arXiv:2501.13748cs.LGcs.CR2025-01ICML被引 7

提出精确快速的侧信道攻击方法,提升密码破解成功率。

Exact Soft Analytical Side-Channel Attacks using Tractable Circuits

  • 用可计算的概率电路实现精确推断,替代传统近似算法。
  • 对AES攻击中,成功率达31%以上,显著优于现有方法。
  • 计算开销低,适合实际应用中的高精度密码分析。

检测密码算法漏洞对构建安全信息系统至关重要。当前最先进的软分析侧信道攻击(SASCA)利用物理泄漏信息对中间计算进行概率预测,并结合已知算法逻辑推导密钥后验分布。该方法通常采用环路信念传播,但缺乏收敛性和推理质量保证。本文提出一种名为ExSASCA的快速精确推断方法,借助知识编译与可计算概率电路,在攻击最广泛使用的高级加密标准(AES)时,相比SASCA的顶1成功率绝对提升超过31%。通过稀疏信念消息,性能提升仅带来轻微额外计算成本,且比穷举精确推断少约3个数量级;即使在密集信念消息下,也仅需穷举法6倍的计算量。

原文摘要 · Abstract (English)

Detecting weaknesses in cryptographic algorithms is of utmost importance for designing secure information systems. The state-of-the-art soft analytical side-channel attack (SASCA) uses physical leakage information to make probabilistic predictions about intermediate computations and combines these "guesses" with the known algorithmic logic to compute the posterior distribution over the key. This attack is commonly performed via loopy belief propagation, which, however, lacks guarantees in terms of convergence and inference quality. In this paper, we develop a fast and exact inference method for SASCA, denoted as ExSASCA, by leveraging knowledge compilation and tractable probabilistic circuits. When attacking the Advanced Encryption Standard (AES), the most widely used encryption algorithm to date, ExSASCA outperforms SASCA by more than 31% top-1 success rate absolute. By leveraging sparse belief messages, this performance is achieved with little more computational cost than SASCA, and about 3 orders of magnitude less than exact inference via exhaustive enumeration. Even with dense belief messages, ExSASCA still uses 6 times less computations than exhaustive inference.

侧信道攻击概率推断密码分析AES

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。