对CHES 2011会议上提出的轻量级分组密码LED进行旁路立方攻击研究。提出一种基于贪心策略的小立方体搜索方法,利用该方法确定了单比特泄露模型和汉明重泄露模型的泄露位;基于两种模型对LED密码进行旁路立方攻击,并对其攻击结果进行比较。仿真结果表明,基于单比特模型进行立方攻击,可将密钥搜索空间降低到2^8~2^11;基于汉明重模型,对第2、3轮的攻击可分别将密钥搜索空间降低到2^48、2^23。对两种模型比较发现,汉明重模型的多项式次数更高,立方大小分布更加集中。
This paper gave side-channel cube attacks on LED,which was a light-weight block cipher proposed in CHES 2011. It proposed a method of searching small cubes based on the greedy strategy. The method had determined the best leakage of sin- gle-bit leakage model and Hamming-weight based leakage model. It applied side-channel cube attacks on LED using two models and then compared the results of them. Simulation results show that the analyses based on single-bit leakage model can reduce the key search space to 2^8-2^11. Based on the other model, attackers can reduce the key search space on round 2 to 2^48 and that on round 3 to 2^23. The comparison indicates that the Hamming-weight based leakage model' s degree is higher and its cube sizes are more concentrated.