{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T17:27:24Z","timestamp":1783790844667,"version":"3.55.0"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031411809","type":"print"},{"value":"9783031411816","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-41181-6_9","type":"book-chapter","created":{"date-parts":[[2023,10,3]],"date-time":"2023-10-03T19:02:38Z","timestamp":1696359758000},"page":"159-177","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["Secret Key Recovery Attack on\u00a0Masked and\u00a0Shuffled Implementations of\u00a0CRYSTALS-Kyber and\u00a0Saber"],"prefix":"10.1007","author":[{"given":"Linus","family":"Backlund","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kalle","family":"Ngo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Joel","family":"G\u00e4rtner","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Elena","family":"Dubrova","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,10,4]]},"reference":[{"key":"9_CR1","unstructured":"Announcing the commercial national security algorithm suite 2.0. National Security Agency, U.S Department of Defense (2022). https:\/\/media.defense.gov\/2022\/Sep\/07\/2003071834\/-1\/-1\/0\/CSA_CNSA_2.0_ALGORITHMS_.PDF"},{"key":"9_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1007\/3-540-36400-5_4","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2002","author":"Dakshi Agrawal","year":"2003","unstructured":"Agrawal, Dakshi, Archambeault, Bruce, Rao, Josyula R.., Rohatgi, Pankaj: The EM side\u2014channel(s). In: Kaliski, Burton S.., Ko\u00e7, \u00e7etin K.., Paar, Christof (eds.) CHES 2002. LNCS, vol. 2523, pp. 29\u201345. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/3-540-36400-5_4"},{"key":"9_CR3","doi-asserted-by":"publisher","unstructured":"Azouaoui, M., et al.: Post-quantum authenticated encryption against chosen-ciphertext side-channel attacks. IACR Trans. Cryptogr. Hardw. Embed. Syst. 372\u2013396 (2022). https:\/\/doi.org\/10.46586\/tches.v2022.i4.372-396","DOI":"10.46586\/tches.v2022.i4.372-396"},{"key":"9_CR4","doi-asserted-by":"publisher","unstructured":"Beirendonck, M.V., et al.: A side-channel-resistant implementation of saber. J. Emerg. Technol. Comput. Syst. 17(2) (2021). https:\/\/doi.org\/10.1145\/3429983","DOI":"10.1145\/3429983"},{"key":"9_CR5","doi-asserted-by":"publisher","unstructured":"Bhasin, S., et al.: Attacking and defending masked polynomial comparison for lattice-based cryptography. IACR Trans. Cryptogr. Hardw. Embed. Syst. 334\u2013359 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i3.334-359","DOI":"10.46586\/tches.v2021.i3.334-359"},{"issue":"4","key":"9_CR6","doi-asserted-by":"publisher","first-page":"173","DOI":"10.46586\/tches.v2021.i4.173-214","volume":"2021","author":"JW Bos","year":"2021","unstructured":"Bos, J.W., et al.: Masking kyber: first-and higher-order implementations. IACR Trans. Cryptogr. Hardw. Embed. Syst 2021(4), 173\u2013214 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i4.173-214","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst"},{"key":"9_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"398","DOI":"10.1007\/3-540-48405-1_26","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 99","author":"Suresh Chari","year":"1999","unstructured":"Chari, Suresh, Jutla, Charanjit S.., Rao, Josyula R.., Rohatgi, Pankaj: Towards sound approaches to counteract power-analysis attacks. In: Wiener, Michael (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 398\u2013412. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_26"},{"key":"9_CR8","unstructured":"Chen, C., et al.: NTRU algorithm specifications and supporting documentation (2020). https:\/\/csrc.nist.gov\/projects\/postquantum-cryptography\/round-3-submissions"},{"key":"9_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1007\/978-3-642-04138-9_12","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2009","author":"Jean-S\u00e9bastien Coron","year":"2009","unstructured":"Coron, Jean-S\u00e9bastien., Kizhvatov, Ilya: An efficient method for random delay generation in embedded software. In: Clavier, Christophe, Gaj, Kris (eds.) CHES 2009. LNCS, vol. 5747, pp. 156\u2013170. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-04138-9_12"},{"key":"9_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-030-56880-1_12","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"Dana Dachman-Soled","year":"2020","unstructured":"Dachman-Soled, Dana, Ducas, L\u00e9o., Gong, Huijing, Rossi, M\u00e9lissa.: LWE with side information: attacks and concrete security estimation. In: Micciancio, Daniele, Ristenpart, Thomas (eds.) CRYPTO 2020. LNCS, vol. 12171, pp. 329\u2013358. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56880-1_12"},{"key":"9_CR11","unstructured":"D\u2019Anvers, J., et al.: Saber algorithm specifications and supporting documentation (2020). https:\/\/www.esat.kuleuven.be\/cosic\/pqcrypto\/saber\/files\/saberspecround3.pdf"},{"key":"9_CR12","unstructured":"D\u2019Anvers, J.P., et al.: Revisiting higher-order masked comparison for lattice-based cryptography: algorithms and bit-sliced implementations. Cryptology ePrint Archive, 2022\/110 (2022). https:\/\/eprint.iacr.org\/2022\/110"},{"key":"9_CR13","unstructured":"Heinz, D., et al.: First-order masked Kyber on ARM Cortex-M4. Cryptology ePrint Archive, Report 2022\/058 (2022). https:\/\/eprint.iacr.org\/2022\/058"},{"key":"9_CR14","unstructured":"Hoffmann, C., et al.: Towards leakage-resistant post-quantum CCA-secure public key encryption. Cryptology ePrint Archive, Report 2022\/873 (2022). https:\/\/eprint.iacr.org\/2022\/873"},{"key":"9_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/978-3-319-70500-2_12","volume-title":"Theory of Cryptography","author":"Dennis Hofheinz","year":"2017","unstructured":"Hofheinz, Dennis, H\u00f6velmanns, Kathrin, Kiltz, Eike: A modular analysis of the Fujisaki-Okamoto transformation. In: Kalai, Yael, Reyzin, Leonid (eds.) TCC 2017. LNCS, vol. 10677, pp. 341\u2013371. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70500-2_12"},{"key":"9_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 99","author":"Paul Kocher","year":"1999","unstructured":"Kocher, Paul, Jaffe, Joshua, Jun, Benjamin: Differential power analysis. In: Wiener, Michael (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 388\u2013397. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_25"},{"key":"9_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201996","author":"Paul C. Kocher","year":"1996","unstructured":"Kocher, Paul C..: Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In: Koblitz, Neal (ed.) CRYPTO 1996. LNCS, vol. 1109, pp. 104\u2013113. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68697-5_9"},{"key":"9_CR18","unstructured":"Kundu, S., et al.: Higher-order masked Saber. Cryptology ePrint Archive, Report 2022\/389 (2022). https:\/\/eprint.iacr.org\/2022\/389"},{"key":"9_CR19","unstructured":"Moody, D.: Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process. Nistir 8309, pp. 1\u201327 (2022). https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2022\/NIST.IR.8413.pdf"},{"key":"9_CR20","doi-asserted-by":"publisher","unstructured":"Ngo, K., Dubrova, E., Guo, Q., Johansson, T.: A side-channel attack on a masked IND-CCA secure saber KEM implementation. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2021(4), 676\u2013707 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i4.676-707","DOI":"10.46586\/tches.v2021.i4.676-707"},{"key":"9_CR21","doi-asserted-by":"crossref","unstructured":"Ngo, K., Dubrova, E., Johansson, T.: Breaking masked and shuffled CCA secure saber KEM by power analysis. In: Proceedings of the 5th Workshop on Attacks and Solutions in Hardware Security, pp. 51\u201361. ACM (2021)","DOI":"10.1145\/3474376.3487277"},{"key":"9_CR22","unstructured":"Ngo, K., Wang, R., Dubrova, E., Paulsrud, N.: Side-channel attacks on lattice-based KEMs are not prevented by higher-order masking. Cryptology ePrint Archive, Report 2022\/919 (2022). https:\/\/eprint.iacr.org\/2022\/919"},{"key":"9_CR23","unstructured":"Paulsrud, N.: A side channel attack on a higher-order masked software implementation of saber. Master\u2019s thesis, KTH (2022)"},{"key":"9_CR24","unstructured":"Ravi, P., et al.: On exploiting message leakage in (few) NIST PQC candidates for practical message recovery and key recovery attacks. Crypt. ePrint Arch., 2020\/1559 (2020). https:\/\/eprint.iacr.org\/2020\/1559"},{"key":"9_CR25","unstructured":"Schwabe, P., et al.: CRYSTALS-Kyber algorithm specifications and supporting documentation (2020). https:\/\/csrc.nist.gov\/projects\/postquantum-cryptography\/round-3-submissions"},{"key":"9_CR26","doi-asserted-by":"crossref","unstructured":"Shen, M., et al.: Find the bad apples: an efficient method for perfect key recovery under imperfect SCA oracles - a case study of Kyber. Cryptology ePrint Archive, Report 2022\/563 (2022). https:\/\/eprint.iacr.org\/2022\/563","DOI":"10.46586\/tches.v2023.i1.89-112"},{"key":"9_CR27","unstructured":"Sim, B.Y., et al.: Single-trace attacks on the message encoding of lattice-based kems. Cryptology ePrint Archive, Report 2020\/992 (2020). https:\/\/eprint.iacr.org\/2020\/992"},{"key":"9_CR28","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1109\/OJCS.2022.3198073","volume":"3","author":"TT Tsai","year":"2022","unstructured":"Tsai, T.T., et al.: Leakage-resilient certificate-based authenticated key exchange protocol. IEEE Open J. Comput. Soc. 3, 137\u2013148 (2022). https:\/\/doi.org\/10.1109\/OJCS.2022.3198073","journal-title":"IEEE Open J. Comput. Soc."},{"key":"9_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"740","DOI":"10.1007\/978-3-642-34961-4_44","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2012","author":"Nicolas Veyrat-Charvillon","year":"2012","unstructured":"Veyrat-Charvillon, Nicolas, Medwed, Marcel, Kerckhof, St\u00e9phanie., Standaert, Fran\u00e7ois-Xavier.: Shuffling against side-channel attacks: a comprehensive study with cautionary note. In: Wang, Xiaoyun, Sako, Kazue (eds.) ASIACRYPT 2012. LNCS, vol. 7658, pp. 740\u2013757. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34961-4_44"},{"key":"9_CR30","doi-asserted-by":"crossref","unstructured":"Wang, J., et al.: Practical side-channel attack on masked message encoding in latticed-based KEM. Cryptology ePrint Archive, Report 2022\/859 (2022). https:\/\/eprint.iacr.org\/2022\/859","DOI":"10.1109\/TrustCom56396.2022.00122"},{"key":"9_CR31","doi-asserted-by":"crossref","unstructured":"Wang, R., Ngo, K., Dubrova, E.: A message recovery attack on LWE\/LWR-based PKE\/KEMs using amplitude-modulated EM emanations. In: International Conference on Information Security and Cryptology (2022). https:\/\/eprint.iacr.org\/2022\/852","DOI":"10.1007\/978-3-031-29371-9_22"},{"key":"9_CR32","doi-asserted-by":"crossref","unstructured":"Wang, R., Ngo, K., Dubrova, E.: Side-channel analysis of Saber KEM using amplitude-modulated EM emanations. In: Proceedings of the 25th Euromicro Conference on Digital System Design (2022). https:\/\/eprint.iacr.org\/2022\/807","DOI":"10.1109\/DSD57027.2022.00071"},{"issue":"1\/2","key":"9_CR33","doi-asserted-by":"publisher","first-page":"28","DOI":"10.2307\/2332510","volume":"34","author":"BL Welch","year":"1947","unstructured":"Welch, B.L.: The generalization of \u2018Student\u2019s\u2019 problem when several different population variances are involved. Biometrika 34(1\/2), 28\u201335 (1947)","journal-title":"Biometrika"},{"key":"9_CR34","doi-asserted-by":"publisher","unstructured":"Xu, Z., et al.: Magnifying side-channel leakage of lattice-based cryptosystems with chosen ciphertexts: the case study of Kyber. Cryptology ePrint Archive, Paper 2020\/912 (2020). https:\/\/doi.org\/10.1109\/TC.2021.3122997","DOI":"10.1109\/TC.2021.3122997"},{"issue":"10","key":"9_CR35","doi-asserted-by":"publisher","first-page":"15","DOI":"10.3390\/e24101489","volume":"24","author":"C Yajing","year":"2022","unstructured":"Yajing, C., et al.: Template attack of LWE\/LWR-based schemes with cyclic message rotation. Entropy 24(10), 15 (2022). https:\/\/doi.org\/10.3390\/e24101489","journal-title":"Entropy"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-41181-6_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,3]],"date-time":"2023-10-03T19:03:51Z","timestamp":1696359831000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-41181-6_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031411809","9783031411816"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-41181-6_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"4 October 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Kyoto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 June 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 June 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/sulab-sever.u-aizu.ac.jp\/ACNS2023\/committees.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"263","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"53","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"20% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.9","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"14.2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"For the workshops 34 full papers have been accepted from a total of 73 submissions; 13 poster papers are also included.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}