Decryption Failure Is More Likely After Success

被引:11
|
作者
Bindel, Nina [1 ]
Schanck, John M. [1 ]
机构
[1] Univ Waterloo, Inst Quantum Comp, Waterloo, ON, Canada
来源
基金
加拿大自然科学与工程研究理事会;
关键词
Public-key cryptography; Lattice-based cryptography; Decryption failure;
D O I
10.1007/978-3-030-44223-1_12
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The user of an imperfectly correct lattice-based public-key encryption scheme leaks information about their secret key with each decryption query that they answer-even if they answer all queries successfully. Through a refinement of the D'Anvers-Guo-Johansson-Nilsson-Vercauteren-Verbauwhede failure boosting attack, we show that an adversary can use this information to improve his odds of finding a decryption failure. We also propose a new definition of delta-correctness, and we re-assess the correctness of several submissions to NIST's post-quantum standardization effort.
引用
收藏
页码:206 / 225
页数:20
相关论文
共 50 条