Hua Chen 0011

dblp:44/2144-11 · DBLP profile ↗
← Back
24ranked-venue papers
3as first author
11since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 2 first-author · 6 since 2021Systems, architecture and hardware · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author
YearPublicationVenuePosition
2025 Secret in OnePiece: Single-Bit Fault Attack on Kyber
Jian Wang 0136, Weiqiong Cao, Hua Chen 0011
SAC3
2025 How to Launch a Powerful Side-Channel Collision Attack?
abstract
A cryptographic implementation produces very similar power leakages when fed with the same input. Side-channel collision attacks exploit these similarities to establish the relationship between sub-keys and improve the efficiency of key recovery. Benefiting from independence of leakage model, they play an important role in non-profiled setting. However, performance of existing approaches against single collision value is still sub-optimal and optimization is promising. Motivated by this, we first theoretically analyze the mathematical dependency between the number of collisions and the number of encryptions, and propose an efficient side-channel attack named Collision-Paired Correlation Attack (CPCA) to guarantee that the side with fewer samples in a collision is completely paired in low noise scenario. This allows overcoming the inefficient utilization of information in existing works. Moreover, to further employ underlying informativeness, we maximize collision pairs as many as possible. This optimization significantly improves performance of CPCA and thereby extends it to large noise scenarios. Finally, to achieve moderate computational complexity, two equivalent variants of CPCA are investigated to address the potential problem of limited computing resources. Our further theoretical study illustrates that CPCA provides the upper security bound of Correlation-Enhanced Collision Attack (CECA), and experimental results fully verify its superiority.
Jiangshan Long, Changhai Ou, Yajun Ma, Yifan Fan, Hua Chen 0011, Shihui Zheng
IEEE Trans. Computers5
2024 Blink: Breaking Parallel Implementation of Crystals-Kyber with Side-Channel Attack
abstract
The post-quantum key encapsulation mechanism, CRYSTALS-Kyber, has recently been selected by the National Institute of Standards and Technology (NIST) for standardization. Consequently, it becomes crucial to assess the resistance of CRYSTALS-Kyber implementations to physical attacks. While side-channel attacks on embedded software platforms have been well studied, this work introduces a novel attack on hardware implementations of CRYSTALS-Kyber. Initially, we propose a multi-ciphertext message recovery attack that is capable of extracting messages from side-channel measurements of parallel message encoding. Building upon this, we further develop a key recovery attack based on an optimal ciphertext-choosing strategy that maximizes key recovery accuracy, as well as a lattice reduction attack capable of solving the entire secret key even when confronted with an imperfect side-channel distinguisher. To evaluate the effectiveness of our attack, we conducted experiments on a Xilinx FPGA board. Our results demonstrate that our attack is capable of successfully recovering the secret key using 96 power traces, with a success rate of$100 \%$. This study reveals that parallel implementations remain vulnerable to sidechannel attacks, underscoring the necessity of additional analysis and countermeasures for lattice-based schemes implemented in parallel.
Jian Wang 0136, Weiqiong Cao, Hua Chen 0011
ICCD3
2024 Optimizing AES Threshold Implementation Under the Glitch-Extended Probing Model
abstract
Threshold Implementation (TI) is a well-known Boolean masking technique that provides provable security against side-channel attacks. In the presence of glitches, the probing model was replaced by the so-called glitch-extended probing model which specifies a broader security framework. In CHES 2021, Shahmirzadi et al. introduced a general search method for finding first-order 2-share TI schemes without fresh randomness (under the presence of glitches) for a given encryption algorithm. Although it handles well single-output Boolean functions, this method has to store output shares in registers when extended to vector Boolean functions, which results in more chip area and increased latency. Therefore, the design of TI schemes that have low implementation cost under the glitch-extended probing model appears to be an important research challenge. In this paper, we propose an approach to design the first-order glitch-extended probing secure TI schemes when quadratic functions are employed in the substitution layer. This method only requires a small amount of fresh random bits and a single clock cycle for its implementation. In particular, the random bits in our approach are reusable and compatible with the changing of the guards technique. Our dedicated TI scheme for the AES cipher gives 20.23% smaller implementation area and 4.2% faster encryption compared to the TI scheme of AES (without using fresh randomness) proposed in CHES 2021. Additionally, we propose a parallel implementation of two S-boxes that further reduces latency (about 39.83%) at the expense of increasing the chip area by 9%. We have positively confirmed the security of AES under the glitch-extended probing model using the verification tool -SILVER and the side-channel leakage assessment method -TVLA.
Fu Yao, Hua Chen 0011, Yongzhuang Wei, Enes Pasalic, Limin Fan
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2023 Improving the Performance of CPA Attacks for Ciphers Using Parallel Implementation of S-Boxes
abstract
Since their introduction in early 2000, CPA (correlation power analysis), as a cryptographic tool, has been widely used in the cryptanalysis of cryptographic algorithms (being applicable to both symmetric key ciphers as well as to public key encryption schemes). An application of the classical CPA method, along with its variants, to cryptographic algorithms that use parallel implementation of its substitution boxes (S‐boxes) commonly requires more power traces to extract the secret key compared to the case when serial implementation of S‐boxes is employed. To reduce the amount of power traces in this scenario, we propose a modification of the standard CPA approaches and demonstrate practically that our method performs better than the existing ones in this respect. To verify the efficiency of our improved CPA method, we apply it to the public databases of DPA Contest V2. In particular, the experimental results show that only 495 power traces are required to recover the secret key of AES. We also compare the performance of our attack to the relevant methods whose parameters are available at DPA Contest V2. The results show that compared to the best nonprofiling side‐channel attack (SCA) attack, our method reduces the number of power traces required to recover the secret key by 6,566. Also, our new method performs almost similarly as the best profiling SCA attack of Benoit Gerard (in terms of the required number of power traces), thus reducing the gap in the performance of profiling and nonprofiling SCA attacks.
Fu Yao, Yongzhuang Wei, Hua Chen 0011, Enes Pasalic
IET Inf. Secur.3
2023 Easily Overlooked Vulnerability in Implementation: Practical Fault Attack on ECDSA Round Counter
abstract
Elliptic curve cryptographic is a widely used public-key cryptosystem. Though it has good theoretical security, it is still vulnerable to some physical attacks due to the implementation weakness. To resist the attacks, a number of physical countermeasures have been proposed. However, there are still some implementation vulnerabilities that may be overlooked, leading to more practical and effective attacks. In this article, we construct a new fault attack on round counter which is a component of scalar multiplications in ECDSA. The attack is divided into two parts. In the first part, the partial bits of nonce in each signature can be recovered by the fault injection on round counter. In the second part, an efficient lattice attack can be constructed to recover the private key by combining the recovered bits. Compared with other lattice-based fault attacks, our attack has the advantage of practicability and effectiveness. Especially, it has less requirement of moment precision and wide applicability of scalar multiplications, which is the critical factors for practicability and effectiveness. To verify the strength of our attack, we carry on the laser injection experiments, respectively, on an AVR MCU (ATmega163L) and a Kintex-7 FPGA (XC7K325T). The experimental results verify the practicability and effectiveness of the attack in both software and hardware platforms. Finally, we also propose two directions for efficient countermeasures against our attack.
Hua Chen 0011, Xucang Han, Weiqiong Cao, Huilong Jiang, Jian Wang 0136
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2023 Error Analysis of NIST SP 800-22 Test Suite
abstract
Statistical tests for randomness play an essential role in cryptography, but the reliability of these tests is rarely taken into account, which may mislead our judgement of randomness especially with extremely large samples. In this paper, we make a two-stage error analysis of the commonly used two-level randomness tests in the NIST SP 800-22 test suite. Especially, we give the estimates of thep-value deviations of chi-square approximation in the basic tests based on our proposed continuity constraints, and mathematically express the reliability of uniformity test used in the test suite with the fact of noncentral chi-square approximation. Finally, we analyze the respective error factors and derive the corresponding probability deviation estimation for the tests, explaining some false positive issues in practical test experiments. With our derived error analysis models, one can get a more reliable randomness test strategy with extremely large samples and wider parameter selections.
Hua Chen 0011, Limin Fan
IEEE Trans. Inf. Forensics Secur.2
2022 Lattice-Based Fault Attacks on Deterministic Signature Schemes of ECDSA and EdDSA
Weiqiong Cao, Hongsong Shi, Hua Chen 0011, Jiazhe Chen, Limin Fan, Wenling Wu
CT-RSA3
2022 Practical Side-Channel Attack on Message Encoding in Masked Kyber
abstract
Since the message encoding in lattice-based schemes is vulnerable to side-channel attacks, a first-order masked message encoder has been proposed and applied to multiple masked implementations. However, the security of the masked encoder still lacks enough evaluation. In this paper, we investigate the security of the masked message encoder in a masked Kyber implementation. First, we give a detailed side-channel leakage analysis of the masked implementation in a specific platform, and we explain the technical challenges of designing a key recovery attack for the masked implementations. Even so, we still found a new 2-stage key recovery attack, which overcomes the difficulties and can recover the whole private key of the masked Kyber implementation with only 9 traces. In our experiments, we validate the attack on a Cortex-M4-based development board and the success rate of key recovery is almost up to 100% in 1000 experiments. According to the experiment results, the masked encoder can not prevent side-channel attacks efficiently and newer masking techniques are needed.
Jian Wang 0136, Weiqiong Cao, Hua Chen 0011
TrustCom3
2021 Lattice-Based Weak Curve Fault Attack on ECDSA
Weiqiong Cao, Hongsong Shi, Hua Chen 0011, Jiazhe Chen
SEC3
2021 Do multiple infections lead to better security? A new study on CHES 2014 infective countermeasure
Jingyi Feng, Hua Chen 0011, Weiqiong Cao, Limin Fan, Dengguo Feng
Sci. China Inf. Sci.2
2020 A Framework for Evaluation and Analysis on Infection Countermeasures Against Fault Attacks
abstract
Infection is a fault attack countermeasure, which aims to destroy the dependency of the faulty ciphertexts on the secret key. However, current security evaluations on infection countermeasures are either tailored for the specific attack scenario or not general enough to apply to various infection instances. They cannot come to convincing results, let alone make comparisons between different countermeasures. Based on information theory, this paper presents a generic evaluation framework that is feasible for various infection countermeasures and attack scenarios. The framework is constructed with the idea to separate the infection function from the unprotected cipher yet consider the fault injection effect on the unprotected cipher in the infection function evaluation. First, the security judging criteria for the infection function under different attack scenarios are personalized according to the injection-caused security loss of the unprotected cipher. Then, a universal method of security quantitative analysis on infection function is proposed with two important steps: the prior knowledge collection and the infection operation decomposition analysis. Because the analysis results of the simple infection operation can be reused within the infection function under various attack scenarios, the security quantifications are efficient. Based on this framework, the paper also reviews some existing infection countermeasures for their fault attack resistances. The result shows that our analysis can expose more infection vulnerabilities than the previous works. Besides, the security quantification and judgment on these countermeasures give us a new insight into their security applicable scopes. They are instructive for the countermeasure selection when the implementation costs are very close. Furthermore, the framework provides an efficient way to evaluate future infection countermeasures.
Jingyi Feng, Hua Chen 0011, Yang Li 0001, Zhipeng Jiao
IEEE Trans. Inf. Forensics Secur.2
2019 A new discrete Fourier transform randomness test
Meihui Chen, Hua Chen 0011, Limin Fan, Shaofeng Zhu, Dengguo Feng
Sci. China Inf. Sci.2
2018 Non-profiled Mask Recovery: The Impact of Independent Component Analysis
Elisabeth Oswald, Hua Chen 0011
CARDIS3
2018 Jitter Estimation with High Accuracy for Oscillator-Based TRNGs
Shaofeng Zhu, Hua Chen 0011, Limin Fan, Meihui Chen, Dengguo Feng
CARDIS2
2018 Impossible meet-in-the-middle fault analysis on the LED lightweight cipher in VANETs
Wei Li 0013, Vincent Rijmen, Qingju Wang 0001, Hua Chen 0011, Yunwen Liu, Chaoyun Li, Ya Liu 0001
Sci. China Inf. Sci.5
2017 My Traces Learn What You Did in the Dark: Recovering Secret Signals Without Key Guesses
Hua Chen 0011, Wenling Wu, Limin Fan, Weiqiong Cao, Xiangliang Ma
CT-RSA2
2016 Linear Regression Attack with F-test: A New SCARE Technique for Secret Block Ciphers
Hua Chen 0011, Wenling Wu, Limin Fan, Jingyi Feng, Xiangliang Ma
CANS2
2016 Improved Fault Analysis on SIMON Block Cipher Family
abstract
SIMON is a new family of lightweight block ciphers proposed by the National Security Agency (NSA) in 2013. Since its publication, it has attracted much research interest and a number of analysis results have been presented. As a popular kind of implementation attack method, the fault attack also works when it is applied to SIMON. In this paper, we propose an effective fault attack on SIMON under the random byte fault model. Compared with the previous attack results, our attack can successfully recover the whole master key with injecting the faults into only one intermediate round for six instances of SIMON. In our attack, we fully utilize a class of differential propagation properties of SIMON to determine the fault injection position as long as the full diffusion of the fault has not been obtained. On the basis of it, we can recover the last round key with the differential analysis technique. The differential propagation properties make it possible to inject the faults into the earlier intermediate round at the beginning than that of the previous attacks. Meanwhile, the same faulty ciphertext set can also help to recover other round keys. So we do not have to inject the faults into any other intermediate rounds to reveal the whole master key. Moreover, in this paper we also give a detailed mathematical analysis on the average number of the fault injections under the random byte fault model. The data complexity analysis shows that less fault injections are required in our attack compared with other work under the same attack model. Finally, we also verify the effectiveness and correctness of our attack with experiments.
Hua Chen 0011, Jingyi Feng, Vincent Rijmen, Yunwen Liu, Limin Fan, Wei Li 0013
FDTC1
2015 Practical Lattice-Based Fault Attack and Countermeasure on SM2 Signature Algorithm
Weiqiong Cao, Jingyi Feng, Shaofeng Zhu, Hua Chen 0011, Wenling Wu, Xucang Han, Xiaoguang Zheng
ICICS4
2013 Padding Oracle Attack on PKCS#1 v1.5: Can Non-standard Implementation Act as a Shelter?
Hua Chen 0011, Limin Fan
CANS2
2007 Differential Fault Analysis on CLEFIA
Hua Chen 0011, Wenling Wu, Dengguo Feng
ICICS1
2004 An effective evolutionary strategy for bijective S-boxes
abstract
Being as unique nonlinear components of block ciphers, S-boxes control the security of the cryptographic algorithms. The design of S-boxes with genetic algorithms is a recent research focus. For the popular bijective S-boxes, an effective evolutionary strategy is given in this paper, including fitness function, breeding strategy and hill climbing algorithm. Under this strategy, an effective genetic algorithm for 8 /spl times/ 8 bijective S-boxes is provided and a large number of S-boxes with high nonlinearity and low difference uniformity can be obtained.
Hua Chen 0011, Dengguo Feng
IEEE Congress on Evolutionary Computation1
2003 UC-RBAC: A Usage Constrained Role-Based Access Control Model
Dengguo Feng, Hua Chen 0011
ICICS4