惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Tailwind CSS Blog
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
N
Netflix TechBlog - Medium
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
The Blog of Author Tim Ferriss
D
Docker
博客园 - 聂微东
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
L
LangChain Blog
量子位
宝玉的分享
宝玉的分享
博客园 - 司徒正美
The Cloudflare Blog
G
Google Developers Blog
Microsoft Security Blog
Microsoft Security Blog
腾讯CDC

Cryptology ePrint Archive

Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning High-Throughput Side-Channel-Protected Stream Cipher Hardware for 6G Systems Efficient e = 3 Threshold RSA via Integer Coordinates for Intel SGX Zeal: PIR for Non-Cooperative Databases VEIL: Lightweight Zero-Knowledge for Hash-Based Multilinear Proof Systems Witness-Indistinguishable Arguments of Knowledge and One-Way Functions The many faces of Schnorr: a touch-up Open Problems in List Decoding and Correlated Agreement Compressed Key Exchange Protocol from Orientations of Large Discriminant Using AVX-512 SPLASH: SPeculative Leakage-Adaptive Secure Hardware An Efficient Identity-Based Blind Signature Scheme from SM9 Efficient Batch Threshold Encryption Using Partial Fraction Techniques A note on the Unsuitability of LIGA for Linkable Ring Signatures: The perils of non-commutativity Verification Facade: Masquerading Insecure Cryptographic Implementations as Verified Code Cryptographic Implications of Worst-Case Hardness of Time-Bounded Kolmogorov Complexity Efficient Merkle-Tree Consistent Accumulator FLOSS: Fast Linear Online Secret-Shared Shuffling Which Privacy Blanket is Optimal in the Shuffle Model? Applications of Bruhat-Chevalley-Renner Decomposition to Metric-Aware Code-Based Cryptography
Rank Ceiling for Twiddle-Perturbation Faults on the Forwa...
Chakshu Gupta, Georgia Institute of Technology · 2026-06-07 · via Cryptology ePrint Archive

Paper 2026/1188

Rank Ceiling for Twiddle-Perturbation Faults on the Forward NTT

Abstract

NIST standardised the lattice-based key-encapsulation mechanism ML-KEM and the lattice-based digital signature scheme ML-DSA in 2024. Both compute a forward number-theoretic transform (NTT) over secret-bearing polynomials; the NTT's twiddle constants are a documented fault-attack surface. Published attacks zero every twiddle at once on ML-KEM key generation, or individual twiddles on ML-DSA signing. Countermeasures detect or mask such faults but none quantifies how much a single-twiddle perturbation disturbs the secret. This paper does, for key generation: the exact rank at each NTT layer of the linear map from the secret to the difference between a correct and a faulted run, for arbitrary twiddle perturbations, bit-flips included. Through that map, a single twiddle fault reveals as many independent linear combinations of a secret polynomial as there are butterflies using the twiddle, an exact count and not just a bound; stacking one fault per layer collapses the map's kernel to two coefficients of that polynomial for ML-KEM and one for ML-DSA. This kernel is the same whichever twiddle is hit in each layer, and no fault set, however large, shrinks it; the rank and kernel are machine-checked in Lean 4. ML-KEM publishes the faulted key uncompressed, so an attacker recovers all but those coefficients for all but a small fraction of keys; ML-DSA compresses its key, leaving the exact recovered count open. The exact per-layer rank tells countermeasure designers how much each layer's fault disturbs the secret.

BibTeX

@misc{cryptoeprint:2026/1188,
      author = {Chakshu Gupta},
      title = {Rank Ceiling for Twiddle-Perturbation Faults on the Forward {NTT}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1188},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1188}
}