Passer à la navigation principale Passer à la recherche Passer au contenu principal

Partial Key Exposure Attacks on BIKE, Rainbow and NTRU

  • Andre Esser
  • , Alexander May
  • , Javier Verbel
  • , Weiqiang Wen
  • Technology Innovation Institute
  • Ruhr-University Bochum
  • Institut Polytechnique de Paris

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

14 Citations (Scopus)

Résumé

In a so-called partial key exposure attack one obtains some information about the secret key, e.g. via some side-channel leakage. This information might be a certain fraction of the secret key bits (erasure model) or some erroneous version of the secret key (error model). The goal is to recover the secret key from the leaked information. There is a common belief that, as opposed to e.g. the RSA cryptosystem, most post-quantum cryptosystems are usually resistant against partial key exposure attacks. We strongly question this belief by constructing partial key exposure attacks on code-based, multivariate, and lattice-based schemes (BIKE, Rainbow and NTRU). Our attacks exploit the redundancy that modern PQ cryptosystems inherently use for efficiency reasons. The application and development of techniques from information set decoding plays a crucial role for achieving our results. On the theoretical side, we show non-trivial information leakage bounds that allow for a polynomial time key recovery attack. As an example, for all schemes the knowledge of a constant fraction of the secret key bits suffices to reconstruct the full key in polynomial time. Even if we no longer insist on polynomial time attacks, most of our attacks extend well and remain feasible up to large erasure and error rates. In the case of BIKE for example we obtain attack complexities around 60 bits when half of the secret key bits are erased, or a quarter of the secret key bits are faulty. Our results show that even highly error-prone key leakage of modern PQ cryptosystems may lead to full secret key recoveries.

langue originaleAnglais
titreAdvances in Cryptology – CRYPTO 2022 - 42nd Annual International Cryptology Conference, CRYPTO 2022, Proceedings
rédacteurs en chefYevgeniy Dodis, Thomas Shrimpton
EditeurSpringer Science and Business Media Deutschland GmbH
Pages346-375
Nombre de pages30
ISBN (imprimé)9783031159817
Les DOIs
étatPublié - 1 janv. 2022
Modification externeOui
Evénement42nd Annual International Cryptology Conference, CRYPTO 2022 - Hybrid, Santa Barbara, États-Unis
Durée: 15 août 202218 août 2022

Série de publications

NomLecture Notes in Computer Science
Volume13509 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence42nd Annual International Cryptology Conference, CRYPTO 2022
Pays/TerritoireÉtats-Unis
La villeHybrid, Santa Barbara
période15/08/2218/08/22

Empreinte digitale

Examiner les sujets de recherche de « Partial Key Exposure Attacks on BIKE, Rainbow and NTRU ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation