Matches in SemOpenAlex for { <https://semopenalex.org/work/W4311167566> ?p ?o ?g. }
- W4311167566 endingPage "14" @default.
- W4311167566 startingPage "1" @default.
- W4311167566 abstract "Side-channel security has become a significant concern in the NIST post-quantum cryptography standardization process. The lattice-based CRYSTALS-Dilithium (abbr. Dilithium) becomes the primary signature standard algorithm recommended by NIST for most use cases in July 2022 due to its excellent performance in security and efficiency. Compared to Dilithium’s rich theoretical security analysis results, the side-channel security of its physical implementations needs to be further explored. In 2021, Liu et al. proposed a two-stage randomness leakage attack against Dilithium, in which only one randomness bit with a probability <inline-formula xmlns:mml=http://www.w3.org/1998/Math/MathML xmlns:xlink=http://www.w3.org/1999/xlink> <tex-math notation=LaTeX>$> 0.5$ </tex-math></inline-formula> per signature is enough to recover the private key. However, they only carried out proof-of-concept experiments on “research-oriented” reference implementation of polynomial addition. Whether this method applies to complete real-world implementations of Dilithium is unknown. In this paper, we put this randomness leakage attack into real-world and recover the private key of unprotected and masked Dilithium on Arm Cortex-M4 processor using non-profiled power analysis attacks. Since randomness is introduced in the signing process, it is challenging to recover the randomness bit of Dilithium with high success rate in only one trace. Inspired by Liu et al., we propose a new non-profiled attack called Public Template Attack (PTA), a template-attack-like method that builds templates using public information. With PTA, we recover the randomness bit of unprotected and masked Dilithium with a success rate of 95% and 62% in one power trace, respectively. To demonstrate practicality, we perform practical power analysis attacks against different security levels of round 3 unprotected and masked Dilithium on STM32F405 microprocessor. Using 10,000 traces, the private key of unprotected Dilithium2 is recovered in 0.5 hours with an ordinary PC desktop. Our attack is 240 times faster than the state-of-the-art non-profiled attack. Moreover, the private key of masked Dilithium2 is recovered using 680,000 traces in 38 hours. To the best of our knowledge, we are the first to successfully attack masked Dilithium using non-profiled attacks." @default.
- W4311167566 created "2022-12-24" @default.
- W4311167566 creator A5026966444 @default.
- W4311167566 creator A5032928754 @default.
- W4311167566 creator A5053096377 @default.
- W4311167566 creator A5062094023 @default.
- W4311167566 creator A5063991302 @default.
- W4311167566 creator A5089419362 @default.
- W4311167566 date "2023-01-01" @default.
- W4311167566 modified "2023-10-14" @default.
- W4311167566 title "Practical Public Template Attacks on CRYSTALS-Dilithium With Randomness Leakages" @default.
- W4311167566 cites W1752434584 @default.
- W4311167566 cites W2168676717 @default.
- W4311167566 cites W2298330307 @default.
- W4311167566 cites W2740580365 @default.
- W4311167566 cites W2791664942 @default.
- W4311167566 cites W3012153794 @default.
- W4311167566 cites W3095245686 @default.
- W4311167566 cites W3115739041 @default.
- W4311167566 cites W3157250574 @default.
- W4311167566 cites W3215616495 @default.
- W4311167566 cites W4200446781 @default.
- W4311167566 cites W4206724325 @default.
- W4311167566 cites W4229637647 @default.
- W4311167566 cites W4232836212 @default.
- W4311167566 cites W4235846187 @default.
- W4311167566 cites W4238796697 @default.
- W4311167566 cites W49132692 @default.
- W4311167566 doi "https://doi.org/10.1109/tifs.2022.3215913" @default.
- W4311167566 hasPublicationYear "2023" @default.
- W4311167566 type Work @default.
- W4311167566 citedByCount "0" @default.
- W4311167566 crossrefType "journal-article" @default.
- W4311167566 hasAuthorship W4311167566A5026966444 @default.
- W4311167566 hasAuthorship W4311167566A5032928754 @default.
- W4311167566 hasAuthorship W4311167566A5053096377 @default.
- W4311167566 hasAuthorship W4311167566A5062094023 @default.
- W4311167566 hasAuthorship W4311167566A5063991302 @default.
- W4311167566 hasAuthorship W4311167566A5089419362 @default.
- W4311167566 hasConcept C105795698 @default.
- W4311167566 hasConcept C111219384 @default.
- W4311167566 hasConcept C11413529 @default.
- W4311167566 hasConcept C118629725 @default.
- W4311167566 hasConcept C121332964 @default.
- W4311167566 hasConcept C125112378 @default.
- W4311167566 hasConcept C145148216 @default.
- W4311167566 hasConcept C148730421 @default.
- W4311167566 hasConcept C178489894 @default.
- W4311167566 hasConcept C18017163 @default.
- W4311167566 hasConcept C181149355 @default.
- W4311167566 hasConcept C203062551 @default.
- W4311167566 hasConcept C204321447 @default.
- W4311167566 hasConcept C2775951159 @default.
- W4311167566 hasConcept C2779201187 @default.
- W4311167566 hasConcept C33923547 @default.
- W4311167566 hasConcept C38652104 @default.
- W4311167566 hasConcept C41008148 @default.
- W4311167566 hasConcept C49289754 @default.
- W4311167566 hasConcept C62520636 @default.
- W4311167566 hasConcept C6295992 @default.
- W4311167566 hasConcept C71743495 @default.
- W4311167566 hasConcept C80444323 @default.
- W4311167566 hasConceptScore W4311167566C105795698 @default.
- W4311167566 hasConceptScore W4311167566C111219384 @default.
- W4311167566 hasConceptScore W4311167566C11413529 @default.
- W4311167566 hasConceptScore W4311167566C118629725 @default.
- W4311167566 hasConceptScore W4311167566C121332964 @default.
- W4311167566 hasConceptScore W4311167566C125112378 @default.
- W4311167566 hasConceptScore W4311167566C145148216 @default.
- W4311167566 hasConceptScore W4311167566C148730421 @default.
- W4311167566 hasConceptScore W4311167566C178489894 @default.
- W4311167566 hasConceptScore W4311167566C18017163 @default.
- W4311167566 hasConceptScore W4311167566C181149355 @default.
- W4311167566 hasConceptScore W4311167566C203062551 @default.
- W4311167566 hasConceptScore W4311167566C204321447 @default.
- W4311167566 hasConceptScore W4311167566C2775951159 @default.
- W4311167566 hasConceptScore W4311167566C2779201187 @default.
- W4311167566 hasConceptScore W4311167566C33923547 @default.
- W4311167566 hasConceptScore W4311167566C38652104 @default.
- W4311167566 hasConceptScore W4311167566C41008148 @default.
- W4311167566 hasConceptScore W4311167566C49289754 @default.
- W4311167566 hasConceptScore W4311167566C62520636 @default.
- W4311167566 hasConceptScore W4311167566C6295992 @default.
- W4311167566 hasConceptScore W4311167566C71743495 @default.
- W4311167566 hasConceptScore W4311167566C80444323 @default.
- W4311167566 hasFunder F4320321001 @default.
- W4311167566 hasFunder F4320321543 @default.
- W4311167566 hasFunder F4320336602 @default.
- W4311167566 hasLocation W43111675661 @default.
- W4311167566 hasOpenAccess W4311167566 @default.
- W4311167566 hasPrimaryLocation W43111675661 @default.
- W4311167566 hasRelatedWork W1488691348 @default.
- W4311167566 hasRelatedWork W1649773923 @default.
- W4311167566 hasRelatedWork W2148684293 @default.
- W4311167566 hasRelatedWork W2170261837 @default.
- W4311167566 hasRelatedWork W2296608643 @default.
- W4311167566 hasRelatedWork W2575400547 @default.
- W4311167566 hasRelatedWork W4282541326 @default.