(One) Failure Is Not an Option: Bootstrapping the Search for Failures in Lattice-Based Encryption Schemes
Jan-Pieter D'Anvers, Mélissa Rossi, Fernando Virdia
Abstract
Lattice-based encryption schemes are often subject to the possibility of decryption failures, in which valid encryptions are decrypted incorrectly. Such failures, in large number, leak information about the secret key, enabling an attack strategy alternative to pure lattice reduction. Extending the "failure boosting" technique of D'Anvers et al. in PKC 2019, we propose an approach that we call "directional failure boosting" that uses previously found "failing ciphertexts" to accelerate the search for new ones. We analyse in detail the case where the lattice is defined over polynomial ring modules quotiented by X N + 1 and demonstrate it on a simple Mod-LWE-based scheme parametrized à la Kyber768/Saber. We show that for a given secret key (single-target setting), the cost of searching for additional failing ciphertexts after one or more have already been found, can be sped up dramatically. We thus demonstrate that, in this single-target model, these schemes should be designed so that it is hard to even obtain one decryption failure. Besides, in a wider security model where there are many target secret keys (multi-target setting), our attack greatly improves over the state of the art.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- LWE with Side Information: Attacks and Concrete Security EstimationDana Dachman-Soled, Léo Ducas, Huijing Gong, Mélissa RossiCRYPTO 2020 · 162 citations
- When Frodo Flips: End-to-End Key Recovery on FrodoKEM via RowhammerMichael Fahr, Hunter Kippen, Andrew Kwong, Thinh Dang et al.CCS 2022 · 34 citations
- (Un)breakable Curses - Re-encryption in the Fujisaki-Okamoto TransformKathrin Hövelmanns, Andreas Hülsing, Christian Majenz, Fabrizio SisinniEUROCRYPT 2025 · 4 citations
- Formally Verified Correctness Bounds for Lattice-Based CryptographyManuel Barbosa, Matthias J. Kannwischer, Thing-Han Lim, Peter Schwabe et al.CCS 2025
Builds on1
Related papers
- Assessing the Impact of a Variant of MATZOV's Dual Attack on KyberKévin Carrier, Charles Meyer-Hilfiger, Yixin Shen, Jean-Pierre TillichCRYPTO 2025 · 3 citations
- Revisiting Security Estimation for LWE with Hints from a Geometric PerspectiveDana Dachman-Soled, Huijing Gong, Tom Hanson, Hunter KippenCRYPTO 2023 · 15 citations
- Benchmarking Attacks on Learning with ErrorsEmily Wenger, Eshika Saxena, Mohamed Malhou, Ellie Thieu et al.S&P 2025
- Exploring Decryption Failures of BIKE: New Class of Weak Keys and Key Recovery AttacksTianrui Wang, Anyu Wang, Xiaoyun WangCRYPTO 2023 · 9 citations
- Faster Lattice-Based KEMs via a Generic Fujisaki-Okamoto Transform Using Prefix HashingJulien Duman, Kathrin Hövelmanns, Eike Kiltz, Vadim Lyubashevsky et al.CCS 2021 · 1 citation
