发表机构
INRIA; École Polytechnique; LIX, CNRS UMR 7161(法国国家信息与自动化研究所; 巴黎综合理工学院; LIX实验室,法国国家科学研究中心)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究将基于线性精确修复方案的泄露攻击从单一秘密扩展到多个线性相关秘密,支持任意线性计算,扩大了易受攻击的码参数范围,并提出了更现实的攻击模型。
AI 中文摘要
针对秘密共享方案的泄露攻击利用关于各个份额的部分信息来恢复底层秘密。在编码理论中,线性精确修复方案(LERSs)使得在码率足够低的情况下,能够从其余符号中获取的少量信息恢复一个码字符号。这可以解释为从份额的部分信息(即子域符号)中恢复秘密。最近,有人提出了一种基于子域子码的随机化构造,用于构建针对基于一般线性码的Massey秘密共享方案的LERS派生泄露攻击。我们将此框架扩展到多个共享秘密,这些秘密对应的份额通过线性计算相关联,并且泄露也允许发生在计算结果上。更精确地说,我们考虑N个秘密,其中K ≤ N个是线性独立的输入值,其余N-K个秘密由这些输入上的线性计算确定。我们分析了利用这种结构的LERS派生泄露的存在性。我们首先研究加法的情况,然后将我们的构造推广到任意线性计算。我们的分析适用于长度为n+1、维度为k(在F_{q^m}上,且k ≤ N n/(Km))的一般线性码,并支持任意线性计算,而之前的子域子码构造仅适用于k ≤ n/m - 1。因此,利用线性关系使得基于LERS的泄露能够扩展易受此类攻击的码参数范围。最后,模拟表明,对于某些线性关系,可以使用相同的泄露函数,从而产生更现实的攻击模型。
英文摘要
Leakage attacks on secret sharing schemes exploit partial information about individual shares to recover the underlying secret. In coding theory, linear exact repair schemes (LERSs) enable the recovery of one codeword symbol from a small amount of information obtained from the remaining symbols, provided that the code has sufficiently low rate. This can be interpreted as recovering the secret from partial information, namely subfield symbols, of the shares. Recently, a randomized construction based on subfield subcodes was proposed for constructing LERS-derived leakage attacks against Massey secret sharing schemes based on general linear codes. We extend this framework to multiple shared secrets whose corresponding shares are related through linear computations, with leakage also allowed on the computation outcomes. More precisely, we consider N secrets, of which K $\le$ N are linearly independent input values and the remaining N -K secrets are determined by linear computations on these inputs. We analyse the existence of LERS-derived leakage that exploits this structure. We first study the case of addition and then generalize our construction to arbitrary linear computations. Our analysis applies to general linear codes of length n+1 and dimension k over F\_{q^m} with k $\le$ N n/(Km), and supports arbitrary linear computations, whereas the previous subfield subcode construction only applies to k $\le$ n/m -1. Consequently, exploiting the linear relations enables LERS based leakage which extend the range of code parameters vulnerable to such attacks. Finally, identical leakage functions can arise for certain linear relations, making this a more realistic yet still potentially powerful attack model. Finally, simulations indicate that identical leakage functions can be used for certain linear relations, yielding a more realistic attack model.