Next Article in Journal
Prior Distribution and Entropy in Computer Adaptive Testing Ability Estimation through MAP or EAP
Next Article in Special Issue
Identity-Based Proxy Signature with Message Recovery over NTRU Lattice
Previous Article in Journal
Why Shape Coding? Asymptotic Analysis of the Entropy Rate for Digital Images
Previous Article in Special Issue
Physical-Layer Security, Quantum Key Distribution, and Post-Quantum Cryptography
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Solving HNP with One Bit Leakage: An Asymmetric Lattice Sieving Algorithm

1
State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou 450001, China
2
Henan Key Laboratory of Network Cryptography Technology, Zhengzhou 450001, China
*
Author to whom correspondence should be addressed.
Entropy 2023, 25(1), 49; https://doi.org/10.3390/e25010049
Submission received: 1 October 2022 / Revised: 18 December 2022 / Accepted: 22 December 2022 / Published: 27 December 2022

Abstract

The Hidden Number Problem (HNP) was introduced by Boneh and Venkastesan to analyze the bit-security of the Diffie–Hellman key exchange scheme. It is often used to mount a side-channel attack on (EC)DSA. The hardness of HNP is mainly determined by the number of nonce leakage bits and the size of the modulus. With the development of lattice reduction algorithms and lattice sieving, the range of practically vulnerable parameters are extended further. However, 1-bit leakage is still believed to be challenging for lattice attacks. In this paper, we proposed an asymmetric lattice sieving algorithm that can solve HNP with 1-bit leakage. The algorithm is composed of a BKZ pre-processing and a sieving step. The novel part of our lattice sieving algorithm is that the lattice used in these two steps have different dimensions. In particular, in the BKZ step we use more samples to derive a better lattice basis, while we just use truncated lattice basis for the lattice sieving step. To verify our algorithm, we use it to solve HNP with 1-bit leakage and 116-bit modulus.
Keywords: HNP; BKZ reduction; sieving; side-channel attack; ECDSA HNP; BKZ reduction; sieving; side-channel attack; ECDSA

Share and Cite

MDPI and ACS Style

Shi, W.; Jiang, H.; Ma, Z. Solving HNP with One Bit Leakage: An Asymmetric Lattice Sieving Algorithm. Entropy 2023, 25, 49. https://doi.org/10.3390/e25010049

AMA Style

Shi W, Jiang H, Ma Z. Solving HNP with One Bit Leakage: An Asymmetric Lattice Sieving Algorithm. Entropy. 2023; 25(1):49. https://doi.org/10.3390/e25010049

Chicago/Turabian Style

Shi, Wenhao, Haodong Jiang, and Zhi Ma. 2023. "Solving HNP with One Bit Leakage: An Asymmetric Lattice Sieving Algorithm" Entropy 25, no. 1: 49. https://doi.org/10.3390/e25010049

APA Style

Shi, W., Jiang, H., & Ma, Z. (2023). Solving HNP with One Bit Leakage: An Asymmetric Lattice Sieving Algorithm. Entropy, 25(1), 49. https://doi.org/10.3390/e25010049

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop