发表机构
Ironproof(Ironproof)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究通过实证分析发现ML-DSA(FIPS 204)签名的提示权重依赖于密钥,其与密钥的t0低阶部分范数相关,可作为弱统计指纹,权重受限签名能削弱该密钥间差异。
AI 中文摘要
每个ML-DSA(FIPS 204)签名都带有一个公开提示向量h。我们发现,每个提示多项式h_k的汉明权重依赖于签名密钥:一阶近似下,它衡量的是(t0)_k的欧几里得范数,其中t0是密钥生成过程中从公钥中剔除的t的低阶部分。一个闭式模型可预测每个密钥的平均权重,其皮尔逊相关系数r介于0.95至0.98之间;在考虑范数后,我们未检测到超出采样噪声的密钥相关信号。我们针对参考C实现进行了测量,每个参数集使用200个密钥,每个密钥对应2000个签名。单因素方差分析拒绝了ML-DSA-44、ML-DSA-65和ML-DSA-87的总提示权重具有密钥独立性的假设(F值分别为30.1、10.3、11.1)。该效应较弱:密钥可解释总权重方差的0.5%至1.5%。单个签名可通过总权重以1.1至1.3倍于随机猜测的准确率识别其对应的200个密钥中的一个,通过每个多项式的权重向量则可达到1.5至1.8倍的准确率。在显著性水平为0.001的单侧检验中,每个密钥约需1300至3700个签名即可以二分之一的概率区分两个典型密钥。提示权重不会危及签名密钥。Dilithium的设计者并未将t0视为秘密,且已知t0可从签名中恢复。然而,提示权重是一种弱统计指纹:在拥有足够多签名的情况下,无需公钥即可用于测试这些签名是否来自同一密钥。权重受限签名是一种向后兼容的过滤器,我们未分析其对安全性论证的影响,它可消除总权重中86%至91%的密钥间差异,但会在很大程度上保留每个多项式的通道。
英文摘要
Every ML-DSA (FIPS 204) signature carries a public hint vector h. We find that the Hamming weight of each hint polynomial h_k depends on the signing key: to first order it measures the Euclidean norm of (t0)_k, the low-order part of t that key generation leaves out of the public key. A closed-form model predicts the per-key mean weight with Pearson r between 0.95 and 0.98; once the norm is accounted for, we detect no key-dependent signal above sampling noise. We measure the effect on the reference C implementation, with 200 keys and 2,000 signatures per key for each parameter set. A one-way ANOVA rejects key-independence of the total hint weight for ML-DSA-44, ML-DSA-65 and ML-DSA-87 (F = 30.1, 10.3, 11.1). The effect is weak: the key explains 0.5% to 1.5% of the variance of the total weight. A single signature identifies its key among 200 with 1.1 to 1.3 times chance accuracy from the total weight, and 1.5 to 1.8 times from the per-polynomial weight vector. A one-sided test at significance 0.001 separates two typical keys with probability one half after about 1,300 to 3,700 signatures per key. The hint weight does not endanger the signing key. The Dilithium designers do not treat t0 as secret, and t0 is known to be recoverable from signatures. The hint weight is, however, a weak statistical fingerprint: with enough signatures, it can be used to test whether they come from a common key, without the public key. Bounded-weight signing, a backward-compatible filter whose effect on the security argument we did not analyze, removes 86-91% of the between-key spread of the total weight but leaves the per-polynomial channel largely intact.
Comments9 pages, 4 tables