Timing leakage to break SM2 signature algorithm

Published: 01 Jan 2022, Last Modified: 08 Mar 2025J. Inf. Secur. Appl. 2022EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: SM2 digital signature algorithm (SM2-DSA) is a Chinese public key cryptography standard, which is also ISO/IEC standard. However, seldom publications show the evaluation results for combination analysis of side-channel and lattice theory. The combination attack is powerful and has been confirmed on ECDSA schemes. We target SM2-DSA to evaluate security with respect to the combinated analysis. Given the most significant zero bits, we provide the detailed deduction of inequations for lattice construction. We confirmed the validity of our deduction and also confirmed security bounder where a successful lattice attack requires at least 6 bits leakage of nonce. Our results show a greatly difference from the results gained under the least significant bits leakage. We then provide a comprehensive analysis on parameters selection of lattice reduction. Our results can be a guide for both security evaluation and secure implementation design.
Loading