Qian Zhang 0042

dblp:04/2024-42 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
3since 2021 · last 2024
0000-0002-6166-5343ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2024 In-depth Correlation Power Analysis Attacks on a Hardware Implementation of CRYSTALS-Dilithium
abstract
Abstract During the standardisation process of post-quantum cryptography, NIST encourages research on side-channel analysis for candidate schemes. As the recommended lattice signature scheme, CRYSTALS-Dilithium, when implemented on hardware, has seen limited research on side-channel analysis, and current attacks are incomplete or requires a substantial quantity of traces. Therefore, we conducted a more complete analysis to investigate the leakage of an FPGA implementation of CRYSTALS-Dilithium using the Correlation Power Analysis (CPA) method, where with a minimum of 70,000 traces partial private key coefficients can be recovered. Furthermore, we optimise the attack by extracting Point-of-Interests using known information due to parallelism (named CPA-PoI) and by iteratively utilising parallel leakages (named CPA-ITR). Our experimental results show that CPA-PoI reduces the number of traces by up to 16.67%, CPA-ITR by up to 25%, and both increase the number of recovered key coefficients by up to 55.17% and 93.10% using the same number of traces. They outperfom the CPA method. As a result, it suggests that the FPGA implementation of CRYSTALS-Dilithium is more vulnerable than thought before to side-channel analysis.
Huaxin Wang, Yiwen Gao 0001, Yuejun Liu, Qian Zhang 0042, Yongbin Zhou
Cybersecur.4
2022 Breaking real-world COTS USIM cards with unknown side-channel countermeasures
Chengbin Jin, Yongbin Zhou, Xinkuan Qiu, Qian Zhang 0042
Comput. Secur.5
2021 A secure and highly efficient first-order masking scheme for AES linear operations
abstract
Abstract Due to its provable security and remarkable device-independence, masking has been widely accepted as a noteworthy algorithmic-level countermeasure against side-channel attacks. However, relatively high cost of masking severely limits its applicability. Considering the high tackling complexity of non-linear operations, most masked AES implementations focus on the security and cost reduction of masked S-boxes. In this paper, we focus on linear operations, which seems to be underestimated, on the contrary. Specifically, we discover some security flaws and redundant processes in popular first-order masked AES linear operations, and pinpoint the underlying root causes. Then we propose a provably secure and highly efficient masking scheme for AES linear operations. In order to show its practical implications, we replace the linear operations of state-of-the-art first-order AES masking schemes with our proposal, while keeping their original non-linear operations unchanged. We implement four newly combined masking schemes on an Intel Core i7-4790 CPU, and the results show they are roughly 20% faster than those original ones. Then we select one masked implementation named RSMv2 due to its popularity, and investigate its security and efficiency on an AVR ATMega163 processor and four different FPGA devices. The results show that no exploitable first-order side-channel leakages are detected. Moreover, compared with original masked AES implementations, our combined approach is nearly 25% faster on the AVR processor, and at least 70% more efficient on four FPGA devices.
Jingdian Ming, Yongbin Zhou, Huizhong Li, Qian Zhang 0042
Cybersecur.4
2020 Mind the Balance: Revealing the Vulnerabilities in Low Entropy Masking Schemes
abstract
Low Entropy Masking Schemes (LEMS) have attracted wide attention due to their implementations simplicity and relatively good performance in protecting cryptographic implementations against Side-Channel-Attacks (SCAs). To achieve desired security, it is necessary (but not sufficient) to find proper low entropy mask sets to protect all sensitive secret-dependant intermediate variables. However, one crucial problem concerning this intuitive idea is that what `proper' mask sets should be. To formally capture such crucial qualification, we introduce the notion of balancedness to characterize this natural attribute of mask sets themselves. Considering that this notion is limited to characterize first-order security, we generalize it to d-dimension balancedness to accommodate dth-order security, then we exhibit lower and upper bounds on d-dimension balancedness for any d. With the help of these essential definitions, we prove that no balanced low entropy mask set really exists, which implies that LEMS implementations always have vulnerabilities in theory due to the unbalancedness of underlying mask sets. In order to further demonstrate the practical implications of balancedness, we show 4 different kinds of attacks on three state-of-the-art LEMS implementations. Specifically, the distribution attack proposed in this paper is a general first-order attack on LEMS. The results demonstrate that unbalanced mask sets actually do lead to serious vulnerabilities.
Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li, Guang Yang 0042, Qian Zhang 0042
IEEE Trans. Inf. Forensics Secur.6
2018 A Compact AES Hardware Implementation Secure Against 1st-Order Side-Channel Attacks
abstract
Efficient cryptographic implementations with desired side-channel attacks (SCA) resistance are highly required, especially for those resources-constrained devices. In this paper, we propose a very compact AES hardware implementation scheme provably secure against 1st-order SCAs. Basically, our scheme is inspired by ideas of Redundant Tower Field (RTF for short) circuit due to Ueno et al. and of private circuits due to Ishai, Sahai and Wagner (ISW for short), and is therefore named ISW-RTF. In terms of security, practical attacks on real leakages from prototype implementation show that ISW-RTF scheme is secure against 1st-order attacks and 2nd-order zero-offset attacks as well. Results of t-test leakage detection of these leakages also verify this observation. In terms of efficiency, compared with the state-of-the-art 1st-order masking scheme, our scheme outperforms at least 55.08% decreases in area, and 34.87% decreases in area-time product on three popular FPGA/ASIC devices. To the best of our knowledge, the proposed ISW-RTF scheme is the most compact one provably secure against SCA.
Qian Zhang 0042, Yongbin Zhou, Shuang Qiu 0004, Wei Cheng 0003, Jingdian Ming, Rui Zhang 0002
ICCD1
2018 Convolutional Neural Network for Larger JPEG Images Steganalysis
Qian Zhang 0042, Xianfeng Zhao
IWDW1
2017 Multi-Channel Fusion Attacks
abstract
Side channel attacks (SCAs) are a kind of the most powerful means to evaluate the physical security of a crypto device. Multi-channel fusion attacks (MCFAs) belong in SCAs and utilize multi-channel leakages simultaneously. As compared with the known mono-channel attacks, MCFAs have higher potential leakage utilization. However, previous research about MCFAs is scarce. MCFAs have not been studied systematically and classified explicitly. It is hard to select MCFAs strategies properly and perform MCFAs efficiently according to the existing research. In light of this, we classify MCFAs into three groups from the view of fusion for the first time, including data-level, feature-level, and decision-level fusion attacks. Accordingly, we construct six MCFAs and verify their effectiveness in typical scenarios. The applicable scopes and the different performances of MCFAs with different fusion activities are also first discussed. To the best of our knowledge, this paper is the first to systematically investigate MCFAs. We hope that this paper will be helpful to understand MCFAs and offer advice on MCFAs against the different implementations of a crypto algorithm. Besides, a fusion metric that determines which channels are suitable for combination is also proposed and verified by practical experiments.
Wei Yang 0008, Yongbin Zhou, Yuchen Cao 0002, Hailong Zhang 0001, Qian Zhang 0042
IEEE Trans. Inf. Forensics Secur.5
2016 Distance Based Leakage Alignment for Side Channel Attacks
abstract
Side Channel Attack (SCA) recovers secret information from an embedded device with implementation of cryptographic algorithm by exploiting its physical leakages. For most SCA methods to achieve good performance, the measured leakages are often desired to be well aligned. However, due to some specific reasons such as inaccurate measurements or carefully designed countermeasures, misalignment of leakages frequently occurs in practice. Misalignment significantly reduces the efficiency of SCA methods, or even makes them fail. To address this issue, two alignment approaches are proposed: a local alignment based onshotgun distanceand a global alignment based onweighted edit distance. Compared with previous methods, the proposed methods are capable of keeping the secret dependant leakages, while not introducing any redundant information. In addition, the proposed methods could also reduce the negative effects of noise, which is another factor seriously decreasing the efficiency of SCA methods. Interestingly, it is pretty easy to set appropriate parameters for these two methods. Practical experiments show that the proposed methods outperform previous methods in three different circumstances and different noise levels.
Wei Yang 0008, Yuchen Cao 0002, Yongbin Zhou, Hailong Zhang 0001, Qian Zhang 0042
IEEE Signal Process. Lett.5