0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
Codeword Masking Can Be Harmful Under Replay Attacks on HQC
- 1.NIST가 2025년 표준으로 선정한 HQC에서 방어책인 코드워드 마스킹이 오히려 재전송 공격 성공률을 크게 높이는 역설 확인
- 2.Reed-Muller 인코더의 새 부채널 누출 지점을 이용해 단일 트레이스·약 80개 프로파일링만으로 비밀키 복구
- 3.마스킹 미적용 시 복구 확률은 10^-555에 불과하지만 마스킹 적용 시 1.0으로 급등
- 4.3-공유로 마스킹 차수를 늘려도 추가 프로파일링 비용 없이 동일하게 복구돼 근본적 대응 실패
왜 중요한가?
NIST 표준으로 채택된 HQC의 공식 대응책이 실제로는 공격을 돕는다는 것을 실증한 결과로, 표준 구현체 전반의 부채널 방어 설계를 재검토해야 함을 시사한다.
본문 미리보기
HQC, selected by NIST for standardization in 2025, was recently shown vulnerable to a replay attack recovering $\mathbf{v} - \mathbf{u}\cdot \mathbf{y}$, from which the long-term secret $\mathbf{y}$ was shown to be recoverable, and against which \emph{codeword masking} was proposed as the countermeasure. We revisit both and demonstrate that the countermeasure yields an opposite effect: on the target build, the unmasked replay attack is ineffective, whereas introducing codeword masking paradoxic
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:24AI 초안



