In response to the potential threat posed by quantum computers to conventional public-key cryptosystems, Post-Quantum Cryptography (PQC) has emerged. As of today, CRYSTALS-Dilithium has been standardized by NIST and renamed ML-DSA. In Dilithium, the random number plays a crucial role in shielding the private key, making its security vital. This paper identifies a potential vulnerability in the random number generation process. We apply an improved fault attack to both unprotected and masked implementations of SHAKE256, which is used to generate the seed for the random number. Our attack method requires only two faulty signatures to fully recover the private key. For the random number generation function, we propose two novel attack methods to recover the private key. Existing attack methods for the random number generally assume it is initialized to 0. In contrast, One of our methods does not rely on this assumption, making it more practically significant. Our findings show that the attack methods are applicable to both deterministic and hedged versions of Dilithium. In practical attacks on the unprotected implementation of Dilithium, we achieve a success rate of up to 80.4%, while the highest success rate for attacks on the masked version is 48.9%.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Breaking the Shield: Novel Fault Attacks on CRYSTALS-Dilithium

  • Dixiao Du,
  • Yuejun Liu,
  • Yiwen Gao,
  • Jingdian Ming,
  • Hao Yuan,
  • Yongbin Zhou

摘要

In response to the potential threat posed by quantum computers to conventional public-key cryptosystems, Post-Quantum Cryptography (PQC) has emerged. As of today, CRYSTALS-Dilithium has been standardized by NIST and renamed ML-DSA. In Dilithium, the random number plays a crucial role in shielding the private key, making its security vital. This paper identifies a potential vulnerability in the random number generation process. We apply an improved fault attack to both unprotected and masked implementations of SHAKE256, which is used to generate the seed for the random number. Our attack method requires only two faulty signatures to fully recover the private key. For the random number generation function, we propose two novel attack methods to recover the private key. Existing attack methods for the random number generally assume it is initialized to 0. In contrast, One of our methods does not rely on this assumption, making it more practically significant. Our findings show that the attack methods are applicable to both deterministic and hedged versions of Dilithium. In practical attacks on the unprotected implementation of Dilithium, we achieve a success rate of up to 80.4%, while the highest success rate for attacks on the masked version is 48.9%.