白盒密码实现的侧信道分析技术综述
网络出版日期: 2025-01-25
基金资助
国家自然科学基金(U2336209,62072192);广东省基础与应用基础研究基金(2022A1515140090)
版权
A survey of side-channel analysis on white-box cryptography
Online published: 2025-01-25
Copyright
白盒攻击假设攻击者完全控制加密算法的执行设备,并可观察和篡改所有内部数据,因此,传统密码算法无法有效防御此类威胁。为应对白盒攻击对分组密码安全的挑战,白盒密码实现已成为研究热点。然而,现有白盒密码实现不仅难以抵御白盒攻击,还可能受到能力更受限的侧信道攻击,如计算分析和故障分析。针对这些威胁,提出了一系列防御策略,但这些策略也导致更强的改进攻击手段。目前,侧信道技术已成为白盒密码设计的主要挑战。根据算法框架和攻击类型对现有攻击手段进行了分类,总结了防御策略及其改进攻击,探讨了面临的威胁与挑战,并展望了未来可能的侧信道攻击技术及防御方案。
赵良驹 , 汤宇锋 , 龚征 . 白盒密码实现的侧信道分析技术综述[J]. 网络空间安全科学学报, 2024 , 2(6) : 57 -73 . DOI: 10.20172/j.issn.2097-3136.240604
White-box attacks assume that the execution device of the encryption algorithm is completely controlled by an attacker, and all the internal data can be observed and tampered with, making the traditional cryptographic algorithms ineffective against such threats. To address the challenges posed by white-box attacks on the block cipher security, white-box cryptography implementations have become a research hotspot. However, the existing white-box cryptography implementations not only struggle to withstand white-box attacks but also are vulnerable to side-channel attacks with more limited capabilities, such as computation analysis and fault analysis. A series of protective strategies have been proposed to counter these threats, but also leading to the development of stronger countermeasures. Currently, side-channel techniques have become the primary challenge during the white-box cryptographic design. The existing attack methods were categorized based on algorithm frameworks and attack types, and the protective strategies along with their corresponding counterattacks were summarized. The threats and challenges currently faced were discussed, and future side-channel attack techniques and defensive solutions were explored.
表 1 白盒实现性能对比Table 1 Comparison of the performances of white-box implementations |
| 算法 | 框架 | 次数 | 内存占用 (MB) | 加密单 分组时 间(ms) | 文献 |
| AES-CEJO | CEJO | — | 1.05 | 0.001 7 | [5] |
| AES-XiaoLai | CEJO | — | 20.33 | 0.001 9 | [18] |
| SM4-XiaoLai | CEJO | — | 1.32 | 0.025 | [26] |
| SM4-BaiWu | CEJO | — | 33.71 | 0.000 79 | [27] |
| SM4-WSISE | CEJO | — | 1.42 | 0.026 | [28] |
| SPECK | SE | — | 1.74 | 0.23 | [24] |
| SPECK | IF | 2 | 4.70 | 18.87 | [25] |
| SPECK | IF | 3 | 45.10 | 166.67 | |
| SPECK | IF | 4 | 788.20 | 2 390.00 | |
| AES | BU掩码 | — | 3.50 | 3.79 | [29] |
| SEL掩码 | 1 | 2.56 | 4.49 | [30] | |
| SEL掩码 | 2 | 2.57 | 5.09 | ||
| SM4 | BU掩码 | — | 5.01 | 2.77 | [29] |
| SEL掩码 | 1 | 3.54 | 3.84 | [30] | |
| SEL掩码 | 2 | 3.62 | 4.30 |
表 2 不同计算分析方法的对比以及对不同次数的内部编码的攻击效果Table 2 Comparison of different computational analyses and the attack effectiveness on internal encodings with varying degree |
| 攻击 | 采集轨迹位置 | 方法 | 攻破编码能力的解释 | 能攻击的编码代数次数 | 时间复杂度 | |
| >50% | 100% | |||||
| DCA | S盒输出 | 相关系数分析 | 线性编码的HW = 1 | 2,3,4,5 | — | 222 |
| IDCA | 1,2,3,4,5 | 1,5 | 227 | |||
| CPA | 中间变量的函数是非注入的且编码是双射 | 2,3,4,5 | — | 222 | ||
| CA | 2,3,4,5 | — | 229 | |||
| MIA | 2,3,4,5 | — | 222 | |||
| SA | 频谱分析 | — | 1,2,3,4,5,6 | 1,2,3,4,5,6 | 227 | |
| MSA | 线性编码的非平衡性 | 1,2,3,4,5 | 1 | 222 | ||
| ISA | 线性编码的不可逆性 | 1,2,3,4,5,6 | 1,2,3,4,5,6 | 232 | ||
| ADCA | 代数次数分析 | S盒和编码次数不同 | 1,2,3,4,5,6 | 1,2,3,4,5,6 | 221.32~224.07 | |
| DCA | 列混淆输出 | 相关系数分析 | 线性编码的HW = 1 | 1,2,3,4,5,6,7 | 1,2,3,4,5,6,7 | 235 |
表 3 现有掩码方案计算形式Table 3 Calculation forms of existing masking schemes |
| 方案 | 计算形式 | 次数(Degree) | 阶数(Order) |
| 线性掩码 | — | n | |
| BU掩码 | 1 | 1 | |
| GRW掩码 | 1 | ||
| 1 | |||
| 1 | |||
| SEL掩码 | d |
| 1 |
吴文玲,冯登国,张文涛. 分组密码的设计与分析[M]. 北京:清华大学出版社,2009.
WU W L,FENG D G,ZHANG W T. Design and analysis of block ciphers [M]. Beijing:Tsinghua University Press,2009.
|
| 2 |
KOCHER P C,JAFFE J,JUN B. Differential power analysis[C]//Advances in Cryptology-CRYPTO’99,19th Annual International Cryptology Conference. Berlin,Heidelberg:Springer,1999:388-397.
|
| 3 |
BONEH D,DEMILLO R A,LIPTON R J. On the importance of checking cryptographic protocols for faults[C]//Proceedings of the Advances in Cryptology-EUROCRYPT’97. Berlin,Heidelberg:Springer,1997:37-51.
|
| 4 |
TSUNOO Y,SAITO T,SUZAKI T,et al. Cryptanalysis of DES implemented on computers with Cache[C]//International Workshop on Cryptographic Hardware and Embedded Systems. Berlin,Heidelberg:Springer,2003:62-76.
|
| 5 |
CHOW S,EISEN P,JOHNSON H,et al. White-box cryptography and an AES implementation[C]//International Workshop on Selected Areas in Cryptography. Berlin,Heidelberg:Springer,2003:250-270.
|
| 6 |
KERCKHOFFS A. La cryptographie militaire[J].Journal des Sciences Militaires,1883,9:5-38.
|
| 7 |
BOS J W,HUBAIN C,MICHIELS W,et al. Differential computation analysis:hiding your white-box designs is not enough[C]//International Conference on Cryptographic Hardware and Embedded Systems. Berlin,Heidelberg:Springer,2016:215-236.
|
| 8 |
SANFELIX E,MUNE C,DE HAAS J. Unboxing the white-box:practical attacks against obfuscated ciphers[Z]. Presentation at BlackHat Europe. 2015.
|
| 9 |
TEUWEN P,HUBAIN C. Differential fault analysis on white-box AES implementations [EB/OL]. (2016-01-19)[2024-12-09]. https://blog.quarkslab.com/differential-fault-analysis-on-white-box-aes-implementations.html.
|
| 10 |
PROUFF E,CHENG C M,YANG B Y,et al. The WhibOx contest:an ecrypt white-box cryptography competition[EB/OL]. (2017-09-30)[2024-12-09]. https://whibox-contest.github.io/2017/.
|
| 11 |
CryptoExperts,CyberCrypt. CHES 2019 capture the flag challenge-the WhibOx contest[EB/OL]. (2019-09-13)[2024-12-09]. https://whibox.io/contests/2019/.
|
| 12 |
林婷婷,来学嘉. 白盒密码研究 [J]. 密码学报,2015,2(3):258-267.
LIN T T,LAI X J. Research on white-box cryptography [J]. Journal of Cryptologic Research,2015,2(3):258-267.
|
| 13 |
荆继武, 李畅. 密码技术的现状与白盒化发展趋势[J]. 中国信息安全, 2021, (8): 49- 53.
JING J W, LI C. Current status of cryptographic technology and the development trend of white-box implementation[J]. China Information Security, 2021, (8): 49- 53.
|
| 14 |
王锦良, 魏英凯. 国内白盒密码算法发展状况的思考[J]. 工业信息安全, 2023, (3): 41- 46.
WANG J L, WEI Y K. Reflections on the development of domestic white-box cryptographic algorithms[J]. Industry Information Security, 2023, (3): 41- 46.
|
| 15 |
CHOW S,EISEN P,JOHNSON H,et al. A white-box DES implementation for DRM applications[C]//ACM Workshop on Digital Rights Management. Berlin,Heidelberg:Springer,2003:1-15.
|
| 16 |
BILLET O,GILBERT H,ECH-CHATBI C. Cryptanalysis of a white-box AES implementation[C]//International Workshop on Selected Areas in Cryptography. Berlin,Heidelberg:Springer,2005:227-240.
|
| 17 |
BRINGER J,CHABANNE H,DOTTAX E. White-box cryptography:another attempt [DB/OL]. (2006-12-20)[2024-12-09]. https://eprint.iacr.org/2006/468.
|
| 18 |
XIAO Y,LAI X. A secure implementation of white-box AES[C]//Proceedings of the 2009 2nd International Conference on Computer Science and Its Applications.IEEE,2009:1-6.
|
| 19 |
KARROUMI M. Protecting white-box AES with dual ciphers[C]// International Conference on Information Security and Cryptology. Berlin,Heidelberg:Springer,2010:278-291.
|
| 20 |
DE MULDER Y,WYSEUR B,PRENEEL B. Cryptanalysis of a perturbated white-box AES implementation[C]//International Conference on Cryptology in India. Berlin,Heidelberg:Springer,2010:292-310.
|
| 21 |
DE MULDER Y,ROELSE P,PRENEEL B. Cryptanalysis of the Xiao-Lai white-box AES implementation[C]//International Conference on Selected Areas in Cryptography. Berlin,Heidelberg:Springer,2013:34-49.
|
| 22 |
MCMILLION B,SULLIVAN N. Attacking white-box AES constructions[C]//2016 ACM SIGSAC Conference on Computer and Communications Security. Association for Computing Machinery,2016:85-90.
|
| 23 |
LEPOINT T,RIVAIN M,DE MULDER Y,et al. Two attacks on a white-box AES implementation[C]//International Conference on Selected Areas in Cryptography. Berlin,Heidelberg:Springer,2014:265-285.
|
| 24 |
VANDERSMISSEN J,RANEA A,PRENEEL B. A white-box speck implementation using self-equivalence encodings[C]//International Conference on Applied Cryptography and Network Security. Cham:Springer,2022:771-791.
|
| 25 |
RANEA A,VANDERSMISSEN J,PRENEEL B. Implicit white-box implementations:White-boxing ARX ciphers[C]//Annual International Cryptology Conference. Cham:Springer,2022:33-63.
|
| 26 |
肖雅莹. 白盒密码及AES 与SMS4 算法的实现[D]. 上海:上海交通大学,2010.
XIAO Y Y. White-box cryptography and implementations of AES and SMS4 [D]. Shanghai:Shanghai Jiao Tong University,2010.
|
| 27 |
BAI K, WU C. A secure white-box SM4 implementation[J]. Security Communication Networks, 2016, 9 (10): 996- 1006.
|
| 28 |
姚思, 陈杰. SM4 算法的一种新型白盒实现[J]. 密码学报, 2020, 7 (3): 358- 374.
YAO S, CHEN J. A new method for white-box implementation of SM4 algorithm[J]. Journal of Cryptologic Research, 2020, 7 (3): 358- 374.
|
| 29 |
BIRYUKOV A,UDOVENKO A. Attacks and countermeasures for white-box designs[C]//International Conference on the Theory and Application of Cryptology and Information Security. Cham:Springer,2018:373-402.
|
| 30 |
SEKER O,EISENBARTH T,LISKIEWICZ M. A white-box masking scheme resisting computational and algebraic attacks[DB/OL]. (2021-01-23)[2024-12-09]. https://eprint.iacr.org/2020/443.
|
| 31 |
Intel. Pin-a dynamic binary instrumentation tool [EB/OL]. (2024-12-23)[2024-12-09]. https://software.intel.com/content/www/us/en/develop/articles/pin-a-dynamic-binary-instrumentation-tool.html/.
|
| 32 |
ALPIREZ BOCK E, BOS J W, BRZUSKA C, et al. White-box cryptography: don’t forget about grey-box attacks[J]. Journal of Cryptology, 2019, 32, 1095- 1143.
|
| 33 |
BOCK E A,BRZUSKA C,MICHIELS W,et al. On the ineffectiveness of internal encodings-revisiting the DCA attack on white-box cryptography[C]//International Conference on Applied Cryptography and Network Security. Cham:Springer,2018:103-120.
|
| 34 |
RIVAIN M, WANG J. Analysis and improvement of differential computation attacks against internally-encoded white-box implementations[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019, (2): 225- 255.
|
| 35 |
SASDRICH P,MORADI A,GÜNEYSU T. White-box cryptography in the gray box[C]//International Conference on Fast Software Encryption. Berlin,Heidelberg:Springer,2016:185-203.
|
| 36 |
LEE S,JHO N S,KIM M. On the linear transformation in white-box cryptography[DB/OL]. (2020-02-28)[2024-12-09]. https://eprint.iacr.org/2018/1047.
|
| 37 |
CARLET C, GUILLEY S, MESNAGER S. Structural attack (and repair) of diffused-input-blocked-output white-box cryptography[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2021, (4): 57- 87.
|
| 38 |
TANG Y, GONG Z, LI B, et al. Revisiting the computation analysis against internal encodings in white-box implementations[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023, (4): 493- 522.
|
| 39 |
CASTELNOVI L, HOUZELOT A. On the (im)possibility of preventing differential computation analysis with internal encodings[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2024, (3): 452- 471.
|
| 40 |
TANG Y, GONG Z, ZHAO L, et al. Unboxing ARX-based white-box ciphers: chosen-plaintext computation analysis and is applications[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2024, (3): 634- 670.
|
| 41 |
BIHAM E,SHAMIR A. Differential fault analysis of secret key cryptosystems[C]//Advances in Cryptology-CRYPTO’97,17th Annual International Cryptology Conference Santa Barbara. Berlin,Heidelberg:Springer,1997:513-525.
|
| 42 |
NETHERCOTE N, SEWARD J. Valgrind: a framework for heavyweight dynamic binary instrumentation[J]. ACM Sigplan notices, 2007, 42 (6): 89- 100.
|
| 43 |
ENGINE U. Unicorn CPU emulator framework[EB/OL]. (2015-8-1)[2022-11-1]. https://www.unicorn-engine.org/.
|
| 44 |
Panda. Platform for architecture-neutral dynamic analysis[EB/OL]. (2018-05-07)[2024-12-09]. https://github.com/panda-re/panda.
|
| 45 |
DUSART P,LETOURNEUX G,VIVOLO O. Differential fault analysis on AES[C]//International Conference on Applied Cryptography and Network Security. Berlin,Heidelberg:Springer,2003:293-306.
|
| 46 |
SideChannelMarvels. Repository of various public white-box cryptographic implementations and their practical attacks[EB/OL]. (2024-07-06)[2024-12-09]. https://github.com/SideChannelMarvels.
|
| 47 |
SECCON. SECCON 2016 online CTF for public [EB/OL]. (2016-12-11)[2024-12-09]. https://github.com/SECCON/SECCON2016_online_CTF/.
|
| 48 |
孙涛,唐国俊,吴昕锴,等. 一种NoisyRounds 保护的白盒AES 实现及其差分故障分析 [J]. 密码学报,2020,7(3):342-357.
SUN T,TANG G J,WU X K,et al. White-box AES implementation protected by NoisyRounds and its differential fault analysis [J]. Journal of Cryptologic Research,2020,7(3):342-357.
|
| 49 |
ISHAI Y,SAHAI A,WAGNER D. Private circuits:securing hardware against probing attacks[C]//Annual International Cryptology Conference. Berlin,Heidelberg:Springer,2003:463-481.
|
| 50 |
GOUBIN L, PAILLIER P, RIVAIN M, et al. How to reveal the secrets of an obscure white-box implementation[J]. Journal of Cryptographic Engineering, 2020, 10 (1): 49- 66.
|
| 51 |
GOUBIN L, RIVAIN M, WANG J. Defeating state-of-the-art white-box countermeasures with advanced gray-box attacks[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020, (3): 454- 482.
|
| 52 |
BOGDANOV A,RIVAIN M,VEJRE P S,et al. Higher-order DCA against standard side-channel countermeasures[C]//International Workshop on Constructive Side-Channel Analysis and Secure Design. Cham:Springer,2019:118-141.
|
| 53 |
LEE S,KIM M. Improvement on a masked white-box cryptographic implementation[DB/OL]. (2020-12-18)[2024-12-09]. https://eprint.iacr.org/2020/199.
|
| 54 |
TANG Y,GONG Z,SUN T,et al. Adaptive side-channel analysis model and its applications to white-box block cipher implementations[C]//International Conference on Information Security and Cryptology. Cham:Springer,2021:399-417.
|
| 55 |
BIRYUKOV A,UDOVENKO A. Dummy shuffling against algebraic attacks in white-box implementations[C]//Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham:Springer,2021:219-248.
|
| 56 |
BATTISTELLO A,CASTELNOVI L,CHABRIER T. Enhanced encodings for white-box designs[C]//International Conference on Smart Card Research and Advanced Applications.Cham: Springer,2022:254-274.
|
| 57 |
TANG Y, GONG Z, CHEN J, et al. Higher-order DCA attacks on white-box implementations with masking and shuffling countermeasures[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2022, (1): 369- 400.
|
| 58 |
LEE S, KIM J N. Balanced encoding of near-zero correlation for an AES implementation[J]. IEEE Transactions on Information Forensics and Security, 2024, (19): 6589- 6603.
|
| 59 |
原梓清, 陈杰. 一种抗差分计算分析的白盒 SM4 方案[J]. 密码学报, 2023, 10 (2): 386- 396.
YUAN Z Q, CHEN J. A white-box SM4 scheme resistant to differential computational analysis[J]. Journal of Cryptologic Research, 2023, 10 (2): 386- 396.
|
| 60 |
CHARLÈS A, UDOVENKO A. LPN-based attacks in the white-box setting[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023, (4): 318- 343.
|
| 61 |
CHARLÈS A, UDOVENKO A. White-box filtering attacks breaking SEL masking: from exponential to polynomial time[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2024, (3): 1- 24.
|
| 62 |
AMADORI A,MICHIELS W,ROELSE P. Automating the BGE attack on white-boxx implementations of AES with external encodings[C]//2020 IEEE 10th International Conference on Consumer Electronics (ICCE-Berlin). IEEE,2020:1-6.
|
| 63 |
LEE S,JHO N S,KIM M. Table redundancy method for protecting against fault attacks[DB/OL]. (2021-06-28)[2024-12-09]. https://eprint.iacr.org/2019/959.
|
| 64 |
DENG T,LI P,YANG S,et al. A deep-learning approach for predicting round obfuscation in white-box block ciphers[C]//Applied Cryptography and Network Security Workshops. Cham:Springer,2023:419-438.
|
| 65 |
GRAVOUIL C. A new generic fault resistant masking scheme using error-correcting codes [DB/OL]. (2023-02-27)[2024-12-09]. https://eprint.iacr.org/2023/118.
|
| 66 |
龚征,黎伟杰,廖国鸿,等. SWAN 分组密码算法 [EB/OL]. (2019-12-31)[2024-12-09]. https://sfjs.cacrnet.org.cn/site/content/397.html
GONG Z,LI W J,LIAO G H,et al. SWAN block cipher [EB/OL]. (2019-12-31)[2024-12-09]. https://sfjs.cacrnet.org.cn/site/content/397.html
|
| 67 |
BAKSI A, BHASIN S, BREIER J, et al. DEFAULT:cipher level resistance against differential fault attack[C]//International Conference on the Theory and Application of Cryptology and Information Security. Cham:Springer,2021:124-256.
|
| 68 |
NAGELER M, DOBRAUNIG C, EICHLSEDER M. Information-combining differential fault attacks on DEFAULT [DB/OL].(2024-06-07)[2024-12-09]. https://eprint.iacr.org/2021/1374.
|
/
| 〈 |
|
〉 |