In 2012, Ding, Xie and Lin designed a key exchange protocol based on Ring-LWE problem, called the DXL key exchange protocol, which can be seen as an extended version of the Diffie-Hellman key exchange. In this protocol, Ding et al. achieved key exchange between the communicating parties according to the associativity of matrix multiplications, that is, \((x^T\cdot \boldsymbol{A})\cdot y = x^T\cdot (\boldsymbol{A}\cdot y)\) , where x, y are column vectors and \(\boldsymbol{A}\) is a square matrix. However, the DXL key exchange protocol cannot resist key reuse attacks. At ESORICS 2022, Qin et al. proposed a method in which an adversary recovers the reused private key after forging the public keys 29 times. From the adversary’s perspective, the adversary expects to recover the reused private key by forging fewer public keys. In order to further reduce the number of forged public keys, we propose a new attack method, which combines signal leakage attacks with depth-first search methods. Compared with the state-of-the-art result, the number of forged public keys is reduced from 29 to 10. In other words, if the number of reuses exceeds 10, the private key will be recovered. Finally, we validate the effectiveness of the results through experiments.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Improved Signal Leakage Attack Against DXL Key Exchange Protocol

  • Zhiwei Li,
  • Jun Xu,
  • Lei Hu

摘要

In 2012, Ding, Xie and Lin designed a key exchange protocol based on Ring-LWE problem, called the DXL key exchange protocol, which can be seen as an extended version of the Diffie-Hellman key exchange. In this protocol, Ding et al. achieved key exchange between the communicating parties according to the associativity of matrix multiplications, that is, \((x^T\cdot \boldsymbol{A})\cdot y = x^T\cdot (\boldsymbol{A}\cdot y)\) , where x, y are column vectors and \(\boldsymbol{A}\) is a square matrix. However, the DXL key exchange protocol cannot resist key reuse attacks. At ESORICS 2022, Qin et al. proposed a method in which an adversary recovers the reused private key after forging the public keys 29 times. From the adversary’s perspective, the adversary expects to recover the reused private key by forging fewer public keys. In order to further reduce the number of forged public keys, we propose a new attack method, which combines signal leakage attacks with depth-first search methods. Compared with the state-of-the-art result, the number of forged public keys is reduced from 29 to 10. In other words, if the number of reuses exceeds 10, the private key will be recovered. Finally, we validate the effectiveness of the results through experiments.