FR1.R1.4

Exploiting signature leakages: breaking Enhanced pqsigRM

Thomas Debris-Alazard, Pierre Loisel, Inria Saclay, Laboratoire LIX, Ecole Polytechnique, France; Valentin Vasseur, Thales, France

Session:
Post-quantum Cryptography

Track:
5: Cryptography

Location:
Ballroom II & III

Presentation Time:
Fri, 12 Jul, 10:45 - 11:05

Session Chair:
Jens Zumbraegel,
Abstract
Enhanced pqsigRM is a code-based hash-and-sign scheme proposed to the second National Institute of Standards and Technology call for post-quantum signatures. The scheme is based on the (U,U+V)-construction and it enjoys remarkably small signature lengths, about 1KBytes for a security level of 128 bits. Unfortunately we will show that signatures leak information about the underlying (U,U+V)-structure. It allows to retrieve the private-key with 100, 000 signatures.
Resources