Passer à la navigation principale Passer à la recherche Passer au contenu principal

Key recovery from gram–schmidt norm leakage in hash-and-sign signatures over NTRU lattices

  • IRISA
  • NTT Secure Platform Laboratories

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

In this paper, we initiate the study of side-channel leakage in hash-and-sign lattice-based signatures, with particular emphasis on the two efficient implementations of the original GPV lattice-trapdoor paradigm for signatures, namely NIST second-round candidate Falcon and its simpler predecessor DLP. Both of these schemes implement the GPV signature scheme over NTRU lattices, achieving great speed-ups over the general lattice case. Our results are mainly threefold. First, we identify a specific source of side-channel leakage in most implementations of those schemes, namely, the one-dimensional Gaussian sampling steps within lattice Gaussian sampling. It turns out that the implementations of these steps often leak the Gram–Schmidt norms of the secret lattice basis. Second, we elucidate the link between this leakage and the secret key, by showing that the entire secret key can be efficiently reconstructed solely from those Gram–Schmidt norms. The result makes heavy use of the algebraic structure of the corresponding schemes, which work over a power-of-two cyclotomic field. Third, we concretely demonstrate the side-channel attack against DLP (but not Falcon due to the different structures of the two schemes). The challenge is that timing information only provides an approximation of the Gram–Schmidt norms, so our algebraic recovery technique needs to be combined with pruned tree search in order to apply it to approximate values. Experimentally, we show that around 235 DLP traces are enough to reconstruct the entire key with good probability.

langue originaleAnglais
titreAdvances in Cryptology – EUROCRYPT 2020 - 39th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Proceedings
rédacteurs en chefAnne Canteaut, Yuval Ishai
EditeurSpringer
Pages34-63
Nombre de pages30
ISBN (imprimé)9783030457266
Les DOIs
étatPublié - 1 janv. 2020
Modification externeOui
Evénement39th Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2020 - Zagreb, Croatie
Durée: 10 mai 202014 mai 2020

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12107 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence39th Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2020
Pays/TerritoireCroatie
La villeZagreb
période10/05/2014/05/20

Empreinte digitale

Examiner les sujets de recherche de « Key recovery from gram–schmidt norm leakage in hash-and-sign signatures over NTRU lattices ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation