{"id":"https://openalex.org/W2977871400","doi":"https://doi.org/10.1007/978-3-030-45721-1_23","title":"Security of Hedged Fiat\u2013Shamir Signatures Under Fault Attacks","display_name":"Security of Hedged Fiat\u2013Shamir Signatures Under Fault Attacks","publication_year":2020,"publication_date":"2020-01-01","ids":{"openalex":"https://openalex.org/W2977871400","doi":"https://doi.org/10.1007/978-3-030-45721-1_23","mag":"2977871400"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-030-45721-1_23","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-030-45721-1_23","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"preprint","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://pure.au.dk/portal/en/publications/e0b82a4f-2524-4820-bd1b-ecb400b732f0","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5020557476","display_name":"Diego F. Aranha","orcid":"https://orcid.org/0000-0002-2457-0783"},"institutions":[{"id":"https://openalex.org/I204337017","display_name":"Aarhus University","ror":"https://ror.org/01aj84f44","country_code":"DK","type":"education","lineage":["https://openalex.org/I204337017"]}],"countries":["DK"],"is_corresponding":true,"raw_author_name":"Diego F. Aranha","raw_affiliation_strings":["Department of Engineering, DIGIT, Aarhus University, Aarhus, Denmark","Aarhus university;"],"affiliations":[{"raw_affiliation_string":"Department of Engineering, DIGIT, Aarhus University, Aarhus, Denmark","institution_ids":["https://openalex.org/I204337017"]},{"raw_affiliation_string":"Aarhus university;","institution_ids":["https://openalex.org/I204337017"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5028570693","display_name":"Claudio Orlandi","orcid":"https://orcid.org/0000-0003-4992-0249"},"institutions":[{"id":"https://openalex.org/I204337017","display_name":"Aarhus University","ror":"https://ror.org/01aj84f44","country_code":"DK","type":"education","lineage":["https://openalex.org/I204337017"]}],"countries":["DK"],"is_corresponding":false,"raw_author_name":"Claudio Orlandi","raw_affiliation_strings":["Department of Computer Science, DIGIT, Aarhus University, Aarhus, Denmark","Aarhus university;"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, DIGIT, Aarhus University, Aarhus, Denmark","institution_ids":["https://openalex.org/I204337017"]},{"raw_affiliation_string":"Aarhus university;","institution_ids":["https://openalex.org/I204337017"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5062998951","display_name":"Akira Takahashi","orcid":"https://orcid.org/0000-0001-8556-3053"},"institutions":[{"id":"https://openalex.org/I204337017","display_name":"Aarhus University","ror":"https://ror.org/01aj84f44","country_code":"DK","type":"education","lineage":["https://openalex.org/I204337017"]}],"countries":["DK"],"is_corresponding":false,"raw_author_name":"Akira Takahashi","raw_affiliation_strings":["Department of Computer Science, DIGIT, Aarhus University, Aarhus, Denmark","Aarhus university;"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, DIGIT, Aarhus University, Aarhus, Denmark","institution_ids":["https://openalex.org/I204337017"]},{"raw_affiliation_string":"Aarhus university;","institution_ids":["https://openalex.org/I204337017"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5002192541","display_name":"Greg Zaverucha","orcid":null},"institutions":[{"id":"https://openalex.org/I1290206253","display_name":"Microsoft (United States)","ror":"https://ror.org/00d0nc645","country_code":"US","type":"company","lineage":["https://openalex.org/I1290206253"]},{"id":"https://openalex.org/I4210164937","display_name":"Microsoft Research (United Kingdom)","ror":"https://ror.org/05k87vq12","country_code":"GB","type":"company","lineage":["https://openalex.org/I1290206253","https://openalex.org/I4210164937"]}],"countries":["GB","US"],"is_corresponding":false,"raw_author_name":"Greg Zaverucha","raw_affiliation_strings":["Microsoft Research, Redmond, USA","Microsoft Research#TAB#"],"affiliations":[{"raw_affiliation_string":"Microsoft Research, Redmond, USA","institution_ids":["https://openalex.org/I1290206253"]},{"raw_affiliation_string":"Microsoft Research#TAB#","institution_ids":["https://openalex.org/I4210164937"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5020557476"],"corresponding_institution_ids":["https://openalex.org/I204337017"],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":{"value":5000,"currency":"EUR","value_usd":5392},"fwci":0.8241,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.73060029,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":"2019","issue":null,"first_page":"644","last_page":"674"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9940999746322632,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9940999746322632,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/cryptographic-nonce","display_name":"Cryptographic nonce","score":0.8101348876953125},{"id":"https://openalex.org/keywords/randomness","display_name":"Randomness","score":0.7493959665298462},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6637381315231323},{"id":"https://openalex.org/keywords/hash-function","display_name":"Hash function","score":0.5345622301101685},{"id":"https://openalex.org/keywords/signature","display_name":"Signature (topology)","score":0.5262542963027954},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.52070552110672},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.42754167318344116},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.4123286306858063},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.2197849452495575},{"id":"https://openalex.org/keywords/statistics","display_name":"Statistics","score":0.08833092451095581}],"concepts":[{"id":"https://openalex.org/C9996903","wikidata":"https://www.wikidata.org/wiki/Q1749235","display_name":"Cryptographic nonce","level":3,"score":0.8101348876953125},{"id":"https://openalex.org/C125112378","wikidata":"https://www.wikidata.org/wiki/Q176640","display_name":"Randomness","level":2,"score":0.7493959665298462},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6637381315231323},{"id":"https://openalex.org/C99138194","wikidata":"https://www.wikidata.org/wiki/Q183427","display_name":"Hash function","level":2,"score":0.5345622301101685},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.5262542963027954},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.52070552110672},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.42754167318344116},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.4123286306858063},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.2197849452495575},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.08833092451095581},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1007/978-3-030-45721-1_23","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-030-45721-1_23","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:pure.atira.dk:publications/e0b82a4f-2524-4820-bd1b-ecb400b732f0","is_oa":true,"landing_page_url":"https://pure.au.dk/portal/en/publications/e0b82a4f-2524-4820-bd1b-ecb400b732f0","pdf_url":null,"source":null,"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Aranha, D F, Orlandi, C, Takahashi, A & Zaverucha, G 2020, Security of Hedged Fiat\u2013Shamir Signatures under Fault Attacks. in A Canteaut & Y Ishai (eds), Advances in Cryptology \u2013 EUROCRYPT 2020. Springer, Cham, Lecture Notes in Computer Science, vol. 12105, pp. 644-674. https://doi.org/10.1007/978-3-030-45721-1_23","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"mag:2977871400","is_oa":false,"landing_page_url":"https://eprint.iacr.org/2019/956.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S2764847869","display_name":"IACR Cryptology ePrint Archive","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":["https://openalex.org/P4322614454"],"host_organization_lineage_names":["Cryptology ePrint Archive"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IACR Cryptology ePrint Archive","raw_type":null}],"best_oa_location":{"id":"pmh:oai:pure.atira.dk:publications/e0b82a4f-2524-4820-bd1b-ecb400b732f0","is_oa":true,"landing_page_url":"https://pure.au.dk/portal/en/publications/e0b82a4f-2524-4820-bd1b-ecb400b732f0","pdf_url":null,"source":null,"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Aranha, D F, Orlandi, C, Takahashi, A & Zaverucha, G 2020, Security of Hedged Fiat\u2013Shamir Signatures under Fault Attacks. in A Canteaut & Y Ishai (eds), Advances in Cryptology \u2013 EUROCRYPT 2020. Springer, Cham, Lecture Notes in Computer Science, vol. 12105, pp. 644-674. https://doi.org/10.1007/978-3-030-45721-1_23","raw_type":"info:eu-repo/semantics/publishedVersion"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.6600000262260437}],"awards":[],"funders":[{"id":"https://openalex.org/F4320309928","display_name":"Aarhus Universitet","ror":"https://ror.org/01aj84f44"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":60,"referenced_works":["https://openalex.org/W57082118","https://openalex.org/W154022573","https://openalex.org/W1489642236","https://openalex.org/W1493213353","https://openalex.org/W1526993157","https://openalex.org/W1580599221","https://openalex.org/W1589034595","https://openalex.org/W1663689473","https://openalex.org/W1666126665","https://openalex.org/W1829732909","https://openalex.org/W1903786769","https://openalex.org/W1956654868","https://openalex.org/W1980227445","https://openalex.org/W2037107113","https://openalex.org/W2072402822","https://openalex.org/W2095708839","https://openalex.org/W2097651164","https://openalex.org/W2101022010","https://openalex.org/W2111725598","https://openalex.org/W2118629598","https://openalex.org/W2136635506","https://openalex.org/W2144952508","https://openalex.org/W2148373594","https://openalex.org/W2157116240","https://openalex.org/W2160586212","https://openalex.org/W2164908759","https://openalex.org/W2169194339","https://openalex.org/W2169290761","https://openalex.org/W2179293241","https://openalex.org/W2182584071","https://openalex.org/W2258874952","https://openalex.org/W2283002900","https://openalex.org/W2417253018","https://openalex.org/W2492190064","https://openalex.org/W2498278624","https://openalex.org/W2511816434","https://openalex.org/W2550039900","https://openalex.org/W2552969007","https://openalex.org/W2555791265","https://openalex.org/W2560885415","https://openalex.org/W2566711147","https://openalex.org/W2621279043","https://openalex.org/W2727566086","https://openalex.org/W2751989631","https://openalex.org/W2774095756","https://openalex.org/W2790894069","https://openalex.org/W2796097963","https://openalex.org/W2805111206","https://openalex.org/W2814895833","https://openalex.org/W2889903231","https://openalex.org/W2891063150","https://openalex.org/W2913851998","https://openalex.org/W2921295905","https://openalex.org/W2961566779","https://openalex.org/W3005704743","https://openalex.org/W4229637647","https://openalex.org/W4239672913","https://openalex.org/W4243016930","https://openalex.org/W4251236654","https://openalex.org/W6696994111"],"related_works":["https://openalex.org/W3003185916","https://openalex.org/W2952381125","https://openalex.org/W3011271729","https://openalex.org/W2621279043","https://openalex.org/W3005704743","https://openalex.org/W2012076388","https://openalex.org/W2111162469","https://openalex.org/W3030577981","https://openalex.org/W1987942835","https://openalex.org/W1976032808","https://openalex.org/W2365802092","https://openalex.org/W3204648425","https://openalex.org/W3029813564","https://openalex.org/W1211073914","https://openalex.org/W2287566666","https://openalex.org/W96636354","https://openalex.org/W2009943525","https://openalex.org/W2118629598","https://openalex.org/W3095549427","https://openalex.org/W1576151945"],"abstract_inverted_index":{"Deterministic":[0],"generation":[1],"of":[2,16,68,75,86,103,114,128,137,141,165,175,204,223],"per-signature":[3,88],"randomness":[4,17,55,70],"has":[5,118],"been":[6,119],"a":[7,83,97,133,151,201,215],"widely":[8],"accepted":[9],"solution":[10],"to":[11,38,45,65,111,122,153,199,213],"mitigate":[12],"the":[13,47,73,87,92,100,104,112,125,138,146,166,181,208,224],"catastrophic":[14],"risk":[15],"failure":[18],"in":[19,60,107,207,220],"Fiat\u2013Shamir":[20,147,217],"type":[21],"signature":[22,79,109,142,218],"schemes.":[23],"However,":[24],"recent":[25],"studies":[26],"have":[27],"practically":[28],"demonstrated":[29],"that":[30],"such":[31],"de-randomized":[32],"schemes,":[33,110],"including":[34],"EdDSA,":[35],"are":[36,81,178],"vulnerable":[37],"differential":[39],"fault":[40,76,126,139,156],"attacks,":[41,157],"which":[42],"enable":[43],"adversaries":[44],"recover":[46],"entire":[48],"secret":[49,93],"signing":[50,167],"key,":[51,94],"by":[52,90,180],"artificially":[53],"provoking":[54],"reuse":[56],"or":[57],"corrupting":[58],"computation":[59],"other":[61],"ways.":[62],"In":[63],"order":[64],"balance":[66],"concerns":[67],"both":[69],"failures":[71],"and":[72,96,158,212],"threat":[74],"injection,":[77],"some":[78,173],"designs":[80],"advocating":[82],"\u201chedged\u201d":[84],"derivation":[85],"randomness,":[89],"hashing":[91],"message,":[95],"nonce.":[98],"Despite":[99],"growing":[101],"popularity":[102],"hedged":[105,129,182,202,216],"paradigm":[106],"practical":[108],"best":[113],"our":[115,197],"knowledge,":[116],"there":[117],"no":[120],"attempt":[121],"formally":[123],"analyze":[124],"resilience":[127,140],"signatures.":[130],"We":[131,149,169],"perform":[132],"formal":[134],"security":[135],"analysis":[136],"schemes":[143],"constructed":[144],"via":[145],"transform.":[148],"propose":[150],"model":[152],"characterize":[154],"bit-tampering":[155],"investigate":[159],"their":[160],"impact":[161],"across":[162],"different":[163],"steps":[164],"operation.":[168],"prove":[170],"that,":[171],"for":[172,188],"types":[174],"faults,":[176],"attacks":[177,185],"mitigated":[179],"paradigm,":[183],"while":[184],"remain":[186],"possible":[187],"others.":[189],"As":[190],"concrete":[191],"case":[192],"studies,":[193],"we":[194],"then":[195],"apply":[196],"results":[198],"XEdDSA,":[200],"version":[203],"EdDSA":[205],"used":[206],"Signal":[209],"messaging":[210],"protocol,":[211],"Picnic2,":[214],"scheme":[219],"Round":[221],"2":[222],"NIST":[225],"Post-Quantum":[226],"standardization":[227],"process.":[228]},"counts_by_year":[{"year":2023,"cited_by_count":1},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
