Lattice-Based Signature Schemes and Their Sensitivity to Fault Attacks
Lattice-Based Signature Schemes and their Sensitivity to Fault Attacks Nina Bindel and Johannes Buchmann and Juliane Krämer Technische Universität Darmstadt, Germany Email: {nbindel, buchmann, jkraemer}@cdc.informatik.tu-darmstadt.de June 10, 2016 Technology (NIST): in 2015, NSA advertised lattice-based cryptography over elliptic curve cryptography [25] and in Abstract Due to their high efficiency and their strong security properties, lattice-based cryptographic 2016, NIST announced to start a standardization process schemes seem to be a very promising post-quantum for post-quantum cryptography [26]. These developments replacement for currently used public key cryptogra- show that post-quantum cryptography is standing on the phy. The security of lattice-based schemes has been edge of being used in practical applications. deeply analyzed mathematically, whereas little effort Lattice-based constructions promise to be a valuable has been spent on the analysis against implementa- post-quantum replacement for current public-key cryp- tion attacks. tography because of their broad applicability, their high In this paper, we start with the fault analysis of one of the most important cryptographic primitives: efficiency, and their strong security properties. However, signature schemes. We investigate the vulnerabil- when novel cryptographic schemes are brought into prac- ity and resistance of the currently most efficient tice, their mathematical security is not sufficient. Physical lattice-based signature schemes BLISS (CRYPTO attacks which target cryptographic schemes while they are 2013), ring-TESLA (AfricaCrypt 2016), and the GLP being executed also have to be considered to provide the scheme (CHES 2012) and their implementations. We desired level of security. For lattice-based cryptographic consider different kinds of (first-order) randomizing, schemes, until now, little effort has been spent in analyzing zeroing, and skipping faults.
[Show full text]