Why the Naive Version Leaks
August 25, 20264 min readbeginner
The obvious thing to try is translating Schnorr into the module setting piece by piece. This note does that, and then breaks it.
The obvious thing to try is translating Schnorr into the module setting piece by piece. This note does that, and then breaks it.
01.The direct translation
Replace the group by , the exponentiation by matrix multiplication, and by . The protocol becomes:
- Commit. Sample with small coefficients, send .
- Challenge. Receive a small .
- Respond. Send .
The verifier checks , which holds because
Algebraically this is fine. It is the exact lattice analogue of , and every equation balances.
It also hands over the secret key.
02.The leak, in one line
Every signature releases , which is the secret multiplied by a known challenge and hidden under a mask that has bounded size. Averaging over many signatures pulls the secret out of the mask.
This is the point where the group argument fails. In Schnorr, was uniform over the whole group, so was still exactly uniform and the shift was invisible. Here has small coefficients drawn from a bounded range, so is that same bounded range shifted. The shift is exactly , and a shifted distribution is distinguishable from an unshifted one.
03.Watching it happen
Forget the ring for a moment and work with a single integer secret, which makes the arithmetic legible.
Take . Let the challenge be or at random, and let be uniform on . The released value is .
When , is uniform on , whose mean is .
When , is uniform on , whose mean is .
So an attacker who collects signatures, separates them by which challenge was used, and takes the mean of each group, will see the two means separated by exactly .
Simulating that with 400,000 signatures:
Half the difference is
against a true secret of . The attacker has recovered it to within rounding, using nothing but arithmetic means.
This is not a side-channel attack and it does not depend on any implementation flaw. It is an algebraic property of the construction. The released values are a shifted distribution and the shift is the secret.
04.Why more noise does not fix it
The natural first response is to make much larger, so the shift is proportionally smaller and harder to detect.
That helps only slowly. The statistical detectability of a shift of size in a distribution of width , given samples, grows like . So doubling forces the attacker to quadruple , and is free to them under EUF-CMA, where they may request unlimited signatures.
Meanwhile cannot grow without bound. It sets the size of , which is most of the signature, so doubling it costs a bit per coefficient across coefficients on every signature ever sent. Buying security this way is paying continuously to make the attacker's job merely tedious.
What is needed is not a bigger mask. It is a construction where the released values carry no shift at all, regardless of the secret.
That exists, and it is the subject of the next note.