Masking the GLP Lattice-Based Signature Scheme at Any Order

被引:28
|
作者
Barthe, Gilles [1 ]
Belaid, Sonia [2 ]
Espitau, Thomas [3 ]
Fouque, Pierre-Alain [4 ]
Gregoire, Benjamin [5 ]
Rossi, Melissa [6 ,7 ]
Tibouchi, Mehdi [8 ]
机构
[1] IMDEA Software Inst, Madrid, Spain
[2] CryptoExperts, Paris, France
[3] UPMC, Paris, France
[4] Univ Rennes, Rennes, France
[5] Inria Sophia Antipolis, Sophia Antipolis, France
[6] Thales, Paris, France
[7] PSL Res Univ, INRIA, CNRS, Dept Informat,Ecole Normale Super Paris, Paris, France
[8] NTT Secure Platform Labs, Tokyo, Japan
基金
欧盟地平线“2020”;
关键词
Side-channel; Masking; GLP lattice-based signature; FIAT-SHAMIR;
D O I
10.1007/978-3-319-78375-8_12
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, numerous physical attacks have been demonstrated against lattice-based schemes, often exploiting their unique properties such as the reliance on Gaussian distributions, rejection sampling and FFT-based polynomial multiplication. As the call for concrete implementations and deployment of postquantum cryptography becomes more pressing, protecting against those attacks is an important problem. However, few countermeasures have been proposed so far. In particular, masking has been applied to the decryption procedure of some lattice-based encryption schemes, but the much more difficult case of signatures (which are highly non-linear and typically involve randomness) has not been considered until now. In this paper, we describe the first masked implementation of a lattice-based signature scheme. Since masking Gaussian sampling and other procedures involving contrived probability distribution would be prohibitively inefficient, we focus on the GLP scheme of Guneysu, Lyubashevsky and Poppelmann (CHES 2012). We show how to provably mask it in the Ishai-Sahai-Wagner model (CRYPTO 2003) at any order in a relatively efficient manner, using extensions of the techniques of Coron et al. for converting between arithmetic and Boolean masking. Our proof relies on a mild generalization of probing security that supports the notion of public outputs. We also provide a proof-of-concept implementation to assess the efficiency of the proposed countermeasure.
引用
收藏
页码:354 / 384
页数:31
相关论文
共 50 条
  • [1] Masking the GLP Lattice-Based Signature Scheme at Any Order
    Barthe, Gilles
    Belaid, Sonia
    Espitau, Thomas
    Fouque, Pierre-Alain
    Gregoire, Benjamin
    Rossi, Melissa
    Tibouchi, Mehdi
    JOURNAL OF CRYPTOLOGY, 2024, 37 (01)
  • [2] Masking the GLP Lattice-Based Signature Scheme at Any Order
    Gilles Barthe
    Sonia Belaïd
    Thomas Espitau
    Pierre-Alain Fouque
    Benjamin Grégoire
    Mélissa Rossi
    Mehdi Tibouchi
    Journal of Cryptology, 2024, 37
  • [3] Lattice-based undeniable signature scheme
    Rawal, Swati
    Padhye, Sahadeo
    He, Debiao
    ANNALS OF TELECOMMUNICATIONS, 2022, 77 (3-4) : 119 - 126
  • [4] A Lattice-Based Incremental Signature Scheme
    Chen, Jing
    Tian, Miaomiao
    Gao, Chuang
    Chen, Zhili
    IEEE ACCESS, 2019, 7 : 21201 - 21210
  • [5] Lattice-based undeniable signature scheme
    Swati Rawal
    Sahadeo Padhye
    Debiao He
    Annals of Telecommunications, 2022, 77 : 119 - 126
  • [6] NSS: An NTRU lattice-based Signature Scheme
    Hoffstein, J
    Pipher, J
    Silverman, JH
    ADVANCES IN CRYPTOLOGY-EUROCRYPT 2001, PROCEEDINGS, 2001, 2045 : 211 - 228
  • [7] Cryptanalysis of the PEREGRINE Lattice-Based Signature Scheme
    Lin, Xiuhan
    Suzuki, Moeto
    Zhang, Shiduo
    Espitau, Thomas
    Yu, Yang
    Tibouchi, Mehdi
    Abe, Masayuki
    PUBLIC-KEY CRYPTOGRAPHY, PT I, PKC 2024, 2024, 14601 : 387 - 412
  • [8] A Lattice-Based Threshold Ring Signature Scheme
    Cayrel, Pierre-Louis
    Lindner, Richard
    Ruckert, Markus
    Silva, Rosemberg
    PROGRESS IN CRYPTOLOGY - LATINCRYPT 2010, 2010, 6212 : 255 - +
  • [9] The Lattice-Based Digital Signature Scheme qTESLA
    Alkim, Erdem
    Barreto, Paulo S. L. M.
    Bindel, Nina
    Kraemer, Juliane
    Longa, Patrick
    Ricardini, Jefferson E.
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY (ACNS 2020), PT I, 2020, 12146 : 441 - 460
  • [10] Lattice-based online/offline signature scheme
    Xiang, Xin-Yin
    Li, Hui
    Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications, 2015, 38 (03): : 117 - 120