Lune

CRYPTO2025顶会

Uncompressing Dilithium's Public Key

Paco Azevedo Oliveira, Andersson Calle Viera, Benoît Cogliati, Louis Goubin

2025年份
10被引次数

摘要

The Dilithium signature scheme – recently standardized by NIST under the name ML-DSA – owes part of its success to a specific mechanism that allows an optimizaion of its public key size. Namely, among the data of the MLWE instance (A,t)\bf (A,\bf{t}), which is at the heart of the construction of Dilithium, the least significant part of t\bf{t} -- denoted by t0\bf{t}_0 -- is not included in the public key. The verification algorithm had been adapted accordingly, so that it should not require the knowledge of t0\bf{t}_0. However, since it is still required to compute valid signatures, it has been made part of the secret key. The knowledge of t0\bf{t}_0 has no impact on the black-box cryptographic security of Dilithium, as can be seen in the security proof. Nevertheless, it does allow the construction of much more efficient side-channel attacks. Whether it is possible to recover t0\bf{t}_0 thus appears to be a sensitive question. In this work, we show that each Dilithium signature leaks information on t0\bf{t}_0, then we construct an attack that retrieves it from Dilithium signatures. Experimentally, depending on the Dilithium security level, between 200 000200\,000 and 500 000500\,000 signatures are sufficient to recover t0\bf{t}_0 on a desktop computer.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖