基于类词元自注意力的SM4算法端到端建模攻击OA
End-to-end profiled attack on SM4 leveraging self-attention with a class token
密码设备的安全性尤为重要,能量分析是评估其硬件安全的关键手段.现有针对搭载SM4密码的设备的能量分析工作对有保护措施的密码设备的关注不足,难以在实际场景下直接应用于原始能量迹分析.同时,现有的端到端建模攻击框架,在分类任务的信息聚合效率上存在局限.针对这些问题,提出了一种基于自注意力机制的端到端建模攻击框架,并评估了有保护措施的SM4加密设备在抗侧信道攻击中的表现.首先引入可训练的类词元,并将其与预处理后的能量迹词元并行输入到多层自注意力编码器中.其次为了提升网络的信息聚合效率,仅使用类词元对应的编码器输出部分来执行分类任务.最后,基于提出的攻击框架,对采用掩码技术和随机延迟保护机制的SM4加密设备进行了端到端建模攻击.为保护加密设备,依据密码算法中间变量的信噪比,采用了轻量级二阶掩码方案以模糊泄露变量的功耗特征.在此基础上,通过对能量迹实施随机延迟,构建了4个不同防护措施下的SM4加密设备的能量迹数据集.在建模阶段,提出的攻击框架在全部4个实验组中的准确率均超过了现有端到端建模攻击框架,且在3个实验组中拥有更低的训练时间复杂度.在攻击阶段,分别使用2、19、23和71条能量迹恢复了无随机延迟及1倍、2倍、4倍时钟周期随机延迟保护下的密钥字节.为了评估模型在更严苛场景下的表现,烧录了三阶掩码和随机延迟交叉防护的密码设备,使用网络结构进行建模攻击,并进行了在单核CPU环境下的密钥攻击实验用以评估资源受限场景下密钥恢复的耗时.因此,所设计的网络结构有效提升了端到端建模攻击框架的信息聚合效率,并成功对SM4加密设备所泄漏原始能量迹进行了能量分析.
The security of cryptographic devices is vital,and power analysis is a key method for evaluating the security of hardware.However,the existing power analytical study of devices implementing the SM4 cipher has not adequately addressed protected cryptographic devices,which makes direct applications to the analysis of raw power trace in real-world scenarios challenging.Additionally,current end-to-end profiling attack frameworks on raw traces face limitations on information aggregation efficiency.To overcome these challenges,we propose an end-to-end profiling attack framework based on the self-attention mechanism and evaluate the side-channel resistance of SM4 encryption devices with protection measures.First,trainable class-token representations are introduced and processed in parallel with preprocessed trace tokens through a multi-layer self-attention encoder.Second,to enhance the information aggregation efficiency of the network,only the output that corresponds to the class-token representations is used for classification.Finally,by utiliz-ing the proposed framework,we conduct end-to-end profiling attacks on SM4 encryption devices with masking and random delay countermeasures.To protect the encryption devices,a lightweight second-order masking scheme is applied,which is based on the signal-to-noise ratios of the intermediate variables in the SM4 cipher,obscuring the power consumption characteristics of leakage variables.In addition,random delay noise is added into the power traces,creating four datasets with different protection configurations for SM4 encryption devices.In the profiling stage,the proposed framework achieves a higher accuracy than existing end-to-end profiling frameworks in all four experiments with a lower training time complexity in three of them.In the attack stage,2,19,23,and 71 power traces are required to recover key bytes under no delay and 1×,2×,and 4×clock-cycle random delay protections,respectively.To evaluate the model's performance in more stringent scenarios,we implement cryptographic devices with third-order masking and random delay cross-protection,apply the proposed network structure for profiling attacks,and conduct key recovery experiments in a single-core CPU environment to assess the time cost of key recovery in resource-constrained scenarios.Thus,the proposed network architecture significantly improves the information aggregation efficiency in end-to-end profiling attack frameworks and successfully performs a power analysis of raw power traces leaked from SM4 encryption devices.
张雨;王子龙;柴进晋;任思语;张柳
西安电子科技大学 网络与信息安全学院,陕西 西安 710071西安电子科技大学 网络与信息安全学院,陕西 西安 710071空军工程大学 防空反导学院,陕西 西安 710051西安电子科技大学 网络与信息安全学院,陕西 西安 710071西安电子科技大学 网络与信息安全学院,陕西 西安 710071
信息技术与安全科学
SM4算法侧信道攻击端到端建模攻击类词元自注意力模型
SM4 algorithmside-channel attackend-to-end profied attackclass tokenself-attention
《西安电子科技大学学报(自然科学版)》 2026 (3)
103-119,17
国家密码科学基金(2025NCSF02016)国家自然科学基金(62572369)陕西省自然科学基金(2024JC-YBQN-0677)
评论