Cross-device artificial intelligence side channel analysis method for cryptographic algorithm
By constructing a key leakage model and training a neural network through a multi-device model and a global domain-adaptive cross-device modeling method, the portability problem of cross-device modeling-type side-channel analysis is solved, and the accurate recovery of symmetric cryptographic algorithm keys is achieved.
Patent Information
- Application Number
- CN202511293488.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-11
- Publication Date
- 2025-11-14
AI Technical Summary
Traditional deep learning-based cross-device modeling cryptographic side-channel analysis methods perform poorly under different hardware manufacturing processes and working environments, leading to portability issues and making it difficult to effectively recover the keys of symmetric cryptographic algorithms.
A cross-device modeling-based side-channel analysis method based on multi-device models and global domain adaptation is adopted. By constructing a key leakage model, a neural network model is trained and fine-tuned on a multi-device dataset to predict the intermediate value information of the side-channel waveform, and finally recover the key of the symmetric cryptographic algorithm.
It effectively alleviates the portability problem of cross-device modeling-type side-channel analysis, can accurately recover the key of symmetric cryptographic algorithms, and improves the performance and applicability of the analysis method.
Smart Images

Figure CN120956403A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a cross-device artificial intelligence side-channel analysis method for cryptographic algorithms, specifically a cross-device modeling-based side-channel analysis method based on multi-device models and global domain adaptation, belonging to the field of information security cryptography technology. Background Technology
[0002] The core characteristic of symmetric cryptography is that the sender and receiver use the same key to encrypt and decrypt data. Common symmetric cryptography algorithms include AES and my country's SM4 algorithm. If the key in a symmetric cryptography protocol is leaked, the communication can be completely compromised. Therefore, it is necessary to study the key leakage security issues inherent in symmetric cryptography.
[0003] While symmetric cryptographic algorithms can be rigorously proven secure in theory under certain mathematical assumptions and specific security models, in real-world applications, electronic devices leak physical information such as electromagnetic radiation and energy consumption during the execution of these algorithms. This physical information may have an inherent connection with the key or intermediate values of the cryptographic algorithm, allowing researchers to potentially recover the key or intermediate values using side-channel analysis. For symmetric cryptographic algorithms, researchers often use deep learning-based cross-device modeling side-channel analysis methods. Cross-device modeling involves researchers first collecting side-channel data on a fully controllable modeling device similar to the target device, building and training a neural network model, and then using this model to analyze the side-channel data of the target device to obtain the secret intermediate values and recover the key.
[0004] In real-world scenarios, traditional deep learning-based cross-device modeling-based cryptographic side-channel analysis methods suffer from poor performance due to differences in hardware manufacturing processes and operating environments between the modeling device and the target device. In 2019, Shivam et al. published "Mind the Portability: A Warriors Guide through Realistic Profiled Side-channel Analysis" at the Network and Distributed System Security Symposium, collectively referring to all factors contributing to the failure of modeling-based cryptographic side-channel analysis methods as the side-channel analysis model portability problem. Solving the portability problem is crucial for improving the performance and applicability of cross-device modeling-based cryptographic side-channel analysis methods. In 2021, Cao et al. published "Cross-Device Profiled Side-Channel Attack with Unsupervised Domain Adaptation" at Transactions on Cryptographic Hardware and Embedded Systems, utilizing transfer learning techniques to adjust the pre-trained model parameters to adapt to the waveform data feature distribution of the target device. This method solved the portability problem under three different environmental variable conditions using unlabeled target device waveform data; however, its performance was poor on datasets with low signal-to-noise ratios. Summary of the Invention
[0005] The purpose of this invention is to address the shortcomings and defects of existing technologies, and to solve the problem of poor portability in cross-device modeling side-channel information analysis processes. This invention creatively proposes a cross-device artificial intelligence side-channel analysis method for cryptographic algorithms. This method can effectively mitigate the impact of portability issues, analyze side-channel information, and thereby recover the cryptographic algorithm key.
[0006] The present invention is achieved using the following technical solution.
[0007] A cross-device AI side-channel analysis method for cryptographic algorithms includes the following steps: Step 1: Collect side information waveforms from multiple devices running symmetric cryptographic algorithm modeling when performing secret information-related operations; Among them, modeling equipment refers to equipment that is fully controllable and similar to the target equipment; Step 2: Based on the principle of symmetric cryptography, construct a key leakage model. Using side information waveforms as samples and the corresponding median value of each side information waveform as a label, combine the samples and labels from multiple modeling devices to construct a multi-device dataset. Step 3: Use a cross-device modeling-based side-channel analysis method with multi-device modeling and global domain adaptation to model on a multi-device dataset, and obtain a pre-trained model that can predict the corresponding label information based on the side information waveform; Step 3.1: Build a neural network model and set hyperparameters for the network; Step 3.2: Use the loss function shown in Equation (1) to train the neural network with a multi-device dataset to obtain a pre-trained model;
[0008] in, The classification loss of the waveform data from the modeling device is calculated using the cross-entropy loss function. This represents sample data from the modeling equipment. This represents the label data of the modeling equipment; Step 4: Collect side information of the target device running the symmetric cryptography algorithm, and fine-tune the pre-trained model using the waveform dataset of the target device with the loss function shown in Equation (2) to obtain the fine-tuned model. Use the fine-tuned model to predict the corresponding intermediate value information of the side information waveform.
[0009]
[0010] in, Represents the source domain and target domain The distance between them is calculated as shown in equation (3). This is a penalty coefficient that needs to be manually tuned in different implementations. and These are the sample data of the modeling device and the target device, respectively. Layer hidden representation, It is a given mapping function. It is a kernel function; Step 5: Calculate the symmetric cryptographic key using the predicted intermediate value information to complete key recovery.
[0011] Beneficial effects This invention enables the modeling, feature extraction, and label prediction of side information waveforms in symmetric cryptography algorithms to obtain intermediate value information related to the key within the algorithm. This method effectively mitigates the impact of portability issues by analyzing side information, thereby recovering the algorithm key. Attached Figure Description
[0012] Figure 1 This is a flowchart of the method of the present invention; Figure 2This is a schematic diagram of the S-box substitution function of the algorithm in an embodiment of the method of the present invention; Figure 3 This refers to the partial electromagnetic trace of the algorithm in the method embodiment of the present invention, where multiple modeling devices execute the S-box substitution function. Figure 4 This is a partial electromagnetic trace of the target device executing the S-box substitution function in the algorithm embodiment of the present invention; Figure 5 This is a schematic diagram of the network structure in an embodiment of the method of the present invention; Figure 6 This is a graph showing the guessing entropy result of key recovery in an embodiment of the method of the present invention. Detailed Implementation
[0013] The detailed steps of the method of the present invention will now be described in conjunction with the accompanying drawings and embodiments.
[0014] Example Taking the AES-128 cryptographic algorithm as an example, four Atmel XMEGA 128A1U microcontrollers are used as modeling devices. Their electromagnetic information is collected and combined with the corresponding intermediate value information to perform modeling. Then, another Atmel XMEGA 128A1U microcontroller is used as the target device, and its electromagnetic information is collected. The method of this invention is used to recover the key from the electromagnetic trace of the target device.
[0015] like Figure 1 As shown, a cross-device AI side-channel analysis method for cryptographic algorithms includes the following steps: Step 1: Collect side information waveforms when multiple devices running symmetric cryptographic algorithm modeling perform secret information-related operations.
[0016] Specifically, the S-box substitution function in the first round of the AES-128 encryption process involves secret information such as the message value and the key, which may result in electromagnetic leakage. Therefore, this electromagnetic trace is chosen as the target for analysis. The S-box substitution function process is as follows: Figure 2 As shown, Indicates the first byte of the plaintext. This represents the first byte of the key. When the output value of the S-box substitution function is recovered, the key value can be deduced from the S-box structure and the known plaintext. In this embodiment, 20,000 electromagnetic traces from the modeling device are collected as the training set, 5,000 electromagnetic traces as the validation set, and 10,000 electromagnetic traces from the target device are collected as the test set. A portion of the electromagnetic traces from the modeling device executing the S-box substitution function are shown below. Figure 3 As shown, the partial electromagnetic trace of the target device executing the S-box substitution function is as follows: Figure 4 As shown.
[0017] Step 2: Based on the principle of symmetric cryptography, construct a key leakage model. Using side information waveforms as samples and the corresponding median value of each side information waveform as a label, combine the samples and labels from multiple modeling devices to construct a multi-device dataset.
[0018] Specifically, the Hamming weight model is used as the key leakage model. The Hamming weight of the first byte output by the first round of S-box substitution function is used as intermediate value information to add labels to the electromagnetic traces. In this embodiment, 5000 electromagnetic traces from each of the four modeling devices are combined to obtain the training set, and 1250 electromagnetic traces from each of the four modeling devices are combined to obtain the validation set. The corresponding label information is also combined accordingly.
[0019] Step 3: Use a cross-device modeling-based side-channel analysis method with multi-device modeling and global domain adaptation to model on a multi-device dataset, and obtain a pre-trained model that can predict the corresponding label information based on the side information waveform.
[0020] Step 3.1: Build a neural network model and set hyperparameters for the network.
[0021] Step 3.2: Use the loss function shown in Equation (1) to train the neural network with a multi-device dataset to obtain a pre-trained model.
[0022]
[0023] in, The classification loss of the waveform data from the modeling device is calculated using the cross-entropy loss function. This represents sample data from the modeling equipment. This represents the label data for the modeling equipment.
[0024] Specifically, the neural network structure in the pre-training stage is shown in Table 1. In this embodiment, the batch size is set to 250, the learning rate is set to 0.001, the number of training cycles is set to 200, and the optimizer is set to Adam.
[0025] Table 1 Neural Network Structure
[0026] Step 4: Collect side information of the target device running the symmetric cryptography algorithm, and fine-tune the pre-trained model using the waveform dataset of the target device with the loss function shown in Equation (2) to obtain the fine-tuned model. Use the fine-tuned model to predict the corresponding intermediate value information of the side information waveform.
[0027]
[0028]
[0029] in, Represents the source domain and target domain The distance between them is calculated as shown in equation (3). This is a penalty coefficient that needs to be manually tuned in different implementations. and These are the sample data of the modeling device and the target device, respectively. Layer hidden representation, It is a given mapping function. It is a kernel function.
[0030] Specifically, in this embodiment, 500 electromagnetic traces from the target device are selected from the test set as the fine-tuning training set. A complete network structure diagram of this embodiment is shown below. Figure 5 As shown, in the fine-tuning stage, the maximum mean difference function is used as an indicator to measure domain differences, and the loss function is set as the sum of the label prediction loss and the maximum mean difference loss, as shown in equation (2). In this embodiment... Set it to 0.1. After obtaining the fine-tuned model, predict the corresponding label information of the test set waveforms.
[0031] Step 5: Calculate the symmetric cryptographic key using the predicted intermediate value information to complete key recovery.
[0032] Specifically, based on the probability distribution output by the model, the probability values of the predicted median values corresponding to each waveform are extracted to form a scoring matrix. These probabilities are then logarithmic and summed for each waveform to form the log-likelihood score of each candidate key. All candidate keys are then sorted in descending order of their log-likelihood scores, and the ranking of the true key is the guessing entropy. When the key is successfully recovered, the minimum number of waveform data points required to make the correct key rank 1 is the key recovery metric. The guessing entropy result of key recovery in this embodiment is shown in the figure below. Figure 6 As shown, using 23 waveforms is sufficient to make the correct key rank 1.
[0033] The above detailed description further illustrates the purpose, technical solution, and beneficial effects of the invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A cross-device AI side-channel analysis method for cryptographic algorithms, characterized in that, Includes the following steps: Step 1: Collect side information waveforms from multiple devices running symmetric cryptographic algorithm modeling when performing secret information-related operations; Among them, modeling equipment refers to equipment that is fully controllable and similar to the target equipment; Step 2: Based on the principle of symmetric cryptography, construct a key leakage model. Using side information waveforms as samples and the corresponding median value of each side information waveform as a label, combine the samples and labels from multiple modeling devices to construct a multi-device dataset. Step 3: Use a cross-device modeling-based side-channel analysis method with multi-device modeling and global domain adaptation to model on a multi-device dataset, and obtain a pre-trained model that can predict the corresponding label information based on the side information waveform; Step 3.1: Build a neural network model and set hyperparameters for the network; Step 3.2: Use the loss function shown in Equation (1) to train the neural network with a multi-device dataset to obtain a pre-trained model; 2. Among them, The classification loss of the waveform data from the modeling device is calculated using the cross-entropy loss function. This represents sample data from the modeling equipment. This represents the label data of the modeling equipment; Step 4: Collect side information of the target device running the symmetric cryptography algorithm, and fine-tune the pre-trained model using the waveform dataset of the target device with the loss function shown in Equation (2) to obtain the fine-tuned model. Use the fine-tuned model to predict the corresponding intermediate value information of the side information waveform.
3. ;in, Represents the source domain and target domain The distance between them is calculated as shown in equation (3). This is a penalty coefficient that needs to be manually tuned in different implementations. and These are the sample data of the modeling device and the target device, respectively. Layer hidden representation, It is a given mapping function. It is a kernel function; Step 5: Calculate the symmetric cryptographic key using the predicted intermediate value information to complete key recovery.
4. The cross-device AI side-channel analysis method for cryptographic algorithms as described in claim 1, characterized in that, In step 2, the waveform and label data from multiple modeling devices are combined to construct a multi-device dataset.
5. The cross-device AI side-channel analysis method for cryptographic algorithms as described in claim 1, characterized in that, In step 3, a cross-device modeling-based side-channel analysis method based on multi-device models and global domain adaptation is used to model the multi-device dataset.
6. The cross-device AI side-channel analysis method for cryptographic algorithms as described in claim 1, characterized in that, In step 4, the pre-trained model is fine-tuned using the waveform dataset of the target device with the loss function shown in equation (2) and the calculation method shown in equation (3).