{ "cells": [ { "cell_type": "markdown", "id": "afc512ca", "metadata": {}, "source": [ "## Speck Simulation" ] }, { "cell_type": "code", "execution_count": 1, "id": "efb373e4", "metadata": {}, "outputs": [], "source": [ "import matplotlib.pyplot as pyplot\n", "import numpy as np\n", "from scipy.stats import pearsonr\n", "import random\n", "from operator import xor\n", "\n", "# Fast implementation of the Hamming weight for 64 bit values\n", "# See book: A Hacker's delight\n", "# not sure if the hamming weight model w0rks for Speck\n", "def popcount(x):\n", " x -= (x >> 1) & 0x5555555555555555\n", " x = (x & 0x3333333333333333) + ((x >> 2) & 0x3333333333333333)\n", " x = (x + (x >> 4)) & 0x0f0f0f0f0f0f0f0f\n", " return ((x * 0x0101010101010101) & 0xffffffffffffffff ) >> 56\n" ] }, { "cell_type": "code", "execution_count": 2, "id": "7654d5a2", "metadata": {}, "outputs": [], "source": [ "import math\n", "\n", "NUM_ROUNDS = 22\n", "BLOCK_SIZE = 32\n", "KEY_SIZE = 64\n", "WORD_SIZE = 16\n", "\n", "\n", "# SHIFTs for SPECK\n", "ALPHA = 7\n", "BETA = 2\n", "\n", "mod_mask = (2 ** WORD_SIZE) -1\n", "mod_mask_sub = (2 ** WORD_SIZE)" ] }, { "cell_type": "markdown", "id": "4bb78fa1", "metadata": {}, "source": [ "## Speck Implementation\n", "\n", "First of all, a very simplified Speck implementation to support Speck 23/64 with 22 rounds and ALPHA = 7 and BETA = 3\n", "\n", "1) Key = bytesToWords16(key)\n", "\n", "2) scheduled_key = key_schedule(Key)\n", "\n", "3) ciphertext = encrypt(plaintext, scheduled_key)\n", "\n", "\n", "-> The encrypt funktion is currently `missing` ... only `simple_speck()`" ] }, { "cell_type": "code", "execution_count": 13, "id": "5c3ade39", "metadata": {}, "outputs": [], "source": [ "'''\n", " Converts a bytestring `0xdeadbeef` to a array of 16-byte integers (len: 4)\n", "'''\n", "def bytesToWords16(b): \n", " return [(b >> (x * WORD_SIZE)) & mod_mask for x in\n", " range(0, math.ceil(KEY_SIZE // WORD_SIZE))]\n", " " ] }, { "cell_type": "code", "execution_count": 14, "id": "01f318ea", "metadata": {}, "outputs": [ { "data": { "text/plain": [ "['0x708', '0x506', '0x304', '0x102']" ] }, "execution_count": 14, "metadata": {}, "output_type": "execute_result" } ], "source": [ "[hex(x) for x in bytesToWords16(0x0102030405060708)]" ] }, { "cell_type": "code", "execution_count": 9, "id": "953621aa", "metadata": {}, "outputs": [], "source": [ "'''\n", " The 16bit Speck roundfunction, this is where the magic happens\n", "'''\n", "def ER16(x, y, k):\n", "\n", " rs_x = ((x << (16 - ALPHA)) + (x >> ALPHA)) & mod_mask\n", "\n", " add_sxy = (rs_x + y) & mod_mask\n", "\n", " new_x = k ^ add_sxy\n", "\n", " ls_y = ((y >> (16 - BETA)) + (y << BETA)) & mod_mask\n", "\n", " new_y = new_x ^ ls_y\n", "\n", " return new_x, new_y\n" ] }, { "cell_type": "markdown", "id": "4b7a7d5d", "metadata": {}, "source": [ "## Running the key schedule" ] }, { "cell_type": "code", "execution_count": 15, "id": "15e86ae3", "metadata": {}, "outputs": [], "source": [ "key = 0x0102030405060708" ] }, { "cell_type": "code", "execution_count": 16, "id": "8c7e9a0c", "metadata": {}, "outputs": [], "source": [ "Key = bytesToWords16(key)" ] }, { "cell_type": "code", "execution_count": 17, "id": "fd523d75", "metadata": {}, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "['0x708', '0x506', '0x304', '0x102']\n" ] } ], "source": [ "print([hex(x) for x in Key])" ] }, { "cell_type": "code", "execution_count": 18, "id": "93e4fb4a", "metadata": {}, "outputs": [], "source": [ "'''\n", "\n", "The 16 bit python key schedule\n", "\n", "void Speck128256KeySchedule(u64 K[],u64 rk[])\n", "{\n", " u64 i,D=K[3],C=K[2],B=K[1],A=K[0];\n", " for(i=0;i<33;){\n", " rk[i]=A; ER64(B,A,i++);\n", " rk[i]=A; ER64(C,A,i++);\n", " rk[i]=A; ER64(D,A,i++);\n", " }\n", " rk[i]=A;\n", "}\n", "'''\n", "def key_schedule(k):\n", "\n", " D=k[3]\n", " C=k[2]\n", " B=k[1]\n", " A=k[0]\n", " out = []\n", " i = 0\n", " while i < 21:\n", " out.append(A)\n", " B, A = ER16(B, A, i)\n", " i += 1\n", " out.append(A)\n", " C, A = ER16(C, A, i)\n", " i+= 1\n", " out.append(A)\n", " D, A = ER16(D, A, i)\n", " i+= 1\n", " out.append(A)\n", " return out\n", " " ] }, { "cell_type": "code", "execution_count": 39, "id": "0061be29", "metadata": {}, "outputs": [], "source": [ "'''\n", "Simple encryption for speck (only the encryption part, without key scheduling)\n", "\n", "void Speck128256Encrypt(u64 Pt[],u64 Ct[],u64 rk[])\n", "{\n", " u64 i;\n", " Ct[0]=Pt[0]; Ct[1]=Pt[1];\n", " for(i=0;i<34;) ER64(Ct[1],Ct[0],rk[i++]);\n", "}\n", "\n", "\n", "'''\n", "def simple_speck(plaintext, key):\n", " Ct_0 = plaintext[0]\n", " Ct_1 = plaintext[1]\n", " \n", " \n", " Ct_1, Ct_0 = ER16(Ct_1, Ct_0, key) # fixed 16 bit key of 0x55\n", " return (Ct_1 << 8) + Ct_0" ] }, { "cell_type": "markdown", "id": "e25af6e8", "metadata": {}, "source": [ "## Running tests to verify the output is still fine" ] }, { "cell_type": "code", "execution_count": 22, "id": "1dd758a0", "metadata": {}, "outputs": [], "source": [ "assert key_schedule(Key) == [0x708,0xf32, 0x2bf1,0x8035,0xa48e,0x8482, 0x74ee, 0xf589, 0xb396, 0xb231, 0xdab2, 0x57bc, 0x704e,0x9947,0xe2d2, 0xea6a, 0x4ebe, 0xdd24, 0x6b64, 0x3ab1, 0x1c57, 0x7bde]" ] }, { "cell_type": "code", "execution_count": 11, "id": "1553c623", "metadata": {}, "outputs": [], "source": [ "ciphertext = simple_speck([0xdead, 0xbeef], 0x55)" ] }, { "cell_type": "code", "execution_count": 12, "id": "5b1da8b8", "metadata": {}, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "0xbe7fc4c8\n" ] } ], "source": [ "# over simplified Speck encryption (no key schedule)\n", "print(hex(ciphertext))" ] }, { "cell_type": "markdown", "id": "22b7bbf5", "metadata": {}, "source": [ "# Simulation" ] }, { "cell_type": "markdown", "id": "7ebbb6f9", "metadata": {}, "source": [ "The following code simulates the Speck encryption process for an randomly choosen plaintext and the choosen key: **0x69**." ] }, { "cell_type": "markdown", "id": "9b8da308", "metadata": {}, "source": [ "It correlates 1000 encryptions for random plaintext and correlates them for execution with every possible keybyte" ] }, { "cell_type": "code", "execution_count": 74, "id": "2f090c78", "metadata": {}, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n", "8000\n", "8000\n", "+++++++++++++++++++++++++++++++++++++++++++\n" ] }, { "data": { "image/png": "\n", "text/plain": [ "
" ] }, "metadata": { "needs_background": "light" }, "output_type": "display_data" }, { "name": "stdout", "output_type": "stream", "text": [ "Correct 8-bit key is: 0x69\n" ] } ], "source": [ "import random\n", "num_traces = 8000\n", "\n", "key_space = 256\n", "\n", "\n", "traces = np.empty(num_traces)\n", "hw_traces = np.empty((key_space, num_traces))\n", "\n", "for i in range(0,num_traces):\n", " #plaintext = [(i**2) % 0xFFFF, i % 0xFFFF]\n", " plaintext = bytes([random.randint(0, 255) for i in range(4)])\n", " traces[i] = popcount(simple_speck(plaintext, 0x69)) + np.random.normal(1, 20, 1) # + noice (seems to need an higher trace-count)\n", " \n", " # this is the simulation of the estimated values, using the popcount\n", " for key in range(0, key_space):\n", " hw_traces[key][i] = popcount(simple_speck(plaintext, key))\n", "\n", "corr = np.empty(key_space)\n", "\n", "#compute pearson correlation for each key\n", "for key in range(0, key_space):\n", " print(len(hw_traces[key])) # estimates\n", " print(len(traces)) # 'captured' traces\n", " print(\"+++++++++++++++++++++++++++++++++++++++++++\")\n", " corr[key],p = pearsonr(hw_traces[key], traces)\n", "\n", "pyplot.plot(corr)\n", "pyplot.show()\n", "\n", "print(\"Correct 8-bit key is: \" + hex(np.argmax(corr)))\n" ] }, { "cell_type": "markdown", "id": "e2532406", "metadata": {}, "source": [ "### $\\rightarrow$ Dafuq, at least something seems to w0rk" ] }, { "cell_type": "markdown", "id": "6baed584", "metadata": {}, "source": [ "## 16-bit key\n", "\n", "Breaking byte-by-byte for a 16-bit key (to not require the full $2^{16}$ keyspace)" ] }, { "cell_type": "code", "execution_count": 52, "id": "34536991", "metadata": {}, "outputs": [], "source": [ "def get_key(current_keybyte):\n", " num_traces = 5000\n", "\n", " key_space = 256\n", "\n", "\n", " traces = np.empty(num_traces)\n", " hw_traces = np.empty((key_space, num_traces))\n", "\n", " for i in range(0,num_traces):\n", " plaintext = [(i**2) % 0xFFFF, i % 0xFFFF]\n", " traces[i] = popcount(simple_speck(plaintext, 0xc0fe)) + np.random.normal(1, 20, 1) # + noice (seems to need an higher trace-count)\n", " for key in range(0, key_space):\n", " if current_keybyte == None:\n", " key_guess = key\n", " else:\n", " key_guess = (key << 8) + current_keybyte\n", " hw_traces[key][i] = popcount(simple_speck(plaintext, key_guess))\n", "\n", " corr = np.empty(key_space)\n", "\n", " #compute pearson correlation for each key\n", " for key in range(0, key_space):\n", " corr[key],p = pearsonr(hw_traces[key], traces)\n", "\n", " #pyplot.plot(corr)\n", " #pyplot.show()\n", "\n", " print(\"Correct 8-bit key is: \" + hex(np.argmax(corr)))\n", " return np.argmax(corr)" ] }, { "cell_type": "code", "execution_count": 55, "id": "84a8e53e", "metadata": {}, "outputs": [], "source": [ "def get_full_key():\n", " int_key = None\n", " full = []\n", " for i in range(WORD_SIZE // 8):\n", " int_key = int(get_key(int_key))\n", " full.append(int_key)\n", " return (full[1] << 8) + full[0]" ] }, { "cell_type": "code", "execution_count": 56, "id": "bd76012f", "metadata": {}, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "Correct 8-bit key is: 0xfe\n", "Correct 8-bit key is: 0xc0\n", "Full 16-bit Key: 0xc0fe\n" ] } ], "source": [ "print(f\"Full 16-bit Key: {hex(get_full_key())}\")" ] }, { "cell_type": "code", "execution_count": null, "id": "3660bcc9", "metadata": {}, "outputs": [], "source": [] }, { "cell_type": "code", "execution_count": null, "id": "42520a86", "metadata": {}, "outputs": [], "source": [] } ], "metadata": { "kernelspec": { "display_name": "Python 3 (ipykernel)", "language": "python", "name": "python3" }, "language_info": { "codemirror_mode": { "name": "ipython", "version": 3 }, "file_extension": ".py", "mimetype": "text/x-python", "name": "python", "nbconvert_exporter": "python", "pygments_lexer": "ipython3", "version": "3.9.7" } }, "nbformat": 4, "nbformat_minor": 5 }