节点文献
SM4密码算法的唯密文故障分析
Ciphertext-Only Fault Analysis of the SM4 Cryptosystem
【摘要】 SM4算法是我国公布的首个商用密码算法,用于保护WAPI无线局域网标准中的数据传输,2012年成为国家密码行业标准,2021年作为ISO/IEC国际标准正式发布.在唯密文攻击中,攻击者除了所截获的密文,没有其它可利用的信息,因而获取的信息最少、攻击难度较大.目前,国内外未有公开发表的SM4算法抵抗唯密文攻击的结果.本文采用巴氏系数汉明重量、詹森香农散度汉明重量和詹森香农散度汉明重量极大似然估计等新型区分器对SM4算法实施唯密文故障分析.仿真实验表明,该方法最少仅需要136个随机故障,可以破译SM4算法的128比特主密钥,且在准确度、成功率、耗时和复杂度等方面攻击效果佳.该结果为无线局域网中密码算法的安全性分析和实现提供了重要参考.
【Abstract】 The SM4 cryptosystem is the first commercial cryptographic algorithm announced by the government of China. It can be used to protect the data transmission in the wireless local area network(LAN) authentication and privacy infrastructure(WAPI). It has been the standard of the national cryptographic industry since 2012 and the international standard of ISO/IEC since 2021. It is the 32-round block cipher with the generalized Feistel network(GFN). It has the 128-bit block size and 128-bit master key. Since the publication of the SM4, there is plenty of cryptanalysis to evaluate its security, including zero-correlation linear analysis, linear analysis, algebraic side-channel analysis, algebraic analysis, integral analysis, impossible differential analysis, rectangle analysis, differential analysis, differential fault analysis and algebraic fault analysis, which have the basic assumptions of chosen plaintext attacks(CPA) or known plaintext attacks(KPA). The CPA needs to acquire the ciphertexts with the corresponding plaintexts, and the KPA demands a great number of known plaintexts and ciphertexts. Compared with the CPA and KPA, the ciphertext-only attack(COA) only requires the ciphertexts. It can do the security analysis of the cryptosystem without other information. Thus, the COA has the flexible applications and can effectively verify the security of the cryptosystem. Up to now, there is no literature about the security of SM4 against the COA. On the designing structure of SM4, this paper proposes the novel ciphertext-only fault analysis, which adopts a random byte-oriented fault model and utilizes a series of distinguishers of Square Euclidean Imbalance(SEI), Hamming Weight(HW), Maximum Likelihood estimate(MLE), Goodness of Fit(GF), Goodness of Fit-Square Euclidean Imbalance(GF-SEI), Maximum Likelihood estimate-Square Euclidean Imbalance(MLE-SEI), Bhattacharyya Coefficient-Hamming Weight(BC-HW), Jensen Shannon distance-Hamming Weight(JSD-HW) and Jensen Shannon distance-Hamming Weight-Maximum Likelihood estimate(JSD-HW-MLE) for statistical analysis. This paper simulates the ciphertext-only fault analysis of SM4 cryptosystem on the computer software and uses indicators, such as accuracy, the number of faults, success probability, latency and complexities to measure the efficiency of different distinguishers. The accuracy is measured by the mean absolute error(MAE), which indicates the ability of different distinguishers to filter the subkey or the master key. When the success probability is highest, the number of faults can reflect the attacking ability. Fewer the number of faults, the stronger the attacking ability. The success probability refers to the probability of the ciphertext-only fault analysis in breaking the SM4 cryptosystem with different distinguishers. The distinguisher is perfect when the success probability is at least 99%. The latency means the time required to restore the master key of SM4 cryptosystem. The complex consists of time complexity, data complexity and memory complexity. The simulation experiments show that SM4 cannot resist the attack of the ciphertext-only fault analysis, the novel distinguishers of BC-HW, JSD-HW and JSD-HW-MLE only require 140, 140 and 136 faults to break SM4 cryptosystem, and the attack performs better in terms of accuracy, success probability, latency and complexities. The results provide an important reference for the security analysis and implementation of cryptographic algorithms.
【Key words】 fault analysis; SM4; the ciphertext-only attack; block cipher; cryptanalysis;
- 【文献出处】 计算机学报 ,Chinese Journal of Computers , 编辑部邮箱 ,2022年08期
- 【分类号】TN918.1
- 【下载频次】253