节点文献

SM4的一阶门限实现优化方法

Optimization Method for First-Order Threshold Implementation of SM4

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 姚富陈华曹伟琼王舰付一方

【Author】 YAO Fu;CHEN Hua;CAO Wei-Qiong;WANG Jian;FU Yi-Fang;Trusted Computing and Information Assurance Laboratory,Institute of Software,Chinese Academy of Sciences;University of Chinese Academy of Sciences;

【通讯作者】 陈华;

【机构】 中国科学院软件研究所可信计算与信息保障实验室中国科学院大学

【摘要】 目前已有的SM4算法一阶防护方案缺少对毛刺攻击的考虑,且资源消耗过大,无法应用到资源受限或中高速运行场景中.本文提出了一种在毛刺条件下抵抗侧信道攻击的SM4算法一阶门限实现方案.本方案针对SM4算法S盒,结合“特殊掩码分量函数的数学性质”与“利用电路中无关中间变量作为新随机源”两种技术,在GF(2~4)域上构建了一阶门限实现的乘法运算模块.对GF(2~4)域的求逆运算采用直接掩码法,并引入16比特额外随机数,不仅保证输出掩码分量的均匀性,还与乘法模块协同实现整体S盒的一阶毛刺探测安全性.采用SILVER自动化评估工具验证了关键部件S盒的一阶毛刺探测安全性,采用通用的TVLA泄露评估测试评估整个防护方案的信息泄露量,采用一阶CPA攻击方法对基于FPGA实现的该防护方案进行了攻击.实验结果显示,在1000万条功耗曲线下,该方案能够在毛刺存在的情况下有效抵抗侧信道攻击.该方案的资源消耗较低,在芯片面积上比已有其他方案对比具有显著优势.

【Abstract】 Existing first-order protected implementations of the SM4 algorithm lacks consideration for glitch attacks and suffers from excessive resource overhead, making them unsuitable for resource constrained or medium-to-high-speed application scenarios. This study proposes a first-order threshold implementation of the SM4 algorithm that resists side-channel attacks under glitch conditions. Specifically, the proposed approach targets the SM4 S-box by combining two techniques, namely, leveraging the mathematical properties of specially designed masked component functions and exploiting uncorrelated intermediate variables in the circuit as fresh randomness, to construct a first-order threshold multiplication module over GF(2~4). For the inversion operation over GF(2~4), the direct masking method is adopted and 16 additional random bits are introduced, which not only ensure uniformity of the output masked shares but also jointly guarantee first-order glitch-resistant security when combined with the multiplication module. The SILVER automated evaluation tool is used to verify the first-order glitch resistance of the critical S-box component, a standard TVLA is performed to evaluate information leakage across the entire protected design, and a first-order CPA attack is mounted on an FPGA-based implementation of the proposed scheme. Experimental results show that, even in the presence of glitches, the proposed implementation effectively resists side-channel attacks under10 million power traces. Moreover, the design exhibits low resource consumption and demonstrates significant advantages in silicon area compared to existing schemes.

【基金】 国家自然科学基金(62172395)~~
  • 【文献出处】 密码学报(中英文) ,Journal of Cryptologic Research , 编辑部邮箱 ,2025年06期
  • 【分类号】TN918.1
  • 【下载频次】11
节点文献中: 

本文链接的文献网络图示:

本文的引文网络