(One) Failure Is Not an Option: Bootstrapping the Search for Failures in Lattice-Based Encryption Schemes
Jan-Pieter D'Anvers, Mélissa Rossi, Fernando Virdia
摘要
Lattice-based encryption schemes are often subject to the possibility of decryption failures, in which valid encryptions are decrypted incorrectly. Such failures, in large number, leak information about the secret key, enabling an attack strategy alternative to pure lattice reduction. Extending the "failure boosting" technique of D'Anvers et al. in PKC 2019, we propose an approach that we call "directional failure boosting" that uses previously found "failing ciphertexts" to accelerate the search for new ones. We analyse in detail the case where the lattice is defined over polynomial ring modules quotiented by X N + 1 and demonstrate it on a simple Mod-LWE-based scheme parametrized à la Kyber768/Saber. We show that for a given secret key (single-target setting), the cost of searching for additional failing ciphertexts after one or more have already been found, can be sped up dramatically. We thus demonstrate that, in this single-target model, these schemes should be designed so that it is hard to even obtain one decryption failure. Besides, in a wider security model where there are many target secret keys (multi-target setting), our attack greatly improves over the state of the art.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- LWE with Side Information: Attacks and Concrete Security EstimationDana Dachman-Soled, Léo Ducas, Huijing Gong, Mélissa RossiCRYPTO 2020 · 被引用 162 次
- When Frodo Flips: End-to-End Key Recovery on FrodoKEM via RowhammerMichael Fahr, Hunter Kippen, Andrew Kwong, Thinh Dang 等CCS 2022 · 被引用 34 次
- (Un)breakable Curses - Re-encryption in the Fujisaki-Okamoto TransformKathrin Hövelmanns, Andreas Hülsing, Christian Majenz, Fabrizio SisinniEUROCRYPT 2025 · 被引用 4 次
- Formally Verified Correctness Bounds for Lattice-Based CryptographyManuel Barbosa, Matthias J. Kannwischer, Thing-Han Lim, Peter Schwabe 等CCS 2025
它引用的顶会 Paper1
相关 Paper
- Assessing the Impact of a Variant of MATZOV's Dual Attack on KyberKévin Carrier, Charles Meyer-Hilfiger, Yixin Shen, Jean-Pierre TillichCRYPTO 2025 · 被引用 3 次
- Revisiting Security Estimation for LWE with Hints from a Geometric PerspectiveDana Dachman-Soled, Huijing Gong, Tom Hanson, Hunter KippenCRYPTO 2023 · 被引用 15 次
- Benchmarking Attacks on Learning with ErrorsEmily Wenger, Eshika Saxena, Mohamed Malhou, Ellie Thieu 等S&P 2025
- Exploring Decryption Failures of BIKE: New Class of Weak Keys and Key Recovery AttacksTianrui Wang, Anyu Wang, Xiaoyun WangCRYPTO 2023 · 被引用 9 次
- Faster Lattice-Based KEMs via a Generic Fujisaki-Okamoto Transform Using Prefix HashingJulien Duman, Kathrin Hövelmanns, Eike Kiltz, Vadim Lyubashevsky 等CCS 2021 · 被引用 1 次
