节点文献
SM4的一阶门限实现优化方法
Optimization Method for First-Order Threshold Implementation of SM4
【摘要】 目前已有的SM4算法一阶防护方案缺少对毛刺攻击的考虑,且资源消耗过大,无法应用到资源受限或中高速运行场景中.本文提出了一种在毛刺条件下抵抗侧信道攻击的SM4算法一阶门限实现方案.本方案针对SM4算法S盒,结合“特殊掩码分量函数的数学性质”与“利用电路中无关中间变量作为新随机源”两种技术,在GF(2~4)域上构建了一阶门限实现的乘法运算模块.对GF(2~4)域的求逆运算采用直接掩码法,并引入16比特额外随机数,不仅保证输出掩码分量的均匀性,还与乘法模块协同实现整体S盒的一阶毛刺探测安全性.采用SILVER自动化评估工具验证了关键部件S盒的一阶毛刺探测安全性,采用通用的TVLA泄露评估测试评估整个防护方案的信息泄露量,采用一阶CPA攻击方法对基于FPGA实现的该防护方案进行了攻击.实验结果显示,在1000万条功耗曲线下,该方案能够在毛刺存在的情况下有效抵抗侧信道攻击.该方案的资源消耗较低,在芯片面积上比已有其他方案对比具有显著优势.
【Abstract】 Existing first-order protected implementations of the SM4 algorithm lacks consideration for glitch attacks and suffers from excessive resource overhead, making them unsuitable for resource constrained or medium-to-high-speed application scenarios. This study proposes a first-order threshold implementation of the SM4 algorithm that resists side-channel attacks under glitch conditions. Specifically, the proposed approach targets the SM4 S-box by combining two techniques, namely, leveraging the mathematical properties of specially designed masked component functions and exploiting uncorrelated intermediate variables in the circuit as fresh randomness, to construct a first-order threshold multiplication module over GF(2~4). For the inversion operation over GF(2~4), the direct masking method is adopted and 16 additional random bits are introduced, which not only ensure uniformity of the output masked shares but also jointly guarantee first-order glitch-resistant security when combined with the multiplication module. The SILVER automated evaluation tool is used to verify the first-order glitch resistance of the critical S-box component, a standard TVLA is performed to evaluate information leakage across the entire protected design, and a first-order CPA attack is mounted on an FPGA-based implementation of the proposed scheme. Experimental results show that, even in the presence of glitches, the proposed implementation effectively resists side-channel attacks under10 million power traces. Moreover, the design exhibits low resource consumption and demonstrates significant advantages in silicon area compared to existing schemes.
【Key words】 SM4 algorithm; side channel attack; threshold implementation; glitch-extended probing model; hardware implementation;
- 【文献出处】 密码学报(中英文) ,Journal of Cryptologic Research , 编辑部邮箱 ,2025年06期
- 【分类号】TN918.1
- 【下载频次】11