基于毛刺探测模型的低随机数SM4一阶门限实现
网络出版日期: 2026-07-09
基金资助
江苏师范大学博士基金(20XSRX014)
版权
Low-randomness first-order threshold implementation for SM4 based on the glitch-extended probing model
Online published: 2026-07-09
Copyright
门限实现作为一种具有可证明安全性的抗侧信道攻击方法,已被广泛应用于各类密码算法中。尽管已有研究提出了多种针对SM4算法的侧信道攻击防护方案,但现有方案在面对毛刺扩展探测等新型攻击模型时仍存在安全缺陷。因此,本文提出一种改进的SM4算法S盒一阶门限实现方案。该方案基于塔域 GF((22)2)2结构设计S盒,重构满足门限特性的乘法器,并引入COTG(changing of the guards)技术优化随机数添加策略,将单个S盒的随机数消耗降低至10 bit。本文借助形式化验证工具SILVER,证明了该方案在毛刺扩展探测模型下的理论安全性,并通过测试向量泄露评估(test vector leakage assessment,TVLA)验证了整体物理电路的实际防护能力。实验结果表明,该方案可有效抵御一阶侧信道攻击。
祝汉鹏 , 胡晓婷 , 张露露 . 基于毛刺探测模型的低随机数SM4一阶门限实现[J]. 网络空间安全科学学报, 2026 , 4(3) : 80 -91 . DOI: 10.20172/j.issn.2097-3136.260602
Threshold implementation (TI), as a countermeasure against side-channel attacks with provable security, has been widely applied in cryptographic algorithms. Although various side-channel attack protection schemes for the SM4 algorithm have been proposed, existing schemes still exhibit security vulnerabilities when facing novel attack models such as the glitch-extended probing model. To this end, this paper proposes an improved first-order threshold implementation scheme for the S-box of the SM4 algorithm. This scheme designs the S-box based on the tower field GF((22)2)2 structure, reconstructs a multiplier that satisfies threshold properties, and introduces COTG (changing of the guards) technique to optimize the randomness addition strategy, reducing the randomness consumption of a single S-box to 10 bits. Furthermore, the theoretical security of the proposed scheme under the glitch-extended probing model is proven by utilizing the formal verification tool SILVER, and the actual protection capability of the overall physical circuit is validated through test vector leakage assessment (TVLA). The results demonstrate that the proposed scheme can effectively resist first-order side-channel attacks.
表 1 符号说明Table 1 Symbol description table |
| 符号说明 | 含义 |
| x=(x0, x1) | 表示x由两个份额x0, x1构成 |
| 表示xi的第k bit | |
| 表示x是1 bit变量 | |
| x||y | x和y拼接 |
| 函数fx的i个分量函数 | |
| mi | 用于刷新函数以满足联合均匀性的随机数, 且该随机数取自S盒或经复用得到 其中,m0~m7为1 bit,m8和m9为4 bit |
| ri | 用于刷新函数以满足联合均匀性的 新随机数,均为1 bit |
图 3 S盒门限实现第1和第2阶段Fig.3 First and second stages of the threshold implementation for S-box |
图 4 S盒门限实现第3和第4阶段Fig.4 Third and fourth stages of the threshold implementation for S-box |
表 2 SM4算法不同门限实现的安全性和硬件性能对比Table 2 Comparison of security and hardware performance for different threshold implementations for SM4 |
| 1 |
Kocher P, Jaffe J, Jun B. Differential power analysis[C]// Advances in Cryptology—CRYPTO'99, 19th Annual International Cryptology Conference, Santa Barbara, CA, USA, 1999: 388-397.
|
| 2 |
Bellizia D, Scotti G, Trifiletti A. Fully integrable current-mode feedback suppressor as an analog countermeasure against CPA attacks in 40nm CMOS technology[C]//13th Conference on Ph. D. Research in Microelectronics and Electronics (PRIME). IEEE, 2017: 349-352.
Bellizia D, Scotti G, Trifiletti A. Fully integrable current-mode feedback suppressor as an analog countermeasure against CPA attacks in 40nm CMOS technology[C]//13th Conference on Ph. D. Research in Microelectronics and Electronics (PRIME). IEEE, 2017: 349-352.
|
| 3 |
Chari S, Rao J R, Rohatgi P. Template attacks[C]//International workshop on cryptographic hardware and embedded systems. Berlin, Heidelberg: Springer Berlin Heidelberg, 2002: 13-28.
Chari S, Rao J R, Rohatgi P. Template attacks[C]//International workshop on cryptographic hardware and embedded systems. Berlin, Heidelberg: Springer Berlin Heidelberg, 2002: 13-28.
|
| 4 |
Fuhr T, Jaulmes É, Lomné V, et al. Fault attacks on AES with faulty ciphertexts only[C]//2013 Workshop on Fault Diagnosis and Tolerance in Cryptography. IEEE, 2013: 108-118.
|
| 5 |
张舒琪, 李延斌, 王蓬勃, 等. 抗侧信道攻击的后量子密码掩码转换方案[J]. 网络空间安全科学学报, 2024, 2 (5): 44- 56.
Zhang S Q, Li Y B, Wang P B, et al. Mask conversion scheme on post quantum cryptographic for resisting side channel attacks[J]. Journal of Cybersecurity, 2024, 2 (5): 44- 56.
|
| 6 |
Nikova S, Rechberger C, Rijmen V. Threshold implementations against sidechannel attacks and glitches[C]//International Conference on Information and Communications Security. Berlin, Heidelberg: Springer Berlin Heidelberg, 2006: 529-545.
|
| 7 |
Reparaz O, Bilgin B, Nikova S, et al. Consolidating masking schemes[C]//Annual Cryptology Conference. Berlin, Heidelberg: Springer Berlin Heidelberg, 2015: 764-783.
|
| 8 |
Daemen J. Changing of the guards: a simple and efficient method for achieving uniformity in threshold sharing[C]//International Conference on Cryptographic Hardware and Embedded Systems. Cham: Springer International Publishing, 2017: 137-153.
|
| 9 |
Liu B, Tang M. MS‐LW‐TI: Primitive‐based first‐order threshold implementation for 4× 4 S‐boxes[J]. IET Information Security, 2024 (1): 8851878.
|
| 10 |
Dhooghe S, Shahmirzadi A R, Moradi A. Second-order low-randomness d+1 hardware sharing of the AES[C]//Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 2022: 815-828.
|
| 11 |
Dhooghe S, Ovchinnikov A. Threshold implementations with non-uniform inputs[C]//International Conference on Selected Areas in Cryptography. Cham: Springer Nature Switzerland, 2023: 97-123.
|
| 12 |
Ishai Y, Sahai A, Wagner D. Private circuits: Securing hardware against probing attacks[C]//CRYPTO 2003: Advances in Cryptology, Santa Barbara, USA, 2003: 463-481.
|
| 13 |
Faust S, Grosso V, Del Pozo S M, et al. Composable masking schemes in the presence of physical defaults & the robust probing model[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2018 (3): 89- 120.
|
| 14 |
Shahmirzadi A R, Moradi A. Reconsolidating first-order masking schemes: nullifying fresh randomness[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2021: 305-342.
|
| 15 |
Yao F, Chen H, Wei Y, et al. Optimizing AES threshold implementation under the glitch-extended probing model[J]. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, 2024, 43 (7): 1984- 1997.
|
| 16 |
谭锐能, 卢元元, 田椒陵. 抗侧信道攻击的 SM4 多路径乘法掩码方法[J]. 计算机工程, 2014, 40 (5): 103- 108.
Tan R N, Lu Y Y, Tian J L. Multi-path multiplicative masking method of SM4 against side-channel attacks[J]. Computer Engineering, 2014, 40 (5): 103- 108.
|
| 17 |
梁浩, 乌力吉, 张向民. 基于复合域的SM4算法的设计与实现[J]. 微电子学与计算机, 2015, 32 (5): 16- 20.
Liang H, Wu L J, Zhang X M. Design and implementation of SM4 block cipher based on composite field[J]. Microelectronics & Computer, 2015, 32 (5): 16- 20.
|
| 18 |
裴超. 一种 SM4 掩码方法和抗 DPA 攻击分析[J]. 密码学报, 2016, 3 (1): 79- 90.
Pei C. A masking method of SM4 and analysis of anti-DPA attack[J]. Journal of Cryptologic Research, 2016, 3 (1): 79- 90.
|
| 19 |
李新超, 钟卫东, 张帅伟, 等. 一种基于门限实现的SM4算法S盒实现方案 [J]. 计算机工程与应用, 2018, 54 (17): 83-88.
Li X C, Zhong W D, Zhang S W, et al. A new threshold implementation of the S-box in SM4[J]. Journal of Cryptologic Research. 2018, 5(6): 641-650.
|
| 20 |
武小年, 李金林, 潘晟, 等. SM4算法门限掩码方案设计与实现[J]. 计算机应用研究, 2022, 39 (2): 572- 576.
Wu X N, Li J L, Pan S, et al. Design and implementation of threshold masking scheme for SM4 algorithm[J]. Application Research of Computers, 2022, 39 (2): 572- 576.
|
| 21 |
蒲金伟, 高倾健, 郑欣, 等. SM4抗差分功耗分析轻量级门限实现[J]. 计算机应用, 2023, 43 (11): 3490- 3496.
Pu J W, Gao Q J, Zheng X, et al. SM4 resistant differential power analysis lightweight threshold implementation[J]. Journal of Computer Applications, 2023, 43 (11): 3490- 3496.
|
| 22 |
吕述望, 苏波展, 王鹏, 等. SM4分组密码算法综述[J]. 信息安全研究, 2016, 2 (11): 995- 1007.
Lü S W, Su B Z, Wang P, et al. A review of the SM4 block cipher algorithm[J]. Information Security Research, 2016, 2 (11): 995- 1007.
|
| 23 |
Knichel D, Sasdrich P, Moradi A. SILVER-statistical independence and leakage verification[C]//International Conference on the Theory and Application of Cryptology and Information Security. Cham: Springer International Publishing, 2020: 787-816.
|
| 24 |
Barthe G, Belaïd S, Cassiers G, et al. maskverif: Automated verification of higher-order masking in presence of physical defaults[C]//European Symposium on Research in Computer Security. Cham: Springer International Publishing, 2019: 300-318.
|
| 25 |
Zhou F, Chen H, Fan L. Prover toward more efficient formal verification of masking in probing model[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2025 (1): 552- 585.
|
| 26 |
Gigerl B, Klug F, Mangard S, et al. Smooth passage with the guards: Second-order hardware masking of the AES with low randomness and low latency[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2024 (1): 309- 335.
|
| 27 |
Samwel N, Daemen J. DPA on hardware implementations of Ascon and Keyak[C]//Proceedings of the Computing Frontiers conference. 2017: 415-424.
|
| 28 |
Canright D. A very compact S-box for AES[C]//International Workshop on Cryptographic Hardware and Embedded Systems. Berlin, Heidelberg: Springer Berlin Heidelberg, 2005: 441-455.
|
| 29 |
郑震, 严迎建, 刘燕江. 侧信道能量信息测试向量泄漏评估技术[J]. 电子与信息学报, 2023, 45 (9): 3109- 3117.
Zheng Z, Yan Y J, Liu Y J. Test vector leakage assessment technique of side-channel power information[J]. Journal of Electronics & Information Technology, 2023, 45 (9): 3109- 3117.
|
/
| 〈 |
|
〉 |