Amortizing Randomness Cost: Efficient Masked Implementation of SDitH Signatures with Common Shares
Guowei Liu, Weijia Wang, Lixuan Wu, Chaoran Wang, Yanhong Fan, Jinliang Wang, Meiqin Wang
摘要
MPC-in-the-Head (MPCitH) signatures are attractive for postquantum deployment, but they are structurally vulnerable to side-channel leakage: verification opens almost all simulated views, so any leakage correlated with the remaining unopened view(s) can be amplified and exploited to recover the witness. Among the MPCitH-based signature candidates considered in NIST's additional-signature round, Syndrome-Decodingin-the-Head (SDitH)-Hypercube is particularly susceptible to this concern, since its signing process combines: (i) offline last-party completion involving nonlinear arithmetic computations, (ii) online Baum-Nof (BN) arithmetic checking, and (iii) Keccak sponge calls that generate or absorb secretbearing values.
To the best of our knowledge, this is the first protocolcompatible masked implementation-level protection architecture for SDitH-Hypercube on Cortex-M4. Our implementation combines three techniques, each protecting one attackcritical hotspot: (i) Common Shares to amortize the masking randomness required by masked multiplications in the offline phase, (ii) a Sec/Pub typing discipline that reconstructs transcript-public and verifier-reconstructible values early to avoid costly Sec×Sec gadgets in the online BN kernels, and (iii) selective masked Keccak backends applied only to secretbearing sponge call sites.
On the L1 parameter set, Common Shares reduces arithmetic masking randomness from 8.37 KiB/signature of the Strong Non-Interference (SNI) profile to 16 B/signature, while the Sec/Pub-typed optimization removes 3,264 B/signature from the online BN kernels. When Keccak is masked, masking randomness is dominated by the sponge: 41,118.75 KiB/signature with DOM-Keccak and 82,237.50 KiB/signature with SNI-Keccak, motivating selective masked hashing and tunable backends. We implement a low-stack reference signer and all protected signers on Cortex-M4. Across protected profiles, signing takes 913.7-1,542.0 Mcycles (1.84×-3.10× over the * Corresponding Author. reference), and fits within 155.6 KiB flash, 136.7 KiB static RAM, and 7.96 KiB signing stack. A 1M-trace first-order fixed-vs-random Test Vector Leakage Assessment (TVLA) experiment on Cortex-M4 no longer detects the previously observed leakage peaks after protection.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- Strong Non-Interference and Type-Directed Higher-Order MaskingGilles Barthe, Sonia Belaïd, François Dupressoir, Pierre-Alain Fouque 等CCS 2016 · 被引用 302 次
- Syndrome Decoding in the Head: Shorter Signatures from Zero-Knowledge ProofsThibauld Feneuil, Antoine Joux, Matthieu RivainCRYPTO 2022 · 被引用 73 次
- Side-Channel Masking with Pseudo-Random GeneratorJean-Sébastien Coron, Aurélien Greuet, Rina ZeitounEUROCRYPT 2020 · 被引用 29 次
- SNI-in-the-head: Protecting MPC-in-the-head Protocols against Side-channel AnalysisOkan Seker, Sebastian Berndt, Luca Wilke, Thomas EisenbarthCCS 2020
相关 Paper
- On Round Elimination for Special-Sound Multi-round Identification and the Generality of the Hypercube for MPCitHAndreas Hülsing, David Joseph, Christian Majenz, Anand Kumar NarayananCRYPTO 2024 · 被引用 2 次
- The Return of the SDitHCarlos Aguilar Melchor, Nicolas Gama, James Howe, Andreas Hülsing 等EUROCRYPT 2023 · 被引用 40 次
- AIM: Symmetric Primitive for Shorter Signatures with Stronger SecuritySeongkwang Kim, Jincheol Ha, Mincheol Son, ByeongHak Lee 等CCS 2023 · 被引用 19 次
- Short Signatures from Regular Syndrome Decoding in the HeadEliana Carozza, Geoffroy Couteau, Antoine JouxEUROCRYPT 2023 · 被引用 25 次
- Accelerating SLH-DSA by Two Orders of Magnitude with a Single Hash UnitMarkku-Juhani O. SaarinenCRYPTO 2024 · 被引用 18 次
