门限实现作为一种具有可证明安全性的抗侧信道攻击方法,已被广泛应用于各类密码算法中。尽管已有研究提出了多种针对SM4算法的侧信道攻击防护方案,但现有方案在面对毛刺扩展探测等新型攻击模型时仍存在安全缺陷。因此,本文提出一种改进...门限实现作为一种具有可证明安全性的抗侧信道攻击方法,已被广泛应用于各类密码算法中。尽管已有研究提出了多种针对SM4算法的侧信道攻击防护方案,但现有方案在面对毛刺扩展探测等新型攻击模型时仍存在安全缺陷。因此,本文提出一种改进的SM4算法S盒一阶门限实现方案。该方案基于塔域GF((22)2)2结构设计S盒,重构满足门限特性的乘法器,并引入COTG(changing of the guards)技术优化随机数添加策略,将单个S盒的随机数消耗降低至10 bit。本文借助形式化验证工具SILVER,证明了该方案在毛刺扩展探测模型下的理论安全性,并通过测试向量泄露评估(test vector leakage assessment,TVLA)验证了整体物理电路的实际防护能力。实验结果表明,该方案可有效抵御一阶侧信道攻击。展开更多
SM4 is a block cipher algorithm among Chinese commer-cial cryptographic algorithms,which is advanced in terms of efficiency and theoretical security and has become national and international stan-dards successively.Howe...SM4 is a block cipher algorithm among Chinese commer-cial cryptographic algorithms,which is advanced in terms of efficiency and theoretical security and has become national and international stan-dards successively.However,existing literature shows that SM4 was not designed with an emphasis on key storage,which means that in today’s world where a single trusted hardware device with the built-in key faces challenges such as vulnerability,high cost,and unreliability,the usabil-ity of SM4 may be limited.Therefore,this paper proposes an imple-mentation scheme for SM4 based on secure multi-party computation(MPC)technology.The scheme involves dispensing the key among mul-tiple users’devices in a distributed manner,and when using the SM4 algorithm for encryption,multiple users perform joint computation with-out opening the full key.Specifically,this paper employs the MP-SPDZ framework,which satisfies security requirements in the presence of a dishonest majority of active adversaries.In view of the fact that this framework can only perform basic linear operations such as addition and multiplication,this paper focuses on the algebraic analysis of Sbox,which is the only non-linear component in SM4,and reconstructs it using the bit decomposition method.Furthermore,this paper demonstrates the conversion between the SM4-Sboxfield GF(28)and the SPDZ parame-terfield GF(240)through the isomorphic mapping,making it possible to perform joint calculations throughout the entire SM4 algorithm.Com-plexity analysis shows that this scheme has advantages in terms of data storage and communication volume,reaching a level of usability.展开更多
在分布式物联网的大规模应用背景下,各实体设备中密码技术作为信息安全的底层支撑架构,正面临着侧信道攻击(SCA)这一物理层安全威胁的严峻挑战. SM4分组密码算法作为我国自主研制的商用密码算法标准,已深度集成于分布式物联网安全协议中...在分布式物联网的大规模应用背景下,各实体设备中密码技术作为信息安全的底层支撑架构,正面临着侧信道攻击(SCA)这一物理层安全威胁的严峻挑战. SM4分组密码算法作为我国自主研制的商用密码算法标准,已深度集成于分布式物联网安全协议中,但其实现层面的侧信道脆弱性问题亟待解决.针对SM4密钥扩展算法的侧信道攻击研究存在空白,现有攻击方法多依赖多能迹统计特性,而单能迹攻击研究匮乏.研究提出一种基于贝叶斯网络结合建模侧信道攻击的单能迹侧信道攻击方法,针对单条能量轨迹,通过构建概率图模型,结合置信传播算法,实现对轮子密钥的高效推测,进而恢复主密钥.仿真实验与实测实验表明该攻击方法有效,在理想实测环境下主密钥恢复成功率达85.74%,即使在实测能迹中添加大量高斯白噪声,使得信噪比仅为10 d B的条件下,成功率仍可达70%.与传统方法相比,所提方法在成功率、所需能量轨迹数量和攻击时间等方面优势显著,为分布式物联网系统含密设备的侧信道攻击研究提供了新的思路与技术手段,也为相关防护设计提供了理论依据和参考.展开更多
控制指令是保障列车安全、可靠、有序运行的关键要素,其安全传输对列控系统的功能安全至关重要。然而,当前列控系统广泛采用的三重数据加密标准(Triple Data Encryption Standard,3DES)算法、离线密钥分发等安全机制较为薄弱,难以应对...控制指令是保障列车安全、可靠、有序运行的关键要素,其安全传输对列控系统的功能安全至关重要。然而,当前列控系统广泛采用的三重数据加密标准(Triple Data Encryption Standard,3DES)算法、离线密钥分发等安全机制较为薄弱,难以应对日益复杂的网络攻击。特别是量子计算的快速发展对经典密码算法的安全性构成根本性威胁,使得控制指令传输面临长期安全风险。为此,系统性地分析既有列控系统的安全机制,识别其在数据安全方面存在的核心风险与需求。在此基础上,结合量子密钥分发(Quantum Key Distribution,QKD)技术的“信息论安全”优势与后量子密码(Post-Quantum Cryptography,PQC)算法的计算安全性,提出一种面向列控系统的新型密码架构。该架构从双向身份认证、在线密钥分发与管理、数据安全传输3个维度,构建了集抗量子攻击与高可用性于一体的安全增强方案,旨在有效提升列控系统的主动防御能力,为应对未来量子计算威胁、保障列控系统数据安全提供前瞻性解决方案。展开更多
摘要门限实现作为一种具有可证明安全性的抗侧信道攻击方法,已被广泛应用于各类密码算法中。尽管已有研究提出了多种针对SM4算法的侧信道攻击防护方案,但现有方案在面对毛刺扩展探测等新型攻击模型时仍存在安全缺陷。因此,本文提出一种改进的SM4算法S盒一阶门限实现方案。该方案基于塔域GF((22)2)2结构设计S盒,重构满足门限特性的乘法器,并引入COTG(changing of the guards)技术优化随机数添加策略,将单个S盒的随机数消耗降低至10 bit。本文借助形式化验证工具SILVER,证明了该方案在毛刺扩展探测模型下的理论安全性,并通过测试向量泄露评估(test vector leakage assessment,TVLA)验证了整体物理电路的实际防护能力。实验结果表明,该方案可有效抵御一阶侧信道攻击。
基金Supported by the National Natural Science Foundation of China under Grant No.61907042Beijing Natural Science Foundation under Grant No.4194090.
摘要SM4 is a block cipher algorithm among Chinese commer-cial cryptographic algorithms,which is advanced in terms of efficiency and theoretical security and has become national and international stan-dards successively.However,existing literature shows that SM4 was not designed with an emphasis on key storage,which means that in today’s world where a single trusted hardware device with the built-in key faces challenges such as vulnerability,high cost,and unreliability,the usabil-ity of SM4 may be limited.Therefore,this paper proposes an imple-mentation scheme for SM4 based on secure multi-party computation(MPC)technology.The scheme involves dispensing the key among mul-tiple users’devices in a distributed manner,and when using the SM4 algorithm for encryption,multiple users perform joint computation with-out opening the full key.Specifically,this paper employs the MP-SPDZ framework,which satisfies security requirements in the presence of a dishonest majority of active adversaries.In view of the fact that this framework can only perform basic linear operations such as addition and multiplication,this paper focuses on the algebraic analysis of Sbox,which is the only non-linear component in SM4,and reconstructs it using the bit decomposition method.Furthermore,this paper demonstrates the conversion between the SM4-Sboxfield GF(28)and the SPDZ parame-terfield GF(240)through the isomorphic mapping,making it possible to perform joint calculations throughout the entire SM4 algorithm.Com-plexity analysis shows that this scheme has advantages in terms of data storage and communication volume,reaching a level of usability.
摘要在分布式物联网的大规模应用背景下,各实体设备中密码技术作为信息安全的底层支撑架构,正面临着侧信道攻击(SCA)这一物理层安全威胁的严峻挑战. SM4分组密码算法作为我国自主研制的商用密码算法标准,已深度集成于分布式物联网安全协议中,但其实现层面的侧信道脆弱性问题亟待解决.针对SM4密钥扩展算法的侧信道攻击研究存在空白,现有攻击方法多依赖多能迹统计特性,而单能迹攻击研究匮乏.研究提出一种基于贝叶斯网络结合建模侧信道攻击的单能迹侧信道攻击方法,针对单条能量轨迹,通过构建概率图模型,结合置信传播算法,实现对轮子密钥的高效推测,进而恢复主密钥.仿真实验与实测实验表明该攻击方法有效,在理想实测环境下主密钥恢复成功率达85.74%,即使在实测能迹中添加大量高斯白噪声,使得信噪比仅为10 d B的条件下,成功率仍可达70%.与传统方法相比,所提方法在成功率、所需能量轨迹数量和攻击时间等方面优势显著,为分布式物联网系统含密设备的侧信道攻击研究提供了新的思路与技术手段,也为相关防护设计提供了理论依据和参考.