kth.sePublications KTH
Change search
Link to record
Permanent link

Direct link
Publications (2 of 2) Show all publications
Wang, R., Backlund, L. & Dubrova, E. (2026). A Chosen-Ciphertext Side-Channel Attack on Protected ML-KEM Using Pairwise Bit-Flipping. In: Proceedings - 2026 IEEE European Test Symposium, ETS 2026: . Paper presented at 31st IEEE European Test Symposium, ETS 2026, Chania, Greece, May 25-29 2026. Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>A Chosen-Ciphertext Side-Channel Attack on Protected ML-KEM Using Pairwise Bit-Flipping
2026 (English)In: Proceedings - 2026 IEEE European Test Symposium, ETS 2026, Institute of Electrical and Electronics Engineers (IEEE) , 2026Conference paper, Published paper (Refereed)
Abstract [en]

Post-quantum cryptography addresses the threat posed by large-scale quantum computers to current public-key cryptosystems. After an eight-year evaluation process, NIST has standardized ML-KEM, a quantum-resistant scheme for publickey encryption and key encapsulation, whose global deployment is anticipated by 2035. Beyond algorithmic security, the resistance of physical implementations of ML-KEM to sidechannel attacks is important for a secure transition. This paper evaluates the resistance of a software implementation of MLKEM protected against side-channel analysis using masking and shuffling. Despite these countermeasures, we can recover the secret key using only one third of the traces compared to the state-of-the-art attack. Our main contribution is a novel chosenciphertext construction method that 1) circumvents the shuffling countermeasure, and 2) overcomes the inter-device variation problem. This method is applicable not only to ML-KEM, but also to other lattice-based PKE or KEM algorithms. We provide an in-depth analysis of the attack methodology, validate the attack on an ARM Cortex-M4 platform recommended by NIST for benchmarking, and suggest potential countermeasures for hardening ML-KEM implementations against side-channel attacks.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2026
Keywords
Bit-Flipping, CRYSTALS-Kyber, Chosen-Ciphertext Construction, ML-KEM, Masking, Shuffling, Side-Channel Attack
National Category
Communication Systems Computer Sciences Computer Engineering
Identifiers
urn:nbn:se:kth:diva-386489 (URN)10.1109/ETS69887.2026.11591846 (DOI)2-s2.0-105045280122 (Scopus ID)
Conference
31st IEEE European Test Symposium, ETS 2026, Chania, Greece, May 25-29 2026
Note

Part of ISBN 979-8-3195-1763-0

QC 20260805

Available from: 2026-08-05 Created: 2026-08-05 Last updated: 2026-08-05Bibliographically approved
Backlund, L., Ngo, K., Gärtner, J. & Dubrova, E. (2023). Secret Key Recovery Attack on Masked and Shuffled Implementations of CRYSTALS-Kyber and Saber. In: Applied Cryptography and Network Security Workshops - ACNS 2023 Satellite Workshops, ADSC, AIBlock, AIHWS, AIoTS, CIMSS, Cloud S and P, SCI, SecMT, SiMLA, Proceedings: . Paper presented at 21st International Conference on Applied Cryptography and Network Security, ACNS 2023, Kyoto, Japan, Jun 19 2023 - Jun 22 2023 (pp. 159-177). Springer Nature
Open this publication in new window or tab >>Secret Key Recovery Attack on Masked and Shuffled Implementations of CRYSTALS-Kyber and Saber
2023 (English)In: Applied Cryptography and Network Security Workshops - ACNS 2023 Satellite Workshops, ADSC, AIBlock, AIHWS, AIoTS, CIMSS, Cloud S and P, SCI, SecMT, SiMLA, Proceedings, Springer Nature , 2023, p. 159-177Conference paper, Published paper (Refereed)
Abstract [en]

Shuffling is a well-known countermeasure against side-channel attacks. It typically uses the Fisher-Yates (FY) algorithm to generate a random permutation which is then utilized as the loop iterator to index the processing of the variables inside the loop. The processing order is scrambled as a result, making side-channel attacks more difficult. Recently, a side-channel attack on a masked and shuffled implementation of Saber requiring 61,680 power traces to extract the long-term secret key was reported. In this paper, we present an attack that can recover the long-term secret key of Saber from 4,608 traces. The key idea behind the 13-fold improvement is to recover FY indexes directly, rather than by extracting the message Hamming weight and bit flipping, as in the previous attack. We capture a power trace during the execution of the decryption algorithm for a given ciphertext, recover FY indexes 0 and 255, and extract the corresponding two message bits. Then, we modify the ciphertext to cyclically rotate the message, capture a power trace, and extract the next two message bits with FY indexes 0 and 255. In this way, all message bits can be extracted. By recovering messages contained in k∗ l chosen ciphertexts constructed using a new method based on error-correcting codes of length l, where k is the module rank, we recover the long-term secret key. To demonstrate the generality of the presented approach, we also recover the secret key from a masked and shuffled implementation of CRYSTALS-Kyber, which NIST recently selected as a new public-key encryption and key-establishment algorithm to be standardized.

Place, publisher, year, edition, pages
Springer Nature, 2023
Keywords
CRYSTALS-Kyber, Post-quantum cryptography, Power analysis, Public-key cryptography, Saber, Side-channel attack
National Category
Signal Processing
Identifiers
urn:nbn:se:kth:diva-339267 (URN)10.1007/978-3-031-41181-6_9 (DOI)001296011500009 ()2-s2.0-85174450161 (Scopus ID)
Conference
21st International Conference on Applied Cryptography and Network Security, ACNS 2023, Kyoto, Japan, Jun 19 2023 - Jun 22 2023
Note

Part of ISBN 9783031411809

QC 20231106

Available from: 2023-11-06 Created: 2023-11-06 Last updated: 2024-10-07Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0003-2021-2994

Search in DiVA

Show all publications