{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T11:20:35Z","timestamp":1778152835017,"version":"3.51.4"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031330162","type":"print"},{"value":"9783031330179","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-33017-9_7","type":"book-chapter","created":{"date-parts":[[2023,5,18]],"date-time":"2023-05-18T12:02:32Z","timestamp":1684411352000},"page":"109-128","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["A Side-Channel Secret Key Recovery Attack on\u00a0CRYSTALS-Kyber Using k Chosen Ciphertexts"],"prefix":"10.1007","author":[{"given":"Ruize","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elena","family":"Dubrova","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,5,19]]},"reference":[{"key":"7_CR1","unstructured":"Announcing the commercial national security algorithm suite 2.0. National Security Agency, U.S Department of Defense, September 2022. https:\/\/media.defense.gov\/2022\/Sep\/07\/2003071834\/-1\/-1\/0\/CSA_CNSA_2.0_ALGORITHMS_.PDF"},{"key":"7_CR2","doi-asserted-by":"crossref","unstructured":"Azouaoui, M., Kuzovkova, Y., Schneider, T., van Vredendaal, C.: Post-quantum authenticated encryption against chosen-ciphertext side-channel attacks. Cryptology ePrint Archive, Paper 2022\/916 (2022). https:\/\/eprint.iacr.org\/2022\/916","DOI":"10.46586\/tches.v2022.i4.372-396"},{"key":"7_CR3","unstructured":"Backlund, L., Ngo, K., Gartner, J., Dubrova, E.: Secret key recovery attacks on masked and shuffled implementations of CRYSTALS-Kyber and Saber. Cryptology ePrint Archive, Paper 2022\/1692 (2022). https:\/\/eprint.iacr.org\/2022\/1692"},{"key":"7_CR4","doi-asserted-by":"crossref","unstructured":"Bhasin, S., D\u2019Anvers, J.P., Heinz, D., P\u00f6ppelmann, T., Beirendonck, M.V.: Attacking and defending masked polynomial comparison for lattice-based cryptography. Cryptology ePrint Archive, Paper 2021\/104 (2021). https:\/\/eprint.iacr.org\/2021\/104","DOI":"10.46586\/tches.v2021.i3.334-359"},{"key":"7_CR5","doi-asserted-by":"publisher","unstructured":"Bos, J.W., Gourjon, M., Renes, J., Schneider, T., van Vredendaal, C.: Masking kyber: first- and higher-order implementations. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2021(4), 173\u2013214 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i4.173-214","DOI":"10.46586\/tches.v2021.i4.173-214"},{"key":"7_CR6","unstructured":"CW308 UFO Board. https:\/\/rtfm.newae.com\/Targets\/CW308"},{"key":"7_CR7","unstructured":"CW308T-STM32F4 target board. https:\/\/rtfm.newae.com\/Targets\/UFO"},{"key":"7_CR8","unstructured":"D\u2019Anvers, J.P., Beirendonck, M.V., Verbauwhede, I.: Revisiting higher-order masked comparison for lattice-based cryptography: algorithms and bit-sliced implementations. Cryptology ePrint Archive, Paper 2022\/110 (2022). https:\/\/eprint.iacr.org\/2022\/110"},{"key":"7_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/3-540-48405-1_34","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 99","author":"E Fujisaki","year":"1999","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 537\u2013554. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_34"},{"key":"7_CR10","doi-asserted-by":"publisher","unstructured":"Hamburg, M., et al.: Chosen ciphertext k-trace attacks on masked cca2 secure kyber. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2021(4), 88\u2013113 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i4.88-113","DOI":"10.46586\/tches.v2021.i4.88-113"},{"key":"7_CR11","unstructured":"Heinz, D., Kannwischer, M.J., Land, G., P\u00f6ppelmann, T., Schwabe, P., Sprenkels, D.: First-order masked Kyber on ARM Cortex-M4. Cryptology ePrint Archive, Paper 2022\/058 (2022). https:\/\/eprint.iacr.org\/2022\/058"},{"key":"7_CR12","unstructured":"Hoffmann, C., Libert, B., Momin, C., Peters, T., Standaert, F.X.: Towards leakage-resistant post-quantum CCA-secure public key encryption. Cryptology ePrint Archive, Paper 2022\/873 (2022). https:\/\/eprint.iacr.org\/2022\/873"},{"key":"7_CR13","unstructured":"Ji, Y., Wang, R., Ngo, K., Dubrova, E., Backlund, L.: A side-channel attack on a hardware implementation of CRYSTALS-Kyber. Cryptology ePrint Archive, Paper 2022\/1452 (2022). https:\/\/eprint.iacr.org\/2022\/1452"},{"key":"7_CR14","unstructured":"Kannwischer, M.J., Petri, R., Rijneveld, J., Schwabe, P., Stoffelen, K.: PQM4: post-quantum crypto library for the ARM Cortex-M4. https:\/\/github.com\/mupq\/pqm4"},{"key":"7_CR15","unstructured":"Moody, D.: Status report on the third round of the NIST post-quantum cryptography standardization process. Nistir 8309, pp. 1\u201327 (2022). https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2022\/NIST.IR.8413.pdf"},{"key":"7_CR16","doi-asserted-by":"crossref","unstructured":"Mu, J., et al.: A voltage template attack on the modular polynomial subtraction in Kyber. In: 2022 27th Asia and South Pacific Design Automation Conference (ASP-DAC), pp. 672\u2013677. IEEE (2022)","DOI":"10.1109\/ASP-DAC52403.2022.9712513"},{"key":"7_CR17","doi-asserted-by":"crossref","unstructured":"Mujdei, C., Beckers, A., Mera, J.M.B., Karmakar, A., Wouters, L., Verbauwhede, I.: Side-channel analysis of lattice-based post-quantum cryptography: Exploiting polynomial multiplication. Cryptology ePrint Archive, Report 2022\/474 (2022). https:\/\/eprint.iacr.org\/2022\/474","DOI":"10.1145\/3569420"},{"key":"7_CR18","unstructured":"NewAE Technology Inc.: Chipwhisperer. https:\/\/newae.com\/tools\/chipwhisperer"},{"issue":"4","key":"7_CR19","doi-asserted-by":"publisher","first-page":"676","DOI":"10.46586\/tches.v2021.i4.676-707","volume":"2021","author":"K Ngo","year":"2021","unstructured":"Ngo, K., Dubrova, E., Guo, Q., Johansson, T.: A side-channel attack on a masked IND-CCA secure saber KEM implementation. IACR Trans. Cryptographic Hardware Embed. Syst. 2021(4), 676\u2013707 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i4.676-707","journal-title":"IACR Trans. Cryptographic Hardware Embed. Syst."},{"key":"7_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1007\/978-3-030-30530-7_7","volume-title":"Progress in Cryptology \u2013 LATINCRYPT 2019","author":"P Pessl","year":"2019","unstructured":"Pessl, P., Primas, R.: More practical single-trace attacks on the number theoretic transform. In: Schwabe, P., Th\u00e9riault, N. (eds.) LATINCRYPT 2019. LNCS, vol. 11774, pp. 130\u2013149. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-30530-7_7"},{"key":"7_CR21","doi-asserted-by":"publisher","first-page":"684","DOI":"10.1109\/TIFS.2021.3139268","volume":"17","author":"P Ravi","year":"2022","unstructured":"Ravi, P., Bhasin, S., Roy, S.S., Chattopadhyay, A.: On exploiting message leakage in (Few) NIST PQC candidates for practical message recovery attacks. IEEE Trans. Inf. Forensics Secur. 17, 684\u2013699 (2022). https:\/\/doi.org\/10.1109\/TIFS.2021.3139268","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"7_CR22","unstructured":"Rodriguez, R.C., Bruguier, F., Valea, E., Benoit, P.: Correlation electromagnetic analysis on an FPGA implementation of CRYSTALS-Kyber. Cryptology ePrint Archive, Paper 2022\/1361 (2022). https:\/\/eprint.iacr.org\/2022\/1361, https:\/\/eprint.iacr.org\/2022\/1361"},{"key":"7_CR23","unstructured":"Schwabe, P., et al.: CRYSTALS-Kyber algorithm specifications and supporting documentation (2020). https:\/\/pq-crystals.org\/kyber\/data\/kyber-specification-round3-20210131.pdf"},{"key":"7_CR24","doi-asserted-by":"crossref","unstructured":"Shen, M., Cheng, C., Zhang, X., Guo, Q., Jiang, T.: Find the bad apples: an efficient method for perfect key recovery under imperfect SCA oracles - a case study of Kyber. Cryptology ePrint Archive, Paper 2022\/563 (2022). https:\/\/eprint.iacr.org\/2022\/563","DOI":"10.46586\/tches.v2023.i1.89-112"},{"key":"7_CR25","doi-asserted-by":"publisher","first-page":"183175","DOI":"10.1109\/ACCESS.2020.3029521","volume":"8","author":"BY Sim","year":"2020","unstructured":"Sim, B.Y., et al.: Single-trace attacks on message encoding in lattice-based KEMs. IEEE Access 8, 183175\u2013183191 (2020)","journal-title":"IEEE Access"},{"key":"7_CR26","doi-asserted-by":"publisher","unstructured":"Sim, B.-Y., Park, A., Han, D.-G.: Chosen-ciphertext clustering attack on CRYSTALS-KYBER using the side-channel leakage of barrett reduction. IEEE Internet Things J. 9(21), 21382\u201321397 (2022). https:\/\/doi.org\/10.1109\/JIOT.2022.3179683","DOI":"10.1109\/JIOT.2022.3179683"},{"key":"7_CR27","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1109\/OJCS.2022.3198073","volume":"3","author":"TT Tsai","year":"2022","unstructured":"Tsai, T.T., Huang, S.S., Tseng, Y.M., Chuang, Y.H., Hung, Y.H.: Leakage-resilient certificate-based authenticated key exchange protocol. IEEE Open J. Comput. Soc. 3, 137\u2013148 (2022). https:\/\/doi.org\/10.1109\/OJCS.2022.3198073","journal-title":"IEEE Open J. Comput. Soc."},{"key":"7_CR28","doi-asserted-by":"publisher","unstructured":"Ueno, R., Xagawa, K., Tanaka, Y., Ito, A., Takahashi, J., Homma, N.: Curse of re-encryption: a generic power\/EM analysis on post-quantum KEMs. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2022(1), 296\u2013322 (2021). https:\/\/doi.org\/10.46586\/tches.v2022.i1.296-322","DOI":"10.46586\/tches.v2022.i1.296-322"},{"key":"7_CR29","doi-asserted-by":"crossref","unstructured":"Wang, J., Cao, W., Chen, H., Li, H.: Practical side-channel attack on masked message encoding in latticed-based KEM. Cryptology ePrint Archive, Paper 2022\/859 (2022). https:\/\/eprint.iacr.org\/2022\/859","DOI":"10.1109\/TrustCom56396.2022.00122"},{"key":"7_CR30","doi-asserted-by":"crossref","unstructured":"Wang, R., Ngo, K., Dubrova, E.: A message recovery attack on LWE\/LWR-based PKE\/KEMs using amplitude-modulated EM emanations. In: Proceedings of the 25th Annual International Conference on Information Security and Cryptology (2022). https:\/\/eprint.iacr.org\/2022\/852","DOI":"10.1007\/978-3-031-29371-9_22"},{"issue":"1\u20132","key":"7_CR31","first-page":"28","volume":"34","author":"BL Welch","year":"1947","unstructured":"Welch, B.L.: The generalization of \u2018Student\u2019s\u2019 problem when several different population variances are involved. Biometrika 34(1\u20132), 28\u201335 (1947)","journal-title":"Biometrika"},{"issue":"9","key":"7_CR32","doi-asserted-by":"publisher","first-page":"2163","DOI":"10.1109\/TC.2021.3122997","volume":"71","author":"Z Xu","year":"2022","unstructured":"Xu, Z., Pemberton, O., Roy, S.S., Oswald, D., Yao, W., Zheng, Z.: Magnifying side-channel leakage of lattice-based cryptosystems with chosen ciphertexts: the case study of Kyber. IEEE Trans. Comput. 71(9), 2163\u20132176 (2022). https:\/\/doi.org\/10.1109\/TC.2021.3122997","journal-title":"IEEE Trans. Comput."},{"key":"7_CR33","doi-asserted-by":"publisher","first-page":"1489","DOI":"10.3390\/e24101489","volume":"24","author":"Y Chang","year":"2022","unstructured":"Chang, Y., Yan, Y., Zhu, C., Guo, P.: Template attack of LWE\/LWR-based schemes with cyclic message rotation. Entropy 24, 1489 (2022). https:\/\/doi.org\/10.3390\/e24101489","journal-title":"Entropy"}],"container-title":["Lecture Notes in Computer Science","Codes, Cryptology and Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-33017-9_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,5]],"date-time":"2024-03-05T16:05:44Z","timestamp":1709654744000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-33017-9_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031330162","9783031330179"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-33017-9_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"19 May 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"C2SI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Codes, Cryptology, and Information Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rabat","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Morocco","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 May 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31 May 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"c2si2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.c2si-conference.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easy Chair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"62","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"21","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"34% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3 (invited papers from invited speakers)","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}