| 注册
首页|期刊导航|密码学报(中英文)|针对Scloud+的高效密钥恢复:基于相关能量分析攻击

针对Scloud+的高效密钥恢复:基于相关能量分析攻击

白航宇 黄帆 段晓林 曾光 胡红钢

密码学报(中英文)2026,Vol.13Issue(4):748-769,22.
✕
密码学报(中英文)2026,Vol.13Issue(4):748-769,22.DOI:10.13868/j.cnki.jcr.000876

针对Scloud+的高效密钥恢复:基于相关能量分析攻击

Efficient Key Recovery via Correlation Power Analysis on Scloud+

白航宇 1黄帆 1段晓林 1曾光 2胡红钢3

作者信息

  • 1. 中国科学技术大学 网络空间安全学院 数字安全安徽省重点实验室,合肥 230026
  • 2. 华为技术有限公司 谢尔德实验室,北京 100195
  • 3. 中国科学技术大学 网络空间安全学院 数字安全安徽省重点实验室,合肥 230026||合肥国家实验室,合肥 230088
  • 折叠

摘要

Abstract

Scloud+is a next-generation post-quantum key encapsulation mechanism(KEM)that combines unstructured-LWE with ternary key encoding to achieve efficient lattice-based operations.This study systematically evaluates the physical security of the unprotected Scloud+implementation by proposing a novel two-phase correlation power analysis(CPA)framework exploiting micro-architectural leakage.First,a specific vulnerability is identified on the ARM Cortex-M4 architecture stemming from the 32-bit bus alignment during sequential LDRH instructions,establishing a micro-architectural Ham-ming distance(HD)leakage model.Based on this,the ternary key pair indistinguishability theorem is formulated and proved,which reveals the equivalence class partitioning of key pairs under a pure HD model.Subsequently,a two-phase attack framework is designed,fusing the bus-level HD model with an instruction-level Hamming weight(HW)model.Phase 1 determines pairwise group membership with low overhead(about 0.9 seconds in the propposed single-threaded implementation),while Phase 2 per-forms constrained iterative recovery within a reduced candidate space,incorporating a cross-validation mechanism to prevent error propagation.Compared with traditional single-HW-model iterative recov-ery schemes,experimental results on all 4800 key elements demonstrate that the proposed framework not only mitigates the accumulation of propagation errors but also reduces the HW evaluation workload by 25.1%,achieving full key recovery with as few as 20 power traces.To mitigate these vulnerabilities,a first-order arithmetic masking countermeasure is further proposed for this algorithm and its impact is discussed on the two leakage sources exploited by the proposed attack.The findings emphasize that robust side-channel resistance must be proactively integrated into the physical implementation of Scloud+to decouple architectural and algorithmic leakages.

关键词

侧信道攻击/相关能量分析/后量子密码/Scloud+

Key words

side channel attack/correlation power analysis(CPA)/post-quantum cryptography/Scloud+

分类

信息技术与安全科学

引用本文复制引用

白航宇,黄帆,段晓林,曾光,胡红钢..针对Scloud+的高效密钥恢复:基于相关能量分析攻击[J].密码学报(中英文),2026,13(4):748-769,22.

基金项目

National Cyber Security-National Science and Technology Major Project(2026ZD1501000) (2026ZD1501000)

National Cryptotologic Science Fund of China(2025NCSF01001) (2025NCSF01001)

National Natural Science Foundation of China(62472397) (62472397)

Quantum Science and Technology-National Science and Technology Major Project(2021ZD0302902) (2021ZD0302902)

密码学报(中英文)

2095-7025

访问量0
|
下载量0
段落导航相关论文