Melissa Rossi

dblp:203/4250 · also Mélissa Rossi · DBLP profile ↗
← Back
19ranked-venue papers
1as first author
10since 2021 · last 2026
0000-0002-9268-3034ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 1 first-author · 10 since 2021
YearPublicationVenuePosition
2026 Learning with Errors with Output Dependencies: LWE, LWR, and Physical Learning Problems Under the Same Umbrella
Clément Hoffmann, Pierrick Méaux, Melissa Rossi, François-Xavier Standaert
PQCrypto (1)3
2025 New Techniques for Random Probing Security and Application to Raccoon Signature Scheme
Sonia Belaïd, Matthieu Rivain, Melissa Rossi
EUROCRYPT (8)3
2024 Raccoon: A Masking-Friendly Signature Proven in the Probing Model
Rafaël Del Pino, Shuichi Katsumata, Thomas Prest, Melissa Rossi
CRYPTO (1)4
2024 Masking the GLP Lattice-Based Signature Scheme at Any Order
Gilles Barthe, Sonia Belaïd, Thomas Espitau, Pierre-Alain Fouque, Benjamin Grégoire, Melissa Rossi, Mehdi Tibouchi
J. Cryptol.6
2023 GeT a CAKE: Generic Transformations from Key Encaspulation Mechanisms to Password Authenticated Key Exchanges
Hugo Beguinet, Céline Chevalier, David Pointcheval, Thomas Ricosset, Melissa Rossi
ACNS5
2023 Constant Input Attribute Based (and Predicate) Encryption from Evasive and Tensor LWE
Shweta Agrawal 0001, Melissa Rossi, Anshu Yadav, Shota Yamada 0001
CRYPTO (4)2
2023 Mask Compression: High-Order Masking on Memory-Constrained Devices
Markku-Juhani O. Saarinen, Melissa Rossi
SAC2
2023 High-Order Masking of Lattice Signatures in Quasilinear Time
abstract
In recent years, lattice-based signature schemes have emerged as the most prominent post-quantum solutions, as illustrated by NIST’s selection of Falcon and Dilithium for standardization. Both schemes enjoy good performance characteristics. However, their efficiency dwindles in the presence of side-channel protections, particularly masking – perhaps the strongest generic side-channel countermeasure. Masking at order d-1 requires randomizing all sensitive intermediate variables into d shares. With existing schemes, signature generation complexity grows quadratically with the number of shares, making high-order masking prohibitively slow.In this paper, we turn the problem upside-down: We design a lattice-based signature scheme specifically for side-channel resistance and optimize the masked efficiency as a function of the number of shares. Our design avoids costly operations such as conversions between arithmetic and boolean encodings (A2B/B2A), masked rejection sampling, and does not require a masked SHAKE implementation or other symmetric primitives. The resulting scheme is called Raccoon and belongs to the family of Fiat-Shamir with aborts lattice-based signatures. Raccoon is the first lattice-based signature whose key generation and signing running time has only an O(d log(d)) overhead, with d being the number of shares.Our Reference C implementation confirms that Raccoon’s performance is comparable to other state-of-the-art signature schemes, except that increasing the number of shares has a near-linear effect on its latency. We also present an FPGA implementation and perform a physical leakage assessment to verify its basic security properties.
Rafaël Del Pino, Thomas Prest, Melissa Rossi, Markku-Juhani O. Saarinen
SP3
2023 On the algebraic immunity - resiliency trade-off, implications for Goldreich's pseudorandom generator
Aurélien Dupin, Pierrick Méaux, Melissa Rossi
Des. Codes Cryptogr.3
2022 Mitaka: A Simpler, Parallelizable, Maskable Variant of Falcon
abstract
This work describes the Mitaka signature scheme: a new hash-and-sign signature scheme over NTRU lattices which can be seen as a variant of NIST finalist Falcon . It achieves comparable efficiency but is considerably simpler, online/offline, and easier to parallelize and protect against side-channels, thus offering significant advantages from an implementation standpoint. It is also much more versatile in terms of parameter selection. We obtain this signature scheme by replacing the FFO lattice Gaussian sampler in Falcon by the “hybrid” sampler of Ducas and Prest, for which we carry out a detailed and corrected security analysis. In principle, such a change can result in a substantial security loss, but we show that this loss can be largely mitigated using new techniques in key generation that allow us to construct much higher quality lattice trapdoors for the hybrid sampler relatively cheaply. This new approach can also be instantiated on a wide variety of base fields, in contrast with Falcon ’s restriction to power-of-two cyclotomics. We also introduce a new lattice Gaussian sampler with the same quality and efficiency, but which is moreover compatible with the integral matrix Gram root technique of Ducas et al., allowing us to avoid floating point arithmetic. This makes it possible to realize the same signature scheme as Mitaka efficiently on platforms with poor support for floating point numbers. Finally, we describe a provably secure masking of Mitaka . More precisely, we introduce novel gadgets that allow provable masking at any order at much lower cost than previous masking techniques for Gaussian sampling-based signature schemes, for cheap and dependable side-channel protection.
Thomas Espitau, Pierre-Alain Fouque, François Gérard, Melissa Rossi, Akira Takahashi 0002, Mehdi Tibouchi, Alexandre Wallet, Yang Yu 0008
EUROCRYPT (3)4
2020 LWE with Side Information: Attacks and Concrete Security Estimation
Dana Dachman-Soled, Léo Ducas, Huijing Gong, Melissa Rossi
CRYPTO (2)4
2020 (One) Failure Is Not an Option: Bootstrapping the Search for Failures in Lattice-Based Encryption Schemes
Jan-Pieter D'Anvers, Melissa Rossi, Fernando Virdia
EUROCRYPT (3)2
2020 Isochronous Gaussian Sampling: From Inception to Implementation
James Howe, Thomas Prest, Thomas Ricosset, Melissa Rossi
PQCrypto4
2019 An Efficient and Provable Masked Implementation of qTESLA
François Gérard, Melissa Rossi
CARDIS2
2019 GALACTICS: Gaussian Sampling for Lattice-Based Constant- Time Implementation of Cryptographic Signatures, Revisited
abstract
In this paper, we propose a constant-time implementation of the BLISS lattice-based signature scheme. BLISS is possibly the most efficient lattice-based signature scheme proposed so far, with a level of performance on par with widely used pre-quantum primitives like ECDSA. It is only one of the few postquantum signatures to have seen real-world deployment, as part of the strongSwan VPN software suite. The outstanding performance of the BLISS signature scheme stems in large part from its reliance on discrete Gaussian distributions, which allow for better parameters and security reductions. However, that advantage has also proved to be its Achilles' heel, as discrete Gaussians pose serious challenges in terms of secure implementations. Implementations of BLISS so far have included secret-dependent branches and memory accesses, both as part of the discrete Gaussian sampling and of the essential rejection sampling step in signature generation. These defects have led to multiple devastating timing attacks, and were a key reason why BLISS was not submitted to the NIST postquantum standardization effort. In fact, almost all of the actual candidates chose to stay away from Gaussians despite their efficiency advantage, due to the serious concerns surrounding implementation security. Moreover, naive countermeasures will often not cut it: we show that a reasonable-looking countermeasure suggested in previous work to protect the BLISS rejection sampling can again be defeated using novel timing attacks, in which the timing information is fed to phase retrieval machine learning algorithm in order to achieve a full key recovery. Fortunately, we also present careful implementation techniques that allow us to describe an implementation of BLISS with complete timing attack protection, achieving the same level of efficiency as the original unprotected code, without resorting on floating point arithmetic or platform-specific optimizations like AVX intrinsics. These techniques, including a new approach to the polynomial approximation of transcendental function, can also be applied to the masking of the BLISS signature scheme, and will hopefully make more efficient and secure implementations of lattice-based cryptography possible going forward.
Gilles Barthe, Sonia Belaïd, Thomas Espitau, Pierre-Alain Fouque, Melissa Rossi, Mehdi Tibouchi
CCS5
2019 Assessment of the Key-Reuse Resilience of NewHope
Aurélie Bauer, Henri Gilbert, Guénaël Renault, Melissa Rossi
CT-RSA4
2018 On the Concrete Security of Goldreich's Pseudorandom Generator
Geoffroy Couteau, Aurélien Dupin, Pierrick Méaux, Melissa Rossi, Yann Rotella
ASIACRYPT (2)4
2018 Masking the GLP Lattice-Based Signature Scheme at Any Order
Gilles Barthe, Sonia Belaïd, Thomas Espitau, Pierre-Alain Fouque, Benjamin Grégoire, Melissa Rossi, Mehdi Tibouchi
EUROCRYPT (2)6
2017 A Side-Channel Assisted Cryptanalytic Attack Against QcBits
Melissa Rossi, Michael Hamburg, Michael Hutter, Mark E. Marson
CHES1