Fault Attack Countermeasures for Error Samplers in Lattice-Based Cryptography

Fault Attack Countermeasures for Error Samplers in Lattice-Based Cryptography
复制标题

DOI:
10.1109/iscas.2019.8702794
复制
发表时间:
2019-02
期刊:
2019 IEEE International Symposium on Circuits and Systems (ISCAS)
影响因子:
--
通讯作者:
James Howe;A. Khalid;Marco Martinoli;F. Regazzoni;E. Oswald
James Howe;A. Khalid;Marco Martinoli;F. Regazzoni;E. Oswald
中科院分区:
其他
文献类型:
--
作者:
James Howe;A. Khalid;Marco Martinoli;F. Regazzoni;E. Oswald

文献摘要

被引文献

相似文献

基于格的密码学是 NIST 后量子标准化工作的主要候选者之一,提供高效的密钥封装和签名方案。大多数这些方案的硬度都基于 LWE 的变体,因此严重依赖误差采样器通过混淆秘密信息的计算来提供必要的不确定性。因此,它是旁路分析的明确且明显的目标,许多类型的攻击都针对该组件来获取秘密密钥信息。为了将潜在的基于格的密码标准带入实际实现,保护这些模块免受过去和未来的故障和旁道攻击非常重要。本文提出了利用这些误差样本的预期分布(即高斯分布或二项式分布)的对策,通过使用统计测试来验证采样器是否正常运行。这些新颖的对策旨在防止之前对错误采样器的所有故障攻击。我们优化了所提出的测试的硬件实现,以避免除法和平方根计算,但是,我们提出的对策足够通用,也适用于软件。我们测量了这些对策对 Xilinx Artix-7 FPGA 性能和面积消耗的影响。我们的对策实现了良好的性能,同时将开销降至最低。
Lattice-based cryptography is one of the leading candidates for NIST's post-quantum standardisation effort, providing efficient key encapsulation and signature schemes. Most of these schemes base their hardness on variants of LWE, and thus rely heavily on error samplers to provide necessary uncertainty by obfuscating computations on secret information. Because of this it is a clear and obvious target for side-channel analysis, with numerous types of attacks targeting this component to gain secret-key information. In order to bring potential lattice-based cryptographic standards to practical realisation, it is important to protect these modules from past and future fault and side-channel attacks. This paper proposes countermeasures that exploit the distributions expected from these error samples, that is either Gaussian or binomial, by using statistical tests to verify the samplers are operating properly. The novel countermeasures are designed to protect against all previous fault attacks on error samplers. We optimize hardware implementation of the proposed tests to avoid division and square root calculations, however, the countermeasure we propose is sufficiently generic to be suitable also for software. We measure the impact of these countermeasures on performance and area consumption on a Xilinx Artix-7 FPGA. Our countermeasure achieve promising performance while resulting in a minimal overhead.