Cipher-text attack protection method and device, equipment and storage medium

CN122764567APending Publication Date: 2026-09-15北京银联金卡科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610797467.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-04
Publication Date
2026-09-15

Smart Images

  • Figure CN122764567A_ABST
    Figure CN122764567A_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a ciphertext attack protection method and device, equipment and a storage medium. The method counts the first failure number of continuous unpacking failures of a target application by using a first counter. The second failure number of unpacking failures of the target application within a target time length is counted by using a second counter. In the case of updating the first failure number or the second failure number, the safety risk level is determined according to the first failure number and the second failure number. The corresponding risk protection means is taken for the target application according to the safety risk level. The application realizes the active defense against the ciphertext attack by recording the unpacking failure number by using the counter. Meanwhile, the application realizes the double risk monitoring in the time dimension and the number dimension by using two counters, so that the attack can be responded quickly when the attack occurs, the attacker can be prevented from bypassing the single-layer protection through the tactical operation, and the defense effect is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security, and includes, but is not limited to, a method, apparatus, device, and storage medium for protecting against selective ciphertext attacks. Background Technology

[0002] Against the backdrop of accelerated global digital transformation, enterprises are adopting digital technologies to improve business processes and increase efficiency in order to adapt to the new situation and achieve long-term development. However, with the rapid expansion of digital infrastructure, especially in critical sectors such as government and finance, data security faces unprecedented challenges. Currently widely used cryptographic systems based on traditional public-key algorithms such as RSA and ECC are vulnerable to quantum computing power, as quantum computers can break these encryption methods in a short time using Shor and Grover algorithms. To address this threat, the international community is actively promoting the development of post-quantum cryptography (PQC) standards. However, current international standards mainly focus on algorithm-level security and do not specify proactive defense mechanisms against such chosen-ciphertext attacks, especially lacking detection and response strategies for abnormal decapsulation requests. Summary of the Invention

[0003] In view of this, the selective ciphertext attack protection method, apparatus, device, and storage medium provided in the embodiments of this application can proactively defend against data attacks at the physical layer.

[0004] The selected ciphertext attack protection method, apparatus, device, and storage medium provided in this application embodiment are implemented as follows: One aspect of this application provides a method for protecting against selective ciphertext attacks, the method comprising: The first counter is used to count the first failure number of consecutive decapsulation failures of the target application. The second counter is used to count the second failure number of the target application's decapsulation failure. If the first or second failure count is updated, the security risk level is determined based on the first and second failure counts. Based on the security risk level, take corresponding risk protection measures for the target application.

[0005] In one possible implementation, corresponding risk protection measures are taken for the target application based on the security risk level, including: If the security risk level is Level 1, record the failure log corresponding to this decapsulation failure operation; If the security risk level is level two, lock the current key and stop key decryption operations until the key is regenerated; When the security risk level is level 3, lock the current key and stop the key decryption operation, while controlling the target application to enter a locked or alarm state.

[0006] In one possible implementation, the method also includes: The key decryption events of the target application are continuously recorded through an event sequence, which includes a success event, a first failure event, and a second failure event. The security risk level is determined based on the number of first and second failures, including: The risk status of the target application is determined based on the number of the first failure event and the number of the second failure event in the time series. The safety risk level is determined based on the number of first failures, the number of second failures, and the risk status.

[0007] In one possible implementation, the security risk level is determined based on the first number of failures, the second number of failures, and the risk status, including: If the number of first failures is less than the first threshold and the number of second failures is less than the second threshold, the security risk level is determined to be Level 1. If the number of first failures is greater than or equal to the first threshold and the risk status is risky, or if the number of second failures is greater than or equal to the second threshold and the risk status is risky, the security risk level is determined to be the second level. If the number of first failures is greater than or equal to the first threshold, the number of second failures is greater than or equal to the second threshold, and the risk status is risky, the security risk level is determined to be the third level.

[0008] In one possible implementation, the security risk level is determined based on the first number of failures and the second number of failures, including: If the number of first failures is less than the first threshold and the number of second failures is less than the second threshold, the security risk level is determined to be Level 1. If the number of first failures is greater than or equal to the first threshold, or the number of second failures is greater than or equal to the second threshold, the security risk level is determined to be the second level. If the number of first failures is greater than or equal to the first threshold and the number of second failures is greater than or equal to the second threshold, the security risk level is determined to be level three.

[0009] In one possible implementation, the method further includes, in the case of updating the first or second failure count: The key decryption response time of the target application is delayed according to preset rules.

[0010] In one possible implementation, the method also includes: If a new success event is added to the event sequence, the key decryption response time of the target application will be reset to the default time.

[0011] Another aspect of this application embodiment also provides a selective ciphertext attack protection device, the device comprising: The first statistics module is used to count the first failure number of consecutive decapsulation failures of the target application through a first counter. The second statistics module is used to count the second failure number of the target application decapsulation failure through the second counter; The risk level determination module is used to determine the security risk level based on the first failure count and the second failure count when the first failure count or the second failure count is updated. The risk handling module is used to take corresponding risk protection measures for target applications based on their security risk levels.

[0012] In one possible implementation, the risk handling module is further used for: If the security risk level is Level 1, record the failure log corresponding to this decapsulation failure operation; If the security risk level is level two, lock the current key and stop key decryption operations until the key is regenerated; When the security risk level is level 3, lock the current key and stop the key decryption operation, while controlling the target application to enter a locked or alarm state.

[0013] In one possible implementation, the device further includes: The event logging module is used to continuously record key decryption events of the target application through event sequences. Key decryption events include success events, first failure events, and second failure events. The risk level determination module is further used for: The risk status of the target application is determined based on the number of the first failure event and the number of the second failure event in the time series. The safety risk level is determined based on the number of first failures, the number of second failures, and the risk status.

[0014] In one possible implementation, the risk level determination module is further used for: If the number of first failures is less than the first threshold and the number of second failures is less than the second threshold, the security risk level is determined to be Level 1. If the number of first failures is greater than or equal to the first threshold and the risk status is risky, or if the number of second failures is greater than or equal to the second threshold and the risk status is risky, the security risk level is determined to be the second level. If the number of first failures is greater than or equal to the first threshold, the number of second failures is greater than or equal to the second threshold, and the risk status is risky, the security risk level is determined to be the third level.

[0015] In one possible implementation, the risk level determination module is further used for: If the number of first failures is less than the first threshold and the number of second failures is less than the second threshold, the security risk level is determined to be Level 1. If the number of first failures is greater than or equal to the first threshold, or the number of second failures is greater than or equal to the second threshold, the security risk level is determined to be the second level. If the number of first failures is greater than or equal to the first threshold and the number of second failures is greater than or equal to the second threshold, the security risk level is determined to be level three.

[0016] In one possible implementation, upon updating the first failure count or the second failure count, the apparatus further includes: The extended response module is used to delay the key decryption response time of the target application according to preset rules.

[0017] In one possible implementation, the device further includes: The response reset module is used to reset the key decryption response duration of the target application to the default duration when a new success event is added to the event sequence.

[0018] The electronic device provided in this application includes a memory and a processor. The memory stores a computer program that can run on the processor. When the processor executes the program, it implements the method described in this application.

[0019] The computer-readable storage medium provided in this application embodiment stores a computer program thereon, which, when executed by a processor, implements the method provided in this application embodiment.

[0020] In this embodiment, the method uses a first counter to count the first number of consecutive decapsulation failures of the target application. A second counter counts the second number of decapsulation failures of the target application within a specified time period. If either the first or second failure count is updated, a security risk level is determined based on the first and second failure counts. Corresponding risk protection measures are then implemented for the target application based on the security risk level. This application uses a counter to record the number of decapsulation failures for risk management, achieving proactive defense against selected ciphertext attacks. Simultaneously, this application uses two counters to achieve dual risk monitoring in both time and quantity dimensions, ensuring a rapid response when an attack occurs and preventing attackers from bypassing single-layer protection through tactical operations, thus improving the defense effectiveness.

[0021] Furthermore, this application also performs risk classification based on the counting results. By classifying attack behaviors into different severity levels and matching corresponding response measures, it achieves the minimization of false alarm rate, the maximization of attack cost, and the maximization of system survivability, thus establishing a proactive defense system with elasticity, intelligence, and adaptability. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 A flowchart illustrating a method for protecting against ciphertext attacks according to an embodiment of this application is shown. Figure 2 This diagram illustrates a selective ciphertext attack protection device according to an embodiment of this application. Figure 3 A schematic diagram of an electronic device according to an embodiment of this application is shown. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the specific technical solutions of this application will be further described in detail below with reference to the accompanying drawings of the embodiments of this application. The following embodiments are used to illustrate this application, but are not intended to limit the scope of this application.

[0025] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0026] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0027] It should be noted that the terms "first, second, third" used in the embodiments of this application are used to distinguish similar or different objects and do not represent a specific order of objects. It can be understood that "first, second, third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0028] The selected ciphertext attack protection method of this application embodiment can be executed by any electronic device, including but not limited to mobile phones, wearable devices (such as smartwatches, smart bracelets, smart glasses, etc.), tablet computers, laptops, vehicle terminals, PCs (Personal Computers), etc. The function implemented by this method can be achieved by the processor in the electronic device calling program code. Of course, the program code can be stored in a computer storage medium. Therefore, the electronic device includes at least a processor and a storage medium.

[0029] The selected ciphertext attack protection method of this application can be used to protect against selected ciphertext attacks on any application and database. For example, this application can be applied to protect against physical layer selected ciphertext attacks on financial payment devices such as POS machines, ATMs, and smart teller machines. Alternatively, it can also be applied to protect against selected ciphertext attacks on dedicated security hardware responsible for key storage and cryptographic operations, such as TPM chips, HSM modules, and smart cards.

[0030] In the above application scenarios, the methods for selecting encrypted attack protection authentication in related technologies have the following drawbacks: Lack of proactive protection mechanisms: Most implementations rely solely on the mathematical security of the algorithm itself and do not deploy monitoring logic for abnormal access patterns at the hardware or firmware level, allowing attackers to repeatedly submit malicious ciphertext for attempts.

[0031] Intermediate value calculations will still be performed: even if the constructed ciphertext is obviously abnormal or destined to fail verification, the system will still perform the complete decapsulation process (including sensitive operations such as NTT transformation, polynomial multiplication, and key reconstruction), causing unnecessary side-channel leakage.

[0032] No failure state accumulation management: Current solutions generally do not count or track the status of decapsulation failure events, making it impossible to identify potential persistent attack behaviors.

[0033] International standards do not cover physical layer protection: The NIST PQC standardization document and related implementation guidelines do not require proactive defense mechanisms based on usage patterns, resulting in security blind spots in actual deployments.

[0034] Therefore, there is an urgent need for a lightweight, efficient, and proactive protection mechanism to enhance the Kyber algorithm's resistance to attacks in physical environments.

[0035] The following describes in detail the selected ciphertext attack protection scheme of this application embodiment with reference to the accompanying drawings.

[0036] Figure 1A flowchart illustrating a method for protecting against ciphertext attacks according to an embodiment of this application is shown. Figure 1 As shown, the method for protecting against ciphertext attacks in this application embodiment may include the following steps S10-S40.

[0037] For ease of description, the selected ciphertext attack protection method of this application is described using an electronic device as the executing entity. It should be understood that the executing entity of this application embodiment can also be a processor or chip in an electronic device, and this application embodiment does not impose any limitations.

[0038] Step S10: Count the first failure number of consecutive decapsulation failures of the target application using the first counter.

[0039] In one possible implementation, a target application is deployed in the electronic device. This application can be encrypted using a dynamic key for access verification. The access permissions can include at least one of data access permissions and application operation permissions. When an accessor needs to access specific data within the target application or perform a specific application operation, they send corresponding encrypted information to perform a decapsulation operation against the target application's key. In this embodiment, the 'decapsulation operation' covers the 'decapsulation' process in the Key Encapsulation Mechanism (KEM), particularly in scenarios where computation execution fails but verification fails. If the decapsulation operation succeeds, the accessor, after authentication, can access data or perform operations. If the decapsulation operation fails, the accessor, without authentication, cannot access data or perform operations. The encrypted information sent by the accessor can be sent to the electronic device via physical triggering methods such as buttons, keyboards, or touchscreens, or via wired / wireless network transmission.

[0040] Optionally, in the electronic device of this application embodiment, a first counter can be set in a cryptographic chip or security module. This first counter is used to count the first number of consecutive decapsulation failures of the target application. The first counter can be stored in a high-security data area of ​​the cryptographic chip, such as TrustZone or Secure Element. The first number of failures recorded by the first counter can be encrypted and stored, and masking techniques or checksum mechanisms can be used to ensure data integrity.

[0041] In some embodiments, using masking techniques to ensure the integrity of the first failure count can be achieved by not directly storing the actual first failure count. Instead, it is split into multiple randomized "shares" for storage. For example, a Boolean mask or an arithmetic mask can be used to... Split into (XOR mask) or (Arithmetic mask). [The following text appears to be incomplete and requires further context: "will..."] and These are stored in different storage areas or registers and are randomized with each update. A checksum mechanism is used to store a checksum (or message authentication code) calculated based on the stored counter value. Common implementations include simple checksum methods such as CRC (Cyclic Redundancy Check) and XOR summation, or secure checksum methods such as HMAC (Hash Message Authentication Code) and CMAC (Clock Cipher Message Authentication Code), which use a key known only to the device itself for calculation.

[0042] Furthermore, in this embodiment, the electronic device can monitor and record the results of the decapsulation operation in real time. Each time the electronic device detects a failure in the decapsulation operation, it determines whether the previous decapsulation operation was a failure. If the previous decapsulation operation was a failure, a first counter increments by one based on the current first failure count.

[0043] Optionally, the first counter is a continuous failure counter, and the recorded number of first failures can be stored in a volatile memory cell or in a non-volatile memory cell (such as EEPROM, Flash or a dedicated security register).

[0044] Step S20: Count the second failure number of the target application decapsulation failure using a second counter.

[0045] In one possible implementation, in addition to the first counter, a second counter can be set in the cryptographic chip or security module in this embodiment. This second counter is used to count the second failure count of the target application's decapsulation failure. The storage location of the second counter can be the same as the first counter, and the storage location and method of the second failure count can also be the same as the first failure count. That is, the second counter can be stored in the high-security data area of ​​the cryptographic chip, such as TrustZone or Secure Element. The second failure count recorded by the second counter can be encrypted and stored, and masking techniques or checksum mechanisms can be used to ensure data integrity.

[0046] In some embodiments of this application, the electronic device can monitor and record the results of the decapsulation operation in real time. Each time the electronic device detects a decapsulation operation failure, a second counter increments by one based on the current second failure count. That is, after a decapsulation operation fails, at least one of the first and second counters will begin counting.

[0047] Optionally, the second counter is a cumulative failure counter, and the recorded number of second failures can be stored in a non-volatile memory unit to ensure that the state can be recovered after power failure.

[0048] Step S30: If the first failure count or the second failure count is updated, determine the security risk level based on the first failure count and the second failure count.

[0049] In one possible implementation, the electronic device determines the corresponding first failure count or second failure count update each time the first counter or the second counter counts again, and determines the security risk level faced by the current target application based on the updated first failure count, second failure count and preset risk classification rules, so as to further take different risk protection measures in a targeted manner.

[0050] In some embodiments, the electronic device can directly determine the security risk level based on a first number of failures and a second number of failures. For example, if the first number of failures is less than a first threshold and the second number of failures is less than a second threshold, the security risk level is determined to be level one. If the first number of failures is greater than or equal to the first threshold, or the second number of failures is greater than or equal to the second threshold, the security risk level is determined to be level two. If the first number of failures is greater than or equal to the first threshold and the second number of failures is greater than or equal to the second threshold, the security risk level is determined to be level three.

[0051] Optionally, the first and second thresholds are pre-set parameters used for risk assessment in terms of frequency and quantity, respectively. If the first number of failures is greater than or equal to the first threshold, the electronic device can determine that the target application has been subjected to a high-frequency selected ciphertext attack. If the second number of failures is greater than or equal to the second threshold, the electronic device can determine that the target application has been subjected to a large number of selected ciphertext attacks. Therefore, the first level indicates that the target application has suffered from both a low frequency and a high number of selected ciphertext attacks. The second level indicates that the target application has suffered from a high frequency or a high number of selected ciphertext attacks. The third level indicates that the target application has suffered from both a high frequency and a high number of selected ciphertext attacks. In other words, the higher the risk level, the greater the attack risk to the target application.

[0052] Based on the above technical features, the risk determination scheme of this application embodiment only needs to set two counters (continuous failure counter and cumulative failure counter), several comparison logics and a state machine to determine the risk intensity of the selected ciphertext attack currently suffered by the target application. It does not require modification of the complex mathematical operations of the Kyber algorithm core. The whole determination process is simple, has low computational overhead and strong applicability.

[0053] In other embodiments, the electronic device in this application can also continuously record key decryption events of the target application through an event sequence, and determine the current risk status of the target application based on the key decryption time recorded in the event sequence. Then, it determines the security risk level based on the first failure count, the second failure count, and the risk status. That is, the electronic device can continuously record key decryption events of the target application through an event sequence, including success events, first failure events, and second failure events. When the electronic device counts again each time the first counter or the second counter, it determines the corresponding first failure count or second failure count, and updates the event sequence. The risk status of the target application is judged based on the number of first failure events and the number of second failure events in the time sequence. The security risk level is determined based on the first failure count, the second failure count, the risk status, and a preset risk grading rule.

[0054] Optionally, in the embodiments of this application, the electronic device will generate a success event, a first failure event, and a second failure event for different situations of the decapsulation and encapsulation operation after receiving ciphertext information. A success event indicates that the decapsulation operation was successful. A first failure event indicates that the ciphertext parameters for decapsulation are invalid, and the decapsulation operation fails. A second failure event indicates that the ciphertext parameters for decapsulation are valid, the operation succeeds, but the decapsulation and encapsulation operation fails. For example, the first failure event could be due to an invalid format such as the length of the ciphertext, while the second failure event could be due to a valid format such as the length of the ciphertext, but the content cannot be decapsulated.

[0055] Electronic devices can determine the risk status of a target application based on the number of first and second failure events in the time series each time a first or second counter recounts. This risk status can include both risk and security. The risk status can be obtained by calculating a risk assessment value, which is continuously updated by the electronic device under any risk status. This risk status value is obtained by calculating the ratio of the number of first and second failure events. If the risk status value is greater than 1, it indicates that the number of first failure events is greater than the number of second failure events, suggesting that the corresponding cryptographic algorithm is likely under attack rather than normal operation. In this case, the attacker will continuously attempt to call the cryptographic algorithm, with the most effective attempts often stemming from real-world scenarios. Since attack methods are diverse, based on select-choice ciphertext attacks, a wide range of attacks, including side-channel attacks, can be launched. However, regardless of the attack method, the characteristic is always successful computation but failed decapsulation. Therefore, continuous sequence detection is a crucial computational step in protecting against such attacks. In other words, this sequence detection mechanism can not only count failed decapsulation operations but also the difference between successful and failed operations, effectively avoiding false detections and reducing the false alarm rate.

[0056] For example, the risk status judgment method of the event detection mechanism in the electronic device in this application embodiment is as follows:

[0057] Optionally, the electronic device may be classified as having a first level of security risk if the first number of failures is less than a first threshold and the second number of failures is less than a second threshold. If the first number of failures is greater than or equal to the first threshold and the risk status is "risk," or if the second number of failures is greater than or equal to the second threshold and the risk status is "risk," the security risk level may be classified as having a second level of security risk. If the first number of failures is greater than or equal to the first threshold, the second number of failures is greater than or equal to the second threshold, and the risk status is "risk," the security risk level may be classified as having a third level of security risk.

[0058] Based on the aforementioned technical features, this application upgrades security protection from static threshold triggering to dynamic behavioral risk assessment. By continuously monitoring event sequences, a buffer zone is established between the "normal" and "locked" states of the key, thereby more intelligently distinguishing between environmental noise and real attacks. In risky states, progressive responses such as delays and logging can be implemented, avoiding misjudgments due to occasional errors while remaining sensitive to attackers' probing behaviors. Simultaneously, the risk value can dynamically regress with successful operations, giving the system self-healing capabilities. This design not only enhances the concealment of the attack and the uncertainty of the attacker, but also achieves a better balance between security and availability.

[0059] In other embodiments, the electronic device can receive ciphertext at predetermined response time intervals and perform key decryption based on the received ciphertext. Therefore, the electronic device not only restricts the counting operation but can also introduce a time dimension to force a delay in the key decryption time interval. For example, upon updating the first or second failure count, the electronic device can delay the key decryption response time of the target application according to preset rules. Furthermore, if a success event is added to the event sequence, the electronic device can also reset the key decryption response time of the target application to a default time.

[0060] Optionally, the preset rule can be to force a delay in response time after each failure. When there is one failure, a 1-second delay is forced; when there are two failures, a 2-second delay is forced; when there are three failures, a 4-second delay is forced; when there are four failures, an 8-second delay is forced, and so on, that is, the delay time for each response increases exponentially.

[0061] Based on the above technical features, the embodiments of this application can replace binary blocking with time penalty by setting a delayed response mechanism, which not only deters attackers due to excessive time costs, but also preserves service continuity for legitimate users, thus achieving low-cost and highly intelligent proactive defense.

[0062] Step S40: Take corresponding risk protection measures for the target application according to the security risk level.

[0063] In one possible implementation, the electronic device in this embodiment pre-sets different risk protection measures for different security risk levels. That is, when a failed decapsulation operation occurs, the electronic device can calculate the corresponding security risk level and trigger the corresponding response mechanism to employ the appropriate risk protection measures. For example, if the security risk level is level one, a failure log corresponding to this failed decapsulation operation is recorded. If the security risk level is level two, the current key is locked and the key decryption operation is stopped until a new key is generated. If the security risk level is level three, the current key is locked and the key decryption operation is stopped, while simultaneously controlling the target application to enter a locked or alarm state.

[0064] Therefore, this application's embodiments avoid the risk of false positives caused by "one-size-fits-all" locking by classifying attack behaviors into different severity levels. In the event of occasional errors, only minor intervention is performed to ensure that legitimate users are not affected. As the threat escalates, the response measures are strengthened at each level, forcing attackers to pay higher costs when breaking through each line of defense, greatly consuming their time and technical resources. At the same time, the graded mechanism retains the system's self-healing channel (such as reducing the risk level if the operation is successful), which not only ensures business continuity but also provides a complete attack trajectory for post-event auditing, enabling the protection system to evolve from a rigid "passive triggering" to an "active defense" with intelligent decision-making capabilities.

[0065] Based on the aforementioned technical features, this application's embodiments introduce a lightweight dual-counter mechanism of consecutive failures and cumulative failures, combined with risk state detection and exponential backoff delayed response. This achieves proactive protection against select-choice ciphertext attacks without increasing hardware burden or modifying the Kyber core algorithm. The scheme constructs a three-dimensional monitoring system from two dimensions: attack frequency and total attack volume. It can quickly block short-term, intensive attacks and effectively identify long-term penetration behaviors, resisting various side-channel attacks. Simultaneously, through dynamic evaluation of event sequences based on risk states, it accurately distinguishes between environmental noise and real attacks, achieving a progressive response while tolerating occasional false positives, thus balancing system security and business continuity. Furthermore, the multi-detection structure combining volatile and non-volatile storage ensures real-time response speed while preventing attackers from bypassing protection through power-off restarts. This provides an efficient, intelligent, and easily integrated physical security enhancement scheme for the practical deployment of post-quantum cryptography algorithms in resource-constrained devices.

[0066] It should be understood that although the steps in the above flowcharts are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the above flowcharts may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0067] Based on the foregoing embodiments, this application provides a selective ciphertext attack protection device, which includes various modules and units included in each module, and can be implemented by a processor; of course, it can also be implemented by specific logic circuits; in the implementation process, the processor can be a central processing unit (CPU), microprocessor (MPU), digital signal processor (DSP) or field programmable gate array (FPGA), etc.

[0068] Figure 2 A schematic diagram of a selective ciphertext attack protection device according to an embodiment of this application is shown. Figure 2 As shown, the encrypted attack protection device selected in this application embodiment includes: The first statistics module 20 is used to count the first failure number of consecutive decapsulation failures of the target application through a first counter; The second statistics module 21 is used to count the second failure number of the target application decapsulation failure through the second counter; Risk level determination module 22 is used to determine the security risk level based on the first failure count and the second failure count when the first failure count or the second failure count is updated. Risk handling module 23 is used to take corresponding risk protection measures for target applications according to the security risk level.

[0069] In one possible implementation, the risk handling module 23 is further used for: If the security risk level is Level 1, record the failure log corresponding to this decapsulation failure operation; If the security risk level is level two, lock the current key and stop key decryption operations until the key is regenerated; When the security risk level is level 3, lock the current key and stop the key decryption operation, while controlling the target application to enter a locked or alarm state.

[0070] In one possible implementation, the device further includes: The event logging module is used to continuously record key decryption events of the target application through event sequences. Key decryption events include success events, first failure events, and second failure events. Risk level determination module 22 is further used for: The risk status of the target application is determined based on the number of the first failure event and the number of the second failure event in the time series. The safety risk level is determined based on the number of first failures, the number of second failures, and the risk status.

[0071] In one possible implementation, the risk level determination module 22 is further used for: If the number of first failures is less than the first threshold and the number of second failures is less than the second threshold, the security risk level is determined to be Level 1. If the number of first failures is greater than or equal to the first threshold and the risk status is risky, or if the number of second failures is greater than or equal to the second threshold and the risk status is risky, the security risk level is determined to be the second level. If the number of first failures is greater than or equal to the first threshold, the number of second failures is greater than or equal to the second threshold, and the risk status is risky, the security risk level is determined to be the third level.

[0072] In one possible implementation, the risk level determination module 22 is further used for: If the number of first failures is less than the first threshold and the number of second failures is less than the second threshold, the security risk level is determined to be Level 1. If the number of first failures is greater than or equal to the first threshold, or the number of second failures is greater than or equal to the second threshold, the security risk level is determined to be the second level. If the number of first failures is greater than or equal to the first threshold and the number of second failures is greater than or equal to the second threshold, the security risk level is determined to be level three.

[0073] In one possible implementation, upon updating the first failure count or the second failure count, the apparatus further includes: The extended response module is used to delay the key decryption response time of the target application according to preset rules.

[0074] In one possible implementation, the device further includes: The response reset module is used to reset the key decryption response duration of the target application to the default duration when a new success event is added to the event sequence.

[0075] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0076] It should be noted that, in the embodiments of this application... Figure 2 The module division shown in the selected ciphertext attack protection device is illustrative and represents only one logical functional division; in actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, exist as separate physical units, or be integrated into one unit by two or more units. The integrated units described above can be implemented in hardware, as software functional units, or in a combination of software and hardware.

[0077] It should be noted that, in the embodiments of this application, if the above-described methods are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0078] Figure 3 A schematic diagram of an electronic device according to an embodiment of this application is shown. For example... Figure 3 As shown in the figure, this application provides an electronic device, which can be a server, and its internal structure diagram can be as follows. Figure 3 As shown, the electronic device includes a processor 320, a memory, and a transceiver 340 connected via a system bus 310. The processor 320 provides computing and control capabilities. The memory includes a non-volatile storage medium 331 and internal memory 332. The non-volatile storage medium 331 stores an operating system, computer programs, and a database. The internal memory 332 provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium 331. The database stores data. The transceiver 340 communicates with external terminals via a network connection. The computer program is executed by the processor 320 to implement the aforementioned methods.

[0079] This application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor 320, implements the steps of the method provided in the above embodiments.

[0080] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the steps in the method provided in the above-described method embodiments.

[0081] Those skilled in the art will understand that Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the electronic device to which the present application is applied. The specific electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0082] In one possible implementation, the apparatus provided in this application can be implemented as a computer program, which can be configured as follows: Figure 3 The device operates on the electronic device shown. The memory of the electronic device can store the various program modules that make up the above-described apparatus. The computer program composed of the various program modules causes the processor 320 to execute the steps of the methods in the various embodiments of this application described in this specification.

[0083] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium, storage medium, and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0084] It should be understood that the phrases "one embodiment," "an embodiment," or "some embodiments" mentioned throughout the specification mean that a specific feature, structure, or characteristic related to an embodiment is included in at least one embodiment of this application. Therefore, phrases such as "in one possible implementation," "in one embodiment," or "in some embodiments" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above-described processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above-described embodiments are merely for descriptive purposes and do not represent the superiority or inferiority of the embodiments. The descriptions of the various embodiments above tend to emphasize the differences between the various embodiments; their similarities or commonalities can be referred to mutually, and for the sake of brevity, they will not be repeated here.

[0085] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three kinds of relationships. For example, object A and / or object B can represent three situations: object A exists alone, object A and object B exist simultaneously, and object B exists alone.

[0086] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0087] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The embodiments described above are merely illustrative. For example, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple modules or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or modules can be electrical, mechanical, or other forms.

[0088] The modules described above as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules. They may be located in one place or distributed across multiple network units. Some or all of the modules may be selected to achieve the purpose of this embodiment according to actual needs.

[0089] In addition, each functional module in the various embodiments of this application can be integrated into one processing unit, or each module can be a separate unit, or two or more modules can be integrated into one unit; the integrated modules can be implemented in hardware or in the form of hardware plus software functional units.

[0090] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, read-only memory (ROM), magnetic disks, or optical disks.

[0091] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.

[0092] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.

[0093] The features disclosed in the several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.

[0094] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0095] The above description is merely an embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method of selective ciphertext attack protection, characterized by, The method includes: The first counter is used to count the first failure number of consecutive decapsulation failures of the target application. The second counter is used to count the second failure number of the target application's decapsulation failure. If the first failure count or the second failure count is updated, the security risk level is determined based on the first failure count and the second failure count; Based on the security risk level, corresponding risk protection measures are taken for the target application.

2. The method of claim 1, wherein, The measures taken to protect the target application according to the security risk level include: If the security risk level is Level 1, record the failure log corresponding to this decapsulation failure operation; If the security risk level is level two, lock the current key and stop key decryption operations until the key is regenerated; When the security risk level is level three, the current key is locked and the key decryption operation is stopped. At the same time, the target application is controlled to enter a locked or alarm state.

3. The method of claim 1, wherein, The method further includes: The key decryption events of the target application are continuously recorded through an event sequence, including a success event, a first failure event, and a second failure event. The step of determining the security risk level based on the first number of failures and the second number of failures includes: The risk status of the target application is determined based on the number of first failure events and the number of second failures in the time series. The security risk level is determined based on the first number of failures, the second number of failures, and the risk status.

4. The method of claim 3, wherein, The step of determining the security risk level based on the first number of failures, the second number of failures, and the risk status includes: If the first number of failures is less than the first threshold and the second number of failures is less than the second threshold, the security risk level is determined to be the first level. If the first number of failures is greater than or equal to the first threshold and the risk status is risky, or if the second number of failures is greater than or equal to the second threshold and the risk status is risky, the security risk level is determined to be the second level. If the first number of failures is greater than or equal to the first threshold, the second number of failures is greater than or equal to the second threshold, and the risk status is risky, the security risk level is determined to be the third level.

5. The method of claim 1, wherein, The step of determining the security risk level based on the first number of failures and the second number of failures includes: If the first number of failures is less than the first threshold and the second number of failures is less than the second threshold, the security risk level is determined to be the first level. If the first number of failures is greater than or equal to the first threshold, or the second number of failures is greater than or equal to the second threshold, the security risk level is determined to be the second level. If the first number of failures is greater than or equal to the first threshold and the second number of failures is greater than or equal to the second threshold, the security risk level is determined to be the third level.

6. The method of claim 3, wherein, In the event that the first failure count or the second failure count is updated, the method further includes: The key decryption response time of the target application is delayed according to preset rules.

7. The method according to claim 6, characterized in that, The method further includes: If a new success event is added to the event sequence, the key decryption response time of the target application will be reset to the default time.

8. A selective ciphertext attack protection device, characterized in that, The device includes: The first statistics module is used to count the first failure number of consecutive decapsulation failures of the target application through a first counter. The second statistics module is used to count the second failure number of the target application's decapsulation failure by using a second counter; The risk level determination module is used to determine the security risk level based on the first failure count and the second failure count when the first failure count or the second failure count is updated. The risk handling module is used to take corresponding risk protection measures for the target application based on the security risk level.

9. An electronic device comprising a memory and a processor, the memory storing a computer program executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 7.