{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,25]],"date-time":"2026-01-25T05:09:43Z","timestamp":1769317783568,"version":"3.49.0"},"publisher-location":"Cham","reference-count":21,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030904012","type":"print"},{"value":"9783030904029","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-90402-9_9","type":"book-chapter","created":{"date-parts":[[2021,11,2]],"date-time":"2021-11-02T00:03:09Z","timestamp":1635811389000},"page":"155-173","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Recovery Attack on Bob\u2019s Reused Randomness in CRYSTALS-KYBER and SABER"],"prefix":"10.1007","author":[{"given":"Satoshi","family":"Okada","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2872-4508","authenticated-orcid":false,"given":"Yuntao","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,11,2]]},"reference":[{"key":"9_CR1","unstructured":"US Department of Commerce: National Institute of Standards and Technology. Post-Quantum Cryptography (2019). http:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography\/"},{"key":"9_CR2","unstructured":"Alkim, E., Ducas, L., P\u00f6ppelmann, T., Schwabe, P.: Post-quantum key exchange - a new hope. In: Proceedings pf the 25th USENIX Security Symposium, USENIX Security 16, August 10\u201312 2016, pp. 327\u2013343 (2016)"},{"key":"9_CR3","doi-asserted-by":"crossref","unstructured":"B\u0103etu, C., Durak, F.B., Huguenin-Dumittan, L., Talayhan, A., Vaudenay, S.: Misuse attacks on post-quantum cryptosystems. In: Proceedings of the EUROCRYPT 2019, May 19\u201323, 2019 , Part II, pp. 747\u2013776 (2019)","DOI":"10.1007\/978-3-030-17656-3_26"},{"key":"9_CR4","doi-asserted-by":"crossref","unstructured":"Bauer, A., Gilbert, H., Renault, G., Rossi, M.: Assessment of the key-reuse resilience of NewHope. In: Proceedings of the The Cryptographers\u2019 Track at the RSA Conference 2019 (CT-RSA 2019), March 4\u20138 2019, pp. 272\u2013292 (2019)","DOI":"10.1007\/978-3-030-12612-4_14"},{"key":"9_CR5","unstructured":"Bindel, N., Stebila, D., Veitch, S.: Improved attacks against key reuse in learning with errors key exchange. Cryptology ePrint Archive, Report 2020\/1288 (2020). https:\/\/eprint.iacr.org\/2020\/1288"},{"key":"9_CR6","doi-asserted-by":"crossref","unstructured":"Bos, J.W., et al.: CRYSTALS - kyber: a CCA-secure module-lattice-based KEM. In: 2018 IEEE European Symposium on Security and Privacy (EuroS&P 2018), London, UK, April 24\u201326 2018, pp. 353\u2013367. IEEE (2018)","DOI":"10.1109\/EuroSP.2018.00032"},{"key":"9_CR7","doi-asserted-by":"crossref","unstructured":"D\u2019Anvers, J., Karmakar, A., Roy, S.S., Vercauteren, F.: Saber: module-IWR based key exchange, CPA-secure encryption and CCA-secure KEM. In: Joux, A., Nitaj, A., Rachidi, T. (eds.) Proceedings of the Progress in Cryptology - AFRICACRYPT 2018\u201310th International Conference on Cryptology in Africa, Marrakesh, Morocco, May 7\u20139 2018, vol. 10831, LNCS, pp. 282\u2013305. Springer (2018)","DOI":"10.1007\/978-3-319-89339-6_16"},{"key":"9_CR8","doi-asserted-by":"crossref","unstructured":"Ding, J., Alsayigh, S., Saraswathy, R.V., Fluhrer, S.R., Lin, X.: Leakage of signal function with reused keys in RLWE key exchange. In: Proceedings of the IEEE International Conference on Communications (ICC 2017), May 21\u201325 2017, pp. 1\u20136 (2017)","DOI":"10.1109\/ICC.2017.7996806"},{"key":"9_CR9","doi-asserted-by":"crossref","unstructured":"Ding, J., Fluhrer, S.R., Saraswathy, R.V.: Complete attack on RLWE key exchange with reused keys, without signal leakage. In: Proceedings of the Information Security and Privacy - 23rd Australasian Conference (ACISP 2018), July 11\u201313 2018, pp. 467\u2013486 (2018)","DOI":"10.1007\/978-3-319-93638-3_27"},{"key":"9_CR10","unstructured":"Fluhrer, S.R.: Cryptanalysis of ring-LWE based key exchange with key share reuse. IACR Cryptology ePrint Archive, 2016:85 (2016). http:\/\/eprint.iacr.org\/2016\/085"},{"key":"9_CR11","doi-asserted-by":"crossref","unstructured":"Greuet, A., Montoya, S., Renault, G.: Attack on LAC key exchange in misuse situation. IACR Cryptology ePrint Archive, 2020:63 (2020). http:\/\/eprint.iacr.org\/2020\/063","DOI":"10.1007\/978-3-030-65411-5_27"},{"key":"9_CR12","doi-asserted-by":"crossref","unstructured":"Liu, C., Zheng, Z., Zou, G.: Key reuse attack on NewHope key exchange protocol. In: Information Security and Cryptology (ICISC 2018), November 28\u201330, 2018, Revised Selected Papers, pp. 163\u2013176 (2018)","DOI":"10.1007\/978-3-030-12146-4_11"},{"key":"9_CR13","unstructured":"Lu, X., et al.: LAC: practical ring-lwe based public-key encryption with byte-level modulus. IACR Cryptol. ePrint Arch. 2018, 1009 (2018)"},{"key":"9_CR14","doi-asserted-by":"crossref","unstructured":"Lyubashevsky, V., Peikert, C., Regev, O.: On ideal lattices and learning with errors over rings. In: Proceedings EUROCRYPT 2010, May 30\u2013June 3 2010, pp. 1\u201323 (2010)","DOI":"10.1007\/978-3-642-13190-5_1"},{"key":"9_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"505","DOI":"10.1007\/978-3-030-55304-3_26","volume-title":"Information Security and Privacy","author":"S Okada","year":"2020","unstructured":"Okada, S., Wang, Y., Takagi, T.: Improving key mismatch attack on NewHope with fewer queries. In: Liu, J.K., Cui, H. (eds.) ACISP 2020. LNCS, vol. 12248, pp. 505\u2013524. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-55304-3_26"},{"key":"9_CR16","doi-asserted-by":"crossref","unstructured":"Qin, Y., Cheng, C., Ding. J.: A complete and optimized key mismatch attack on NIST candidate newhope. In: Proceedings of the 4th European Symposium on Research in Computer Security (ESORICS 2019), September 23\u201327 2019, Part II, pp. 504\u2013520 (2019)","DOI":"10.1007\/978-3-030-29962-0_24"},{"key":"9_CR17","unstructured":"Cin, Y., Cheng, C., Din, J.: An efficient key mismatch attack on the NIST second round candidate Kyber. IACR Cryptology ePrint Archive. 2019:1343 (2019). http:\/\/eprint.iacr.org\/2019\/1343"},{"key":"9_CR18","unstructured":"Rescorla, E.: The transport layer security (TLS) protocol version 1.3. Technical report. http:\/\/www.rfc-editor.org\/info\/rfc8446"},{"issue":"5","key":"9_CR19","doi-asserted-by":"publisher","first-page":"1484","DOI":"10.1137\/S0097539795293172","volume":"26","author":"PW Shor","year":"1997","unstructured":"Shor, P.W.: Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 26(5), 1484\u20131509 (1997)","journal-title":"SIAM J. Comput."},{"key":"9_CR20","first-page":"1389","volume":"2020","author":"J Vacek","year":"2020","unstructured":"Vacek, J., V\u00e1clavek, J.: Key mismatch attack on newhope revisited. IACR Cryptol. ePrint Arch. 2020, 1389 (2020)","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"9_CR21","doi-asserted-by":"crossref","unstructured":"Wang, K., Zhang, Z., Jiang, H.: Security of two NIST candidates in the presence of randomness reuse. In: Proceedings of the Provable and Practical Security - 14th International Conference (ProvSec 2020), Singapore, November 29\u2013December 1, 2020, pp. 402\u2013421 (2020)","DOI":"10.1007\/978-3-030-62576-4_20"}],"container-title":["Lecture Notes in Computer Science","Provable and Practical Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-90402-9_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,11,2]],"date-time":"2021-11-02T00:04:09Z","timestamp":1635811449000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-90402-9_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030904012","9783030904029"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-90402-9_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"2 November 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ProvSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Provable Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Guangzhou","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"5 November 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 November 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"provsec2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/provsec2021.scau.edu.cn\/index\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"67","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"21","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"31% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}