To BLISS-B or not to be: Attacking strongSwan's Implementation of Post-Quantum Signatures
Peter Pessl, Leon Groot Bruinderink, Yuval Yarom
摘要
In the search for post-quantum secure alternatives to RSA and ECC, lattice-based cryptography appears to be an attractive and efficient option. A particularly interesting lattice-based signature scheme is BLISS, offering key and signature sizes in the range of RSA moduli. A range of works on efficient implementations of BLISS is available, and the scheme has seen a first real-world adoption in strongSwan, an IPsec-based VPN suite. In contrast, the implementation-security aspects of BLISS, and lattice-based cryptography in general, are still largely unexplored.
At CHES 2016, Groot Bruinderink et al. presented the first sidechannel attack on BLISS, thus proving that this topic cannot be neglected. Nevertheless, their attack has some limitations. First, the technique is demonstrated via a proof-of-concept experiment that was not performed under realistic attack settings. Furthermore, the attack does not apply to BLISS-B, an improved variant of BLISS and also the default option in strongSwan. This problem also applies to later works on implementation security of BLISS.
In this work, we solve both of the above problems. We present a new side-channel key-recovery algorithm against both the original BLISS and the BLISS-B variant. Our key-recovery algorithm draws on a wide array of techniques, including learning-parity with noise, integer programs, maximimum likelihood tests, and a lattice-basis reduction. With each application of a technique, we reveal additional information on the secret key culminating in a complete key recovery.
Finally, we show that cache attacks on post-quantum cryptography are not only possible, but also practical. We mount an asynchronous cache attack on the production-grade BLISS-B implementation of strongSwan. The attack recovers the secret signing key after observing roughly 6 000 signature generations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Fallout: Leaking Data on Meltdown-resistant CPUsClaudio Canella, Daniel Genkin, Lukas Giner, Daniel Gruss 等CCS 2019 · 被引用 289 次
- "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing AttacksJan Jancar, Marcel Fourné, Daniel De Almeida Braga, Mohamed Sabt 等S&P 2022 · 被引用 61 次
- LadderLeak: Breaking ECDSA with Less than One Bit of Nonce LeakageDiego F. Aranha, Felipe Rodrigues Novaes, Akira Takahashi, Mehdi Tibouchi 等CCS 2020 · 被引用 58 次
- GALACTICS: Gaussian Sampling for Lattice-Based Constant- Time Implementation of Cryptographic Signatures, RevisitedGilles Barthe, Sonia Belaïd, Thomas Espitau, Pierre-Alain Fouque 等CCS 2019 · 被引用 37 次
- Pseudorandom Black Swans: Cache Attacks on CTR_DRBGShaanan Cohney, Andrew Kwong, Shahar Paz, Daniel Genkin 等S&P 2020 · 被引用 36 次
它引用的顶会 Paper3
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 被引用 972 次
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 被引用 93 次
- Constant-Time Callees with Variable-Time CallersCesar Pereida García, Billy Bob BrumleyUSENIX Security 2017 · 被引用 63 次
相关 Paper
- Side-Channel Attacks on BLISS Lattice-Based Signatures: Exploiting Branch Tracing against strongSwan and Electromagnetic Emanations in MicrocontrollersThomas Espitau, Pierre-Alain Fouque, Benoît Gérard, Mehdi TibouchiCCS 2017 · 被引用 145 次
- A Little LESS Secure - Side-Channel Attacks Exploiting Randomness LeakageDina Hesse, Elisabeth Krahmer, Yi-Fu Lai, Jonas MeersCRYPTO 2026
- HAWK with Hint: Algebraic Key Recovery from Side-Channel LeakageByoungchan Chi, Changmin Lee, Inhun LeeCCS 2026
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet 等EUROCRYPT 2020 · 被引用 19 次
- Finding and Protecting the Weakest Link - On Side-Channel Attacks on in Masked ML-DSAJulius Hermelink, Kai-Chun Ning, Richard PetriCRYPTO 2025 · 被引用 4 次
