METHODS OF PROTECTION AGAINST SIDE-CHANNEL ATTACKS IN THE HARDWARE IMPLEMENTATION OF POST-QUANTUM SIGNATURE SCHEMES BASED ON THE STERN IDENTIFICATION PROTOCOL
D.K. Smirnov, Ivan Vladimirovich Chizhov, JSC «NPK Kryptonite» · Voprosy kiberbezopasnosti · 2025
Purpose of the study: the development of a secure Stern identification protocol resistant to side-channel attacks. Methods of research: the study of modern techniques for attacking cryptographic systems with similar computational components, methods to protect against these attacks, and modifications to the system in order to safeguard the private key in the event of a token theft. Result(s): Vulnerable computational elements of the protocol, such as addition of vectors modulo 2 and matrix multiplication by a vector, are identified. The main methods of protecting these elements from leakage through side channels, including masking, balancing, and mixing, are analyzed. A matrix multiplication method resistant to horizontal correlation attacks used against the McEliece cryptosystem is proposed. The basic requirements for implementing the scheme on field-programmable gate arrays (FPGAs) are established. A modification of the scheme with key masking that does not compromise the strength of the original scheme is proposed to protect the secret in the event of token theft and prevent impersonation attacks due to key masking. The method of key mask generation is selected to minimize the amount of space occupied on an FPGA, specifically by hashing the passphrase using the «Stribog-K» function with a counter. It has been shown that the stability of the modified Stern identification protocol is the same as the stability of the original protocol in a model without side channel leakage, and it is even better in a model with side channel leakage. Scientific novelty: the results of the work allow us to implement the post-quantum signature algorithm «Shipovnik», which is being developed by the TK26 working group and is currently being standardized.