Machine-Learning Side-Channel Attacks on the GALACTICS Constant-Time Implementation of BLISS

Machine-Learning Side-Channel Attacks on the GALACTICS Constant-Time Implementation of BLISS
复制标题

对 BLISS 的 GALACTICS 恒定时间实现的机器学习侧通道攻击

DOI:
--
复制
发表时间:
2021
期刊:
ARES
影响因子:
--
通讯作者:
Jean
Jean
中科院分区:
--
文献类型:
--
作者:
Soundes Marzougui;Nils Wisiol;Patrick Gersch;Juliane Krämer;Jean

文献摘要

参考文献

被引文献

相似文献

由于量子计算机的发展,对传统公钥密码学的实际攻击可能在未来几十年内成为可能。为了应对这一风险,人们正在开发被认为是安全的、不受量子攻击的后量子方案。基于格的算法有望取代传统的方案,BLISS是该家族中最早的后量子签名方案之一。然而,所需的子例程,如高斯抽样,已被证明是对BLISS的安全的风险,因为实现关于物理攻击的高效和安全的高斯抽样是具有挑战性的。本文提出了三种相关的对Galactics的功率侧信道攻击,Galactics是BLISS的最新恒定时间实现。所有攻击都基于我们在Galactics的高斯采样和签名算法中识别的功率侧信道泄漏。要运行攻击,需要对与被攻击设备相同的设备进行分析阶段,以训练机器学习分类器。在攻击阶段,Galactics的泄漏使训练好的分类器能够高精度地预测敏感的内部信息。我们通过在Cortex-M4上运行Galactics演示了攻击的实用性,并为我们的所有攻击提供了概念验证数据和实施。
Due to the advancing development of quantum computers, practical attacks on conventional public-key cryptography may become feasible in the next few decades. To address this risk, post-quantum schemes that are assumed to be secure against quantum attacks are being developed. Lattice-based algorithms are promising replacements for conventional schemes, with BLISS being one of the earliest post-quantum signature schemes in this family. However, required subroutines such as Gaussian sampling have been demonstrated to be a risk for the security of BLISS, since implementing Gaussian sampling both efficient and secure with respect to physical attacks is challenging. This paper presents three related power side-channel attacks on GALACTICS, the latest constant-time implementation of BLISS. All attacks are based on power side-channel leakages we identified in the Gaussian sampling and signing algorithm of GALACTICS. To run the attacks, a profiling phase on a device identical to the device under attack is required to train machine learning classifiers. In the attack phase, the leakages of GALACTICS enable the trained classifiers to predict sensitive internal information with high accuracy. We demonstrate the practicality of the attacks by running GALACTICS on a Cortex-M4 and provide proof-of-concept data and implementation for all our attacks.
DOI: 10.1007/978-3-662-44709-3_20
发表时间: 2014-09
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
T. Pöppelmann;L. Ducas;Tim Güneysu
通讯作者: T. Pöppelmann;L. Ducas;Tim Güneysu