Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU Lattices
Pierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet, Yang Yu
Abstract
In this paper, we initiate the study of side-channel leakage in hash-and-sign lattice-based signatures, with particular emphasis on the two efficient implementations of the original GPV lattice-trapdoor paradigm for signatures, namely NIST second-round candidate Falcon and its simpler predecessor DLP. Both of these schemes implement the GPV signature scheme over NTRU lattices, achieving great speed-ups over the general lattice case. Our results are mainly threefold.
First, we identify a specific source of side-channel leakage in most implementations of those schemes, namely, the one-dimensional Gaussian sampling steps within lattice Gaussian sampling. It turns out that the implementations of these steps often leak the Gram-Schmidt norms of the secret lattice basis.
Second, we elucidate the link between this leakage and the secret key, by showing that the entire secret key can be efficiently reconstructed solely from those Gram-Schmidt norms. The result makes heavy use of the algebraic structure of the corresponding schemes, which work over a power-of-two cyclotomic field.
Third, we concretely demonstrate the side-channel attack against DLP (but not Falcon due to the different structures of the two schemes). The challenge is that timing information only provides an approximation of the Gram-Schmidt norms, so our algebraic recovery technique needs to be combined with pruned tree search in order to apply it to approximate values. Experimentally, we show that around 2 35 DLP traces are enough to reconstruct the entire key with good probability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 407d1302-1a59-4e08-bce8-ce309de32c03Cited by top-tier papers1
Ask how each one uses itBuilds on4
- Side-Channel Attacks on BLISS Lattice-Based Signatures: Exploiting Branch Tracing against strongSwan and Electromagnetic Emanations in MicrocontrollersThomas Espitau, Pierre-Alain Fouque, Benoît Gérard, Mehdi TibouchiCCS 2017 · 145 citations
- To BLISS-B or not to be: Attacking strongSwan's Implementation of Post-Quantum SignaturesPeter Pessl, Leon Groot Bruinderink, Yuval YaromCCS 2017 · 88 citations
- GALACTICS: Gaussian Sampling for Lattice-Based Constant- Time Implementation of Cryptographic Signatures, RevisitedGilles Barthe, Sonia Belaïd, Thomas Espitau, Pierre-Alain Fouque et al.CCS 2019 · 37 citations
- Integral Matrix Gram Root and Lattice Gaussian Sampling Without FloatsLéo Ducas, Steven D. Galbraith, Thomas Prest, Yang YuEUROCRYPT 2020 · 22 citations
Related papers
- Shorter Hash-and-Sign Lattice-Based SignaturesThomas Espitau, Mehdi Tibouchi, Alexandre Wallet, Yang YuCRYPTO 2022 · 38 citations
- Improved Power Analysis Attacks on FalconShiduo Zhang, Xiuhan Lin, Yang Yu, Weijia WangEUROCRYPT 2023 · 26 citations
- HAWK with Hint: Algebraic Key Recovery from Side-Channel LeakageByoungchan Chi, Changmin Lee, Inhun LeeCCS 2026
- Crowhammer: Full Key Recovery Attack on Falcon with a Single Rowhammer Bit FlipCalvin Abou Haidar, Quentin Payet, Mehdi TibouchiCRYPTO 2025 · 4 citations
- Halfspace Learning for Lattice Signature Key Recovery from SignsMarcus Brinkmann, Nicolai Kraus, Alexander MayCRYPTO 2026 · 1 citation
