通信学报 ›› 2023, Vol. 44 ›› Issue (4): 38-49.doi: 10.11959/j.issn.1000-436x.2023063

• 学术论文 • 上一篇    下一篇

新的抵抗鬼峰的关联矩阵差分能量分析

姜子敬, 丁群   

  1. 黑龙江大学电子工程学院,黑龙江 哈尔滨 150080
  • 修回日期:2023-01-20 出版日期:2023-04-25 发布日期:2023-04-01
  • 作者简介:姜子敬(1994- ),男,黑龙江哈尔滨人,黑龙江大学博士生,主要研究方向为网络信息安全及硬件加密侧信道分析
    丁群(1957- ),女,黑龙江哈尔滨人,黑龙江大学教授、博士生导师,主要研究方向为硬件逻辑加密与系统集成、混沌保密通信和网络信息安全等
  • 基金资助:
    国家自然科学基金资助项目(61471158);黑龙江省自然科学基金优秀青年基金资助项目(YQ2020F012)

Nove lincidence matrix differential power analysis for resisting ghost peak

Zijing JIANG, Qun DING   

  1. College of Electronic Engineering, Heilongjiang University, Harbin 150080, China
  • Revised:2023-01-20 Online:2023-04-25 Published:2023-04-01
  • Supported by:
    The National Natural Science Foundation of China(61471158);The Natural Science Foundation of Hei-longjiang Province for Distinguished Young Scholars(YQ2020F012)

摘要:

差分能量分析(DPA)是对芯片中分组密码实现安全性的最主要威胁之一,当采集的能量迹不足时,DPA容易受到错误密钥产生的差分均值影响产生鬼峰。基于DPA,提出了一种可以有效抵抗鬼峰的关联矩阵差分能量分析(IMDPA)。通过构造预测差分均值矩阵,利用猜测密钥在非泄露区间的弱相关性,避免非泄露区间对泄露区间内密钥猜测的影响。对IMDPA在AES-128算法的不同泄露区间进行了实验验证,结果表明,与传统的DPA相比,IMDPA 需要更少(达到 85%)的能量迹来猜测正确的密钥。同时 IMDPA 在实施防护措施下的 AES-128的密钥猜测效率仍然存在显著的优势。为了进一步验证IMDPA在分组密码中的通用性,在SM4算法上进行了实验验证,与传统的DPA相比,IMDPA需要更少(达到87.5%)的能量迹来猜测正确的密钥。

关键词: AES, 鬼峰, 差分能量分析, SM4

Abstract:

At present, differential power analysis (DPA) is one of the most important threats to the security of block ciphers in chips.When the collected power trace is insufficient, DPA is vulnerable to ghost peak caused by the difference mean value generated by the wrong key.Based on DPA, a incidence matrix differential power analysis (IMDPA) was proposed which could effectively resist ghost peak.The prediction difference mean matrix was constructed to avoid the influence of the non leaking interval on the key guessing of the leaking interval by using the weak correlation of the guessing key in the non leaking interval.The proposed IMDPA was tested in different leak intervals of AES-128 algorithm.The results show that compared with traditional DPA, IMDPA requires less (up to 85%) power trace to guess the correct key.At the same time, the key guessing efficiency of AES-128 under the implementation of protective measures by IMDPA still has obvious advantages.In order to further verify the universality of IMDPA in block ciphers, experimental verification is conducted on SM4 algorithm.Compared with traditional DPA, IMDPA requires less (up to 87.5%) power traces to guess the correct key.

Key words: AES, ghost peak, differential power analysis, SM4

中图分类号: 

No Suggested Reading articles found!