{ "cells": [ { "cell_type": "markdown", "id": "afc512ca", "metadata": {}, "source": [ "## Speck Simulation" ] }, { "cell_type": "code", "execution_count": 2, "id": "efb373e4", "metadata": {}, "outputs": [], "source": [ "import matplotlib.pyplot as pyplot\n", "import numpy as np\n", "from scipy.stats import pearsonr\n", "import random\n", "from operator import xor\n", "\n", "# Fast implementation of the Hamming weight for 64 bit values\n", "# See book: A Hacker's delight\n", "# not sure if the hamming weight model w0rks for Speck\n", "def popcount(x):\n", " x -= (x >> 1) & 0x5555555555555555\n", " x = (x & 0x3333333333333333) + ((x >> 2) & 0x3333333333333333)\n", " x = (x + (x >> 4)) & 0x0f0f0f0f0f0f0f0f\n", " return ((x * 0x0101010101010101) & 0xffffffffffffffff ) >> 56\n" ] }, { "cell_type": "code", "execution_count": 3, "id": "7654d5a2", "metadata": {}, "outputs": [], "source": [ "import math\n", "\n", "NUM_ROUNDS = 22\n", "BLOCK_SIZE = 32\n", "KEY_SIZE = 64\n", "WORD_SIZE = 16\n", "\n", "\n", "# SHIFTs for SPECK\n", "ALPHA = 7\n", "BETA = 2\n", "\n", "mod_mask = (2 ** WORD_SIZE) -1\n", "mod_mask_sub = (2 ** WORD_SIZE)" ] }, { "cell_type": "markdown", "id": "4bb78fa1", "metadata": {}, "source": [ "## Speck Implementation\n", "\n", "First of all, a very simplified Speck implementation to support Speck 23/64 with 22 rounds and ALPHA = 7 and BETA = 3\n", "\n", "1) Key = bytesToWords16(key)\n", "\n", "2) scheduled_key = key_schedule(Key)\n", "\n", "3) ciphertext = encrypt(plaintext, scheduled_key)\n", "\n", "\n", "-> The encrypt funktion is currently `missing` ... only `simple_speck()`" ] }, { "cell_type": "code", "execution_count": 4, "id": "5c3ade39", "metadata": {}, "outputs": [], "source": [ "'''\n", " Converts a bytestring `0xdeadbeef` to a array of 16-byte integers (len: 4)\n", "'''\n", "def bytesToWords16(b): \n", " return [(b >> (x * WORD_SIZE)) & mod_mask for x in\n", " range(0, math.ceil(KEY_SIZE // WORD_SIZE))]\n", " " ] }, { "cell_type": "code", "execution_count": 5, "id": "953621aa", "metadata": {}, "outputs": [], "source": [ "'''\n", " The 16bit Speck roundfunction, this is where the magic happens\n", "'''\n", "def ER16(x, y, k):\n", "\n", " rs_x = ((x << (16 - ALPHA)) + (x >> ALPHA)) & mod_mask\n", "\n", " add_sxy = (rs_x + y) & mod_mask\n", "\n", " new_x = k ^ add_sxy\n", "\n", " ls_y = ((y >> (16 - BETA)) + (y << BETA)) & mod_mask\n", "\n", " new_y = new_x ^ ls_y\n", "\n", " return new_x, new_y\n" ] }, { "cell_type": "markdown", "id": "4b7a7d5d", "metadata": {}, "source": [ "## Running the key schedule" ] }, { "cell_type": "code", "execution_count": 6, "id": "15e86ae3", "metadata": {}, "outputs": [], "source": [ "key = 0x0102030405060708" ] }, { "cell_type": "code", "execution_count": 7, "id": "8c7e9a0c", "metadata": {}, "outputs": [], "source": [ "Key = bytesToWords16(key)" ] }, { "cell_type": "code", "execution_count": 8, "id": "93e4fb4a", "metadata": {}, "outputs": [], "source": [ "'''\n", "\n", "The 16 bit python key schedule\n", "\n", "void Speck128256KeySchedule(u64 K[],u64 rk[])\n", "{\n", " u64 i,D=K[3],C=K[2],B=K[1],A=K[0];\n", " for(i=0;i<33;){\n", " rk[i]=A; ER64(B,A,i++);\n", " rk[i]=A; ER64(C,A,i++);\n", " rk[i]=A; ER64(D,A,i++);\n", " }\n", " rk[i]=A;\n", "}\n", "'''\n", "def key_schedule(k):\n", "\n", " D=k[3]\n", " C=k[2]\n", " B=k[1]\n", " A=k[0]\n", " out = []\n", " i = 0\n", " while i < 21:\n", " out.append(A)\n", " B, A = ER16(B, A, i)\n", " i += 1\n", " out.append(A)\n", " C, A = ER16(C, A, i)\n", " i+= 1\n", " out.append(A)\n", " D, A = ER16(D, A, i)\n", " i+= 1\n", " out.append(A)\n", " return out\n", " " ] }, { "cell_type": "code", "execution_count": 9, "id": "0061be29", "metadata": {}, "outputs": [], "source": [ "'''\n", "Simple encryption for speck (only the encryption part, without key scheduling)\n", "\n", "void Speck128256Encrypt(u64 Pt[],u64 Ct[],u64 rk[])\n", "{\n", " u64 i;\n", " Ct[0]=Pt[0]; Ct[1]=Pt[1];\n", " for(i=0;i<34;) ER64(Ct[1],Ct[0],rk[i++]);\n", "}\n", "\n", "\n", "'''\n", "def simple_speck(plaintext, key):\n", " Ct_0 = plaintext[0]\n", " Ct_1 = plaintext[1]\n", " \n", " #for i in range(34):\n", " Ct_1, Ct_0 = ER16(Ct_1, Ct_0, key) # fixed 16 bit key of 0x55\n", " return (Ct_1 << WORD_SIZE) + Ct_0" ] }, { "cell_type": "markdown", "id": "e25af6e8", "metadata": {}, "source": [ "## Running tests to verify the output is still fine" ] }, { "cell_type": "code", "execution_count": 10, "id": "1dd758a0", "metadata": {}, "outputs": [], "source": [ "assert key_schedule(Key) == [0x708,0xf32, 0x2bf1,0x8035,0xa48e,0x8482, 0x74ee, 0xf589, 0xb396, 0xb231, 0xdab2, 0x57bc, 0x704e,0x9947,0xe2d2, 0xea6a, 0x4ebe, 0xdd24, 0x6b64, 0x3ab1, 0x1c57, 0x7bde]" ] }, { "cell_type": "code", "execution_count": 11, "id": "1553c623", "metadata": {}, "outputs": [], "source": [ "ciphertext = simple_speck([0xdead, 0xbeef], 0x55)" ] }, { "cell_type": "code", "execution_count": 12, "id": "5b1da8b8", "metadata": {}, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "0xbe7fc4c8\n" ] } ], "source": [ "# over simplified Speck encryption (no key schedule)\n", "print(hex(ciphertext))" ] }, { "cell_type": "markdown", "id": "22b7bbf5", "metadata": {}, "source": [ "# Simulation" ] }, { "cell_type": "markdown", "id": "7ebbb6f9", "metadata": {}, "source": [ "The following code simulates the Speck encryption process for an randomly choosen plaintext and the choosen key: **0x69**." ] }, { "cell_type": "markdown", "id": "9b8da308", "metadata": {}, "source": [ "It correlates 1000 encryptions for random plaintext and correlates them for execution with every possible keybyte" ] }, { "cell_type": "code", "execution_count": 16, "id": "2f090c78", "metadata": {}, "outputs": [ { "data": { "image/png": "\n", "text/plain": [ "
" ] }, "metadata": { "needs_background": "light" }, "output_type": "display_data" }, { "name": "stdout", "output_type": "stream", "text": [ "Correct 8-bit key is: 0xde\n" ] } ], "source": [ "num_traces = 3000\n", "\n", "key_space = 256\n", "\n", "\n", "traces = np.empty(num_traces)\n", "hw_traces = np.empty((key_space, num_traces))\n", "\n", "for i in range(0,num_traces):\n", " plaintext = [(i**2) % 0xFFFF, i % 0xFFFF]\n", " traces[i] = popcount(simple_speck(plaintext, 0x69de)) + np.random.normal(1, 20, 1) # + noice (seems to need an higher trace-count)\n", " for key in range(0, key_space):\n", " hw_traces[key][i] = popcount(simple_speck(plaintext, key))\n", "\n", "corr = np.empty(key_space)\n", "\n", "#compute pearson correlation for each key\n", "for key in range(0, key_space):\n", " corr[key],p = pearsonr(hw_traces[key], traces)\n", "\n", "pyplot.plot(corr)\n", "pyplot.show()\n", "\n", "print(\"Correct 8-bit key is: \" + hex(np.argmax(corr)))\n" ] }, { "cell_type": "markdown", "id": "e2532406", "metadata": {}, "source": [ "### $\\rightarrow$ Dafuq, at least something seems to w0rk" ] }, { "cell_type": "markdown", "id": "01603335", "metadata": {}, "source": [ "## 16-bit key\n", "\n", "Breaking byte-by-byte for a 16-bit key (to not require the full $2^{16}$ keyspace)" ] }, { "cell_type": "code", "execution_count": 109, "id": "34536991", "metadata": {}, "outputs": [], "source": [ "def get_key(current_keybyte):\n", " num_traces = 5000\n", "\n", " key_space = 256\n", "\n", "\n", " traces = np.empty(num_traces)\n", " hw_traces = np.empty((key_space, num_traces))\n", "\n", " for i in range(0,num_traces):\n", " plaintext = [(i**2) % 0xFFFF, i % 0xFFFF]\n", " traces[i] = popcount(simple_speck(plaintext, 0xdead)) + np.random.normal(1, 20, 1) # + noice (seems to need an higher trace-count)\n", " for key in range(0, key_space):\n", " if current_keybyte == None:\n", " key_guess = key\n", " else:\n", " key_guess = (key << 8) + current_keybyte\n", " hw_traces[key][i] = popcount(simple_speck(plaintext, key_guess))\n", "\n", " corr = np.empty(key_space)\n", "\n", " #compute pearson correlation for each key\n", " for key in range(0, key_space):\n", " corr[key],p = pearsonr(hw_traces[key], traces)\n", "\n", " #pyplot.plot(corr)\n", " #pyplot.show()\n", "\n", " print(\"Correct 8-bit key is: \" + hex(np.argmax(corr)))\n", " return np.argmax(corr)" ] }, { "cell_type": "code", "execution_count": 110, "id": "84a8e53e", "metadata": {}, "outputs": [], "source": [ "def get_full_key():\n", " int_key = None\n", " full = []\n", " for i in range(WORD_SIZE // 8):\n", " int_key = int(get_key(int_key))\n", " full.append(int_key)\n", " return (full[1] << 8) + full[0]" ] }, { "cell_type": "code", "execution_count": 112, "id": "bd76012f", "metadata": {}, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "Correct 8-bit key is: 0xad\n", "Correct 8-bit key is: 0xde\n", "Full 16-bit Key: 0xdead\n" ] } ], "source": [ "print(f\"Full 16-bit Key: {hex(get_full_key())}\")" ] }, { "cell_type": "code", "execution_count": null, "id": "3660bcc9", "metadata": {}, "outputs": [], "source": [] }, { "cell_type": "code", "execution_count": null, "id": "7b532103", "metadata": {}, "outputs": [], "source": [] } ], "metadata": { "kernelspec": { "display_name": "Python 3 (ipykernel)", "language": "python", "name": "python3" }, "language_info": { "codemirror_mode": { "name": "ipython", "version": 3 }, "file_extension": ".py", "mimetype": "text/x-python", "name": "python", "nbconvert_exporter": "python", "pygments_lexer": "ipython3", "version": "3.9.7" } }, "nbformat": 4, "nbformat_minor": 5 }