{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T22:26:47Z","timestamp":1780352807913,"version":"3.54.1"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031708954","type":"print"},{"value":"9783031708961","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-70896-1_13","type":"book-chapter","created":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T12:03:57Z","timestamp":1725537837000},"page":"259-278","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Key Recovery Attack on\u00a0CRYSTALS-Kyber and\u00a0Saber KEMs in\u00a0Key Reuse Scenario"],"prefix":"10.1007","author":[{"given":"Zhiwei","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jun","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanli","family":"Zou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lei","family":"Hu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,9,6]]},"reference":[{"key":"13_CR1","unstructured":"Submission Requirements and Evaluation Criteria for the Post-Quantum Cryptography Standardization Process. https:\/\/csrc.nist.gov\/CSRC\/media\/Projects\/Post-Quantum-Cryptography\/documents\/call-for-proposals-final-dec-2016.pdf"},{"key":"13_CR2","unstructured":"Albrecht, M.R., et al.: Classic McEliece: conservative code-based cryptography (2020). https:\/\/classic.mceliece.org\/"},{"key":"13_CR3","unstructured":"Aragon, N., et al.: BIKE: bit flipping key encapsulation (2020). https:\/\/bikesuite.org\/"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"Aumasson, J.P., et\u00a0al.: $$SPHINCS^+$$ (2020). https:\/\/sphincs.org\/","DOI":"10.1007\/978-3-030-57682-0_9"},{"key":"13_CR5","unstructured":"Avanzi, R., et al.: CRYSTALS-kyber algorithm specifications and supporting documentation. In: NIST PQC Round, vol. 2, no. 4 (2019). https:\/\/pq-crystals.org\/kyber\/index.shtml"},{"key":"13_CR6","unstructured":"Bai, S., et al.: Crystals-dilithium algorithm specifications and supporting documentation (version 3.1). In: NIST Post-Quantum Cryptography Standardization Round, vol. 3 (2021). https:\/\/pq-crystals.org\/dilithium\/index.shtml"},{"key":"13_CR7","unstructured":"Basso, A., et al.: SABER: Mod-LWR based KEM (Round 3 Submission) (2020). https:\/\/www.esat.kuleuven.be\/cosic\/pqcrypto\/saber\/"},{"key":"13_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"272","DOI":"10.1007\/978-3-030-12612-4_14","volume-title":"Topics in Cryptology \u2013 CT-RSA 2019","author":"A Bauer","year":"2019","unstructured":"Bauer, A., Gilbert, H., Renault, G., Rossi, M.: Assessment of the key-reuse resilience of newhope. In: Matsui, M. (ed.) CT-RSA 2019. LNCS, vol. 11405, pp. 272\u2013292. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-12612-4_14"},{"key":"13_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"747","DOI":"10.1007\/978-3-030-17656-3_26","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2019","author":"C B\u0103etu","year":"2019","unstructured":"B\u0103etu, C., Durak, F.B., Huguenin-Dumittan, L., Talayhan, A., Vaudenay, S.: Misuse attacks on post-quantum cryptosystems. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019. LNCS, vol. 11477, pp. 747\u2013776. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17656-3_26"},{"issue":"4","key":"13_CR10","doi-asserted-by":"publisher","first-page":"5067","DOI":"10.1109\/JSYST.2020.3023808","volume":"15","author":"V Dabra","year":"2021","unstructured":"Dabra, V., Bala, A., Kumari, S.: LBA-PAKE: lattice-based anonymous password authenticated key exchange for mobile devices. IEEE Syst. J. 15(4), 5067\u20135077 (2021). https:\/\/doi.org\/10.1109\/JSYST.2020.3023808","journal-title":"IEEE Syst. J."},{"key":"13_CR11","unstructured":"Ding, J., Branco, P., Schmitt, K.: Key exchange and authenticated key exchange with reusable keys based on RLWE assumption. Cryptology ePrint Archive, Paper 2019\/665 (2019). https:\/\/eprint.iacr.org\/2019\/665"},{"key":"13_CR12","unstructured":"Ding, J., et al.: Rainbow (2020). https:\/\/www.pqcrainbow.org\/"},{"key":"13_CR13","unstructured":"Ding, J., Xie, X., Lin, X.: A simple provably secure key exchange scheme based on the learning with errors problem. Cryptology ePrint Archive (2012)"},{"key":"13_CR14","unstructured":"Dion, A., Aragon, N., Bos, J., et\u00a0al.: Hamming Quasi-Cyclic (2020), https:\/\/pqc-hqc.org"},{"key":"13_CR15","unstructured":"Fouque, P.A., et al.: Falcon: fast-fourier lattice-based compact signatures over NTRU (2020). https:\/\/falcon-sign.info\/"},{"issue":"1","key":"13_CR16","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/s00145-011-9114-1","volume":"26","author":"E Fujisaki","year":"2013","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. J. Cryptol. 26(1), 80\u2013101 (2013)","journal-title":"J. Cryptol."},{"key":"13_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"549","DOI":"10.1007\/978-3-030-65411-5_27","volume-title":"Cryptology and Network Security","author":"A Greuet","year":"2020","unstructured":"Greuet, A., Montoya, S., Renault, G.: Attack on LAC key exchange in misuse situation. In: Krenn, S., Shulman, H., Vaudenay, S. (eds.) CANS 2020. LNCS, vol. 12579, pp. 549\u2013569. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-65411-5_27"},{"key":"13_CR18","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1007\/978-3-031-40003-2_11","volume-title":"Post-Quantum Cryptography","author":"Q Guo","year":"2023","unstructured":"Guo, Q., M\u00e5rtensson, E.: Do not bound to a single position: Near-optimal multi-positional mismatch attacks against kyber and saber. In: Johansson, T., Smith-Tone, D. (eds.) PQCrypto 2023. LNCS, pp. 291\u2013320. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-40003-2_11"},{"key":"13_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1007\/978-3-030-57808-4_11","volume-title":"Applied Cryptography and Network Security","author":"L Huguenin-Dumittan","year":"2020","unstructured":"Huguenin-Dumittan, L., Vaudenay, S.: Classical misuse attacks on NIST round 2 PQC. In: Conti, M., Zhou, J., Casalicchio, E., Spognardi, A. (eds.) ACNS 2020. LNCS, vol. 12146, pp. 208\u2013227. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-57808-4_11"},{"key":"13_CR20","doi-asserted-by":"crossref","unstructured":"Jao, D., et al.: Supersingular isogeny key encapsulation (2020). https:\/\/sike.org\/","DOI":"10.1007\/978-3-642-27739-9_1572-1"},{"key":"13_CR21","unstructured":"Mi, R., Jiang, H., Zhang, Z.: Lattice reduction meets key-mismatch: new misuse attack on lattice-based NIST candidate KEMs. Cryptology ePrint Archive, Paper 2022\/1064 (2022). https:\/\/eprint.iacr.org\/2022\/1064"},{"key":"13_CR22","unstructured":"Moody, D.: Post-quantum cryptography standardization: announcement and outline of NIST\u2019s call for submissions. In: International Conference on Post-Quantum Cryptography-PQCrypto (2016)"},{"key":"13_CR23","unstructured":"Qin, Y., Cheng, C., Ding, J.: An efficient key mismatch attack on the NIST second round candidate kyber. Cryptology ePrint Archive (2019)"},{"key":"13_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1007\/978-3-030-92068-5_4","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"Y Qin","year":"2021","unstructured":"Qin, Y., Cheng, C., Zhang, X., Pan, Y., Hu, L., Ding, J.: A systematic approach and\u00a0analysis of\u00a0key mismatch attacks on\u00a0lattice-based NIST candidate KEMs. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13093, pp. 92\u2013121. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_4"},{"key":"13_CR25","doi-asserted-by":"publisher","first-page":"684","DOI":"10.1109\/TIFS.2021.3139268","volume":"17","author":"P Ravi","year":"2021","unstructured":"Ravi, P., Bhasin, S., Roy, S.S., Chattopadhyay, A.: On exploiting message leakage in (few) NIST PQC candidates for practical message recovery attacks. IEEE Trans. Inf. Forensics Secur. 17, 684\u2013699 (2021)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"13_CR26","doi-asserted-by":"publisher","unstructured":"Ravi, P., Roy, S.S., Chattopadhyay, A., Bhasin, S.: Generic side-channel attacks on CCA-secure lattice-based PKE and KEMs. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2020(3), 307\u2013335 (2020). https:\/\/doi.org\/10.13154\/tches.v2020.i3.307-335","DOI":"10.13154\/tches.v2020.i3.307-335"},{"issue":"6","key":"13_CR27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1568318.1568324","volume":"56","author":"O Regev","year":"2009","unstructured":"Regev, O.: On lattices, learning with errors, random linear codes, and cryptography. J. ACM (JACM) 56(6), 1\u201340 (2009)","journal-title":"J. ACM (JACM)"},{"key":"13_CR28","unstructured":"Shao, M., Liu, Y., Zhou, Y.: Pairwise and parallel: enhancing the key mismatch attacks on kyber and beyond. Cryptology ePrint Archive, Paper 2023\/887 (2023). https:\/\/eprint.iacr.org\/2023\/887"},{"key":"13_CR29","doi-asserted-by":"crossref","unstructured":"Shor, P.W.: Algorithms for quantum computation: discrete logarithms and factoring. In: Proceedings 35th Annual Symposium on Foundations of Computer Science, pp. 124\u2013134. IEEE (1994)","DOI":"10.1109\/SFCS.1994.365700"},{"key":"13_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1007\/978-3-030-88052-1_17","volume-title":"Information and Communications Security","author":"X Zhang","year":"2021","unstructured":"Zhang, X., Cheng, C., Ding, R.: Small leaks sink a great ship: an\u00a0evaluation of key reuse resilience of\u00a0PQC third round finalist NTRU-HRSS. In: Gao, D., Li, Q., Guan, X., Liao, X. (eds.) ICICS 2021. LNCS, vol. 12919, pp. 283\u2013300. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-88052-1_17"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-70896-1_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T20:22:48Z","timestamp":1732738968000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-70896-1_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031708954","9783031708961"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-70896-1_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"6 September 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bydgoszcz","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2024.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}