Multi-source fusion side channel analysis method for anti-quantum cryptography algorithm
By employing a multi-source fusion side-channel analysis method, combining electromagnetic and energy-side information, a template attack classifier is constructed, and a belief propagation algorithm is used to solve the key leakage problem of quantum cryptography algorithms during device deployment, achieving efficient key recovery.
Patent Information
- Application Number
- CN202511293489.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-11
- Publication Date
- 2025-11-07
AI Technical Summary
Existing quantum-resistant cryptographic algorithms may lead to the leakage of physical information related to keys during device deployment. The single-channel analysis template modeling capability is limited, making it difficult to effectively recover keys.
A multi-source fusion side-channel analysis method is adopted, which combines electromagnetic and energy side information. A template attack classifier is constructed through feature-level, model-level and decision-level fusion methods, and the belief propagation algorithm is used to recover the key.
It achieves efficient recovery of keys resistant to quantum cryptography algorithms, and improves the accuracy and efficiency of key recovery by utilizing synchronous acquisition of multi-source information.
Smart Images

Figure CN120915426A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a multi-source fusion side channel analysis method against quantum-resistant cryptographic algorithms, in particular to a side channel analysis method based on template attack and belief propagation algorithm, and belongs to the field of information security cryptography. BACKGROUND
[0002] Public key cryptography is widely used in public key encryption, key agreement and digital signature schemes. Common public key cryptographic algorithms include RSA and ECC. These algorithms are designed based on mathematical problems that are difficult for traditional computers to solve, but can be solved using quantum computers. Therefore, it is necessary to study quantum-resistant cryptographic algorithms that cannot be cracked by quantum computers.
[0003] Quantum-resistant cryptographic algorithms are designed based on computational problems that cannot be solved by traditional computers or quantum computers. In order to standardize quantum-resistant cryptography, the National Institute of Standards and Technology (NIST) in the United States collected quantum-resistant cryptographic schemes from the public in 2017, and finally selected four algorithms as the results of the standardization process.
[0004] Although quantum-resistant cryptographic algorithms have the ability to resist quantum computers from cracking mathematical problems, when they are deployed on devices for use, they may leak physical information related to the key, making them vulnerable to side channel analysis. In recent years, there has been an increasing number of side channel attacks against CRYSTALS-Dilithium. In 2024, Olivier Bronchain et al. published "Exploiting Small-Norm Polynomial Multiplication with Physical Attacks Application to CRYSTALS-Dilithium" in IACR Transactions on Cryptographic Hardware and Embedded Systems, proposing a key recovery framework that combines physical leakage and Belief Propagation. This method estimates the probability distribution of intermediate variables through side channel analysis, and uses the Belief Propagation algorithm to gradually recover the private key. However, this method only uses a single electromagnetic wave for attack modeling, lacks collaborative analysis of multi-source information, and has limited template modeling capabilities. SUMMARY
[0005] The purpose of the present application is to address the deficiencies and shortcomings of the prior art, in order to make more full use of side information, and creatively proposes a multi-source fusion side channel analysis method for anti-quantum cryptography algorithm. The method can simultaneously use any number of channel information, and can recover the key through less waves.
[0006] The present application adopts the following technical solutions.
[0007] A multi-source fusion side channel analysis method for anti-quantum cryptography algorithm, comprising the following steps: Step 1: First, collect the electromagnetic and energy side information of the anti-quantum cryptography algorithm device during the signature process, and use the trigger signal to locate the effective waveform segment in the side information; Step 2: Analyze the side information waveform of the signature operation, and divide it into several segments according to the waveform characteristics; Step 3: Combine the anti-quantum cryptography algorithm principle, and propose a multi-source fusion method at the feature level, model level and decision level, use intermediate variables to construct a template attack classifier, and obtain the probability distribution of template classification; Step 4: Build a factor graph and execute a belief propagation algorithm to recover the key.
[0008] Advantages The present application uses side information from multiple channels, synchronously collects electromagnetic waves and energy waves, and performs fusion at the feature level, model level and decision level to perform multi-source fusion side channel analysis on the signature process of the anti-quantum cryptography algorithm, and can efficiently recover the key. BRIEF DESCRIPTION OF DRAWINGS
[0009] Figure 1 is a flowchart of the method of the present application; Figure 2 is the key operation positioning result of the electromagnetic wave in the embodiment of the method of the present application; Figure 3 is the key operation positioning result of the energy wave in the embodiment of the method of the present application; DETAILED DESCRIPTION
[0010] The detailed steps of the method described in the present application will be described below in conjunction with the drawings and embodiments.
[0011] EMBODIMENT Take the CRYSTALS-Dilithium algorithm as an application example, run its signature process, and collect the electromagnetic information and energy information of the device during the signature generation process respectively to obtain multi-source side channel waveform data. The CRYSTALS-Dilithium algorithm is an anti-quantum digital signature algorithm based on the modular problem, which has high security and high efficiency, and has been selected by NIST as one of the four anti-quantum cryptography standards.
[0012] AsFigure 1 As shown in the figure, a multi-source fusion side channel analysis method for quantum-resistant cryptographic algorithms includes the following steps: Step 1: First, collect the electromagnetic and energy side information of the quantum-resistant cryptographic algorithm device during the signature process, and use the trigger signal to locate the effective waveform segment in the side information.
[0013] Specifically, the Dilithium algorithm signature process involves multiple intermediate variables, including random vector y, response value z, challenge vector c, and private key vector s1, where y and private key vector s1 have a linear relationship: z=y+c·s1. Therefore, y is a key leakage point. In actual operation, the signature operation of the Dilithium algorithm is performed, and the electromagnetic and energy waveforms are collected synchronously through an oscilloscope, and the trigger signal is recorded for accurate cutting of the effective interval. The trigger signal is used to automatically intercept the key waveform segment during each signature process, which contains the intermediate variable operation execution process.
[0014] Step 2: Analyze the side information waveform of the signature operation, and divide it into several segments according to the waveform characteristics.
[0015] Specifically, the Dilithium signature process includes 256 iterative assignments and vector processing operations on y[i] and z[i], which are represented as 64 repeated operation segments in the waveform. These operations form periodic peak structures in the electromagnetic and energy trajectories. Based on the starting point of the first operation segment, iterative search is performed, and the maximum value of each segment is found as the cut point using a sliding window. The distance of each cut point extraction is set to [min_range, max_range], and the final cut point list cut_point_y is obtained. For example, Figure 2 And Figure 3 As shown, after the operation segment is divided, 64 key waveform segments can be obtained, each containing a fixed length of sampling points, which are used for subsequent template construction and classifier training.
[0016] Step 3: Based on the principle of quantum-resistant cryptographic algorithms, a multi-source fusion method at the feature level, model level, and decision level is proposed, and a template attack classifier is constructed using intermediate variables to obtain the probability distribution of template classification.
[0017] Specifically, first, the corresponding y[i] operation segment is extracted according to the segmentation point, and a total of 256 waveform segments are obtained. For each signature waveform in the training set, the waveform segment corresponding to the position is extracted to form a training sample pair (trace, y[i]). To reduce the high-dimensional waveform calculation complexity, LDA is used to reduce each waveform segment to a preset dimension. LDA optimizes the class separability according to the label, which can more effectively enhance the subsequent classification performance. The within-class mean and covariance matrix of the reduced features are calculated to construct a classification model. The model can calculate the probability density belonging to each class according to the test waveform segment. For the waveform segment in the test set, the likelihood value of each class is calculated after inputting the established template model, and the prediction probability distribution is obtained after normalization. The "feature level" refers to splicing the waveforms in the corresponding time window of the electromagnetic wave and the energy wave as a joint input, and then performing template attack; the "model level" refers to training classification models for electromagnetic and energy respectively, and the obtained probability constraints are used to construct a factor graph; the "decision level" refers to voting the recovered keys of each model.
[0018] Step 4: Construct a factor graph and execute a belief propagation algorithm to recover the key.
[0019] Specifically, the intermediate variable triple (y[i], c[i], z[i]) of each signature is a constraint factor node, which constitutes a factor graph. y[i] in each node comes from the probability distribution output by the template attack, and joint inference is performed through the belief propagation algorithm. The algorithm flow is as follows: first, construct a factor graph, and each group of signature samples constitutes a subgraph. The nodes in the graph are divided into variable nodes and factor nodes, the variable nodes represent the private keys to be recovered, and the factor nodes represent the constraints; then, the template attack probability output obtained in step 3 is used to initialize the prior distribution of each variable node; execute the Belief Propagation algorithm, iterate and transmit messages in the constructed factor graph, calculate the marginal distribution of each private key byte, transmit the current belief from the variable node to the factor node, and the factor node returns consistency information according to the constraint rule. The probability distribution of the variable node is updated after each iteration until convergence; finally, the maximum a posteriori probability value of each variable node is selected as the prediction result, and the complete private key vector is recovered.
Claims
1. A multi-source fusion side-channel analysis method against quantum-resistant cryptographic algorithms, characterized in that, The method comprises the following steps: Step 1: First, collect the electromagnetic and energy side information of the running anti-quantum cryptographic algorithm device during the signature process, and use the trigger signal to locate the effective waveform segment in the side information; Step 2: Analyze the side information waveform of the signature operation, and divide it into several segments according to the characteristics; Step 3: Combined with the principle of anti-quantum cryptographic algorithm, a multi-source fusion method of feature level, model level and decision level is proposed, an intermediate variable is used to construct a template attack classifier, and the probability distribution of template classification is obtained; Step 4: Construct a factor graph and execute a belief propagation algorithm to recover the key.
2. The multi-source fusion side-channel analysis method against quantum-resistant cryptographic algorithms of claim 1, wherein, In step 3, combined with the principle of Dilithium algorithm, a multi-source fusion analysis strategy is used: "The feature level" refers to aligning and splicing the waveform data from multiple physical channels in the corresponding time window to form a joint feature input for training a unified template attack classifier. This method can extract more information in the same operation, which helps to improve the discrimination ability of the classifier; "The model level" refers to training independent template classification models for each type of physical channel, extracting their respective probability distributions, and all channel output probabilities participating in the subsequent factor graph construction and belief propagation calculation; "The decision level" refers to designing a voting mechanism to comprehensively judge multiple recovery results based on the key candidates recovered independently by each channel, which can effectively avoid false recovery caused by false judgment or interference of a single channel, and improve the accuracy of the final key recovery.