A one-time single-bit fault leaks all previous NTRU-HRSS session keys to a chosen-ciphertext attack
A one-time single-bit fault leaks all previous NTRU-HRSS session keys to a chosen-ciphertext attack
复制标题
DOI:
10.1007/978-3-031-22912-1_27
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
D. Bernstein
中科院分区:
文献类型:
--
作者:
D. Bernstein
This paper presents an efficient attack that, in the standard IND-CCA2 attack model plus a one-time single-bit fault, recovers the NTRU-HRSS session key. This type of fault is expected to occur for many users through natural DRAM bit flips. In a multi-target IND-CCA2 attack model plus a one-time single-bit fault, the attack recovers every NTRU-HRSS session key that was encapsulated to the targeted public key before the fault. Software carrying out the full multi-target attack, using a simulated fault, is provided for verification. This paper also explains how a change in NTRU-HRSS in 2019 enabled this attack.