Side-Channel Attacks and Countermeasures for Identity-Based Cryptographic Algorithm SM9

Side-Channel Attacks and Countermeasures for Identity-Based Cryptographic Algorithm SM9
复制标题

基于身份的密码算法SM9的侧信道攻击及对策

DOI:
10.1155/2018/9701756
复制
发表时间:
2018
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
Liehuang Zhu
Liehuang Zhu
中科院分区:
--
文献类型:
--
作者:
Qi Zhang;An Wang;Yongchuan Niu;Ning Shang;Rixin Xu;Guoshuang Zhang;Liehuang Zhu

文献摘要

被引文献

相似文献

基于身份的加密算法SM9于2017年11月成为ISO/IEC 14888-3/AMD1标准的主要组成部分,该算法利用用户的身份生成公私钥对。在没有数字证书支持的情况下,它已被应用于云计算、网络物理系统、物联网等领域。本文讨论了SM9算法的实现及其简单功率攻击(SPA)。然后,我们提出了抗spa的SM9的模板攻击和故障攻击。我们的实验证明,如果攻击者尝试在8位微控制单元上进行模板攻击,则可以通过使设备执行一次来泄露密钥。故障攻击甚至允许攻击者通过两次执行算法并分析两次不同的结果来获得SM9的256位密钥。在此基础上,提出了抵御上述三种攻击的对策。
Identity-based cryptographic algorithm SM9, which has become the main part of the ISO/IEC 14888-3/AMD1 standard in November 2017, employs the identities of users to generate public-private key pairs. Without the support of digital certificate, it has been applied for cloud computing, cyber-physical system, Internet of Things, and so on. In this paper, the implementation of SM9 algorithm and its Simple Power Attack (SPA) are discussed. Then, we present template attack and fault attack on SPA-resistant SM9. Our experiments have proved that if attackers try the template attack on an 8-bit microcontrol unit, the secret key can be revealed by enabling the device to execute one time. Fault attack even allows the attackers to obtain the 256-bit key of SM9 by performing the algorithm twice and analyzing the two different results. Accordingly, some countermeasures to resist the three kinds of attacks above are given.