Fault-Injection Attacks Against NIST’s Post-Quantum Cryptography Round 3 KEM Candidates

Keita Xagawa, Akira Ito, Rei Ueno, Junko Takahashi, Naofumi Homma

研究成果: 書籍の章/レポート/Proceedings会議への寄与査読

32 被引用数 (Scopus)

抄録

We investigate all NIST PQC Round 3 KEM candidates from the viewpoint of fault-injection attacks: Classic McEliece, Kyber, NTRU, Saber, BIKE, FrodoKEM, HQC, NTRU Prime, and SIKE. All KEM schemes use variants of the Fujisaki-Okamoto transformation, so the equality test with re-encryption in decapsulation is critical. We survey effective key-recovery attacks when we can skip the equality test. We found the existing key-recovery attacks against Kyber, NTRU, Saber, FrodoKEM, HQC, one of two KEM schemes in NTRU Prime, and SIKE. We propose a new key-recovery attack against the other KEM scheme in NTRU Prime. We also report an attack against BIKE that leads to leakage of information of secret keys. The open-source pqm4 library contains all KEM schemes except Classic McEliece and HQC. We show that giving a single instruction-skipping fault in the decapsulation processes leads to skipping the equality test virtually for Kyber, NTRU, Saber, BIKE, and SIKE. We also report the experimental attacks against them. We also report the implementation of NTRU Prime allows chosen-ciphertext attacks freely and the timing side-channel of FrodoKEM reported in Guo, Johansson, and Nilsson (CRYPTO 2020) remains, while there are no such bugs in their NIST PQC Round 3 submissions.

本文言語英語
ホスト出版物のタイトルAdvances in Cryptology – ASIACRYPT 2021 - 27th International Conference on the Theory and Application of Cryptology and Information Security, Proceedings, Part 2
編集者Mehdi Tibouchi, Huaxiong Wang
出版社Springer Science and Business Media Deutschland GmbH
ページ33-61
ページ数29
ISBN(印刷版)9783030920746
DOI
出版ステータス出版済み - 2021
イベント27th International Conference on Theory and Application of Cryptology and Information Security, ASIACRYPT 2021 - Virtual, Online
継続期間: 2021 12月 62021 12月 10

出版物シリーズ

名前Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
13091 LNCS
ISSN(印刷版)0302-9743
ISSN(電子版)1611-3349

会議

会議27th International Conference on Theory and Application of Cryptology and Information Security, ASIACRYPT 2021
CityVirtual, Online
Period21/12/621/12/10

フィンガープリント

「Fault-Injection Attacks Against NIST’s Post-Quantum Cryptography Round 3 KEM Candidates」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル