Securing Crystals-Dilithium Verification Against Fault Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Dillithium lattice-based cryptographic scheme is vulnerable to fault attacks during the signature verification process, which could lead to the acceptance of forged signatures.

Innovation Solution

A method is introduced to secure the Dillithium signature verification process against fault attacks by detecting and preventing attacks that aim to verify conditions P1, P2, or P3, ensuring that a forged signature is not accepted even if a fault attack occurs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the Dillithium signature verification algorithm is implemented without additional security measures, then the verification process is simple and fast, but it is vulnerable to fault attacks that could lead to acceptance of forged signatures

Engineering Contradiction:
Improvesecurity against fault attacksVSAvoidverification algorithm complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing fault detection checks before the final signature acceptance decision. The verification algorithm includes intermediate checks that detect potential fault attacks early in the verification process, preventing forged signatures from being accepted while maintaining a relatively simple overall structure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the verification process continuously monitors intermediate results and compares them against expected values. When deviations are detected (indicating potential fault attacks), the system provides feedback to reject the signature, creating a self-correcting verification process that enhances security without significantly increasing complexity.

Inventive Principle:
Principle #23Feedback

2Reliability

If additional verification steps are added to detect fault attacks, then security against forged signatures is improved, but the verification time and processing complexity increase

Engineering Contradiction:
Improverejection of forged signaturesVSAvoidverification execution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by implementing selective verification checks that focus on the most critical aspects of fault detection. Rather than verifying every possible parameter, the algorithm performs targeted checks on key intermediate values that are most susceptible to fault attacks, achieving adequate security with minimal additional time overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4554138A1Method for securing against fault attacks an execution of a verification of a crystals-dilithium post-quantum signature
Publication Date: 2025.05.14 THALES DIS FRANCE SA
  • EP4554138A1 patent drawingFigure 1
  • EP4554138A1 patent drawingFigure 2~3
  • EP4554138A1 patent drawingFigure 4

AI summary

The present invention relates to a method for securing against fault attacks the execution of the verification of a Crystals-Dilithium post-quantum digital signature σ of a message M comprising a challenge seed c̃, a test vector z and a hint vector of polynomials h generated with a secret key sk = (ρ, K, tr, s1, s2, t0), said digital signature verification taking as inputs, said digital signature σ, said message M and a public key pk = (ρ, t1) and comprising a step of ensuring that a fault attack aiming at verifying one of the conditions P1, P2 and P3 does not lead to accept a forged signature, where : ct1.2d=0, ‖ct1.2d‖∞<βand‖LowBitsq(Az−ct1.2d,2γ2‖∞<γ2−β, ‖ct1.2d‖∞<γ2.