SNI-in-the-head: Protecting MPC-in-the-head Protocols against Side-channel Analysis
Okan Seker, Sebastian Berndt, Luca Wilke, Thomas Eisenbarth
摘要
MPC-in-the-head based protocols have recently gained much popularity and are at the brink of seeing widespread usage. With widespread use come the spectres of implementation issues and implementation attacks such as side-channel attacks. We show that implementations of protocols implementing the MPC-in-the-head paradigm are vulnerable to side-channel attacks. As a case study, we choose the ZKBoo-protocol of Giacomelli, Madsen, and Orlandi (USENIX 2016) and show that even a single leaked value is sufficient to break the security of the protocol. To show that this attack is not just a theoretical vulnerability, we apply differential power analysis to show the vulnerabilities via a simulation. In order to remedy this situation, we extend and generalize the ZKBoo-protocol by making use of the notion of strong non-interference of Barthe et al. (CCS 2016). To apply this notion to ZKBoo, we construct novel versions of strongly non-interfering gadgets that balance the randomness across the different branches evenly. Finally, we show that each circuit can be decomposed into branches using only these balanced strongly non-interfering gadgets. This allows us to construct a version of ZKBoo, called -ZKBoo which is secure against side-channel attacks with limited overhead in both signature-size and running time. Furthermore, -ZKBoo is scalable to the desired security against adversarial probes. We experimentally confirm that the attacks successful against ZKBoo no longer work on -ZKBoo. Moreover, we present an extensive performance analysis and quantify the overhead of our scheme using a practical implementation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- CrypTen: Secure Multi-Party Computation Meets Machine LearningBrian Knott, Shobha Venkataraman, Awni Y. Hannun, Shubho Sengupta 等NeurIPS 2021 · 被引用 573 次
- Privacy and Integrity Preserving Computations with CRISPSylvain Chatel, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, Jean-Pierre HubauxUSENIX Security 2021 · 被引用 12 次
- Amortizing Randomness Cost: Efficient Masked Implementation of SDitH Signatures with Common SharesGuowei Liu, Weijia Wang, Lixuan Wu, Chaoran Wang 等USENIX Security 2026
它引用的顶会 Paper6
- Ligero: Lightweight Sublinear Arguments Without a Trusted SetupScott Ames, Carmit Hazay, Yuval Ishai, Muthuramakrishnan VenkitasubramaniamCCS 2017 · 被引用 338 次
- Post-Quantum Zero-Knowledge and Signatures from Symmetric-Key PrimitivesMelissa Chase, David Derler, Steven Goldfeder, Claudio Orlandi 等CCS 2017 · 被引用 316 次
- Strong Non-Interference and Type-Directed Higher-Order MaskingGilles Barthe, Sonia Belaïd, François Dupressoir, Pierre-Alain Fouque 等CCS 2016 · 被引用 302 次
- ZKBoo: Faster Zero-Knowledge for Boolean CircuitsIrene Giacomelli, Jesper Madsen, Claudio OrlandiUSENIX Security 2016 · 被引用 287 次
- Improved Non-Interactive Zero Knowledge with Applications to Post-Quantum SignaturesJonathan Katz, Vladimir Kolesnikov, Xiao WangCCS 2018 · 被引用 257 次
相关 Paper
- Rushing at SPDZ: On the Practical Security of Malicious MPC ImplementationsAlexander Kyster, Frederik Huss Nielsen, Sabine Oechsner, Peter SchollS&P 2025
- Zero-Knowledge Contingent Payments Revisited: Attacks and Payments for ServicesMatteo Campanelli, Rosario Gennaro, Steven Goldfeder, Luca NizzardoCCS 2017 · 被引用 170 次
- Efficient 3PC for Binary Circuits with Application to Maliciously-Secure DNN InferenceYun Li, Yufei Duan, Zhicong Huang, Cheng Hong 等USENIX Security 2023
- Low-Latency Hardware Private CircuitsDavid Knichel, Amir MoradiCCS 2022 · 被引用 20 次
- Remote Side-Channel Attacks on Anonymous TransactionsFlorian Tramèr, Dan Boneh, Kenny PatersonUSENIX Security 2020
