Skip to content
Open access

A side-channel attack for recovering keys in HMAC-SM3 algorithm

Aug 2026 · Frontiers of Physics · 0 citations · 14 references

Abstract

Cyber-Physical-Social Systems (CPSS) face escalating side-channel threats that undermine secure data transmission and authentication. As China’s national cryptographic hash standard, SM3 is widely deployed in CPSS-integrated social network ecosystems for identity authentication, API signing, and cross-platform data integrity verification—yet its key-dependent input vulnerabilities against side-channel attacks remain inadequately addressed. This study tackles two critical limitations of traditional side-channel attacks for HMAC-SM3 key recovery: non-profiling methods fail due to absent plaintext correlations, while profiling-based approaches suffer from error accumulation and near-zero success rates in single-trace scenarios. We propose a self-calibrating side-channel attack (SC-SCA) that enables high-accuracy HMAC-SM3 key recovery using only a single power trace during the attack phase. The method constructs a Bayesian network to integrate power trace statistics with prior knowledge of input dependencies, then performs joint probabilistic inference via belief propagation. Experimental results demonstrate 100% key recovery success under simulated noiseless conditions, 91.45% success on a real smart card system, and 73% effectiveness at a 10 dB signal-to-noise ratio. Crucially, this work exposes a previously overlooked attack surface in CPSS-based social networks: a single compromised HMAC-SM3 key can enable forged device control commands, large-scale privacy breaches, and cascading identity theft across linked social platforms. Our findings provide both a practical security benchmark for CPSS edge devices and theoretical foundations for designing side-channel-resistant cryptographic implementations.

Read PDF