Practical CCA2-Secure and Masked Ring-LWE Implementation

Practical CCA2-Secure and Masked Ring-LWE Implementation
复制标题

DOI:
10.13154/tches.v2018.i1.142-174
复制
发表时间:
2018-02
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Tobias Oder;Tobias Schneider;T. Pöppelmann;Tim Güneysu
Tobias Oder;Tobias Schneider;T. Pöppelmann;Tim Güneysu
中科院分区:
其他
文献类型:
--
作者:
Tobias Oder;Tobias Schneider;T. Pöppelmann;Tim Güneysu

文献摘要

被引文献

相似文献

在过去的几年中,基于Ring-lwe的硬度的公共钥匙加密计划已获得了巨大的普及。对于假设强大的对手模型的实际安全应用程序,仍然需要解决许多实际问题。因此,在这项工作中,我们提出了一个戒指加密的实例,该实例可免受主动攻击(即自适应选择 - 封闭式攻击),并配备对侧通道分析的对策。我们的解决方案基于Fujisaki-Okamoto(FO)变换的Quantum变体与可证明的安全的一阶遮罩相结合。为了保护在解密过程中的密钥和消息,我们开发了一个掩盖的二项式采样器,该采样器确保了FO所需的重新加密过程。我们的工作表明,基于CCA2固定的RLWE加密可以通过在受限设备上进行合理的性能来实现,但也强调说,解密错误所需的转换和处理意味着迄今为止社区已经忽略的绩效开销。通过提供233位量子安全性的参数,我们的实现需要4,176,684个循环以进行加密和25,640,380个循环,以解密,并在Cortex-M4F上掩盖和隐藏对策。我们的掩盖实现的一阶安全性也可以使用非特异性t检验评估方法实际验证。
During the last years public-key encryption schemes based on the hardness of ring-LWE have gained significant popularity. For real-world security applications assuming strong adversary models, a number of practical issues still need to be addressed. In this work we thus present an instance of ring-LWE encryption that is protected against active attacks (i.e., adaptive chosen-ciphertext attacks) and equipped with countermeasures against side-channel analysis. Our solution is based on a postquantum variant of the Fujisaki-Okamoto (FO) transform combined with provably secure first-order masking. To protect the key and message during decryption, we developed a masked binomial sampler that secures the re-encryption process required by FO. Our work shows that CCA2-secured RLWE-based encryption can be achieved with reasonable performance on constrained devices but also stresses that the required transformation and handling of decryption errors implies a performance overhead that has been overlooked by the community so far. With parameters providing 233 bits of quantum security, our implementation requires 4,176,684 cycles for encryption and 25,640,380 cycles for decryption with masking and hiding countermeasures on a Cortex-M4F. The first-order security of our masked implementation is also practically verified using the non-specific t-test evaluation methodology.