Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

159 results about "Side channel attack" patented technology

In computer security, a side-channel attack is any attack based on information gained from the implementation of a computer system, rather than weaknesses in the implemented algorithm itself (e.g. cryptanalysis and software bugs). Timing information, power consumption, electromagnetic leaks or even sound can provide an extra source of information, which can be exploited.

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Chip security key protection method and system capable of resisting side channel attack

The invention provides a chip security key protection method and system capable of resisting side channel attack, and relates to the technical field of chips, which comprises the following steps of: obtaining a key operation request, performing address space mapping based on a dynamic mapping rule to obtain encrypted key data, decrypting the encrypted key data, fragmenting key intermediate data, and allocating an independent processing channel to perform decoupling operation; and injecting a time-varying noise signal to cover the association between the key and the physical characteristics, and finally performing recombination and reverse conversion to generate a final key output. According to the method, side channel attacks such as power consumption analysis and electromagnetic analysis are effectively resisted, and the security of key storage and operation processes is improved.
Owner:WING SHIELD (SHANGHAI) INTELLIGENT TECH CO LTD

Multi-level security protection method taking persistent memory as core level

The invention discloses a multi-level security protection method taking a persistent memory as a core level, and relates to the technical field of computer storage security. The method comprises the following steps: constructing a cross-level security abstract model, and implementing NUMA perception encryption on the basis of the cross-level security abstract model, including a localization encryption strategy and an intelligent key distribution system; based on a cross-hierarchy security abstract model and NUMA perception encryption, dynamic key hierarchical derivation is realized, a tree topology structure is adopted in the derivation process, generation of a root key and sub-keys of each hierarchy depends on a hierarchical key derivation engine, and cross-node synchronization is completed through an intelligent key distribution system during key cascade update; a side channel attack resisting system is constructed, support for CXL equipment is matched with establishment of a CXL metadata consistency group in NUMA perception encryption, and the security of data transmission and storage of the CXL equipment is guaranteed. According to the invention, the encryption performance is obviously improved.
Owner:Shanxi Taihang Laboratory Co., Ltd.

Safe starting method, device and equipment and readable storage medium

The invention provides a safety starting method, device and equipment and a readable storage medium, and the method comprises the steps: responding to a request for starting chip firmware, and building communication connection with a safety chip through inter-core communication; obtaining a trusted key root from the security component according to the security chip, and performing mutual challenge authentication with the security chip; according to a mutual challenge authentication with the security chip, a mutual legal authentication result is obtained, and the security chip is requested to start security signature verification; and starting the chip firmware according to a result fed back by the security chip that the signature verification is legal through security starting of the security component. Through the technical scheme of the specification, the isolation security component forms a hardware-level protection island, the risk of physical detection or bypass attack is eradicated, the security chip agents all operations to ensure that the root key cannot be directly accessed by the main MCU, the two-way challenge authentication is combined with the dynamic session key to realize tamper-proofing of inter-core communication, and on the premise of completely eradicating the tamper-proofing process from being hijacked, the security of the main MCU is improved. And the starting reliability and timeliness of the chip are ensured.
Owner:XINHUASAN INFORMATION TECH CO LTD

Double-dynamic key encryption circuit and method capable of dynamically changing after dynamic key interpretation

The invention belongs to the technical field of integrated circuit hardware security, and discloses a double-dynamic key encryption circuit and method for dynamically changing dynamic keys after interpretation, and the circuit comprises an external dynamic key module, an internal dynamic key module and a circuit original logic module. And the external dynamic key module generates a dynamic key signal through the linear feedback shift register unit, and the internal dynamic key module generates a D / T selection signal according to a parity check result of the dynamic key signal to dynamically change the type of a trigger in the state machine. The state machine is divided into a group A and a group B, key updating is triggered at an entrance state through a state detection unit, and it is ensured that the key is still dynamically changed after being interpreted. Through a double-dynamic key mechanism and state machine jump confusion, probe detection and bypass attacks are effectively resisted, and the safety of the circuit is remarkably improved. And when the initial key is wrong, circuit jump is abnormal, so that IP protection is realized. The method has the advantages of high attack resistance, dynamic key change, high security and the like.
Owner:ZHEJIANG UNIV

Natural language processing system encryption method, electronic equipment and computer readable medium

The invention discloses a natural language processing system encryption method, electronic equipment and a computer readable medium. The method comprises the following steps: acquiring a character mapping relationship between an original character and an encrypted character determined based on a character encryption algorithm; according to a Token ID transformation algorithm, a Token ID mapping relation between the original Token ID and the transformed Token ID is determined; and according to the character mapping relationship and the Token ID mapping relationship, encrypting a pre-trained natural language processing system, so that the encrypted natural language processing system can output a ciphertext response based on an input ciphertext prompt word. Side channel attacks and middle eavesdropping can be resisted, the exposure risk of original data is remarkably reduced, the data security is improved, mathematical reconstruction of computational logic of the system is avoided, so that the computational overhead is remarkably reduced, the reasoning delay is reduced, the computational efficiency and the response real-time performance are improved, a natural language processing system does not need to be retrained, and the method is easy to implement. The calculation overhead is further reduced, and the encryption efficiency is improved.
Owner:CLP (TIANJIN) NETWORK INFORMATION SECURITY CO LTD

Decentralized virtual identity key collaborative management system based on block chain

The invention discloses a decentralized virtual identity key collaborative management system based on a block chain, and belongs to the field of block chain technology and cryptography. The system comprises a block chain network layer used for distributed storage of key fragments and execution of an automation strategy; the virtual identity management module is used for generating a unique identity identifier (DID) through a threshold signature algorithm after fusing the biological characteristics and the device fingerprints; the key collaborative management module is used for storing the main key in a fragmented manner through a Shamir secret sharing algorithm, and dynamically selecting an encryption algorithm to generate a sub-key according to the security score of the target platform; the verification and auditing module is used for verifying the holding legality of the secret key through a zk-SNARKs technology and injecting random noise to resist side channel attacks; and the block chain network layer, the virtual identity management module, the key collaborative management module and the verification and auditing module are connected with an encrypted communication protocol through an intelligent contract interface.
Owner:HENAN INFORMATIZATION GRP CO LTD

Bidirectional channel authentication communication device and method based on dynamic network fingerprint

The invention provides a two-way channel authentication communication device based on dynamic network fingerprints, which comprises a network fingerprint generation module for generating equipment network fingerprints and platform network fingerprints; the bidirectional authentication protocol module is used for verifying the equipment network fingerprint and the platform network fingerprint; and the self-adaptive verification gateway module is used for generating and updating a dynamic port sequence based on the block chain intelligent contract, and selecting an encryption algorithm and verification strength of transmission data in real time. The invention also provides a two-way channel authentication communication method based on the dynamic network fingerprint. The method comprises the following steps: generating a device network fingerprint and a platform network fingerprint; the platform and the equipment respectively verify whether the fingerprints are matched; network environment parameters are collected in real time, a dynamic port sequence is generated and updated based on a block chain smart contract, and an encryption algorithm and verification strength of transmission data are selected according to real-time network information. According to the method, the three problems of bypass attack defense, bidirectional identity path verification and dynamic network adaptability are solved, and the security of communication authentication is improved.
Owner:SUZHOU CROSS-HEAD DIGITAL TECHNOLOGY CO LTD

Link encryption and key diversification on a hardware security module

A Hardware Security Module (HSM) (900), and method thereof, suitable for use in securely servicing cryptographic requests from multiple tenant applications to preserve end-to-end privacy is provided. A Link Encryption and Key Diversification interoperability (43) between two processors provides cryptographic and logical isolation between multiple tenant applications on the HSM (900) that use and share more than one PCIe Physical Function (30) over more than one Virtual Function (VF) (21) to one or more Crypto Units (CU) (61) for satisfying a request (46) of an HSM cryptographic services. An Output Feedback (OFB) block with CRC support is further provided with encryption and decryption. The HSM as configured is more resistant to side channel attacks.
Owner:THALES DIS CPL USA INC

SMBA encryption algorithm side channel attack method based on CPA and related equipment

The invention relates to the technical field of data security, in particular to a CPA-based SMBA encryption algorithm side channel attack method and related equipment, and the method comprises the steps that a collection probe and a programmable oscilloscope are used to collect side channel leakage information when a cryptographic chip runs an SMBA algorithm, and the side channel leakage information comprises a power consumption curve, a current curve or an electromagnetic signal; selecting a result of whitening transformation in a round function of the SMBA encryption algorithm as an intermediate value, calculating the result of whitening transformation in the encryption process for each input data and the assumed encryption sub-key, and constructing an intermediate value set; performing correlation analysis by using the side channel leakage information and the intermediate value set to deduce an encryption sub-key of an SMBA encryption algorithm; the invention provides an effective security assessment means for the practical application of the SMBA encryption algorithm.
Owner:GUANGDONG VOCATIONAL & TECHNICAL COLLEGE

Unmanned aerial vehicle chip sensitive data access control method based on trusted execution environment

The invention discloses an unmanned aerial vehicle chip sensitive data access control method based on a trusted execution environment, and relates to the technical field of unmanned aerial vehicle security. If data encryption is carried out, real-time confusion processing is carried out on power consumption, electromagnetic signals and execution time of the unmanned aerial vehicle chip; the trusted execution environment isolates a processing space of sensitive data from a logic level to prevent unauthorized access; the real-time confusion processing performs dynamic interference aiming at the core physical characteristics of the side channel attack, so that an attacker cannot derive an encryption key or algorithm logic through a physical signal of a monitoring chip; according to the method, the chip presents highly unpredictable physical characteristics in the encryption process through the synergistic effect of the power consumption, the electromagnetic signal and the execution time, the side channel attack difficulty is remarkably improved, and multi-level guarantee is provided for safe processing of sensitive data of the unmanned aerial vehicle.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Cache row rollback-based processor architecture optimization method free from side channel attack

The invention belongs to the technical field of computer system security. The invention provides a processor architecture optimization method free of side channel attack based on cache line rollback. According to the embodiment of the invention, whether speculative execution of the memory access instruction is consistent with an actual result is checked; and sending a Rollback or Commit signal according to a branch prediction result and an actual branch jump result so as to trigger rollback or submission operation of a cache line. And when the memory access instruction is in a speculative execution state and Cache miss occurs, recording detailed information of the replaced cache line in the Line Buffer. When a Rollback signal is received, the information stored in the Line Buffer is utilized to restore the cache line to a state before branch prediction; when a Commit signal is received, it is confirmed that the previous speculation execution is correct, and the corresponding cache line can continue to be reserved or updated, so that side channel attacks are effectively defended.
Owner:XIDIAN UNIV

Longitudinal federated learning method based on fully homomorphic ScureBoost model

The invention provides a longitudinal federated learning method based on a fully homomorphic ScureBoost model, which comprises the following steps that: an active node calculates a first derivative g and a second derivative h for each sample, encrypts and packs the first derivative g and the second derivative h by using a fully homomorphic encryption algorithm CKKS and sends the first derivative g and the second derivative h to a passive node; the passive node uses a security weighted quantile algorithm to find candidate segmentation points, and gradient aggregation is carried out on the encrypted derivative according to a result; the active node determines an optimal split point by utilizing a bucket subtraction method between tree nodes based on the aggregation gradient sent by the passive node and the own aggregation gradient; the passive node divides sample data according to the optimal splitting point; the active node updates the node information and the sample distribution condition of the split tree model; repeating the steps to the maximum depth of the tree to obtain a complete tree model; and after the model training is finished, carrying out PSI-based model federated reasoning. According to the method, the model training efficiency can be improved, the side channel attack resistance and security are improved, the communication traffic is reduced, and the practical application value of the fully homomorphic encryption algorithm is proved.
Owner:BEIJING JIAOTONG UNIV

Quantum key generation method and device, electronic equipment and storage medium

The invention provides a quantum key generation method and device, electronic equipment and a storage medium. The method comprises the following steps: receiving a generation request of a quantum key sent by first equipment; in response to the generation request, obtaining a plurality of random numbers, and based on the random numbers, marking polynomials in the polynomial set and sorting an operation sequence; performing time equalization operation on the polynomial set to obtain a time equalization factor; based on the time equalization factor and the polynomial set, performing key generation according to the operation sequence to obtain a quantum key; and sending the quantum key to the first device, wherein the quantum key is used for encrypting data and / or messages to be sent by the first device. Therefore, according to the scheme, the quantum key is used for encryption, and the security of information encryption can be enhanced. In the generation process of the quantum key, side channel attacks can be protected through time balancing operation, the randomness of encryption operation can be increased by marking through random numbers, and the security of key generation is improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Commercial password evaluation system and evaluation method

The invention belongs to the technical field of information security, and particularly relates to a commercial password evaluation system and method, and the system comprises a protocol dynamic analysis layer, a multi-modal knowledge center, and an evaluation engine. The protocol dynamic analysis layer comprises a protocol grammar feature library used for defining protocol features; the SM-BERT semantic understanding module is used for protocol logic semantic extraction; the multi-modal knowledge center comprises a data modal fusion module used for integrating data and executing cross-modal alignment; the dynamic relation inference engine is used for performing incremental learning, generating association rules and filtering invalid rules; the evaluation engine comprises a multi-modal feature extraction module used for analyzing cipher suite configuration and a secret key life cycle; the compliance rule engine executes national cryptographic algorithm coverage detection and sensitive data protection verification; the physical security enhancement module simulates side channel attacks; according to the method, the problems of a static rule base, data splitting and high misjudgment rate in traditional password evaluation are solved, and the safety and evaluation efficiency of commercial password application can be remarkably improved.
Owner:FUJIAN JINMI NETWORK SECURITY EVALUATION TECH CO LTD

Implementation method and system of dual access control mechanism based on block chain and encryption machine

The invention relates to the technical field of data security and access control, in particular to an implementation method and system of a dual access control mechanism based on a block chain and an encryption machine, and the implementation method comprises the steps of authority management based on a smart contract, encryption machine dynamic key generation, dual access control, and exception handling and auditing. The method has the beneficial effects that the non-tampering property of authority distribution and operation records is ensured through a distributed account book technology of the block chain, and a double-layer security barrier of logic credibility and physical isolation is formed in combination with hardware-level key protection (such as a security chip HSM) of an encryption machine. And the anti-attack capability is improved, the block chain resists data tampering and insider disintegration, the encryption machine prevents key side channel attacks, and the double mechanisms can cope with complex attack modes such as man-in-the-middle attacks, replay attacks and advanced persistent threats (APT).
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Side channel protection method and device based on noise disturbance, equipment and medium

The invention relates to the technical field of encrypted transmission, and discloses a side channel protection method and device based on noise disturbance, equipment and a medium. The method comprises the following steps: performing iterative training on disturbance to be adjusted according to a preset disturbance discrimination model to obtain expected disturbance with unlearnable characteristics; converting the desired perturbations into guard noise that can be generated by the cryptographic device; determining a data acquisition mode for the side channel; when the data acquisition mode is a training stage, determining an encryption state of the password device, and generating a target type of protection noise according to the encryption state; and when the data acquisition mode is an attack stage, controlling the password device to stop generating the protection noise. According to the method and the device, the expected disturbance of the unlearnable characteristic is added in the training stage of the side channel attack model, so that the training effect of the side channel attack model is interfered, the attack of the side channel attack model fails in the attack stage, and the protection effect and the security are remarkably improved.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

Low-overhead processor cache micro-architecture defense method and device and computer equipment

The invention relates to a low-overhead processor cache micro-architecture defense method and device and computer device.The low-overhead processor cache micro-architecture defense method comprises the steps that when a missing state keeping register module takes out a loading instruction waiting for data from a replay queue, a target branch mask of the loading instruction is obtained; the replay queue is used for storing an instruction which is stagnated due to miss of the cache; judging whether the loading instruction is in a speculative execution state or not according to the target branch mask; and when the loading instruction is in the speculative execution state, stopping a cache write-in operation corresponding to the loading instruction. Through the method and the device, the problem of sensitive information leakage caused by incapability of defending against the cache side channel attack is solved, defending against the cache side channel attack is realized, and sensitive information leakage is prevented.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1

Binomial sampling circuit for side-channel attack resistance in post-quantum cryptography

The application discloses a binomial sampling circuit applied to post-quantum cryptographic algorithm and resisting side channel attacks, comprising a random number generation unit, a binomial sampling unit and a control logic unit; the random number generation unit is used for generating pseudo random numbers according to input data; the pseudo random numbers comprise true data and false data; the binomial sampling unit is used for synchronously performing binomial sampling on the true data and the false data; and the control logic unit is used for controlling the random number generation unit and the binomial sampling unit to operate according to external instructions. The binomial sampling circuit applied to post-quantum cryptographic algorithm and resisting side channel attacks disclosed by the application increases the difficulty of analysis of attackers by generating pseudo random numbers, synchronously samples the true data and the false data to interfere with the attackers, and jointly realizes the protection against side channel attacks, thereby effectively improving the security of a Kyber cryptographic system and reducing the risk of being attacked by side channels.
Owner:HUAZHONG UNIV OF SCI & TECH +1

A private AI model calling method and system based on encrypted data interaction

The application belongs to the technical field of artificial intelligence, and particularly relates to a private AI model calling method and system based on encrypted data interaction, which comprises the following steps: S1, a client generates a series of structured random numbers through a key derivation function based on a main random number seed and each dimension index, encrypts an original input vector into an initial ciphertext vector by using a partial homomorphism encryption public key and the structured random numbers, generates a conditional re-encoding key pair for nonlinear calculation in the AI model, and sends a re-encoding public key to a server. The application can eliminate the confusion ciphertext, so that the server side constructs a quasi-gradient noise based on the intermediate state of the calculation process and injects the result, resisting side channel attacks on the output ciphertext; and the client can reconstruct and remove the noise, so that the lossless calling result is obtained without sacrificing any calculation accuracy, and end-to-end privacy protection of the whole model reasoning process is realized.
Owner:XIAN MINGFU CLOUD COMPUTING CO LTD

Data processing method, device, circuit and equipment based on SHA3

The invention provides an SHA3-based data processing method, device, circuit and equipment, and the method comprises the steps: obtaining a target message carrying a mask, dividing the target message into a plurality of message blocks, sequentially inputting each message block into a sponge structure, and carrying out the iteration, the method comprises the steps that a message block and current mask information are spliced, then iteration is conducted on the spliced message block and current encrypted information, updated encrypted information and updated mask information are output, finally, an output result of a specified bit segment is intercepted from the encrypted information updated each time, and an encryption result is updated based on the output result. And generating an anti-leakage hash value based on the updated encryption result. According to the method, the input and the intermediate state of the sponge structure each time are randomized through the dynamically updated mask information, so that a real data processing path is effectively masked, a key or original data is prevented from being restored through side channel attack, the risk of information leakage is reduced, and the method has the capability of resisting side channel attack in the whole process.
Owner:GUANGZHOU WANXIETONG INFORMATION TECH CO LTD

Satellite-borne safe intelligent computing system

A satellite-borne safety intelligent computing system is used for guaranteeing safety of a satellite edge computing system and comprises a host processor, an AI accelerator and a safety bus connected with the host processor and the accelerator. The satellite-borne safe intelligent computing system further comprises a bus stream encoding and decoding engine which is embedded in the interface controller of the data bus and used for encrypting and decrypting transmission data of the data bus. By encrypting the cache stream on the data bus, key data such as Bias bias cache and the like can be protected. In addition, an attacker can be prevented from stealing structural information of the neural network model through interrupt signals by interrupting obfuscated codes, dual protection of'signal + data 'is formed, and time sequence detection Trojan horse and side channel attacks can be effectively resisted.
Owner:BEIJING BLUE TOWER OPTICAL TRANSMISSION INTELLIGENT TECHNOLOGY CO LTD

Physical-level anti-quantum key packaging device and method

The invention discloses a physical-level anti-quantum key packaging device and method, and the method comprises the steps: cutting off a byte stream to a first modulus through a bit mask operation, and generating a polynomial matrix in a constant physical clock period; calculating an inner product of a private key vector of the polynomial matrix, executing logic combination operation, compressing modulus, and generating a public key vector; after receiving the public key vector, the second communication node reconstructs a system state by using the temporary private key and outputs a ciphertext; and the first communication node receives the ciphertext, performs fault-tolerant restoration and re-encryption, drives a bottom multiplexer to generate a mask, and selects one of a real session key and a random noise key to be output in a constant physical clock period. According to the anti-quantum cryptography algorithm, logic combination operation, algebraic divide-and-conquer and physical circuit characteristics are utilized, hardware simplification is achieved, meanwhile, safety is improved, strategic expansion capacity is achieved, and the problems that an existing anti-quantum cryptography algorithm faces the computing power bottleneck and the side channel attack risk in a low-power-consumption node lacking a hardware divider circuit are solved.
Owner:SUZHOU LANGKONGHOU QUANTUM TECHNOLOGY CO LTD

Chip security key protection method and system against side-channel attacks

The application provides a chip security key protection method and system against side channel attacks, relates to the technical field of chips, and comprises the following steps: obtaining a key operation request, performing address space mapping based on a dynamic mapping rule to obtain encrypted key data and decryption, fragmenting key intermediate data and allocating independent processing channels for decoupling operation, injecting a time-varying noise signal to mask the association between the key and physical characteristics, and finally recombining and reversely converting to generate a final key output. The application effectively resists side channel attacks such as power analysis and electromagnetic analysis, and improves the security of the key storage and operation process.
Owner:WING SHIELD (SHANGHAI) INTELLIGENT TECH CO LTD

Training method and device of side channel attack identification model, and prediction method and device

This specification provides a method and apparatus for training a side-channel attack identification model, as well as a method and apparatus for predicting side-channel attacks. In this method, a device is deployed as a simulated target device, and a side-channel information acquisition device is deployed within a predetermined distance range outside the device. The side-channel information acquisition device collects side-channel information generated during device operation; it collects first side-channel information generated when the device is running but the acquisition device is not running; it collects second side-channel information generated when both the device and the acquisition device are running. Using the first and second side-channel information, a side-channel attack identification model is trained. This model is then used to predict side-channel attacks. This specification's embodiments can more accurately predict whether a side-channel attack has occurred against a device.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Encryption chip random mask generation system and method for preventing side channel attack

The invention discloses an encryption chip random mask generation system and method for preventing side channel attacks, and belongs to the technical field of encryption chip information security protection. Comprising an encryption operation unit, a mask generation unit, an FPGA real-time power consumption anomaly detection unit, an attack risk level identification unit, a mask order adjustment unit and an anti-shake stabilization unit. The FPGA real-time power consumption anomaly detection unit collects and filters power consumption trajectory data, the attack risk level identification unit judges the attack risk level accordingly, the mask order adjustment unit dynamically adjusts the mask order according to the risk level, the anti-shake stabilization unit avoids timing sequence disorder caused by frequent order switching, and encryption operation is not interrupted in the adjustment process. According to the method, the dynamic adaptation of the mask order is realized, the security protection and the chip performance are balanced, the continuity and the stability of the encryption operation are ensured, and the side channel attack resistance of the encryption chip is effectively improved.
Owner:SHENZHEN BOSSTON TECHNOLOGY CO LTD

Side channel attack method based on multi-label and multi-expert network

The invention discloses a side channel attack method based on a multi-label and multi-expert network, and the method comprises the steps: firstly designing and constructing a three-dimensional multi-label matrix based on a binary label calculation method for a public original data set of a target cryptographic algorithm; secondly, designing a multi-expert network model based on an attention mechanism, comprising an input layer, an expert network layer, a sharing layer and an output layer, and realizing parallel recovery of all key bytes of the target cryptographic algorithm; and completing training through grid search, and finally completing side channel attack by using the trained model. According to the method, parallel recovery of all key bytes of the target cryptographic algorithm is completed through one-time model training, manual selection of interest point intervals is avoided, side channel attack complexity is reduced, and attack efficiency is improved; meanwhile, the learning ability of the model is improved through an attention mechanism, and the robustness of the model is improved through common learning of a sharing layer, so that the success rate of side channel attacks is improved.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Confidential calculation method, system and device, storage medium and product

The invention belongs to the technical field of computers, and discloses a confidential calculation method, system and device, a storage medium and a product. After a target trusted instance receives a confidential calculation request, a function identifier is read from the received confidential calculation request, and the confidential calculation request is sent to the target trusted instance by a master control application through trusted connection; obtaining a target function corresponding to the function identifier; and executing the objective function to perform the confidential calculation. When confidential calculation needs to be carried out, the main control application is used for calling the corresponding function in the confidential calculation board card through the trusted connection to execute confidential calculation, and confidential calculation power and general calculation power are isolated through the special confidential calculation board card in the process, so that better resource isolation is realized, and side channel attack can be avoided.
Owner:ZTE CORP +1