慣性聚合 高效追讀感興趣之博客、新聞、科技資訊
閱原文 以慣性聚合開啟

推薦訂閱源

博客园 - 司徒正美
V
V2EX
T
Tailwind CSS Blog
有赞技术团队
有赞技术团队
aimingoo的专栏
aimingoo的专栏
Apple Machine Learning Research
Apple Machine Learning Research
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
A
About on SuperTechFans
月光博客
月光博客
T
The Blog of Author Tim Ferriss
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI

Cryptology ePrint Archive

Dynamic Group Time-based One-time Passwords MBU: Scalable and Constant-Round Evaluation of Non-linear Functions in Standard MPC Setting CEDAR: A Compact and Efficient Decoder Architecture for RS-RM Code in HQC LEAH: Lightweight and Efficient Hardware Accelerator for Code-based PQC Scheme HQC The Sum-Check Protocol over the Monomial Basis, and Other Optimizations How to Authenticate a Non-Deterministic Computation Fully Adaptive Threshold Blind Signature Without AGM Additive FFTs for HQC on ARM Cortex-M4, Revisited SPoCK: Sequential Proofs of Complete Knowledge Blind Verifiable Delay Functions Compact Fully Asynchronous Updatable Public Key Encryption Scheme from Hamming Quasi-Cyclic Cryptosystem CLAASP-MP: An Automated MILP Framework for Monomial Prediction Assessing Geometric Security of AES Neural Realizations: Linear-Time Key Recovery via Neural Leakage Explicit Bounds on the Existence Probability of Random Multivariate Quadratic Systems over Finite Fields Faster Logical Operations from Discrete CKKS SecDTD: Dynamic Token Drop for Secure Transformers Inference Towards Zero Rotation and Beyond: Architecting Neural Networks for Fast Secure Inference with Homomorphic Encryption Code-based Scalable Collaborative SNARKs MAGNET: MAsked Gaussian Now Efficient and Table-less Automated formal analysis of Signal’s Double Ratchet: attacks, fixes and security proofs Bitsliced Segment-Based Search Technique for Low-Depth and Hardware-Efficient S-Box Circuits The Cost of Fluidity: Communication Complexity Trade-offs in Fluid MPC Decomposition of Large Look-Up Tables for Fast Homomorphic Evaluation Hint-Free Multi-Signatures (Mis)using the Lattice Isomorphism Problem. Cryptanalysis of the double-LIP and Construction of LIP-Based Blind Signatures Improving LatticeFold+ with ℓ2-norm Checks ABRA-CAPA-DABRA: Full break of CAPA Polynomial-Time Cryptanalytic Extraction of Graph Neural Networks in the Hard-Label Setting Zero-Knowledge Proof of Progress: Secure Multi-Phase Capture-the-Flag Competitions Scalable Registration-Based Encryption from Lattices ISE-supported erasure of residual shares Chorus: Secret Recovery with Ephemeral Client Committees $\mathsf{Veloz}$: Efficient and Flexible Distribution Framework for Code-Based Polynomial Commitment Scheme How to construct even faster and indifferentiable hash functions from random permutations Public Key Encryption from High-Corruption Constraint Satisfaction Problems Drop-In Masked Modular Reduction for ML-DSA: Cutting Side-Channel Cost in the Root-of-Trust Optimizing and Implementing Threshold MAYO Improved Cryptanalysis of the Permuted Kernel Problem with Applications to PERK v2.2.0, SUSHSYFISH and PKP-DSS Cross-Paradigm Models of Restricted Syndrome Decoding with Application to CROSS Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies
移减失当:审察生产ML-DSA实现中减法之置
Sunwoo Lee · 2026-05-22 · via Cryptology ePrint Archive

论文 2026/1032

移除约简失当:审查生产ML-DSA实现中约简之置放

李勋韩国能源技术研究院(KENTECH)

尹胜勋韩国能源技术研究院(KENTECH)

摘要

量子后签名术于生产密码库中正确实现,虽经标准化,犹存难处。ML-DSA之实,赖于基于NTT之多项式运算,兼用惰性Montgomery约减,然省略约减,或为有效之优化,或为潜藏之算术缺陷。实践中,为求效能、内存或嵌入式部署之故,约减调用常被删去,然所需正确条件乃跨程序:某处看似冗余,于后继InvNTT阶段或为负重之关键。本文献中,吾等提出一种凭证书之审计方法,用于生产ML-DSA实现中约减之置放。自保守之pq-crystals拓扑始,吾等之分析,将系数界限沿全签名路径传递,将约减之位分类为冗余或必要。关键之技术要素,乃对稀疏挑战乘积之精确整数恢复结果,此结果将InvNTT后之界限自(-Q,Q)紧缩为[-τη, τη],并区分稀疏乘积路径上之安全省略与负重之密集乘积位。将此方法施于八种ML-DSA库,吾等发现wolfSSL之内存优化WOLFSSL-DILITHIUM-SMALL路径中,此前未报之缺陷,其省略矩阵乘法后之约减,致溢出、非合规算术及签名失败,然犹能通过该实现现有之KAT测试。此位分类有可重演之SMT-LIB2证书为据,核心整数界限之引理,于无公理之Coq开发中交叉检验。

《BibTeX》

@misc{cryptoeprint:2026/1032,
      author = {Sunwoo Lee and Hyuk Lim and Seunghyun Yoon},
      title = {When Removing Reductions Goes Wrong: Auditing Reduction Placement in Production {ML}-{DSA} Implementations},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1032},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1032}
}