Paper 2025/1629

Solving Concealed ILWE and its Application for Breaking Masked Dilithium

Simon Damm, Ruhr University Bochum
Asja Fischer, Ruhr University Bochum
Alexander May, Ruhr University Bochum
Soundes Marzougui, Deutsches Elektronen-Synchrotron
Leander Schwarz, Technical University of Berlin
Henning Seidler, Technical University of Berlin
Jean-Pierre Seifert, Technical University of Berlin
Jonas Thietke, Ruhr University Bochum
Vincent Quentin Ulitzsch, Technical University of Berlin
Abstract

Lattice-based signatures like Dilithium (ML-DSA) prove knowledge of a secret key $s \in \mathbb{Z}_n$ by using Integer LWE (ILWE) samples $z = \langle \vec c, \vec s \rangle +y $, for some known hash value $c \in \mathbb{Z}_n$ of the message and unknown error $y$. Rejection sampling guarantees zero-knowledge, which makes the ILWE problem, that asks to recover s from many z’s, unsolvable. Side-channel attacks partially recover y, thereby obtaining more informative samples resulting in a—potentially tractable—ILWE problem. The standard method to solve the resulting problem is Ordinary Least Squares (OLS), which requires independence of $y$ from $\langle c, s \rangle$ —an assumption that is violated by zero-knowledge samples. We present efficient algorithms for a variant of the ILWE problem that was not addressed in prior work, which we coin Concealed ILWE (CILWE). In this variant, only a fraction of the ILWE samples is zero-knowledge. We call this fraction the concealment rate. This ILWE variant naturally occurs in side-channel attacks on lattice-based signatures. A case in point are profiling side-channel attacks on Dilithium implementations that classify whether $y = 0$. This gives rise to either zero-error ILWE samples $z = \langle c, s \rangle$ with $y = 0$ (in case of correct classification), or ordinary zero-knowledge ILWE samples (in case of misclassification). As we show, OLS is not practical for CILWE instances, as it requires a prohibitively large amount of samples for even small (under 10%) concealment rates. A known integer linear programming-based approach can solve some CILWE instances, but suffers from two short-comings. First, it lacks provable efficiency guarantees, as ILP is NP-hard in the worst case. Second, it does not utilize small, independent error $y$ samples, that could occur in addition to zero-knowledge samples. We introduce two statistical regression methods to cryptanalysis, Huber and Cauchy regression. They are both efficient and can handle instances with all three types of samples. At the same time, they are capable of handling high concealment rates, up to 90% in practical experiments. While Huber regression comes with theoretically appealing correctness guarantees, Cauchy regression performs best in practice. We use this efficacy to execute a novel profiling attack against a masked Dilithium implementation. The resulting ILWE instances suffer from both concealment and small, independent errors. As such, neither OLS nor ILP can recover the secret key. Cauchy regression, however, allows us to recover the secret key in under two minutes for all NIST security levels.

Note: This is the full version of the Asiacrypt 2025 paper (including appendix).

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
A major revision of an IACR publication in ASIACRYPT 2025
Keywords
LWEConcealed LWEInteger Learning With ErrorsDilithiumML-DSASide-ChannelFiat-Shamir With Aborts
Contact author(s)
simon damm @ rub de
asja fischer @ rub de
alex may @ rub de
soundes marzougui @ desy de
leander schwarz @ campus tu-berlin de
henning seidler @ sect tu-berlin de
jean-pierre seifert @ tu-berlin de
jonas thietke @ rub de
vincent @ sect tu-berlin de
History
2025-09-15: revised
2025-09-10: received
See all versions
Short URL
https://ia.cr/2025/1629
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1629,
      author = {Simon Damm and Asja Fischer and Alexander May and Soundes Marzougui and Leander Schwarz and Henning Seidler and Jean-Pierre Seifert and Jonas Thietke and Vincent Quentin Ulitzsch},
      title = {Solving Concealed {ILWE} and its Application for Breaking Masked Dilithium},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1629},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1629}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.