低随机数依赖的二阶毛刺探测安全uBlock实现OA
Implementation of Secure uBlock for Second-Order Glitch Detection with Low Random Number Dependence
布尔掩码技术作为一种主流的侧信道防护手段,在提升密码实现的安全性、灵活性、组合性和广泛应用方面具有显著优势,但高阶布尔掩码通常需要消耗大量的资源.本文研究并设计了两种针对uBlock的二阶门限实现方案,显著降低了 S盒模块对随机数的需求.第一种方案基于直接型S盒,采用三项式的门限实现方法,仅需74比特的随机数;第二种方案基于分解型S盒,采用面向域掩码的设计方案,仅需14比特的随机数,大幅减少了随机数的使用.使用形式化验证工具PROVER对两种S盒实现进行了毛剌探测模型下的安全性验证.使用Synopsys Design Compiler工具对所提两种方案的资源消耗进行了分析和对比.最后,使用泄漏评估技术(TVLA)对方案的硬件实现进行了分析与评估.实验结果显示,本文所提两种方案在一阶和二阶t-test下均是安全的.
As a mainstream side-channel protection method,Boolean masking technology has signif-icant advantages in improving the security,flexibility,composability,and wide application of crypto-graphic implementation,while high-order Boolean masking usually costs a large amount of resources,such as random numbers and area.This work studies and designs two second-order threshold im-plementation schemes for uBlock,which significantly reduce the random number requirement for the S-box module.The first scheme is based on the direct S-box,using a trinomial threshold implementa-tion method,requiring only 74 bit of random numbers;the second scheme is based on the decomposed S-box,using a domain-oriented masking technology,which only requires 14 bit of random numbers,thereby greatly reduced the use of random numbers.The formal verification tool PROVER is used to conduct security verification under the glitch detection model on the two S-box implementations.The Synopsys Design Compiler tool is used to analyze and compare the resource consumption of the two proposed solutions.Finally,the hardware implementation of the solution is analyzed and evalu-ated using Test Vector Leakage Assessment(TVLA).Experimental results show that the two schemes proposed in this work are safe under first-order and second-order t-tests.
戴泽龙;胡晓婷;祝汉鹏;张毅豪
江苏师范大学计算机科学与技术学院,徐州 221000江苏师范大学计算机科学与技术学院,徐州 221000江苏师范大学计算机科学与技术学院,徐州 221000江苏师范大学计算机科学与技术学院,徐州 221000
信息技术与安全科学
uBlock算法侧信道防护二阶门限实现面向域掩码毛剌探测模型
uBlock algorithmside-channel protectionsecond-order threshold implementationdomain-oriented maskingglitch-extended probing model
《密码学报(中英文)》 2026 (1)
43-59,17
江苏师范大学博士基金(20XSRX014)江苏师范大学研究生科研与实践创新计划(2024XKT2597)Jiangsu Normal University Doctoral Fund(20XSRX014)Jiangsu Normal University Graduate Student Research and Practice Innovation Program(2024XKT2597)
评论