Power Analysis Attack Based on Chosen-Plaintext
摘要
In the engineering implementation of cryptographic algorithm, random mask is always adopted to avoid power analysis attacks. Previously, machine learning or machine learning combined with related power analysis attacks could be used to attack masked cryptographic algorithm. However, this method requires more than 20 power curves. and they are ineffective when the captured power curve is limited. In order to solve this problem. In this paper, a new method is proposed. In the method, the relationship between the Hamming weight of S-box output and the input plaintext can be obtained by analyzing the mask and the Hamming weight characteristics of AES S-box. Then, the relationship between the S-box output Hamming weight and the key is built in the form of lookup table and formula. The key can be got by substituting the S-box output Hamming weight into the lookup table or formula. Finally, the theoretical analysis is validated by experiment, in which the proposed method is applied to the masked AES_RSM energy curve of DPA (Differential Power Analysis) Contest v4. Experiment results demonstrate that only 6 curves are required for a successful attack, which is in good agreement with the theoretical analysis.