节点文献

SM4密码算法的唯密文故障分析

Ciphertext-Only Fault Analysis of the SM4 Cryptosystem

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 李玮汪梦林谷大武温云华李嘉耀张雨希

【Author】 LI Wei;WANG Meng-Lin;GU Da-Wu;WEN Yun-Hua;LI Jia-Yao;ZHANG Yu-Xi;School of Computer Science and Technology,Donghua University;Department of Computer and Science and Engineering,Shanghai Jiao Tong University;Shanghai Key Laboratory of Scalable Computing and System,Shanghai Jiao Tong University;

【通讯作者】 李嘉耀;

【机构】 东华大学计算机科学与技术学院上海交通大学计算机科学与工程系上海交通大学上海市可扩展计算与系统重点实验室

【摘要】 SM4算法是我国公布的首个商用密码算法,用于保护WAPI无线局域网标准中的数据传输,2012年成为国家密码行业标准,2021年作为ISO/IEC国际标准正式发布.在唯密文攻击中,攻击者除了所截获的密文,没有其它可利用的信息,因而获取的信息最少、攻击难度较大.目前,国内外未有公开发表的SM4算法抵抗唯密文攻击的结果.本文采用巴氏系数汉明重量、詹森香农散度汉明重量和詹森香农散度汉明重量极大似然估计等新型区分器对SM4算法实施唯密文故障分析.仿真实验表明,该方法最少仅需要136个随机故障,可以破译SM4算法的128比特主密钥,且在准确度、成功率、耗时和复杂度等方面攻击效果佳.该结果为无线局域网中密码算法的安全性分析和实现提供了重要参考.

【Abstract】 The SM4 cryptosystem is the first commercial cryptographic algorithm announced by the government of China. It can be used to protect the data transmission in the wireless local area network(LAN) authentication and privacy infrastructure(WAPI). It has been the standard of the national cryptographic industry since 2012 and the international standard of ISO/IEC since 2021. It is the 32-round block cipher with the generalized Feistel network(GFN). It has the 128-bit block size and 128-bit master key. Since the publication of the SM4, there is plenty of cryptanalysis to evaluate its security, including zero-correlation linear analysis, linear analysis, algebraic side-channel analysis, algebraic analysis, integral analysis, impossible differential analysis, rectangle analysis, differential analysis, differential fault analysis and algebraic fault analysis, which have the basic assumptions of chosen plaintext attacks(CPA) or known plaintext attacks(KPA). The CPA needs to acquire the ciphertexts with the corresponding plaintexts, and the KPA demands a great number of known plaintexts and ciphertexts. Compared with the CPA and KPA, the ciphertext-only attack(COA) only requires the ciphertexts. It can do the security analysis of the cryptosystem without other information. Thus, the COA has the flexible applications and can effectively verify the security of the cryptosystem. Up to now, there is no literature about the security of SM4 against the COA. On the designing structure of SM4, this paper proposes the novel ciphertext-only fault analysis, which adopts a random byte-oriented fault model and utilizes a series of distinguishers of Square Euclidean Imbalance(SEI), Hamming Weight(HW), Maximum Likelihood estimate(MLE), Goodness of Fit(GF), Goodness of Fit-Square Euclidean Imbalance(GF-SEI), Maximum Likelihood estimate-Square Euclidean Imbalance(MLE-SEI), Bhattacharyya Coefficient-Hamming Weight(BC-HW), Jensen Shannon distance-Hamming Weight(JSD-HW) and Jensen Shannon distance-Hamming Weight-Maximum Likelihood estimate(JSD-HW-MLE) for statistical analysis. This paper simulates the ciphertext-only fault analysis of SM4 cryptosystem on the computer software and uses indicators, such as accuracy, the number of faults, success probability, latency and complexities to measure the efficiency of different distinguishers. The accuracy is measured by the mean absolute error(MAE), which indicates the ability of different distinguishers to filter the subkey or the master key. When the success probability is highest, the number of faults can reflect the attacking ability. Fewer the number of faults, the stronger the attacking ability. The success probability refers to the probability of the ciphertext-only fault analysis in breaking the SM4 cryptosystem with different distinguishers. The distinguisher is perfect when the success probability is at least 99%. The latency means the time required to restore the master key of SM4 cryptosystem. The complex consists of time complexity, data complexity and memory complexity. The simulation experiments show that SM4 cannot resist the attack of the ciphertext-only fault analysis, the novel distinguishers of BC-HW, JSD-HW and JSD-HW-MLE only require 140, 140 and 136 faults to break SM4 cryptosystem, and the attack performs better in terms of accuracy, success probability, latency and complexities. The results provide an important reference for the security analysis and implementation of cryptographic algorithms.

【基金】 国家自然科学基金项目(61772129,61932014,62102077);国家密码发展基金项目(MMJJ20180101);上海市自然科学基金;上海市扬帆计划(21YF1401200);上海市可扩展计算与系统重点实验室开放课题;中央高校基本科研业务费专项资金资助~~
  • 【文献出处】 计算机学报 ,Chinese Journal of Computers , 编辑部邮箱 ,2022年08期
  • 【分类号】TN918.1
  • 【下载频次】253
节点文献中: 

本文链接的文献网络图示:

本文的引文网络