Hailong Zhang 0001

dblp:59/2151-1 · DBLP profile ↗
← Back
40ranked-venue papers
10as first author
20since 2021 · last 2026
0000-0002-8401-9838ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 21 · 4 first-author · 10 since 2021Systems, architecture and hardware · 6 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-author · 3 since 2021Computer networks · 3 · 1 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 LP-VFedNN: A Lightweight and Lossless Privacy-Preserving Vertical Federated Learning Framework For Heterogeneous Neural Network Via Homomorphic Encryption and Intel SGX
abstract
Vertical federated learning (VFL) enhances model performance by jointly leveraging features from multiple parties. However, its intensive interactions increase the risk of privacy leakage. Existing privacy-preserving VFL solutions based on cryptographic primitives suffer from high computation and communication costs, limited algorithmic support, and poor scalability. We propose LP-VFedNN, a lightweight and lossless heterogeneous neural network framework for VFL that integrates CKKS fully homomorphic encryption (FHE) with a trusted execution environment (TEE) and requires no trusted third party. LP-VFedNN adopts a linear-nonlinear separation design: linear operations are executed in the CKKS ciphertext domain, while nonlinear functions are decrypted and accelerated inside the TEE. This avoids the high cost of high-order homomorphic computations and eliminates accuracy degradation caused by polynomial approximations, overcoming the limitations of generalized linear models (GLMs). We further introduce enhanced remote attestation and key agreement to support bidirectional authentication and secure key delivery. For multi-party settings, we propose an adaptive strategy that operates in an efficiency-oriented, restricted-leakage execution mode, improving scalability by offloading substantial TEE computation to secure plaintext computation after decryption. Experiments show that, compared to Paillier-based and pure-TEE schemes, LP-VFedNN significantly reduces communication and computation costs while maintaining accuracy, demonstrating robust scalability with controlled complexity growth as the number of parties increases. Additional experiments on a real-world multimedia dataset further validate its applicability for privacy-aware multimedia retrieval systems.
Liji Wu, Baisong Li, Huiping Zhuang, Weiping Wang 0007, Yaoyi Deng, Hailong Zhang 0001
ICMR9
2026 Quadruplet network based template attack
abstract
Abstract The raw traces collected in side channel attacks are composed of high-dimensional signals with severe noise, which significantly increases the computational complexity of an attack, reduces the performance and the accuracy of an attack, and may even make an attack infeasible. In order to efficiently extract the critical and low-dimensional features from traces to optimize the accuracy of an attack, quadruplet network based template attack is proposed. Firstly, a quadruple sample selection strategy is designed to screen out quadruples that meet the requirements, and a quadruple loss function is designed to measure the similarity between trace sample pairs. Secondly, a quadruplet network model based on densely connected convolutional networks is constructed and trained to obtain an optimal quadruplet network model. Further, the critical and low-dimensional embedded features are extracted by the optimal quadruplet network model. Finally, efficient templates are constructed based on the embedded features to perform template attack. The test results show that the proposed method can efficiently extract the key embedded features from traces to construct efficient templates and optimize the efficiency of template attack. Compared with its counterparts, this technique can optimize the efficiency of template attack on different datasets.
Xiaonian Wu, Yu Mo, Minghui Hou, Hailong Zhang 0001, Runlian Zhang
Comput. J.4
2026 The world is not enough: Another look on the constructions of comparison-based distinguishers
abstract
Partition-based and comparison-based distinguishers are two types of side-channel distinguishers. Here, compared with partition-based distinguishers, the constructions of comparison-based distinguishers are simpler, their efficiencies are higher, and they are less picky about leakage models. Therefore, comparison-based distinguishers are widely used in the attack scenario to recover the secret key used by a cryptographic device. However, comparison-based distinguishers rely on the assumptions of normal distribution and linear relationship, if these assumptions do not hold, their efficiencies decrease. Tie, outlier, and extreme can also decrease the efficiencies of comparison-based distinguishers. In light of this, this work proposes four distinguishers TieGiniHM, TieGiniSYM, Tau-b, and Gamma. They do not rely on the assumptions of normal distribution and linear relationship, can avoid the problem of tie, and are resilient to outlier and extreme. The efficiencies of the proposed distinguishers are evaluated in both the simulated scenario and the real scenario. According to the evaluation results, the efficiencies of four distinguishers can be higher than existing partition-based and comparison-based distinguishers. Apart from that, four distinguishers are less picky about leakage models than existing comparison-based and partition-based distinguishers. Overall, this work provides side-channel analyzers useful tools to accurately evaluate the security of a cryptographic device in the side-channel analysis scenario.
Keting Wei, Hailong Zhang 0001
J. Comput. Secur.2
2026 Enhanced Template Attack Against Dilithium: Leveraging Dual-Loss Feature Extraction
abstract
As a post-quantum digital signature scheme, Dilithium was specifically designed to withstand known quantum algorithm attacks, and its side-channel resistance has garnered significant research attention. However, current side-channel attacks against Dilithium exhibit several limitations: (1) failure to leverage low-correlation characteristics in power traces, (2) loss functions limited to categorical information extraction from power traces, (3) dependency on specific coefficient recovery conditions while neglecting inter-coefficient statistical dependencies, (4) requirement for separate profiling models per intermediate value, resulting in substantial information loss. To address these limitations, we propose an enhanced template attack framework integrating deep learning with classical template attack methodology. Our approach employs a dual-loss similarity learning mechanism for feature extraction from high-dimensional power traces, enabling the construction of more discriminative templates while preserving weakly correlated features. Through assembly-level analysis of the y polynomial generation routine, we reveal inherent correlations among coefficientsyk0,yk1,yk2,yk3. Building on this discovery, our dual-loss similarity learning framework is designed to capture these inter-coefficient relationships, preserving their intrinsic dependencies while achieving effective inter-class separation and intra-class aggregation properties, which significantly enhances the effectiveness of subsequent template attacks. Experimental results on Cortex-M4 power traces demonstrate our method achieves 32.94% polynomial coefficient recovery accuracy for polynomial coefficients y, outperforming conventional SOD-based (83% improvement), T-Test-based (97%), and PCA-based template attacks (197% enhancement). Furthermore, complete private key recovery is achieved with merely 14 power traces under specific conditions. This DL-enhanced template attack framework demonstrates superior side-channel leakage exploitation, yielding substantial performance enhancements over conventional approaches.
Haojin Zhang, Qingjun Yuan, Yaoling Ding, An Wang 0001, Hailong Zhang 0001, Haopeng Fan, Siqi Lu, Yongjuan Wang
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2025 A Novel S-Box Construction Technique Based on the Improved Genetic Algorithms through 2 N-Round Searching
Runlian Zhang, Zhaowen Huang, Xiaonian Wu, Hailong Zhang 0001, Lingchen Li
ISPEC4
2025 Intra-class CutMix data augmentation based deep learning side channel attacks
Runlian Zhang, Yu Mo, Zhaoxuan Pan, Hailong Zhang 0001, Yongzhuang Wei, Xiaonian Wu
Integr.4
2025 Multivariate Template Attack Against NTT-Based Polynomial Multiplication of Dilithium
Haopeng Fan, Hailong Zhang 0001, Yongjuan Wang, Wenhao Wang 0001, Haojin Zhang, Qingjun Yuan
IEEE Trans. Inf. Forensics Secur.2
2024 SSIDB: Secure Sharing of IoT Data on Blockchain with CP-ABE and Trusted Environment Assistance
abstract
With the popularization and broad application of the Internet of Things (IoT), the emergence of massive heterogeneous data brings serious privacy and security challenges to the traditionally centralized data storage and sharing architecture. Current research tends to leverage distributed blockchain technology and cryptographic algorithms to address these challenges. In particular, ciphertext-policy attribute-based encryption (CP-ABE) has shown great potential in protecting data privacy and realizing fine-grained access control. However, these approaches still cannot effectively support the integrated implementation of policy update and attribute revocation, and the key security during data sharing is difficult to guarantee. To address the above issues, we propose a secure IoT data sharing scheme on blockchain, called SSIDB, which is assisted by CP-ABE and Trusted Execution Environment (TEE). The scheme utilizes symmetric proxy re-encryption technology to achieve an efficient update of ciphertext access policy. Besides, based on the privacy of TEE, we realize the revocation of user attributes without having to update ciphertext. At the same time, we introduce TEE to manage keys and provide a secure execution environment for sensitive computations. We analyze the security of SSIDB scheme and evaluate its performance by conducting experiments on blockchain and TEE. The results show that the time consumption of our SSIDB scheme in encryption, decryption, policy update and attribute revocation phase is lower than other schemes by 144%, 126%, 176%, and 950%, respectively.
Sixiang Wang, Dongdong Huo, Hailong Zhang 0001, Yu Wang 0243, Fei Shao
ISPA3
2024 Differential Cryptanalysis Against SIMECK Implementation in a Leakage Profiling Scenario
Hailong Zhang 0001
ISPEC1
2024 A Novel Two-Stage Model Based SCA against secAES
Xiaonian Wu, Runlian Zhang, Hailong Zhang 0001
J. Electron. Test.4
2024 Screening Least Square Technique Assisted Multivariate Template Attack Against the Random Polynomial Generation of Dilithium
abstract
In recent years, the security of Dilithium against side-channel attacks (SCA) has attracted great attentions from the cryptographic engineering community. However, existing power analysis attacks cannot fully utilize the side-channel leakages of the Dilithium reference implementation to efficiently recover the private key. In light of this, a screening least square technique assisted multivariate template attack (SLST assisted MTA) is proposed in this paper. In SLST assisted MTA, side-channel leakages of coefficient$y_{i}$of random polynomial y, unsigned number$x_{i}$and random byte string$a_{i^{\prime }}$can be utilized simultaneously to recover coefficient$y_{i}$of random polynomial y with MTA. Then, one can build error-tolerant equations, and the private key$\mathbf {s_{1}}$can be solved with SLST efficiently. We evaluate the private key recovery efficiency of SLST assisted MTA with real traces measured from the Cortex-M4 processor based Dilithium reference implementation, and the evaluation results show that with MTA, 19.41%, 15.70% and 16.88% of the coefficients of y can be accurately recovered in cases of Dilithium 2, 3 and 5. Besides, using SLST, after five times screening, only 38, 40 and 39 power traces are enough to recover private key$\mathbf {s_{1}}$of Dilithium 2, 3 and 5 with 100% of success rate.
Haopeng Fan, Hailong Zhang 0001, Yongjuan Wang, Wenhao Wang 0001, Yanbei Zhu, Haojin Zhang, Qingjun Yuan
IEEE Trans. Inf. Forensics Secur.2
2023 Building Efficient Parallel Endorsement Node on Blockchain Systems
abstract
With blockchain technology taking the world by storm, Hyperledger Fabric has large potential for application, but low throughput hinders its development. Especially Fabric endorsement phase serves as the upper process of transaction lifestyle, and its low throughput can diminish the performance of the entire system. In this paper, we focus on performance optimization in the endorsement phase. We design an efficient parallel endorsement node (EPEN) and implement the optimization in two steps. The first is parallel endorsement architecture, which improves the concurrency of endorsements and increases the scalability of peer nodes. Then we propose a load balancing algorithm based on consistent hash and design multilayer consistent hash load minimization (MCHLM) to load balance the chaincode containers and improve its utilization. In addition, we implement these optimizations scheme in Hyperledger Fabric 2.2 LTS and conduct a series of evaluation experiments. The experimental results demonstrated that EPEN improves Fabric system throughput by 204.3% and reduces transaction latency by 77.8%, with a 7.9% increase in CPU overhead.
Yaoyi Deng, Hailong Zhang 0001, Dongdong Huo, Yanqiu Zhang, Shuai Yun, Yu Wang 0243, Zhen Xu 0009
CSCWD3
2023 Template Attack Assisted Linear Cryptanalysis on Outer Rounds Protected DES Implementations
abstract
Abstract In practice, when the security of a block cipher implementation is considered, the leakages related to the outer rounds encryptions can be used by side channel attacks (SCA) to recover the secret key. Therefore, the outer rounds of block cipher implementations should be protected. However, in order to lower the implementation price, the inner rounds of block cipher implementations may be unprotected. In light of this, the security of an outer rounds protected DES implementation is considered. In detail, template attack (TA), which is information theoretically the strongest SCA style, can be used to obtain the inner round output. Then, linear cryptanalysis (LC) can be used to recover the secret key. Finally, the optimal key enumeration algorithm can be used to optimize the efficiency of TA assisted LC. We evaluate the efficiency of TA assisted LC in simulated scenarios where a three outer rounds protected DES implementation is targeted. The evaluation results show that when 800 correct samples are available and the number of key enumeration is $2^{10}$, the efficiency of TA assisted LC can reach 83% of success rate. Overall, an efficient combination attack style that can be used to accurately evaluate the security of an outer rounds protected DES implementation is proposed.
Hailong Zhang 0001, Wei Yang 0008
Comput. J.1
2022 Higher-Order Masking Scheme for Trivium Hardware Implementation
Bohan Li 0004, Hailong Zhang 0001, Dongdai Lin
Inscrypt2
2021 On Characterization of Transparency Order for (n, m)-functions
Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Enes Pasalic, Wenling Wu
Inscrypt3
2021 Transparency Order of (n, m)-Functions - Its Further Characterization and Applications
Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Enes Pasalic, Wenling Wu
ISC3
2021 Theoretical Estimation on the Success Rate of the Asymptotic Higher Order Optimal Distinguisher
abstract
Abstract Since its first publication at ASIACRYPT 2014, higher order optimal distinguisher (HOOD) has been the most efficient style of higher order side channel attacks that can be used to evaluate the physical security of a masking device. In practice, the efficiency of HOOD can be empirically evaluated with the success rate (SR) metric. In the empirical evaluation, a large number of power traces are needed, and HOOD should be repeated thousands of times under the values of different parameters, which can make the evaluation process cumbersome and the evaluation price high. In light of this, the exact relationship between the SR of the asymptotic HOOD and the values of different parameters is theoretically built, and the soundness of the theoretical analysis is empirically verified in both the simulated scenario and the real scenario. Then, by setting the values of different parameters, the SR of the asymptotic HOOD can be theoretically estimated. Here, as the signal-to-noise ratio of a masking device approaches to zero, the SR of the asymptotic HOOD approaches to the SR of HOOD. Overall, this contribution may help evaluators to efficiently evaluate the physical security of a masking device with HOOD.
Hailong Zhang 0001, Wei Yang 0008
Comput. J.1
2021 Multi-channel time-frequency fusion attacks
Yuchen Cao 0002, Yongbin Zhou, Hailong Zhang 0001
Int. J. Inf. Comput. Secur.3
2021 Verifiable Public-Key Encryption with Keyword Search Secure against Continual Memory Attacks
Chengyu Hu 0001, Pengtao Liu, Rupeng Yang, Shanqing Guo, Hailong Zhang 0001
Mob. Networks Appl.6
2021 On the Modified Transparency Order of n , m -Functions
abstract
The concept of transparency order is introduced to measure the resistance of n , m -functions against multi-bit differential power analysis in the Hamming weight model, including the original transparency order (denoted by TO ), redefined transparency order (denoted by RTO ), and modified transparency order (denoted by MTO ). In this paper, we firstly give a relationship between MTO and RTO and show that RTO is less than or equal to MTO for any n , m -functions. We also give a tight upper bound and a tight lower bound on MTO for balanced n , m -functions. Secondly, some relationships between MTO and the maximal absolute value of the Walsh transform (or the sum-of-squares indicator, algebraic immunity, and the nonlinearity of its coordinates) for n , m -functions are obtained, respectively. Finally, we give MTO and RTO for (4,4) S-boxes which are commonly used in the design of lightweight block ciphers, respectively.
Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Wenzheng Zhang 0001
Secur. Commun. Networks3
2020 Side-Channel Leakage Detection Based on Constant Parameter Channel Model
abstract
Side-channel analysis (SCA) becomes a serious realistic threat to crypto devices, it is thus imperative to evaluate the resistance of a device to SCA. Side-channel leakage detection aiming to identify the leakage points potentially revealing secrets in side channel signals, is considered as a preliminary step before further security assessment. This work proposes a novel black-box leakage detection approach, which views the side channel as a constant parameter communication channel when it outputs leakage points. The approach distinguishes leakage points by utilizing the kurtosis-based consistency check for channel parameter estimators. To examine the efficiency of this approach, false negative and false positive rates were first quantitatively analyzed by comprehensive experiments. Considering the fact that side-channel leakage can be from multiple channels in practice, we further investigated the applicability of the proposed approach to multi-channel leakage detection. Interestingly, equipped with the proposed detection approach, we correspondingly devised a novel side-channel attack exploiting a kurtosis-based distinguisher. Overall, extensive experiments have validated the efficiencies of our proposed leakage detection method and the novel SCA attack.
Wei Yang 0008, Hailong Zhang 0001, Yansong Gao 0001, Anmin Fu, Songjie Wei
ICCD2
2020 Improving Efficiency of Key Enumeration Based on Side-Channel Analysis
abstract
Side-channel analysis (SCA) is usually used for analyzing the side-channel resistance of a crypto device. However, it does not mean “practical secure” when a SCA attack fails since SCA only provides a success or failure conclusion. On the basis of the SCA data about scores and ranks of all candidates for each subkey, it is still possible to apply key enumeration (KE) algorithms to search the correct master key at an affordable overhead. Nevertheless, the efficiency of KE is limited by the SCA data in essence. To address the issue, we proposed two methods to exploit the SCA data and Riemann integral of the rank curves of all subkey candidates to update each correct sub key rank before carrying out KE. We applied the proposed methods for different crypto implementations running on different devices to verify their performance. Experimental studies for both mono-channel and multi-channel leakages verified that the proposed methods were effective in improving the efficiency of KE to recover the correct key. The proposed methods are designed for processing the SCA data and can be deemed as a preliminary before executing KE. The work of this paper bridges the gap between SCA and KE.
Wei Yang 0008, Anmin Fu, Hailong Zhang 0001, Chanying Huang
TrustCom3
2020 On the Exact Relationship Between the Success Rate of Template Attack and Different Parameters
abstract
In practice, the Template Attack (TA) is widely accepted as the strongest side channel attack, and it is used to evaluate the physical security of crypto devices in practice. In TA, different statistical tools, such as the Euclidean distance (ED) and the Mahalanobis distance (MD), can be used to recover the secret key used by the target device. In practice, values of different parameters influence the key-recovery efficiency of TA. However, until now, the exact relationship between the success rate (SR) of TA and different parameters is not very clear. Therefore, in order to accurately evaluate the physical security of crypto devices with TA, evaluators need to vary values of different parameters and empirically evaluate the SR of TA in different cases. Considering that both the computational complexity and the measurement complexity of the empirical evaluation are high, this may induce unnecessary evaluation overhead and make the evaluation period long. In light of this, in this paper, the exact relationship between the SR of TA and values of different parameters is theoretically analyzed, and the soundness of the theoretical analysis is empirically verified in both simulated and real scenarios. Then, by setting the values of different parameters, the SR of TA can be accurately and efficiently estimated. Overall, this contribution may help evaluators to efficiently evaluate the physical security of crypto devices with TA in practice.
Hailong Zhang 0001
IEEE Trans. Inf. Forensics Secur.1
2019 Side-Channel Leakage Amount Estimation Based on Communication Theory
abstract
Side-channel attacks (SCAs) have been a serious threat to crypto devices. It is necessary to evaluate the resistance of a crypto device to SCAs. The evaluation criteria include information theoretic metrics and security metrics. The former measure the leakage amount of a crypto device, e.g. mutual information (MI). MI is one of the most commonly used metrics because of its clear information theoretic meaning. However, due to the fact that the real leakage distribution of a crypto device is hard to know, the estimation of MI is difficult. In previous work, there are two ways to estimate the leakage distribution: the nonparametric one and the parametric one. The former is non-profiling, but may bring a significant error because the leakage model is empirically selected by an evaluator. By comparison, the latter is more precise, but needs to profile the leakage model, which may be unfeasible in practice. To combine the merits of two kinds of methods, we bypass the estimation of the leakage distribution, and propose a parametric estimation method without profiling from the view of the noise distribution estimation. The side-channel is viewed as a communication channel in this paper, and naturally the side-channel MI can be deemed to be the average MI of the communication channel. Moreover, the channel capacity can be regarded as a new information theoretic metric which furnishes an estimation of the leakage amount in the worst case scenario. As compared to the previous research, the paper provides a novel black box method to estimate the side-channel leakage amount of a crypto device. The evaluation procedure can be viewed as a preliminary before advanced security evaluation.
Wei Yang 0008, Hailong Zhang 0001
GLOBECOM2
2018 Electro-magnetic analysis of GPU-based AES implementation
abstract
In this work, for the first time, we investigate Electro-Magnetic (EM) attacks on GPU-based AES implementation. In detail, we first sample EM traces using a delicate trigger; then, we build a heuristic leakage model and a novel leakage model to exploit the simultaneous EM leakages in parallel scenarios. After that, we evaluate the effectiveness of EM attacks on GPU-based AES implementation. Our evaluation results show that GPU-based AES implementation is vulnerable to EM attacks. This work also suggests that GPU-based AES implementation needs to be protected against EM attacks in real scenarios.
Yiwen Gao 0001, Hailong Zhang 0001, Wei Cheng 0003, Yongbin Zhou, Yuchen Cao 0002
DAC2
2018 On the exact relationship between the Mutual Information Metric and the Success Rate Metric
Hailong Zhang 0001, Yongbin Zhou
Inf. Sci.1
2018 Multiple leakage samples based higher order optimal distinguisher
Hailong Zhang 0001, Yongbin Zhou
Inf. Sci.1
2017 Reducing Randomness Complexity of Mask Refreshing Algorithm
Shuang Qiu 0004, Rui Zhang 0002, Yongbin Zhou, Hailong Zhang 0001
ICICS4
2017 Mahalanobis Distance Similarity Measure Based Higher Order Optimal Distinguisher
abstract
Higher order side channel attacks (HOSCAs) exploit the side channel leakages of a masked crypto device at multiple leakage samples to recover the secret key used by the target crypto device. The attack price of HOSCA increases exponentially with the attack order, and HOSCA becomes infeasible when the attack order is high. Therefore, it is utmost important to employ the higher order optimal distinguishers (HOODs) to effectively decrease the attack price of HOSCA and make it applicable in a wide scenario. Recently, under the assumption that noises at different leakage samples are independent and that the noise at a single leakage sample follow the Gaussian distribution, Bruneau et al. proposed one HOOD. However, the two assumptions made by Bruneau et al. do not fit in with the real cases well. In light of this, the HOOD proposed by Bruneau et al. cannot be strictly speaking the optimal. Therefore, in this paper we propose the mahalanobis distance similarity measure (MDSM)-based HOOD. In the MDSM-based HOOD, no unsuitable assumptions are made. Therefore, the key-recovery efficiency of the MDSM-based HOOD should be higher than that of the maximum likelihood principle-based HOOD. In fact, both empirical and real evaluations are performed to support our point.
Hailong Zhang 0001, Yongbin Zhou
Comput. J.1
2017 Multi-Channel Fusion Attacks
abstract
Side channel attacks (SCAs) are a kind of the most powerful means to evaluate the physical security of a crypto device. Multi-channel fusion attacks (MCFAs) belong in SCAs and utilize multi-channel leakages simultaneously. As compared with the known mono-channel attacks, MCFAs have higher potential leakage utilization. However, previous research about MCFAs is scarce. MCFAs have not been studied systematically and classified explicitly. It is hard to select MCFAs strategies properly and perform MCFAs efficiently according to the existing research. In light of this, we classify MCFAs into three groups from the view of fusion for the first time, including data-level, feature-level, and decision-level fusion attacks. Accordingly, we construct six MCFAs and verify their effectiveness in typical scenarios. The applicable scopes and the different performances of MCFAs with different fusion activities are also first discussed. To the best of our knowledge, this paper is the first to systematically investigate MCFAs. We hope that this paper will be helpful to understand MCFAs and offer advice on MCFAs against the different implementations of a crypto algorithm. Besides, a fusion metric that determines which channels are suitable for combination is also proposed and verified by practical experiments.
Wei Yang 0008, Yongbin Zhou, Yuchen Cao 0002, Hailong Zhang 0001, Qian Zhang 0042
IEEE Trans. Inf. Forensics Secur.4
2016 Hilbert Transform Based Vertical Preprocessing for Side-Channel Analysis
abstract
Evaluating the success rate of a side-channel attack in design phase is of great significance for the design of secure crypto device. The reason is evaluation in design phase can help find and fix security vulnerabilities early. Existing methods of success rate evaluation in design phase ignore the preprocessing of real attacks. This results in a big gap between the success rate evaluated in design phase and that got in practical attacks. In this paper we propose a Hilbert Transform based vertical preprocessing, aiming at enhancing the signal-to-noise ratio. Compared to existing preprocessing methods aiming at a similar purposes, it can be mounted in design phase, which makes it possible to refine evaluation in design phase. Furthermore, the Hilbert Transform based vertical preprocessing can be used in real attacks as well, and its working efficiency is higher than that of other advanced preprocessing. We perform the vertical preprocessing not only in simulated scenarios but also in practical scenarios. Evaluation results confirm that vertical preprocessing leads to significant improvement of success rate. Therefore, we note vertical preprocessing can be an important tool for evaluating and analyzing of the practical security of crypto device.
Yuchen Cao 0002, Yongbin Zhou, Hailong Zhang 0001, Wei Yang 0008
ICCCN3
2016 How many interesting points should be used in a template attack?
Hailong Zhang 0001, Yongbin Zhou
J. Syst. Softw.1
2016 Towards optimal leakage exploitation rate in template attacks
abstract
Abstract. Under the assumption that one has a reference device iden-tical or similar to the target device, and thus be well capable of char-acterizing power leakages of the target device, Template Attacks are widely accepted to be the most powerful side-channel attacks. However, the question of whether Template Attacks are really optimal in terms of the leakage exploitation rate is still unclear. In this paper, we present a negative answer to this crucial question by introducing a normalization process into classical Template Attacks. Specifically, our contributions are two folds. On the theoretical side, we prove that Normalized Tem-plate Attacks are better in terms of the leakage exploitation rate than Template Attacks; on the practical side, we evaluate the key-recovery efficiency of Normalized Template Attacks and Template Attacks in the same attacking scenario. Evaluation results show that, compared with Template Attacks, Normalized Template Attacks are more effective. We note that, the computational price of the normalization process is of ex-tremely low, and thus it is very easy-to-implement in practice. Therefore, the normalization process should be integrated into Template Attacks as a necessary step, so that one can better understand practical threats of
Guangjun Fan, Yongbin Zhou, Hailong Zhang 0001, Dengguo Feng
Secur. Commun. Networks3
2016 Theoretical and practical aspects of multiple samples correlation power analysis
abstract
Abstract There is more than one sample in a power trace, corresponding to the process of the target intermediate value, which are known as interesting points. One can exploit the power leakages at multiple samples to recover the secret key used by the crypto device, and that is the idea of multiple samples correlation power analysis (MSCPA). Considering that the leakage exploitation of MSCPA is more efficient than that of correlation power analysis (CPA), the power of MSCPA should be stronger than that of CPA. We theoretically prove and practically verify this fact. Theoretically, we show the advantage of MSCPA over CPA in terms of the correct key distinguishing level. We show that compared with CPA, MSCPA enlarges the gap between the correlation coefficient computed under the correct key and the correlation coefficients computed under wrong key guesses, which makes the correct key easier to be distinguished. Practically, we evaluate the performance of MSCPA in real scenarios. Using power traces provided by DPA Contest v2 and v4.1, we compare the key‐recovery efficiency of MSCPA with that of CPA. Experimental results show that compared with CPA, MSCPA can reach a higher key‐recovery efficiency in the same scenario. Copyright © 2016 John Wiley & Sons, Ltd.
Hailong Zhang 0001, Yongbin Zhou, Dengguo Feng
Secur. Commun. Networks1
2016 Distance Based Leakage Alignment for Side Channel Attacks
abstract
Side Channel Attack (SCA) recovers secret information from an embedded device with implementation of cryptographic algorithm by exploiting its physical leakages. For most SCA methods to achieve good performance, the measured leakages are often desired to be well aligned. However, due to some specific reasons such as inaccurate measurements or carefully designed countermeasures, misalignment of leakages frequently occurs in practice. Misalignment significantly reduces the efficiency of SCA methods, or even makes them fail. To address this issue, two alignment approaches are proposed: a local alignment based onshotgun distanceand a global alignment based onweighted edit distance. Compared with previous methods, the proposed methods are capable of keeping the secret dependant leakages, while not introducing any redundant information. In addition, the proposed methods could also reduce the negative effects of noise, which is another factor seriously decreasing the efficiency of SCA methods. Interestingly, it is pretty easy to set appropriate parameters for these two methods. Practical experiments show that the proposed methods outperform previous methods in three different circumstances and different noise levels.
Wei Yang 0008, Yuchen Cao 0002, Yongbin Zhou, Hailong Zhang 0001, Qian Zhang 0042
IEEE Signal Process. Lett.4
2015 Higher-Order Masking Schemes for Simon
Jiehui Tang, Yongbin Zhou, Hailong Zhang 0001, Shuang Qiu 0004
ICICS3
2015 Estimating Differential-Linear Distinguishers and Applications to CTC2
Chun Guo 0002, Hailong Zhang 0001, Dongdai Lin
ISPEC2
2015 Mahalanobis distance similarity measure based distinguisher for template attack
abstract
Abstract Under the assumption that power leakages at different interesting points follow multivariate normal distribution , maximum likelihood principle (MLP) can be used as an efficient distinguisher for template attack (TA). Therefore, in key‐recovery, one uses MLP to recover the correct key. In pattern recognition, Mahalanobis distance similarity measure (MDSM) is usually used to measure the similarity of two vectors in terms of their distance. A merit of MDSM is that, when measuring the similarity of two vectors, one takes the cross correlation between different variables into consideration. In this paper, we investigate the application of MDSM as a distinguisher in TA. We will show that there exists a certain relationship between MLP‐based TA and MDSM‐based TA under the assumption that the covariance matrices of different templates are identical . However, in MDSM‐based TA, power leakages at different interesting points are not required to follow multivariate normal distribution . We perform practical experiments to evaluate the key‐recovery efficiency of MDSM‐based TA. Experimental results verify that, in the same attack scenario, the key‐recovery efficiency of MDSM‐based TA can be higher than that of MLP‐based TA. Copyright © 2014 John Wiley & Sons, Ltd.
Hailong Zhang 0001, Yongbin Zhou, Dengguo Feng
Secur. Commun. Networks1
2014 How to Compare Selections of Points of Interest for Side-Channel Distinguishers in Practice?
Yingxian Zheng, Yongbin Zhou, Zhenmei Yu, Chengyu Hu 0001, Hailong Zhang 0001
ICICS5
2013 Systematic Construction and Comprehensive Evaluation of Kolmogorov-Smirnov Test Based Side-Channel Distinguishers
Yongbin Zhou, François-Xavier Standaert, Hailong Zhang 0001
ISPEC4