A one-time single-bit fault leaks all previous NTRU-HRSS session keys to a chosen-ciphertext attack

A one-time single-bit fault leaks all previous NTRU-HRSS session keys to a chosen-ciphertext attack
复制标题

DOI:
10.1007/978-3-031-22912-1_27
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
D. Bernstein
D. Bernstein
中科院分区:
其他
文献类型:
--
作者:
D. Bernstein

文献摘要

相似文献

本文提出了一种在标准IND-CCA2攻击模型加上一次性单比特错误的情况下恢复NTRU-HRSS会话密钥的有效攻击方法。这种类型的故障预计会通过自然的DRAM位翻转发生在许多用户身上。在多目标IND-CCA2攻击模型中加上一次单比特故障,攻击恢复故障前封装到目标公钥的每个NTRU-HRSS会话密钥。提供了使用模拟故障执行全多目标攻击的软件以供验证。本文还解释了NTRU-HRSS在2019年的变化如何启用了这种攻击。
This paper presents an efficient attack that, in the standard IND-CCA2 attack model plus a one-time single-bit fault, recovers the NTRU-HRSS session key. This type of fault is expected to occur for many users through natural DRAM bit flips. In a multi-target IND-CCA2 attack model plus a one-time single-bit fault, the attack recovers every NTRU-HRSS session key that was encapsulated to the targeted public key before the fault. Software carrying out the full multi-target attack, using a simulated fault, is provided for verification. This paper also explains how a change in NTRU-HRSS in 2019 enabled this attack.