{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:35:48Z","timestamp":1783611348873,"version":"3.55.0"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030925178","type":"print"},{"value":"9783030925185","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-92518-5_15","type":"book-chapter","created":{"date-parts":[[2021,12,8]],"date-time":"2021-12-08T07:03:27Z","timestamp":1638947007000},"page":"311-334","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Fault-Enabled Chosen-Ciphertext Attacks on\u00a0Kyber"],"prefix":"10.1007","author":[{"given":"Julius","family":"Hermelink","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peter","family":"Pessl","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas","family":"P\u00f6ppelmann","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,12,9]]},"reference":[{"key":"15_CR1","unstructured":"Alkim, E., et al.: NewHope - Submission to the NIST post-quantum project (2019). https:\/\/newhopecrypto.org\/data\/NewHope_2019_07_10.pdf"},{"key":"15_CR2","unstructured":"Alkim, E., et al.: FrodoKEM Learning With Errors Key Encapsulation (2021). https:\/\/frodokem.org\/files\/FrodoKEM-specification-20210604.pdf"},{"key":"15_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1007\/978-3-030-44223-1_11","volume-title":"Post-Quantum Cryptography","author":"D Amiet","year":"2020","unstructured":"Amiet, D., Curiger, A., Leuenberger, L., Zbinden, P.: Defeating NewHope with a single trace. In: Ding, J., Tillich, J.-P. (eds.) PQCrypto 2020. LNCS, vol. 12100, pp. 189\u2013205. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-44223-1_11"},{"key":"15_CR4","doi-asserted-by":"crossref","unstructured":"Bhasin, S., D\u2019Anvers, J.-P., Heinz, D., P\u00f6ppelmann, T., Van Beirendonck, M.: Attacking and defending masked polynomial comparison for lattice-based cryptography. IACR Cryptology ePrint Archive 2021, 104 (2021)","DOI":"10.46586\/tches.v2021.i3.334-359"},{"key":"15_CR5","doi-asserted-by":"crossref","unstructured":"Bos, J.W., et al.: CRYSTALS - Kyber: a CCA-secure module-lattice-based KEM. In: 2018 IEEE European Symposium on Security and Privacy, EuroS&P 2018, London, UK, 24\u201326 April 2018, pp. 353\u2013367. IEEE (2018)","DOI":"10.1109\/EuroSP.2018.00032"},{"key":"15_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"272","DOI":"10.1007\/978-3-030-12612-4_14","volume-title":"Topics in Cryptology \u2013 CT-RSA 2019","author":"A Bauer","year":"2019","unstructured":"Bauer, A., Gilbert, H., Renault, G., Rossi, M.: Assessment of the key-reuse resilience of NewHope. In: Matsui, M. (ed.) CT-RSA 2019. LNCS, vol. 11405, pp. 272\u2013292. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-12612-4_14"},{"issue":"3","key":"15_CR7","doi-asserted-by":"publisher","first-page":"483","DOI":"10.46586\/tches.v2020.i3.483-507","volume":"2020","author":"F Bache","year":"2020","unstructured":"Bache, F., Paglialonga, C., Oder, T., Schneider, T., G\u00fcneysu, T.: High-speed masking for polynomial comparison in lattice-based KEMs. TCHES 2020(3), 483\u2013507 (2020)","journal-title":"TCHES"},{"key":"15_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-25385-0_1","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2011","author":"Y Chen","year":"2011","unstructured":"Chen, Y., Nguyen, P.Q.: BKZ 2.0: better lattice security estimates. In: Lee, D.H., Wang, X. (eds.) ASIACRYPT 2011. LNCS, vol. 7073, pp. 1\u201320. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25385-0_1"},{"key":"15_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1007\/978-3-319-89339-6_16","volume-title":"Progress in Cryptology \u2013 AFRICACRYPT 2018","author":"J-P D\u2019Anvers","year":"2018","unstructured":"D\u2019Anvers, J.-P., Karmakar, A., Sinha Roy, S., Vercauteren, F.: Saber: module-LWR based key exchange, CPA-secure encryption and CCA-secure KEM. In: Joux, A., Nitaj, A., Rachidi, T. (eds.) AFRICACRYPT 2018. LNCS, vol. 10831, pp. 282\u2013305. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-89339-6_16"},{"key":"15_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/3-540-48405-1_34","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 99","author":"E Fujisaki","year":"1999","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 537\u2013554. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_34"},{"issue":"4","key":"15_CR11","doi-asserted-by":"publisher","first-page":"209","DOI":"10.46586\/tches.v2020.i4.209-238","volume":"2020","author":"Q Guo","year":"2020","unstructured":"Guo, Q., Grosso, V., Standaert, F.-X., Bronchain, O.: Modeling soft analytical side-channel attacks from a coding theory viewpoint. IACR TCHES 2020(4), 209\u2013238 (2020)","journal-title":"IACR TCHES"},{"key":"15_CR12","doi-asserted-by":"crossref","unstructured":"Guo, Q., Johansson, T., Nilsson, A.: A key-recovery timing attack on post-quantum primitives using the Fujisaki-Okamoto transformation and its application on FrodoKEM. IACR Cryptology ePrint Archive 2020, 743 (2020)","DOI":"10.1007\/978-3-030-56880-1_13"},{"key":"15_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1007\/978-3-030-15462-2_2","volume-title":"Smart Card Research and Advanced Applications","author":"J Green","year":"2019","unstructured":"Green, J., Roy, A., Oswald, E.: A systematic study of the impact of graphical models on inference-based attacks on AES. In: Bilgin, B., Fischer, J.-B. (eds.) CARDIS 2018. LNCS, vol. 11389, pp. 18\u201334. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-15462-2_2"},{"key":"15_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/978-3-319-70500-2_12","volume-title":"Theory of Cryptography","author":"D Hofheinz","year":"2017","unstructured":"Hofheinz, D., H\u00f6velmanns, K., Kiltz, E.: A modular analysis of the Fujisaki-Okamoto transformation. In: Kalai, Y., Reyzin, L. (eds.) TCC 2017. LNCS, vol. 10677, pp. 341\u2013371. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70500-2_12"},{"key":"15_CR15","doi-asserted-by":"crossref","unstructured":"Hamburg, M., et al.: Chosen ciphertext k-trace attacks on masked CCA2 secure kyber. IACR Cryptology ePrint Archive 2021, 956 (2021)","DOI":"10.46586\/tches.v2021.i4.88-113"},{"key":"15_CR16","unstructured":"Heinz, D., P\u00f6ppelmann, T.: Combined fault and DPA protection for lattice-based cryptography. IACR Cryptology ePrint Archive 2021, 101 (2021)"},{"issue":"3","key":"15_CR17","doi-asserted-by":"publisher","first-page":"243","DOI":"10.46586\/tches.v2020.i3.243-268","volume":"2020","author":"MJ Kannwischer","year":"2020","unstructured":"Kannwischer, M.J., Pessl, P., Primas, R.: Single-trace attacks on Keccak. TCHES 2020(3), 243\u2013268 (2020)","journal-title":"TCHES"},{"issue":"6","key":"15_CR18","doi-asserted-by":"publisher","first-page":"43:1","DOI":"10.1145\/2535925","volume":"60","author":"V Lyubashevsky","year":"2013","unstructured":"Lyubashevsky, V., Peikert, C., Regev, O.: On ideal lattices and learning with errors over rings. J. ACM 60(6), 43:1-43:35 (2013)","journal-title":"J. ACM"},{"issue":"3","key":"15_CR19","doi-asserted-by":"publisher","first-page":"565","DOI":"10.1007\/s10623-014-9938-4","volume":"75","author":"A Langlois","year":"2014","unstructured":"Langlois, A., Stehl\u00e9, D.: Worst-case to average-case reductions for module lattices. Des. Codes Crypt. 75(3), 565\u2013599 (2014). https:\/\/doi.org\/10.1007\/s10623-014-9938-4","journal-title":"Des. Codes Crypt."},{"key":"15_CR20","volume-title":"Information Theory, Inference, and Learning Algorithms","author":"DJC MacKay","year":"2003","unstructured":"MacKay, D.J.C.: Information Theory, Inference, and Learning Algorithms. Cambridge University Press, Cambridge (2003)"},{"key":"15_CR21","unstructured":"National Institute of Standards and Technology. NIST Status Update on the 3rd Round. https:\/\/csrc.nist.gov\/CSRC\/media\/Presentations\/status-update-on-the-3rd-round\/images-media\/session-1-moody-nist-round-3-update.pdf"},{"key":"15_CR22","unstructured":"National Institute of Standards and Technology. Post-Quantum Cryptography Standardization. https:\/\/csrc.nist.gov\/Projects\/Post-Quantum-Cryptography\/Post-Quantum-Cryptography-Standardization"},{"issue":"3","key":"15_CR23","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1007\/s13389-016-0128-3","volume":"7","author":"S Ordas","year":"2016","unstructured":"Ordas, S., Guillaume-Sage, L., Maurine, P.: Electromagnetic fault injection: the curse of flip-flops. J. Cryptogr. Eng. 7(3), 183\u2013197 (2016). https:\/\/doi.org\/10.1007\/s13389-016-0128-3","journal-title":"J. Cryptogr. Eng."},{"issue":"1","key":"15_CR24","doi-asserted-by":"publisher","first-page":"142","DOI":"10.46586\/tches.v2018.i1.142-174","volume":"2018","author":"T Oder","year":"2018","unstructured":"Oder, T., Schneider, T., P\u00f6ppelmann, T., G\u00fcneysu, T.: Practical CCA2-secure and masked Ring-LWE implementation. TCHES 2018(1), 142\u2013174 (2018)","journal-title":"TCHES"},{"key":"15_CR25","doi-asserted-by":"crossref","unstructured":"Park, A., Han, D.-G.: Chosen ciphertext Simple Power Analysis on software 8-bit implementation of Ring-LWE encryption. In: 2016 IEEE Asian Hardware-Oriented Security and Trust, AsianHOST 2016, Yilan, Taiwan, 19\u201320 December 2016, pp. 1\u20136. IEEE Computer Society (2016)","DOI":"10.1109\/AsianHOST.2016.7835555"},{"key":"15_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1007\/978-3-030-30530-7_7","volume-title":"Progress in Cryptology \u2013 LATINCRYPT 2019","author":"P Pessl","year":"2019","unstructured":"Pessl, P., Primas, R.: More practical single-trace attacks on the number theoretic transform. In: Schwabe, P., Th\u00e9riault, N. (eds.) LATINCRYPT 2019. LNCS, vol. 11774, pp. 130\u2013149. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-30530-7_7"},{"issue":"2","key":"15_CR27","doi-asserted-by":"publisher","first-page":"37","DOI":"10.46586\/tches.v2021.i2.37-60","volume":"2021","author":"P Pessl","year":"2021","unstructured":"Pessl, P., Prokop, L.: Fault attacks on CCA-secure lattice KEMs. TCHES 2021(2), 37\u201360 (2021)","journal-title":"TCHES"},{"key":"15_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1007\/978-3-319-66787-4_25","volume-title":"Cryptographic Hardware and Embedded Systems \u2013 CHES 2017","author":"R Primas","year":"2017","unstructured":"Primas, R., Pessl, P., Mangard, S.: Single-trace side-channel attacks on masked lattice-based encryption. In: Fischer, W., Homma, N. (eds.) CHES 2017. LNCS, vol. 10529, pp. 513\u2013533. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-66787-4_25"},{"key":"15_CR29","unstructured":"Contributors to PQClean. PQClean. https:\/\/github.com\/PQClean\/PQClean"},{"key":"15_CR30","unstructured":"Ravi, P., Bhasin, S., Roy, S.S., Chattopadhyay, A.: Drop by Drop you break the rock - Exploiting generic vulnerabilities in Lattice-based PKE\/KEMs using EM-based Physical Attacks. IACR Cryptology ePrint Archive, p. 549 (2020)"},{"issue":"3","key":"15_CR31","doi-asserted-by":"publisher","first-page":"307","DOI":"10.46586\/tches.v2020.i3.307-335","volume":"2020","author":"P Ravi","year":"2020","unstructured":"Ravi, P., Roy, S.S., Chattopadhyay, A., Bhasin, S.: Generic side-channel attacks on CCA-secure lattice-based PKE and KEMs. TCHES 2020(3), 307\u2013335 (2020)","journal-title":"TCHES"},{"issue":"2","key":"15_CR32","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1007\/s13389-016-0126-5","volume":"6","author":"O Reparaz","year":"2016","unstructured":"Reparaz, O., Roy, S.S., de Clercq, R., Vercauteren, F., Verbauwhede, I.: Masking Ring-LWE. J. Cryptogr. Eng. 6(2), 139\u2013153 (2016)","journal-title":"J. Cryptogr. Eng."},{"key":"15_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"683","DOI":"10.1007\/978-3-662-48324-4_34","volume-title":"Cryptographic Hardware and Embedded Systems \u2013 CHES 2015","author":"O Reparaz","year":"2015","unstructured":"Reparaz, O., Sinha Roy, S., Vercauteren, F., Verbauwhede, I.: A masked Ring-LWE implementation. In: G\u00fcneysu, T., Handschuh, H. (eds.) CHES 2015. LNCS, vol. 9293, pp. 683\u2013702. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48324-4_34"},{"key":"15_CR34","doi-asserted-by":"crossref","unstructured":"Roscian, C., Sarafianos, A., Dutertre, J.-M., Tria, A.: Fault model analysis of laser-induced faults in SRAM memory cells. In: Fischer, W., Schmidt, J.-M. (eds.) 2013 Workshop on Fault Diagnosis and Tolerance in Cryptography, Los Alamitos, CA, USA, 20 August 2013, pp. 89\u201398. IEEE Computer Society (2013)","DOI":"10.1109\/FDTC.2013.17"},{"key":"15_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1007\/978-3-662-45611-8_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2014","author":"N Veyrat-Charvillon","year":"2014","unstructured":"Veyrat-Charvillon, N., G\u00e9rard, B., Standaert, F.-X.: Soft analytical side-channel attacks. In: Sarkar, P., Iwata, T. (eds.) ASIACRYPT 2014. LNCS, vol. 8873, pp. 282\u2013296. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-45611-8_15"},{"key":"15_CR36","doi-asserted-by":"crossref","unstructured":"Valencia, F., Oder, T., G\u00fcneysu, T., Regazzoni, F.: Exploring the vulnerability of R-LWE encryption to fault attacks. In: Goodacre, J., Luj\u00e1n, M., Agosta, G., Barenghi, A., Koren, I., Pelosi, G. (eds.) Proceedings of the Fifth Workshop on Cryptography and Security in Computing Systems, CS2 2018, Manchester, UK, 24 January 2018, pp. 7\u201312. ACM (2018)","DOI":"10.1145\/3178291.3178294"},{"key":"15_CR37","doi-asserted-by":"crossref","unstructured":"Xagawa, K., Ito, A., Ueno, R., Takahashi, J., Homma, N.: Fault-injection attacks against NIST\u2019s post-quantum cryptography round 3 KEM candidates. IACR Cryptology ePrint Archive 2021, 840 (2021)","DOI":"10.1007\/978-3-030-92075-3_2"}],"container-title":["Lecture Notes in Computer Science","Progress in Cryptology \u2013 INDOCRYPT 2021"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-92518-5_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,12]],"date-time":"2024-03-12T18:36:53Z","timestamp":1710268613000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-92518-5_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030925178","9783030925185"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-92518-5_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"9 December 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"INDOCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Cryptology in India","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Jaipur","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 December 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 December 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"indocrypt2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/indocrypt2021.lnmiit.ac.in\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"65","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"42% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}