Cold Boot Attacks on Ring & Module-LWE Under the NTT
Martin R. Albrecht, Amit Deo, Kenneth G. Paterson
Royal Holloway, University of London
September 12, 2018
1 / 30
Cold Boot Attacks on Ring & Module-LWE Under the NTT Martin R. - - PowerPoint PPT Presentation
Cold Boot Attacks on Ring & Module-LWE Under the NTT Martin R. Albrecht, Amit Deo, Kenneth G. Paterson Royal Holloway, University of London September 12, 2018 1 / 30 Cold boot attack scenario Originally investigated by [HSHCPCFAF09]
1 / 30
2 / 30
3 / 30
4 / 30
4 / 30
4 / 30
◮ Standard bit flips (towards memory ground state) rate ρ0 ◮ Retrograde bit flips (away from memory ground state) rate
5 / 30
◮ AES-128: (0.7,0) bit-flip rate in 1 sec on average [KY10] ◮ AES-256: (0.65,0) bit-flip rate in 90 secs on average [Tso09]
6 / 30
7 / 30
7 / 30
◮ SecKey = s ∈ Rq
◮ SecKey = s ∈ Rd
q
8 / 30
◮ SecKey = s ∈ Rq
◮ SecKey = s ∈ Rd
q
8 / 30
9 / 30
10 / 30
10 / 30
11 / 30
12 / 30
13 / 30
14 / 30
15 / 30
15 / 30
16 / 30
16 / 30
16 / 30
16 / 30
1Compare to
κ
17 / 30
18 / 30
18 / 30
18 / 30
18 / 30
18 / 30
19 / 30
20 / 30
20 / 30
20 / 30
21 / 30
21 / 30
22 / 30
22 / 30
23 / 30
24 / 30
25 / 30
26 / 30
26 / 30
2Code available in paper 3https://github.com/fplll/fplll 27 / 30
28 / 30
29 / 30
30 / 30