Post-quantum cryptography addresses the threat posed by large-scale quantum computers to current public-key cryptosystems. After an eight-year evaluation process, NIST has standardized ML-KEM, a quantum-resistant scheme for publickey encryption and key encapsulation, whose global deployment is anticipated by 2035. Beyond algorithmic security, the resistance of physical implementations of ML-KEM to sidechannel attacks is important for a secure transition. This paper evaluates the resistance of a software implementation of MLKEM protected against side-channel analysis using masking and shuffling. Despite these countermeasures, we can recover the secret key using only one third of the traces compared to the state-of-the-art attack. Our main contribution is a novel chosenciphertext construction method that 1) circumvents the shuffling countermeasure, and 2) overcomes the inter-device variation problem. This method is applicable not only to ML-KEM, but also to other lattice-based PKE or KEM algorithms. We provide an in-depth analysis of the attack methodology, validate the attack on an ARM Cortex-M4 platform recommended by NIST for benchmarking, and suggest potential countermeasures for hardening ML-KEM implementations against side-channel attacks.
Part of ISBN 979-8-3195-1763-0
QC 20260805