抗侧信道攻击的后量子密码掩码转换方案
网络出版日期: 2025-01-25
基金资助
国家自然科学基金(62072247, 62472259, 62172258);泰山学者青年项目;山东省自然科学基金(ZR2024QF098)
版权
Mask conversion scheme on post quantum cryptographic for resisting side channel attacks
Online published: 2025-01-25
Copyright
随着物联网(Internet of Things,IoT)技术的迅猛发展,数以亿计的设备通过网络互联,物联网安全性问题日益突出。尤其是在量子计算技术的推进下,传统的密码算法面临着前所未有的安全威胁。物联网设备所依赖的传统公钥加密算法在量子计算时代可能失效,给全球范围内的物联网应用带来了巨大的风险。作为抵御量子计算攻击的新型密码体系,后量子密码算法在物联网设备的安全性中起着至关重要的作用。然而,尽管后量子密码算法在理论上能够抵御量子计算的威胁,但在实际实现中,侧信道攻击(Side Channel Attaclss,SCA)风险依然不容忽视。侧信道攻击不依赖破解算法本身,而是通过分析物联网设备在运行加密算法时泄露的物理信息来破坏安全性。在此背景下,针对后量子密码算法的侧信道攻击掩码防护问题,综述了掩码转换方案——布尔到算术转换(Boolean to Arithmetic conversion,B2A)。通过对现有掩码技术的深入分析,详细阐述了B2A算法的原理、实现过程及其在抗侧信道攻击中的优势,为后量子密码算法在物联网设备中的安全实现提供思路,也为我国密码学领域的研究和发展提供参考。
张舒琪 , 李延斌 , 王蓬勃 , 葛春鹏 , 徐秋亮 . 抗侧信道攻击的后量子密码掩码转换方案[J]. 网络空间安全科学学报, 2024 , 2(5) : 44 -56 . DOI: 10.20172/j.issn.2097-3136.240504
With the rapid development of the Internet of Things (IoT) technology, billions of devices are interconnected through networks, and IoT security issues are becoming increasingly prominent. Especially with the advancement of quantum computing technology, traditional cryptographic algorithms are facing unprecedented security threats. The traditional public key encryption algorithms relied upon by IoT devices may become ineffective in the era of quantum computing, posing significant risks to IoT applications worldwide. As a new cryptographic system to resist quantum computing attacks, post quantum cryptographic algorithms play a crucial role in the security of IoT devices. However, although post quantum cryptography algorithms can theoretically resist the threat of quantum computing, the risk of side channel attacks (SCA) in their practical implementation cannot be ignored. Side channel attacks do not rely on the cracking algorithm itself, but instead undermine security by analyzing the physical information leaked by IoT devices when running encryption algorithms. In this context, a mask conversion scheme called boolean to arithmetic conversion (B2A) is reviewed to address the issue of side channel attack mask protection in post quantum cryptography algorithms. Through in-depth analysis of existing masking techniques, the principle, implementation process, and advantages of B2A method in resisting side channel attacks are elaborated in detail, providing ideas for the secure implementation of post quantum cryptography algorithms in IoT devices and references for research and development in the field of cryptography in China.
表 1 B2A算法的操作计数,阶数最高为t=12,掩码份额为n=t+1Table 1 Operation count for B2A conversion algorithms, up to security order t = 12, with n = t + 1 shares |
表 2 B2A算法的运行时间(μs),在3.2 GHz英特尔处理器的iMac上用C语言实现Table 2 Running time (μs) for B2A conversion algorithms. The implementation was done in C on a iMac running a 3.2 GHz Intel processor |
表 3 对于算法12 |
| n | |||||||||||
| 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 16 | |
| k=4 | 76 | 174 | 308 | 478 | 684 | 926 | 1 204 | 1 518 | 1 868 | 2 254 | 4 724 |
| k=8 | 156 | 354 | 624 | 966 | 1 380 | 1 866 | 2 424 | 3 054 | 3 756 | 4 530 | 9 480 |
| k=15 | 296 | 669 | 1 177 | 1 820 | 2 598 | 3 511 | 4 559 | 5 742 | 7 060 | 8 513 | 17 803 |
表 4 对于素数q=223−213+1,18位模q B2A算法的操作计数,安全阶数达到t=12,使用n=t+1个份额Table 4 Operation count for 18-bit B2A modulo q conversion algorithms, up to security order t = 12, with n = t + 1 shares, for prime q=223−213+1 |
| B→A mod q | 安全阶数 t | |||||||
| 2 | 3 | 4 | 5 | 6 | 8 | 10 | 12 | |
| [SPOG19] 18→mod q | 804 | 1 414 | 2 186 | 3 120 | 4 216 | 6 894 | 10 220 | 14 194 |
| BtoAqApprox | 58 | 135 | 292 | 609 | 1 246 | 5 080 | 20 434 | 81 868 |
| BtoAqExact | 154 | 285 | 610 | 1 032 | 1 786 | 6 160 | 21 938 | 83 860 |
表 5 μ位模q的B2A算法的循环计数(μ=18, |
| B→A mod q | Security order t | |||||
| 1 | 2 | 3 | 4 | 5 | 6 | |
| [SPOG19] | 694 | |||||
| BtoAqApprox | 24 | 80 | 310 | 518 | 908 | 1963 |
| BtoAqExact | 351 | 445 | 979 | |||
| 1 |
BANERJEE U,PATHAK A,CHANDRAKASAN A P. An energy-efficient configurable lattice cryptography processor for the quantum-secure Internet of Things[C]//2019 IEEE International Solid-State Circuits Conference (ISSCC). IEEE,2019:46-48.
|
| 2 |
眭晗, 吴文玲. 后量子对称密码的研究现状与发展趋势[J]. 电子与信息学报, 2020, 42 (2): 287- 294.
SUI H, WU W L. Research status and development trend of posterior quantum symmetric cryptography[J]. Journal of Electronics and Informatics, 2020, 42 (2): 287- 294.
|
| 3 |
王永利, 徐秋亮. 量子计算与量子密码的原理及研究进展综述[J]. 计算机研究与发展, 2020, 57 (10): 2015- 2026.
WANG Y L, XU Q L. Review on the principle and research progress of quantum computing and quantum cryptography[J]. Computer Research & Development, 2020, 57 (10): 2015- 2026.
|
| 4 |
LI J, LOUCKS W, ZHAI Y I, et al. The national institute of standards and technology post-quantum cryptography[EB/OL].(2016-08-02)[2024-08-07] https://csrc.nist.gov/projects/post-quantum-cryptography.
|
| 5 |
ROY K S, KALITA H K. A survey on post-quantum cryptography for constrained devices[J]. International Journal of Applied Engineering Research, 2019, 14 (11): 2608- 2615.
|
| 6 |
LU X, LIU Y, ZHANG Z, et al. LAC: practical ring-LWE based public-key encryption with byte-level modulus[J]. IRCA Cryptology ePrint Archive, 2018, 2018, 1009.
|
| 7 |
ZHANG J, YU Y, FAN S, et al. Improved lattice-based CCA2-secure PKE in the standard model[J]. Science China Information Sciences, 2020, 63 (8): 1- 22.
|
| 8 |
XU Z, PEMBERTON O, ROY S S, et al. Magnifying side-channel leakage of lattice-based cryptosystems with chosen ciphertexts: the case study of kyber[J]. IEEE Transactions on Computers, 2021, 71 (9): 2163- 2176.
|
| 9 |
BHASIN S,D'ANVERS J P,HEINZ D,et al. Attacking and defending masked polynomial comparison for lattice-based cryptography[J]//IACR Transactions on Cryptographic Hardware and Embedded Systems,2021:334-359.
|
| 10 |
AMIET D,CURIGER A,LEUENBERGER L,et al. Defeating Newhope with a Single Trace[C]//International Conference on Post-Quantum Cryptography. Cham:Springer,2020:189-205.
|
| 11 |
ZHANG F, YANG B, DONG X, et al. Side-channel analysis and countermeasure design on arm-based quantum-resistant SIKE[J]. IEEE Transactions on Computers, 2020, 69 (11): 1681- 1693.
|
| 12 |
KANNWISCHER M J,PESSL P,PRIMAS R. Single-trace attacks on keccak[C]//IACR Transactions on Cryptographic Hardware and Embedded Systems,2020:243-268.
|
| 13 |
HASSAN S,GRIDIN I,DELGADO-LOZANO I M,et al. Déjà Vu:side-channel analysis of mozilla’s NSS[C]//Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security. ACM,2020:1887-1902.
|
| 14 |
PESSL P,PRIMAS R. More practical single-trace attacks on the number theoretic transform[C]//International Conference on Cryptology and Information Security in Latin America. Cham:Springer,2019:130-149.
|
| 15 |
SCHAMBERGER T,RENNER J,SIGL G,et al. A power side-channel attack on the CCA2-secure HQC KEM[C]//19th Smart Card Research and Advanced Application Conference (CARDIS2020). Cham:Springer International Publishing,2021:119-134.
|
| 16 |
GELLERSEN T,SEKER O,EISENBARTH T. Differential power analysis of the picnic signature scheme[C]//Post-Quantum Cryptography:12th International Workshop,PQCrypto 2021, Daejeon, South Korea, July 20–22, 2021, Proceedings 12. Springer International Publishing, 2021: 177-194.
|
| 17 |
LIU Y, ZHOU Y, SUN S, et al. On the security of lattice-based Fiat-Shamir signatures in the presence of randomness leakage[J]. IEEE Transactions on Information Forensics and Security, 2020, 16, 1868- 1879.
|
| 18 |
CHARI S,JUTLA C S,RAO J R,et al. Towards sound approaches to counteract power-analysis attacks[C]//Advances in Cryptology-CRYPTO’ 99: 19th Annual International Cryptology Conference Santa Barbara, California, USA, August 15–19, 1999 Proceedings 19. Springer Berlin Heidelberg, 1999: 398-412.
|
| 19 |
PROUFF E,RIVAIN M. Masking against side-channel attacks:a formal security proof[C]//Annual International Conference on the Theory and Applications of Cryptographic Techniques. Berlin, Heidelberg: Springer Berlin Heidelberg, 2013:142-159.
|
| 20 |
CHARI S,RAO J R,ROHATGI P. Template attacks[C]//Cryptographic Hardware and Embedded Systems-CHES 2002:4th International Workshop Redwood Shores. Berlin,Heidelberg:Springer,2003:13-28.
|
| 21 |
BARTHE G,BELAÏD S,ESPITAU T,et al. Masking the GLP lattice-based signature scheme at any order[C]//Advances in Cryptology-EUROCRYPT 2018:37th Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham:Springer International Publishing,2018:354-384.
|
| 22 |
BOS J W,GOURJON M,RENES J,et al. Masking kyber:first-and higher-order implementations[J]//IACR Transactions on Cryptographic Hardware and Embedded Systems. 2021:173-214.
|
| 23 |
MIGLIORE V,GÉRARD B,TIBOUCHI M,et al. Masking dilithium-efficient implementation and side-channel evaluation[C]//Applied Cryptography and Network Security:17th International Conference,ACNS 2019. Cham:Springer International Publishing,2019:344-362.
|
| 24 |
GOUBIN L. A sound method for switching between boolean and arithmetic masking[C]//Cryptographic Hardware and Embedded Systems-CHES 2001:3rd International Workshop. Berlin,Heidelberg:Springer,2001:3-15.
|
| 25 |
CORON J S. High-order conversion from boolean to arithmetic masking[C]//International Conference on Cryptographic Hardware and Embedded Systems. Cham:Springer International Publishing,2017:93-114.
|
| 26 |
BETTALE L,CORON J S,ZEITOUN R. Improved high-order conversion from Boolean to arithmetic masking[J]//IACR Transactions on Cryptographic Hardware and Embedded Systems. 2018:22-45.
|
| 27 |
SCHNEIDER T,PAGLIALONGA C,ODER T,et al. Efficiently masking binomial sampling at arbitrary orders for lattice-based crypto[C]//Public-Key Cryptography-PKC 2019:22nd IACR International Conference on Practice and Theory of Public-Key Cryptography. Cham:Springer International Publishing,2019:534-564.
|
| 28 |
CORON J S,GÉRARD F,TRANNOY M,et al. Improved gadgets for the high-order masking of Dilithium. [J]//IACR Transactions on Cryptographic Hardware and Embedded Systems. 2023:110-145.
|
| 29 |
HUTTER M, TUNSTALL M. Constant-time higher-order boolean-to-arithmetic masking[J]. Journal of Cryptographic Engineering, 2019, 9 (2): 173- 184.
|
| 30 |
CORON J S,GROßSCHÄDL J,VADNALA P K. Secure conversion between boolean and arithmetic masking of any order[C]//International Workshop on Cryptographic Hardware and Embedded Systems. Berlin,Heidelberg:Springer,2014:188-205.
|
/
| 〈 |
|
〉 |