AI 中文总结
针对ML-DSA随机性泄漏攻击中求解器作用探索不足的问题,提出统一框架评估不同恢复求解器,涵盖多种ILWE实例及求解器类型,实验表明求解器对密钥恢复效率影响大,为相关攻击分析提供系统评估和新基准。
AI 中文摘要
ML-DSA是NIST标准化的基于格的签名方案,依赖签名随机性和拒绝采样确保签名与密钥统计独立。但实际实现可能泄漏随机性信息,导致公钥签名转化为ILWE类型问题,引发密钥泄露风险。随机性泄漏攻击可分为两阶段密钥恢复过程,现有工作主要关注第一阶段,第二阶段求解器作用探索不足。本文提出统一框架系统评估不同恢复求解器,涵盖三种ILWE实例及三类求解器。实验表明求解器对密钥恢复效率影响显著,如先验感知离散推理在FS-ILWE上比基线减少一到两个数量级的信息关系数量。本文为随机性泄漏攻击中不同求解器提供系统评估,为ML-DSA未来分析提供新基准。
英文摘要
ML-DSA is a representative lattice-based signature scheme standardized by NIST. It relies on signing randomness and rejection sampling to ensure that released signatures are statistically independent of the secret key. Practical implementations, however, may leak partial information about this randomness, and such leakage can transform public signatures into ILWE-type problems, resulting in secret key disclosure risks. Such randomness leakage attack can be formulated as a two-stage key-recovery procedure, in which leaked partial information and public signatures are first transformed into an ILWE-family instance, and then a recovery solver is applied to recover the secret key. Existing work has mainly focused on the first stage by constructing such instances under different leakage models. By contrast, the role of solver in the subsequent instance-solving stage remains under-explored, and existing attacks often rely on ad-hoc model-specific solvers. To address this gap, we propose a unified framework to systematically evaluate different recovery solvers on leakage-derived ILWE-family instances. The framework covers three ILWE instances, including the ordinary ILWE, Fiat-Shamir ILWE (FS-ILWE) and Concealed ILWE (CILWE) under different scenarios. Within our framework, we explore three classes of solvers. Our experiments show that the solver has a significant impact on the secret-key recovery efficiency. In particular, on FS-ILWE, prior-aware discrete-inference reduces the number of informative relations by one to two orders of magnitude compared to the baselines: Compared with OLS, BP constitutes a reduction by a factor of 15.4x-64.9x in noise-free settings, and by a factor of 10.5x-73.9x in noisy settings. Overall, this work provides a systematic evaluation on different solvers in randomness leakage attacks, and presents new benchmarks for future analysis on ML-DSA.