2 Secure Implementation of Lattice-Based Encryption Schemes
29
Fig. 2.1 CCA2-secured decryption
˜ r
2 ∈ Rq
˜ r
2 ∈ Rq
˜
c1 ∈ Rq
˜
c1 ∈ Rq
c2 ∈ Rq
×
×
+
INTT
INTT
m
cpa ∈ {0, 1}
256
m
cpa ∈ {0, 1}
256
z
∈ Rq
z
∈ Rq
Fig. 2.2 Proposed masking scheme for ring-LWE decryption
In the following, we analyze the first-order security of each module separately
in the common probing model [28]. To this end, we show that an attacker, who
can probe one intermediate variable of the computation, cannot derive any secret
information. This notion is equivalent to showing that each intermediate variable
follows a distribution independent of any sensitive variable, i.e., the secret key r 2 .
For one probe it is indeed sufficient to analyze each module separately, if the input
and output distributions between the modules are consistent. Therefore, 1-probing
security with correct input distributions for each module implies 1-probing security
of the complete masked CCA2-secured decryption. However, for more probes (i.e.,
2-probing security) this approach would not cover every possible attack vector and
a more sophisticated analysis has to be utilized [7].
Ring-LWE Decryption As mentioned in Sect. 2.1, the masking schemes of the
ring-LWE decryption from works like [43, 46] and [45] suffer from a higher failure
probability and slower performance. Therefore, we present a new approach which
avoids the aforementioned problems and still provides side-channel protection.
Figure 2.2 shows the basic structure of our masked ring-LWE decryption. For
the initial multiplications, additions, and INTTs we rely on a simple randomized sharing of r 2 = r
2 + r
2 with r
2
$
←R q similar to [43, 46]. Given the
Précédent

- 37/268

Suivant