利用稀疏向量的加载/存储泄漏进行HQC中的密钥恢复
Exploiting Load/Store Leakage of Sparse Vectors for Key Recovery in HQC
浏览论文内容
中文总结 AI 辅助
研究针对HQC密钥恢复的侧信道攻击,利用其稀疏秘密向量操作中的加载/存储泄漏,通过分析Cortex-M4汇编识别泄漏面,构建零字鉴别器简化解码问题,分析解码复杂度并经实验验证,还讨论了消除攻击利用的稀疏性的对策。
中文摘要 AI 辅助
汉明准循环(HQC)是美国国家标准与技术研究院(NIST)选择用于标准化的基于代码的密钥封装机制,因此其对实现攻击的抗性至关重要。我们提出了一种侧信道攻击,该攻击利用HQC稀疏秘密向量操作中的加载/存储泄漏。通过分析参考实现生成的Cortex-M4汇编代码,我们识别出一个泄漏面,由于编译器生成的寄存器溢出,每个64位字的低32位和高32位以不同强度泄漏。我们利用这种泄漏构建了一个简单的零字鉴别器,通过电磁测量将秘密向量的机器字分类为零或非零。然后将恢复的零位置转换为解码提示,将HQC密钥恢复简化为缩短的伴随式解码问题。我们分析了所有HQC参数集的解码复杂度:在32位粒度下,对于HQC-1,y的机器字预期有88.7%为零,将解码减少到约2^46位操作。在Cortex-M4上的实验验证了预测的低/高半部分不对称性——较强的低半部分通道约需500条迹线,较弱的高半部分通道约需5000条迹线——并在32位粒度下恢复了HQC-1密钥的零字。最后,我们讨论了消除攻击所利用的稀疏性的实际对策。
英文摘要
Hamming Quasi-Cyclic (HQC) is a code-based key encapsulation mechanism selected by NIST for standardization, making its resistance to implementation attacks critically important. We present a side-channel attack that exploits load/store leakage in the manipulation of HQC's sparse secret vectors. Analysing Cortex-M4 assembly generated from the reference implementation, we identify a leakage surface in which the low and high 32-bit halves of each 64-bit word leak with different strengths, due to compiler-generated register spilling. We exploit this leakage to construct a simple zero-word distinguisher classifying machine words of the secret vector as zero or nonzero from electromagnetic measurements. The recovered zero positions are then translated into decoding hints, reducing HQC key recovery to a shortened syndrome-decoding problem. We analyse the resulting decoding complexity for all HQC parameter sets: at 32-bit granularity an expected 88.7% of the machine words of y are zero for HQC-1, cutting the decoding to $\approx$ 2 46 bit operations. Experiments on a Cortex-M4 validate the predicted low/high-half asymmetry-approximately 500 traces for the stronger low-half channel and 5,000 for the weaker high-half channeland recover the zero words of an HQC-1 key at 32-bit granularity. Finally, we discuss practical countermeasures that eliminate the sparsity exploited by the attack.