ (·) indicates key extension mask insertion.

[0195] Combine Figure 12 and Figure 13 As shown, the round function mask is inserted: Among them, MASK is the mask value, ⊕ represents the bitwise exclusive OR (XOR) operation, T() is the round function, MASK_T ′ (·) indicates round function mask insertion.

[0196] This embodiment also provides a device for resisting side-channel attacks, which is used to implement the above-mentioned embodiments and preferred embodiments. Details that have already been described will not be repeated. As used below, the term "module" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.

[0197] This embodiment provides an anti-side-channel attack device, which includes: an acquisition module, used to obtain a first operand when a target segment among multiple segments to be acted upon performs an action; wherein the action includes encryption or decryption, and the target segment is any one of the multiple segments to be acted upon; a first determination module, used to determine, based on the first operand, a target mask storage area corresponding to the first operand from multiple preset mask storage areas, and to obtain a target mask value in the target mask storage area; wherein the target mask value is generated based on a sampled random number before the target segment performs the action, and the target mask storage area includes at least one of the multiple preset mask storage areas; and a second determination module, used to determine, based on the target mask value and input data, output data corresponding to the target mask value.

[0198] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0199] The anti-side channel attack device in this embodiment is presented in the form of a functional unit, where the functional unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0200] An embodiment of the present invention further provides a computer device having the above-mentioned anti-side channel attack device.

[0201] See also Figure 14 , Figure 14 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 14 As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 14 A processor 10 is taken as an example.

[0202] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.

[0203] The memory 20 stores instructions that can be executed by at least one processor 10, so as to enable at least one processor 10 to execute the method shown in the above embodiment.

[0204] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0205] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0206] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 can be connected via a bus or other means. Figure 14 The bus connection is taken as an example.

[0207] The input device 30 can receive input digital or character information and generate key signal input related to user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touch pad, an indicator stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 can include a display device, an auxiliary lighting device (e.g., an LED), and a tactile feedback device (e.g., a vibration motor). The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display, and a plasma display. In some optional embodiments, the display device can be a touch screen.

[0208] The computer device further includes a communication interface for the computer device to communicate with other devices or a communication network.

[0209] The embodiment of the present invention also provides a computer-readable storage medium. The above-mentioned method according to the embodiment of the present invention can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.

[0210] A portion of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium that can be accessed by the computer.

[0211] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention. Such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A method for resisting side channel attacks, characterized in that: The method comprises: Obtaining a first operand when a target segment among multiple segments to be acted upon performs an action; wherein the action includes encryption or decryption, and the target segment is any one of the multiple segments to be acted upon; Determining, based on the first operand, a target mask storage area corresponding to the first operand from a plurality of preset mask storage areas, and obtaining a target mask value from the target mask storage area; wherein the target mask value is generated based on a sampled random number before the target fragment performs an action, and the target mask storage area includes at least one of the plurality of preset mask storage areas; According to the target mask value and the input data, output data corresponding to the target mask value is determined.

2. The method for resisting side channel attacks according to claim 1, wherein: The method further comprises: Obtaining a second operand; wherein the second operand is used to select a target operation from the obfuscation operation, the obfuscation operation including: a timing random perturbation operation; Obtaining target bit data, and determining a random delay of a target number of clock cycles based on the target bit data; The output data is delayed according to a random delay of a target number of clock cycles to obtain target output data.

3. The method for resisting side channel attacks according to claim 2, wherein: The obfuscation operation further includes: random pseudo operation and redundant operation; and the method further includes: When the target operation is a random pseudo operation, sampling a target bit random number; Processing the target bit random number to obtain first bit data and second bit data; wherein the last data in the first bit data is before the first data in the second bit data, and the number of bits of the random numbers in the first bit data and the second bit data is the same; Performing an XOR operation on the preset data and the first bit of data to obtain first target data; Determine second target data from a preset S-box table according to the first target data; performing an XOR operation on the second target data and the second bit data to obtain third target data; Performing T transformation on the third target data to obtain first pseudo data; When the target operation is a redundant operation, at least one of modular addition, modular subtraction, modular multiplication and cyclic shift is performed on the preset data to obtain second pseudo data.

4. The method for resisting side channel attacks according to claim 1, wherein: The determining, based on the target mask value and the input data, output data corresponding to the target mask value includes: When the target mask value includes the input data mask value and the output data mask value, performing an XOR operation on the input data and the input data mask value to obtain the input data to be processed; Using the SM4 block cipher algorithm, processing is performed according to the input data to be processed to obtain the output data to be processed; Performing an XOR operation on the output data to be processed and the data mask value to obtain output data; When the target mask value is a round function mask value, the SM4 block cipher algorithm is used to perform round function processing on the input data to obtain a plurality of intermediate data; wherein the plurality of intermediate data are iteratively generated by the input data, and the number of the round function mask values, the number of the intermediate data, and the number of iterations are the same; Performing an XOR operation on the round function mask value and the intermediate data corresponding to the round function mask value to obtain output data; When the target mask value is the key expansion mask value, the SM4 block cipher algorithm is used to perform key expansion on the input data to obtain the key-expanded data; Performing an exclusive OR operation on the key expansion mask value and the key expanded data to obtain output data.

5. The method for resisting side channel attacks according to claim 3, wherein: The method further comprises: Get the voltage, temperature and power consumption values ​​of the system on chip; Comparing the voltage with a voltage threshold to obtain a first comparison result; comparing the temperature with a temperature threshold to obtain a second comparison result; Comparing the power consumption value with a power consumption threshold to obtain a third comparison result; determining a first operand according to the first comparison result, the second comparison result, and the third comparison result; A second operand is determined according to the first comparison result, the second comparison result, and the third comparison result.

6. The method for resisting side channel attacks according to claim 5, wherein: The plurality of preset mask storage areas include a round function mask value storage area, a key expansion mask value storage area, and a data mask value storage area; And determining a first operand according to the first comparison result, the second comparison result, and the third comparison result includes: When any one of the following is not true: the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, generating a first target operand and using the first target operand as the first operand; wherein the first target operand indicates that the selected target mask storage area includes: the round function mask value storage area, the key expansion mask value storage area, and the data mask value storage area; When the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, a second target operand is generated, and the second target operand is used as the first operand; wherein the second target operand indicates that the selected target mask storage area includes: any one of the round function mask value storage area, the key extension mask value storage area, and the data mask value storage area, or any two of the round function mask value storage area, the key extension mask value storage area, and the data mask value storage area.

7. The method for resisting side channel attacks according to claim 5, wherein: The determining a second operand according to the first comparison result, the second comparison result, and the third comparison result includes: When any one of the following conditions is not true: the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, a third target operand is generated, and the third target operand is used as the second operand; wherein the third target operand indicates that the target operation determined from the obfuscation operation includes: a timing random perturbation operation, a random dummy operation, and a redundant operation; When the first comparison result indicates that the voltage is less than the voltage threshold, the second comparison result indicates that the temperature is less than the temperature threshold, and the third comparison result indicates that the power consumption value is less than the power consumption threshold, a fourth target operand is generated, and the fourth target operand is used as the second operand; wherein the fourth target operand indicates that the target operation determined from the confusion operation includes: any one of a timing random perturbation operation, a random pseudo operation, and a redundant operation, or any two of the timing random perturbation operation, the random pseudo operation, and the redundant operation.

8. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the anti-side channel attack method according to any one of claims 1 to 7 by executing the computer instructions.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the anti-side channel attack method according to any one of claims 1 to 7.

10. A computer program product, characterized in that The method comprises computer instructions, wherein the computer instructions are used to cause a computer to execute the side channel attack resistance method according to any one of claims 1 to 7.