暗号デバイスの物理セキュリティの数学的証明に成功―安全な暗号デバイスの設計方法を確立―

2026-08-19 京都大学

京都大学、東北大学、日本電気(NEC)の研究グループは、暗号デバイスの物理的安全性を数学的に証明する理論を確立し、低コストで高い耐サイドチャネル攻撃性を実現する設計手法を開発しました。サイドチャネル攻撃は、暗号処理中に発生する消費電力や電磁波などの物理情報を解析して秘密鍵を推測する攻撃であり、スマートフォンやICカード、IoT機器の安全性を脅かす課題となっています。本研究では、暗号回路の安全性評価で用いられる複数の理論モデルの関係を厳密に解析し、強いノイズを含む物理漏えい環境においても安全性を保証できる条件を数学的に導出しました。さらに、その理論を利用して、従来より少ないコストで実装可能な耐漏えい暗号回路設計技術を実現しました。これにより、暗号デバイスの物理セキュリティを理論的に保証する道筋が示され、今後の安全な情報通信基盤や組込み機器向け暗号技術の発展に大きく貢献すると期待されます。

暗号デバイスの物理セキュリティの数学的証明に成功―安全な暗号デバイスの設計方法を確立―
サイドチャネル攻撃の概要。攻撃者は暗号デバイスの物理的漏えいL(Z) から暗号演算内部の秘密情報Zを推測して、秘密鍵Kを詐取する。(この図では国際標準暗号AESのような暗号を想定している。)

<関連情報>

マスキングの形式的安全性証明:強雑音漏えいからプロービングモデルへの乱択プロービングを用いない帰着と漏えい耐性プリミティブへの応用 A Formal Security Proof of Masking: Reduction from Strong Noisy Leakage to Probing Model without Random Probing and Application to LR Primitive

Rei Ueno,Akiko Inoue,Kazuhiko Minematsu,Akira Ito & Naofumi Homma
Proceedings of Annual International Cryptology Conference (CRYPTO 2026)
DOI:https://doi.org/10.1007/978-3-032-35415-0_11

Abstract

This paper provides upper bounds on the success rate (SR) of side-channel attacks (SCAs) on masked implementations. We present a formal security proof of additive masking over any finite abelian group—including Boolean and arithmetic maskings—through new reductions from strong noisy leakage (SNL) to the probing model. Unlike existing proofs relying on noisy leakage (NL) and random probing (RP), our proof introduces a novel security notion named leakage energy (LE), which enables a stronger bound. Our proof reveals the necessary and sufficient condition for asymptotic security of additive masking in both the NL and mutual information frameworks, which includes a resolution to an open problem in TCC 2016. Our claims are validated through numerical evaluations. As an application of our theorems, we propose a binary block-cipher based leakage-resilient primitive based on a variant of XEX, which claims d-th order SCA security of arithmetic masking by design under some assumptions, enabling efficient OCB-style authenticated encryption with implementation cost of O(d).

1602ソフトウェア工学
ad
ad
Follow
ad
タイトルとURLをコピーしました