High-Order Masking of Lattice Signatures in Quasilinear Time
Rafaël del Pino, Thomas Prest, Mélissa Rossi, Markku-Juhani O. Saarinen
摘要
In recent years, lattice-based signature schemes have emerged as the most prominent post-quantum solutions, as illustrated by NIST's selection of Falcon and Dilithium for standardization. Both schemes enjoy good performance characteristics. However, their efficiency dwindles in the presence of side-channel protections, particularly masking -perhaps the strongest generic side-channel countermeasure. Masking at order d-1 requires randomizing all sensitive intermediate variables into d shares. With existing schemes, signature generation complexity grows quadratically with the number of shares, making high-order masking prohibitively slow.
In this paper, we turn the problem upside-down: We design a lattice-based signature scheme specifically for sidechannel resistance and optimize the masked efficiency as a function of the number of shares. Our design avoids costly operations such as conversions between arithmetic and boolean encodings (A2B/B2A), masked rejection sampling, and does not require a masked SHAKE implementation or other symmetric primitives. The resulting scheme is called Raccoon and belongs to the family of Fiat-Shamir with aborts lattice-based signatures. Raccoon is the first lattice-based signature whose key generation and signing running time has only an O(d log(d)) overhead, with d being the number of shares.
Our Reference C implementation confirms that Raccoon's performance is comparable to other state-of-the-art signature schemes, except that increasing the number of shares has a near-linear effect on its latency. We also present an FPGA implementation and perform a physical leakage assessment to verify its basic security properties.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper6
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 被引用 972 次
- Strong Non-Interference and Type-Directed Higher-Order MaskingGilles Barthe, Sonia Belaïd, François Dupressoir, Pierre-Alain Fouque 等CCS 2016 · 被引用 302 次
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi 等EUROCRYPT 2022 · 被引用 67 次
- FALCON Down: Breaking FALCON Post-Quantum Signature Scheme through Side-Channel AttacksEmre Karabulut, Aydin AysuDAC 2021 · 被引用 65 次
- Real-World Snapshots vs. Theory: Questioning the t-Probing Security ModelThilo Krachenfels, Fatemeh Ganji, Amir Moradi, Shahin Tajik 等S&P 2021 · 被引用 42 次
相关 Paper
- Raccoon: A Masking-Friendly Signature Proven in the Probing ModelRafaël del Pino, Shuichi Katsumata, Thomas Prest, Mélissa RossiCRYPTO 2024 · 被引用 24 次
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet 等EUROCRYPT 2020 · 被引用 19 次
- Improved Power Analysis Attacks on FalconShiduo Zhang, Xiuhan Lin, Yang Yu, Weijia WangEUROCRYPT 2023 · 被引用 26 次
- Olingo: Threshold Lattice Signatures with DKG and Identifiable AbortKamil Doruk Gur, Patrick Hough, Jonathan Katz, Caroline Sandsbråten 等CCS 2026
- New Techniques for Random Probing Security and Application to Raccoon Signature SchemeSonia Belaïd, Matthieu Rivain, Mélissa RossiEUROCRYPT 2025 · 被引用 5 次
