Paper 2024/690

LPN-based Attacks in the White-box Setting

Alex Charlès, University of Luxembourg
Aleksei Udovenko, University of Luxembourg
Abstract

In white-box cryptography, early protection techniques have fallen to the automated Differential Computation Analysis attack (DCA), leading to new countermeasures and attacks. A standard side-channel countermeasure, Ishai-Sahai-Wagner's masking scheme (ISW, CRYPTO 2003) prevents Differential Computation Analysis but was shown to be vulnerable in the white-box context to the Linear Decoding Analysis attack (LDA). However, recent quadratic and cubic masking schemes by Biryukov-Udovenko (ASIACRYPT 2018) and Seker-Eisenbarth-Liskiewicz (CHES 2021) prevent LDA and force to use its higher-degree generalizations with much higher complexity. In this work, we study the relationship between the security of these and related schemes to the Learning Parity with Noise (LPN) problem and propose a new automated attack by applying an LPN-solving algorithm to white-box implementations. The attack effectively exploits strong linear approximations of the masking scheme and thus can be seen as a combination of the DCA and LDA techniques. Different from previous attacks, the complexity of this algorithm depends on the approximation error, henceforth allowing new practical attacks on masking schemes that previously resisted automated analysis. We demonstrate it theoretically and experimentally, exposing multiple cases where the LPN-based method significantly outperforms LDA and DCA methods, including their higher-order variants. This work applies the LPN problem beyond its usual post-quantum cryptography boundary, strengthening its interest in the cryptographic community, while expanding the range of automated attacks by presenting a new direction for breaking masking schemes in the white-box model.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published by the IACR in TCHES 2023
DOI
10.46586/tches.v2023.i4.318-343
Keywords
White-box CryptographyCryptanalysisLPNDCALDAMaskingDummy Shuffling
Contact author(s)
alex charles205 @ gmail com
aleksei @ affine group
History
2024-05-06: revised
2024-05-06: received
See all versions
Short URL
https://ia.cr/2024/690
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/690,
      author = {Alex Charlès and Aleksei Udovenko},
      title = {LPN-based Attacks in the White-box Setting},
      howpublished = {Cryptology ePrint Archive, Paper 2024/690},
      year = {2024},
      doi = {10.46586/tches.v2023.i4.318-343},
      note = {\url{https://eprint.iacr.org/2024/690}},
      url = {https://eprint.iacr.org/2024/690}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.