Page 415 - 《软件学报》2026年第2期
P. 415
软件学报 ISSN 1000-9825, CODEN RUXUEW E-mail: jos@iscas.ac.cn
2026,37(2):894−914 [doi: 10.13328/j.cnki.jos.007455] [CSTR: 32375.14.jos.007455] http://www.jos.org.cn
©中国科学院软件研究所版权所有. Tel: +86-10-62562563
*
私有算法密码芯片非入侵式攻击检测框架
魏淙洺 1,3 , 王 菁 2 , 王 安 1 , 丁瑶玲 1 , 孙绍飞 1 , 祝烈煌 1
1
(北京理工大学 网络空间安全学院, 北京 100081)
2
(北京理工大学 计算机学院, 北京 100081)
3
(先进密码技术与系统安全四川省重点实验室 (成都信息工程大学), 四川 成都 610054)
通信作者: 王安, E-mail: wanganl@bit.edu.cn
摘 要: 近年来, 密码芯片迅速发展, 与此同时也面临着非入侵式攻击的严重威胁. 目前已有国内外标准给出了非
入侵式攻击检测流程与方法, 但这些标准均针对公开算法制定, 对于私有算法并不适用, 私有算法密码芯片存在着
很大的安全隐患. 针对这一问题, 提出面向私有算法密码芯片的非入侵式攻击检测框架, 该框架包含计时分析测试、
简单能量/电磁分析测试、差分能量/电磁分析测试 3 大部分. 对于计时分析测试, 采用基于平均去噪的计时分析方
法, 提高所采集时间的可用性. 针对简单能量/电磁分析, 提出面向私有密码算法的视觉观察法和交叉关联分析方
法. 针对差分能量/电磁分析, 通过 TVLA-1 和 TVLA-2 双重检测方法有效检测私有算法密码芯片不同来源的泄露,
评估私有算法密码芯片的抗差分能量/电磁攻击能力. 该框架是对传统非入侵式攻击检测的有效补充, 极大提高了
非入侵式攻击检测的检测范围. 为了验证该框架的有效性, 在多款密码芯片上开展黑盒实验, 实验结果表明该框架
能够有效检测私有算法密码芯片的抗非入侵式攻击安全性.
关键词: 非入侵式攻击; 私有算法; 密码芯片; 计时分析; 能量分析
中图法分类号: TP309
中文引用格式: 魏淙洺, 王菁, 王安, 丁瑶玲, 孙绍飞, 祝烈煌. 私有算法密码芯片非入侵式攻击检测框架. 软件学报, 2026, 37(2):
894–914. http://www.jos.org.cn/1000-9825/7455.htm
英文引用格式: Wei CM, Wang J, Wang A, Ding YL, Sun SF, Zhu LH. Detection Framework of Non-invasive Attack Against Private-
algorithm Cryptographic Chips. Ruan Jian Xue Bao/Journal of Software, 2026, 37(2): 894–914 (in Chinese). http://www.jos.org.cn/
1000-9825/7455.htm
Detection Framework of Non-invasive Attack Against Private-algorithm Cryptographic Chips
2
1,3
1
1
1
WEI Cong-Ming , WANG Jing , WANG An , DING Yao-Ling , SUN Shao-Fei , ZHU Lie-Huang 1
1
(School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing 100081, China)
2
(School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081, China)
3
(Advanced Cryptography and System Security Key Laboratory of Sichuan Province (Chengdu University of Information Technology),
Chengdu 610054, China)
Abstract: In recent years, cryptographic chips have developed rapidly. However, they are also facing a significant threat from non-
invasive attacks. Although both international and domestic standards provide testing methods for non-invasive attacks, these standards are
formulated for public algorithms and are not applicable to private algorithms, which still present considerable security risks. This study
proposes a detection framework for private-algorithm cryptographic chips, which includes three components: timing analysis tests, simple
power/electromagnetic analysis tests, and differential power/electromagnetic analysis tests. For the timing analysis test, a method based on
average denoising is adopted, which significantly improves the accuracy of execution time measurements. Methods based on visual
* 基金项目: 国家重点研发计划 (2022YFB3103800); 国家自然科学基金 (62272047, 62302036, 62402039); 北京市自然科学基金 (L244044,
QY24173)
收稿时间: 2024-04-16; 修改时间: 2025-01-15; 采用时间: 2025-04-29; jos 在线出版时间: 2025-09-10
CNKI 网络首发时间: 2025-09-11

