Quantum-Resistance Meets White-Box Cryptography: How to Implement Hash-Based Signatures against White-Box Attackers?

Author:

Bicakci Kemal12,Ulker Kemal32,Uzunay Yusuf2,Şahin Halis14,Gündoğan Muhammed4

Affiliation:

1. Informatics Institute, Istanbul Technical University

2. Securify Information Tech. and Security Training Consulting Ltd.

3. TOBB University of Economics and Technology

4. TÜBİTAK

Abstract

The adversary model of white-box cryptography includes an extreme case where the adversary, sitting at the endpoint, has full access to a cryptographic scheme. Motivating by the fact that most existing white-box implementations focus on symmetric encryption, we present implementations for hash-based signatures so that the security against white-box attackers (who have read-only access to data with a size bounded by a space-hardness parameter M) depends on the availability of a white-box secure cipher (in addition to a general one-way function). We also introduce parameters and key-generation complexity results for white-box secure instantiation of stateless hash-based signature scheme SPHINCS+, one of the NIST selections for quantum-resistant digital signature algorithms, and its older version SPHINCS. We also present a hash tree-based solution for one-time passwords secure in a white-box attacker context. We implement the proposed solutions and share our performance results.

Publisher

International Association for Cryptologic Research

Reference28 articles.

1. White-Box Cryptography and an AES Implementation;Stanley Chow,2003

2. White-Box Cryptography Revisited: Space-Hard Ciphers;Andrey Bogdanov,2015

3. Towards Practical Whitebox Cryptography: Optimizing Efficiency and Space Hardness;Andrey Bogdanov,2016

4. Recommendation for stateful hash-based signature schemes;D. A. Cooper;NIST Special Publication,2020

5. Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process;Gorjan Alagic,2022

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3