Uncompressing Dilithium's Public Key
Paco Azevedo Oliveira, Andersson Calle Viera, Benoît Cogliati, Louis Goubin
Abstract
The Dilithium signature scheme – recently standardized by NIST under the name ML-DSA – owes part of its success to a specific mechanism that allows an optimizaion of its public key size. Namely, among the data of the MLWE instance , which is at the heart of the construction of Dilithium, the least significant part of -- denoted by -- is not included in the public key. The verification algorithm had been adapted accordingly, so that it should not require the knowledge of . However, since it is still required to compute valid signatures, it has been made part of the secret key. The knowledge of has no impact on the black-box cryptographic security of Dilithium, as can be seen in the security proof. Nevertheless, it does allow the construction of much more efficient side-channel attacks. Whether it is possible to recover thus appears to be a sensitive question. In this work, we show that each Dilithium signature leaks information on , then we construct an attack that retrieves it from Dilithium signatures. Experimentally, depending on the Dilithium security level, between and signatures are sufficient to recover on a desktop computer.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Halfspace Learning for Lattice Signature Key Recovery from SignsMarcus Brinkmann, Nicolai Kraus, Alexander MayCRYPTO 2026 · 1 citation
- A Little LESS Secure - Side-Channel Attacks Exploiting Randomness LeakageDina Hesse, Elisabeth Krahmer, Yi-Fu Lai, Jonas MeersCRYPTO 2026
- Finding and Protecting the Weakest Link - On Side-Channel Attacks on in Masked ML-DSAJulius Hermelink, Kai-Chun Ning, Richard PetriCRYPTO 2025 · 4 citations
- When Module Lattice Leaks: Horizontal Fusion Attacks on ML-DSA ImplementationYuhan Zhao, Dalin He, Wei Cheng, Yuejun Liu et al.CCS 2026
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet et al.EUROCRYPT 2020 · 19 citations
