引用本文:魏淙洺,王菁,王安,丁瑶玲,孙绍飞,祝烈煌.私有算法密码芯片非入侵式攻击检测框架.软件学报,2026,37(2):894-914
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 725次   下载 1116 本文二维码信息
码上扫一扫!
分享到: 微信 更多
私有算法密码芯片非入侵式攻击检测框架
魏淙洺1,2, 王菁3, 王安1, 丁瑶玲1, 孙绍飞1, 祝烈煌1
1.北京理工大学 网络空间安全学院, 北京 100081;2.先进密码技术与系统安全四川省重点实验室 (成都信息工程大学), 四川 成都 610054;3.北京理工大学 计算机学院, 北京 100081
摘要:
近年来, 密码芯片迅速发展, 与此同时也面临着非入侵式攻击的严重威胁. 目前已有国内外标准给出了非入侵式攻击检测流程与方法, 但这些标准均针对公开算法制定, 对于私有算法并不适用, 私有算法密码芯片存在着很大的安全隐患. 针对这一问题, 提出面向私有算法密码芯片的非入侵式攻击检测框架, 该框架包含计时分析测试、简单能量/电磁分析测试、差分能量/电磁分析测试3大部分. 对于计时分析测试, 采用基于平均去噪的计时分析方法, 提高所采集时间的可用性. 针对简单能量/电磁分析, 提出面向私有密码算法的视觉观察法和交叉关联分析方法. 针对差分能量/电磁分析, 通过TVLA-1和TVLA-2双重检测方法有效检测私有算法密码芯片不同来源的泄露, 评估私有算法密码芯片的抗差分能量/电磁攻击能力. 该框架是对传统非入侵式攻击检测的有效补充, 极大提高了非入侵式攻击检测的检测范围. 为了验证该框架的有效性, 在多款密码芯片上开展黑盒实验, 实验结果表明该框架能够有效检测私有算法密码芯片的抗非入侵式攻击安全性.
关键词:  非入侵式攻击  私有算法  密码芯片  计时分析  能量分析
DOI:10.13328/j.cnki.jos.007455
分类号:TP309
基金项目:国家重点研发计划(2022YFB3103800); 国家自然科学基金(62272047, 62302036, 62402039); 北京市自然科学基金(L244044, QY24173)
Detection Framework of Non-invasive Attack Against Private-algorithm Cryptographic Chips
WEI Cong-Ming1,2, WANG Jing3, WANG An1, DING Yao-Ling1, SUN Shao-Fei1, ZHU Lie-Huang1
1.School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing 100081, China;2.Advanced Cryptography and System Security Key Laboratory of Sichuan Province (Chengdu University of Information Technology), Chengdu 610054, China;3.School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081, China
Abstract:
In recent years, cryptographic chips have developed rapidly. However, they are also facing a significant threat from non-invasive attacks. Although both international and domestic standards provide testing methods for non-invasive attacks, these standards are formulated for public algorithms and are not applicable to private algorithms, which still present considerable security risks. This study proposes a detection framework for private-algorithm cryptographic chips, which includes three components: timing analysis tests, simple power/electromagnetic analysis tests, and differential power/electromagnetic analysis tests. For the timing analysis test, a method based on average denoising is adopted, which significantly improves the accuracy of execution time measurements. Methods based on visual observation and cross-correlation analysis are presented for simple power/electromagnetic analysis tests. Finally, for differential power analysis, TVLA-1 and TVLA-2 are employed to detect leakages from various sources and evaluate the vulnerabilities of private-algorithm cryptographic chips to differential power attacks. The proposed framework serves as an effective supplement to traditional non-invasive attack detection, significantly expanding its application range. To verify the effectiveness of the framework, black-box experiments are conducted on several cryptographic chips. The results demonstrate that the framework can effectively assess the resilience of private-algorithm cryptographic chips against non-invasive attacks.
Key words:  non-invasive attack  private algorithm  cryptographic chip  timing analysis  power analysis

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: