2023
DOI: 10.1007/978-3-031-31371-4_4
|View full text |Cite
|
Sign up to set email alerts
|

A Holistic Approach Towards Side-Channel Secure Fixed-Weight Polynomial Sampling

Abstract: The sampling of polynomials with fixed weight is a procedure required by round-4 Key Encapsulation Mechanisms (KEMs) for Post-Quantum Cryptography (PQC) standardization (BIKE, HQC, McEliece) as well as NTRU, Streamlined NTRU Prime, and NTRU LPRrime. Recent attacks have shown in this context that side-channel leakage of sampling methods can be exploited for key recoveries. While countermeasures regarding such timing attacks have already been presented, still, there is no comprehensive work covering solutions th… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
3
1

Relationship

0
4

Authors

Journals

citations
Cited by 4 publications
(1 citation statement)
references
References 14 publications
0
1
0
Order By: Relevance
“…From a side-channel point of view, multiplying the public challenge polynomial c with the secret key vector s 1 , followed by an addition to the nonce y, is the most critical operation for signature generation in Dilithium [SLKG23]. We highlight that the challenge polynomial c is also public for rejected signature candidates [KLRBG23] and is sparse and ternary. The coefficients of the secret key polynomial vector s 1 are uniformly random with a small bound (i.e., there are only five or nine possible values).…”
Section: Applicability To Dilithiummentioning
confidence: 99%
“…From a side-channel point of view, multiplying the public challenge polynomial c with the secret key vector s 1 , followed by an addition to the nonce y, is the most critical operation for signature generation in Dilithium [SLKG23]. We highlight that the challenge polynomial c is also public for rejected signature candidates [KLRBG23] and is sparse and ternary. The coefficients of the secret key polynomial vector s 1 are uniformly random with a small bound (i.e., there are only five or nine possible values).…”
Section: Applicability To Dilithiummentioning
confidence: 99%