Security Analysis of Integer Learning with Errors with Rejection Sampling
Kyle Yates, Antsa Pierrottet, Abdullah Al Mamun, Ryann Cartor, Mashrur Chowdhury, Shuhong Gao

TL;DR
This paper investigates the effectiveness of a linear algebra-based attack on small ILWE instances used in digital signatures like CRYSTALS-Dilithium, combining theoretical analysis and experiments to assess security.
Contribution
It introduces novel simulation techniques and directly applies the attack to real-world signature schemes, providing new insights into their security against ILWE-based attacks.
Findings
The attack is less effective on small ILWE instances in practical schemes.
Experimental results support the security of ILWE-based signatures.
The study offers new methods for simulating ILWE attacks efficiently.
Abstract
At ASIACRYPT 2018, a digital attack based on linear least squares was introduced for a variant of the learning with errors (LWE) problem which omits modular reduction known as the integer learning with errors problem (ILWE). In this paper, we present a theoretical and experimental study of the effectiveness of the attack when applied directly to small parameter ILWE instances found in popular digital signature schemes such as CRYSTALS-Dilithium which utilize rejection sampling. Unlike other studies which form ILWE instances based on additional information obtained from side-channel attacks, we take a more direct approach to the problem by constructing our ILWE instance from only the obtained signatures. We outline and introduce novel techniques in our simulation designs such as modular polynomial arithmetic via matrices in , as well as algorithms for handling large sample…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPolynomial and algebraic computation · Cryptography and Data Security · Cryptography and Residue Arithmetic
