密码学报(中英文)2026,Vol.13Issue(4):748-769,22.DOI:10.13868/j.cnki.jcr.000876
针对Scloud+的高效密钥恢复:基于相关能量分析攻击
Efficient Key Recovery via Correlation Power Analysis on Scloud+
摘要
Abstract
Scloud+is a next-generation post-quantum key encapsulation mechanism(KEM)that combines unstructured-LWE with ternary key encoding to achieve efficient lattice-based operations.This study systematically evaluates the physical security of the unprotected Scloud+implementation by proposing a novel two-phase correlation power analysis(CPA)framework exploiting micro-architectural leakage.First,a specific vulnerability is identified on the ARM Cortex-M4 architecture stemming from the 32-bit bus alignment during sequential LDRH instructions,establishing a micro-architectural Ham-ming distance(HD)leakage model.Based on this,the ternary key pair indistinguishability theorem is formulated and proved,which reveals the equivalence class partitioning of key pairs under a pure HD model.Subsequently,a two-phase attack framework is designed,fusing the bus-level HD model with an instruction-level Hamming weight(HW)model.Phase 1 determines pairwise group membership with low overhead(about 0.9 seconds in the propposed single-threaded implementation),while Phase 2 per-forms constrained iterative recovery within a reduced candidate space,incorporating a cross-validation mechanism to prevent error propagation.Compared with traditional single-HW-model iterative recov-ery schemes,experimental results on all 4800 key elements demonstrate that the proposed framework not only mitigates the accumulation of propagation errors but also reduces the HW evaluation workload by 25.1%,achieving full key recovery with as few as 20 power traces.To mitigate these vulnerabilities,a first-order arithmetic masking countermeasure is further proposed for this algorithm and its impact is discussed on the two leakage sources exploited by the proposed attack.The findings emphasize that robust side-channel resistance must be proactively integrated into the physical implementation of Scloud+to decouple architectural and algorithmic leakages.关键词
侧信道攻击/相关能量分析/后量子密码/Scloud+Key words
side channel attack/correlation power analysis(CPA)/post-quantum cryptography/Scloud+分类
信息技术与安全科学引用本文复制引用
白航宇,黄帆,段晓林,曾光,胡红钢..针对Scloud+的高效密钥恢复:基于相关能量分析攻击[J].密码学报(中英文),2026,13(4):748-769,22.基金项目
National Cyber Security-National Science and Technology Major Project(2026ZD1501000) (2026ZD1501000)
National Cryptotologic Science Fund of China(2025NCSF01001) (2025NCSF01001)
National Natural Science Foundation of China(62472397) (62472397)
Quantum Science and Technology-National Science and Technology Major Project(2021ZD0302902) (2021ZD0302902)