{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T18:23:21Z","timestamp":1740162201805,"version":"3.37.3"},"reference-count":63,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2023,4,25]],"date-time":"2023-04-25T00:00:00Z","timestamp":1682380800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,4,25]],"date-time":"2023-04-25T00:00:00Z","timestamp":1682380800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100009527","name":"Myndigheten f\u00f6r Samh\u00e4llsskydd och Beredskap","doi-asserted-by":"publisher","award":["2020-11632"],"award-info":[{"award-number":["2020-11632"]}],"id":[{"id":"10.13039\/100009527","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004359","name":"Vetenskapsr\u00e5det","doi-asserted-by":"publisher","award":["2018-04482","2019-04166"],"award-info":[{"award-number":["2018-04482","2019-04166"]}],"id":[{"id":"10.13039\/501100004359","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001729","name":"Stiftelsen f\u00f6r Strategisk Forskning","doi-asserted-by":"publisher","award":["RIT17-0005"],"award-info":[{"award-number":["RIT17-0005"]}],"id":[{"id":"10.13039\/501100001729","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2023,11]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>In this paper, we show that a software implementation of IND-CCA-secure Saber key encapsulation mechanism protected by first-order masking and shuffling can be broken by deep learning-based power analysis. Using an ensemble of deep neural networks trained at the profiling stage, we can recover the session key and the secret key from <jats:inline-formula><jats:alternatives><jats:tex-math>$$257 \\times N$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mn>257<\/mml:mn>\n                    <mml:mo>\u00d7<\/mml:mo>\n                    <mml:mi>N<\/mml:mi>\n                  <\/mml:mrow>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula> and <jats:inline-formula><jats:alternatives><jats:tex-math>$$24 \\times 257 \\times N$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mn>24<\/mml:mn>\n                    <mml:mo>\u00d7<\/mml:mo>\n                    <mml:mn>257<\/mml:mn>\n                    <mml:mo>\u00d7<\/mml:mo>\n                    <mml:mi>N<\/mml:mi>\n                  <\/mml:mrow>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula> traces, respectively, where <jats:italic>N<\/jats:italic> is the number of repetitions of the same measurement. The value of <jats:italic>N<\/jats:italic> depends on the implementation of the algorithm, the type of device under attack, environmental factors, acquisition noise, etc.; in our experiments <jats:inline-formula><jats:alternatives><jats:tex-math>$$N = 10$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mi>N<\/mml:mi>\n                    <mml:mo>=<\/mml:mo>\n                    <mml:mn>10<\/mml:mn>\n                  <\/mml:mrow>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula> is sufficient for a successful attack. The neural networks are trained on a combination of 80% of traces from the profiling device with a known shuffling order and 20% of traces from the device under attack captured for all-0 and all-1 messages. \u201cSpicing\u201d the training set with traces from the device under attack helps us minimize the negative effect of inter-device variability.\n<\/jats:p>","DOI":"10.1007\/s13389-023-00315-3","type":"journal-article","created":{"date-parts":[[2023,4,25]],"date-time":"2023-04-25T14:04:34Z","timestamp":1682431474000},"page":"443-460","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A side-channel attack on a masked and shuffled software implementation of Saber"],"prefix":"10.1007","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9842-2038","authenticated-orcid":false,"given":"Kalle","family":"Ngo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elena","family":"Dubrova","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas","family":"Johansson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,4,25]]},"reference":[{"key":"315_CR1","doi-asserted-by":"crossref","unstructured":"Agrawal, D., Archambeault, B., Rao, J.R., Rohatgi, P.: The EM side-channel(s). In: Cryptographic Hardware and Embedded Systems, pp. 29\u201345 (2003)","DOI":"10.1007\/3-540-36400-5_4"},{"key":"315_CR2","doi-asserted-by":"crossref","unstructured":"Amiet, D., Curiger, A., Leuenberger, L., Zbinden, P.:Defeating NewHope with a single trace. In: International Conference on Post-Quantum Cryptography, pp. 189\u2013205. Springer (2020). https:\/\/doi.org\/10.1007\/978-3-030-44223-1_11","DOI":"10.1007\/978-3-030-44223-1_11"},{"key":"315_CR3","doi-asserted-by":"crossref","unstructured":"Archambeau, C., Peeters, E., Standaert, F.X., Quisquater, J.J.: Template attacks in principal subspaces. In: Cryptographic Hardware and Embedded Systems, pp. 1\u201314 (2006)","DOI":"10.1007\/11894063_1"},{"key":"315_CR4","unstructured":"Avanzi, R.M., Bos, J.W., Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V., Schanck, J.M., Schwabe, P., Seiler, G., Stehl\u00e9, D.: CRYSTALS-Kyber algorithm specifications and supporting documentation (2020)"},{"key":"315_CR5","doi-asserted-by":"publisher","first-page":"354","DOI":"10.1007\/978-3-319-78375-8_12","volume-title":"Advances in Cryptology - EUROCRYPT 2018","author":"G Barthe","year":"2018","unstructured":"Barthe, G., Bela\u00efd, S., Espitau, T., Fouque, P.-A., Gr\u00e9goire, B., Rossi, M., Tibouchi, M.: Masking the GLP lattice-based signature scheme at any order. In: Nielsen, J.B., Rijmen, V. (eds.) Advances in Cryptology - EUROCRYPT 2018, pp. 354\u2013384. Springer International Publishing, Cham (2018)"},{"key":"315_CR6","unstructured":"Beirendonck, M.V., D\u2019Anvers, J-P., Karmakar, A., Balasch, J., Verbauwhede, I.: A side-channel resistant implementation of SABER. Cryptology ePrint Archive, Report 2020\/733 (2020). https:\/\/eprint.iacr.org\/2020\/733"},{"issue":"4","key":"315_CR7","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3281662","volume":"16","author":"N Belleville","year":"2018","unstructured":"Belleville, N., Courousse, D., Heydemann, K., Charles, H.-P.: Automated software protection for the masses against side-channel attacks. ACM Trans. Archit. Code Optim. 16(4), 1 (2018)","journal-title":"ACM Trans. Archit. Code Optim."},{"key":"315_CR8","doi-asserted-by":"crossref","unstructured":"Bhasin, S., D\u2019Anvers, J-P., Heinz, D., P\u00f6ppelmann, T., Van Beirendonck, M.: Attacking and defending masked polynomial comparison for lattice-based cryptography. Cryptology ePrint Archive, Paper 2021\/104 (2021). https:\/\/eprint.iacr.org\/2021\/104","DOI":"10.46586\/tches.v2021.i3.334-359"},{"key":"315_CR9","doi-asserted-by":"crossref","unstructured":"Bhasin, S., D\u2019Anvers, J-P., Heinz, D., P\u00f6ppelmann, T., Van\u00a0Beirendonck, M.: Attacking and defending masked polynomial comparison for lattice-based cryptography. IACR Trans. Cryptogr. Hardw. Embed. Syst. 3, 334\u2013359 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i3.334-359","DOI":"10.46586\/tches.v2021.i3.334-359"},{"key":"315_CR10","doi-asserted-by":"crossref","unstructured":"Brisfors, M., Forsmark, S., Dubrova, E.: How deep learning helps compromising USIM. In: Proceedings of the 19th Smart Card Research and Advanced Application Conference (CARDIS\u20192020) (2020)","DOI":"10.1007\/978-3-030-68487-7_9"},{"key":"315_CR11","doi-asserted-by":"crossref","unstructured":"Brumley, B.B., Hakala, R.M., Nyberg, K., Sovio, S.: Consecutive S-box lookups: a timing attack on SNOW 3G. In: Soriano, M., Qing, S., L\u00f3pez, J. (eds.) Information and Communications Security, pp. 171\u2013185. Springer, Berlin, Heidelberg (2010)","DOI":"10.1007\/978-3-642-17650-0_13"},{"key":"315_CR12","doi-asserted-by":"crossref","unstructured":"Cagli, E, Dumas, C., Prouff, E.: Convolutional neural networks with data augmentation against jitter-based countermeasures. In: Cryptographic Hardware and Embedded Systems - CHES 2017, pp. 45\u201368 (2017)","DOI":"10.1007\/978-3-319-66787-4_3"},{"key":"315_CR13","doi-asserted-by":"crossref","unstructured":"Camurati, G., Poeplau, S., Muench, M., Hayes, T., Francillon, A.: Screaming channels: when electromagnetic side channels meet radio transceivers. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp. 163\u2013177 (2018)","DOI":"10.1145\/3243734.3243802"},{"key":"315_CR14","doi-asserted-by":"crossref","unstructured":"Chari, S., Jutla, C.S., Rao, J.R., Rohatgi, P.: Towards sound approaches to counteract power-analysis attacks. In: Advances in Cryptology - CRYPTO \u201999, 19th Annual International Cryptology Conference, USA, vol.\u00a01666, pp. 398\u2013412. Springer (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_26","DOI":"10.1007\/3-540-48405-1_26"},{"key":"315_CR15","unstructured":"Chen, C., Danba, O., Stein, J., H\u00fclsing, A., Rijneveld, J., Schanck, J.M., Schwabe, P., Whyte, W., Zhang, Z.: NTRU algorithm specifications and supporting documentation (2020). https:\/\/csrc.nist.gov\/projects\/postquantum-cryptography\/round-3-submissions"},{"key":"315_CR16","doi-asserted-by":"crossref","unstructured":"Coron, J., Kizhvatov, I.: An efficient method for random delay generation in embedded software. In: Clavier, C., Gaj, K. (eds.) Cryptographic Hardware and Embedded Systems - CHES 2009, pp. 156\u2013170. Springer, Berlin, Heidelberg (2009)","DOI":"10.1007\/978-3-642-04138-9_12"},{"key":"315_CR17","unstructured":"CW308 UFO Target. [n.d.]. https:\/\/wiki.newae.com\/CW308_UFO_Target. Accessed 2022"},{"key":"315_CR18","unstructured":"D\u2019Anvers, J., et\u00a0al.: SABER algorithm specifications and supporting documentation (2020). https:\/\/csrc.nist.gov\/projects\/postquantum-cryptography\/round-3-submissions"},{"key":"315_CR19","unstructured":"Dozat, T.: Incorporating nesterov momentum into adam (2016)"},{"issue":"7","key":"315_CR20","doi-asserted-by":"publisher","first-page":"420","DOI":"10.1145\/364520.364540","volume":"7","author":"R Durstenfeld","year":"1964","unstructured":"Durstenfeld, R.: Algorithm 235: random permutation. Commun. ACM 7(7), 420 (1964). https:\/\/doi.org\/10.1145\/364520.364540","journal-title":"Commun. ACM"},{"issue":"1","key":"315_CR21","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/s00145-011-9114-1","volume":"26","author":"E Fujisaki","year":"2013","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. J. Cryptol. 26(1), 80\u2013101 (2013). https:\/\/doi.org\/10.1007\/s00145-011-9114-1","journal-title":"J. Cryptol."},{"key":"315_CR22","doi-asserted-by":"crossref","unstructured":"G\u00e9rard, F., Rossi, M.: An efficient and provable masked implementation of qTESLA. In: International Conference on Smart Card Research and Advanced Applications, pp. 74\u201391. Springer (2019)","DOI":"10.1007\/978-3-030-42068-0_5"},{"key":"315_CR23","unstructured":"Goodfellow, I., Bengio, Y., Courville, A.: Deep Learning. MIT Press (2016). http:\/\/www.deeplearningbook.org"},{"key":"315_CR24","unstructured":"Goodwill, G., Jun, B., Jaffe, J., Rohatgi, P.: A testing methodology for side-channel resistance validation. In: NIST Non-Invasive Attack Testing Workshop, vol. 7, pp. 115\u2013136 (2011)"},{"key":"315_CR25","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-030-56880-1_13","volume-title":"Advances in Cryptology - CRYPTO 2020","author":"Q Guo","year":"2020","unstructured":"Guo, Q., Johansson, T., Nilsson, A.: A key-recovery timing attack on post-quantum primitives using the Fujisaki-Okamoto transformation and its application on FrodoKEM. In: Micciancio, D., Ristenpart, T. (eds.) Advances in Cryptology - CRYPTO 2020, pp. 359\u2013386. Springer International Publishing, Cham (2020)"},{"key":"315_CR26","doi-asserted-by":"crossref","unstructured":"Guo, Q., Johansson, T., Nilsson, A.: A key-recovery timing attack on post-quantum primitives using the Fujisaki-Okamoto transformation and its application on FrodoKEM. In: Advances in Cryptology - CRYPTO 2020: 40th Annual International Cryptology Conference, CRYPTO 2020, Santa Barbara, CA, USA, August 17\u201321, 2020, Proceedings, Part II. Santa Barbara, CA, USA, pp. 359-386. Springer, Berlin, Heidelberg (2020). https:\/\/doi.org\/10.1007\/978-3-030-56880-1_13","DOI":"10.1007\/978-3-030-56880-1_13"},{"key":"315_CR27","doi-asserted-by":"crossref","unstructured":"Hoffman, C., Gebotys, C., Aranha, D.F., Cortes, M., Ara\u00fajo, G.: Circumventing uniqueness of XOR Arbiter PUFs. In: 2019 22nd Euromicro Conference on Digital System Design (DSD), pp. 222\u2013229 (2019). https:\/\/doi.org\/10.1109\/DSD.2019.00041","DOI":"10.1109\/DSD.2019.00041"},{"key":"315_CR28","doi-asserted-by":"crossref","unstructured":"Hofheinz, D., H\u00f6velmanns, K., Kiltz, E.: A modular analysis of the Fujisaki-Okamoto transformation. In: Theory of Cryptography: 15th International Conference, TCC 2017, Baltimore, MD, USA, November 12\u201315, 2017, Proceedings, Part I, Baltimore, USA, pp. 341-371 Springer, Berlin, Heidelberg (2017). https:\/\/doi.org\/10.1007\/978-3-319-70500-2_12","DOI":"10.1007\/978-3-319-70500-2_12"},{"issue":"3","key":"315_CR29","doi-asserted-by":"publisher","first-page":"148","DOI":"10.46586\/tches.v2019.i3.148-179","volume":"2019","author":"J Kim","year":"2019","unstructured":"Kim, J., Picek, S., Heuser, A., Bhasin, S., Hanjalic, A.: Make some noise. Unleashing the power of convolutional neural networks for profiled side-channel analysis. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2019(3), 148\u2013179 (2019)","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"315_CR30","doi-asserted-by":"crossref","unstructured":"Kocher, P., Jaffe, J., Jun, B.: Differential power analysis. In: Annual International Cryptology Conference, pp. 388\u2013397. Springer (1999)","DOI":"10.1007\/3-540-48405-1_25"},{"key":"315_CR31","doi-asserted-by":"crossref","unstructured":"Kocher, P.C.: Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In: Koblitz, N. (ed.) Advances in Cryptology \u2014 CRYPTO \u201996, pp. 104\u2013113. Springer, Berlin, Heidelberg (1996)","DOI":"10.1007\/3-540-68697-5_9"},{"key":"315_CR32","doi-asserted-by":"crossref","unstructured":"Maghrebi, H., Portigliatti, T., Prouff, E.: Breaking cryptographic implementations using deep learning techniques. In: Security, Privacy, and Applied Cryptography Engineering. Springer International Publishing (2016)","DOI":"10.1007\/978-3-319-49445-6_1"},{"key":"315_CR33","doi-asserted-by":"crossref","unstructured":"Maghrebi, H., Servant, V., Bringer, J.: There is wisdom in harnessing the strengths of your enemy: customized encoding to thwart side-channel attacks. In: Peyrin, T. (ed.) Fast Software Encryption, pp. 223\u2013243. Springer, Berlin, Heidelberg (2016)","DOI":"10.1007\/978-3-662-52993-5_12"},{"key":"315_CR34","doi-asserted-by":"crossref","unstructured":"Masure, Lo\u00efc., Belleville, N., Cagli, E., Cornelie, M-A., Courouss\u00e9, D., Dumas, C., Maingault, L.: Deep learning side-channel analysis on large-scale traces - a case study on a polymorphic AES. Cryptology ePrint Archive, Paper 2020\/881 (2020). https:\/\/eprint.iacr.org\/2020\/881","DOI":"10.1007\/978-3-030-58951-6_22"},{"key":"315_CR35","doi-asserted-by":"crossref","unstructured":"Migliore, V., G\u00e9rard, B., Tibouchi, M., Fouque, P-A.: Masking dilithium. In: Deng, R.H., Gauthier-Uma\u00f1a, V., Ochoa, M., Yung, M. (eds.) Applied Cryptography and Network Security, pp. 344\u2013362. Springer International Publishing, Cham (2019)","DOI":"10.1007\/978-3-030-21568-2_17"},{"key":"315_CR36","unstructured":"Moody, D.: Status report on the third round of the NIST post-quantum cryptography standardization process. Nistir 8309, pp. 1\u201327 (2022). https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2022\/NIST.IR.8413.pdf"},{"key":"315_CR37","doi-asserted-by":"crossref","unstructured":"Mujdei, C., Beckers, A., Mera, J.M.B., Karmakar, A., Wouters, L., Verbauwhede, I.: Side-channel analysis of lattice-based post-quantum cryptography: exploiting polynomial multiplication. Cryptology ePrint Archive, Paper 2022\/474 (2022). https:\/\/eprint.iacr.org\/2022\/474","DOI":"10.1145\/3569420"},{"key":"315_CR38","unstructured":"NewAE Technology Inc. [n.d.]. ChipWhisperer. https:\/\/newae.com\/tools\/chipwhisperer. Accessed 2022"},{"key":"315_CR39","doi-asserted-by":"crossref","unstructured":"Ngo, K., Dubrova, E.: Side-channel analysis of the random number generator in STM32 MCUs. In: Proceedings of the Great Lakes Symposium on VLSI (GLSVLSI \u201922) (2022). https:\/\/doi.org\/10.1145\/3526241.3530324","DOI":"10.1145\/3526241.3530324"},{"issue":"4","key":"315_CR40","doi-asserted-by":"publisher","first-page":"676","DOI":"10.46586\/tches.v2021.i4.676-707","volume":"2021","author":"K Ngo","year":"2021","unstructured":"Ngo, K., Dubrova, E., Guo, Q., Johansson, T.: A side-channel attack on a masked IND-CCA secure saber KEM implementation. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2021(4), 676\u2013707 (2021). https:\/\/doi.org\/10.46586\/tches.v2021.i4.676-707","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"315_CR41","doi-asserted-by":"crossref","unstructured":"Ngo, K., Dubrova, E., Johansson, T.: Breaking Masked and Shuffled CCA Secure Saber KEM by Power Analysis, pp. 51-61, Association for Computing Machinery, New York, NY, USA (2021). https:\/\/doi.org\/10.1145\/3474376.3487277","DOI":"10.1145\/3474376.3487277"},{"issue":"1","key":"315_CR42","doi-asserted-by":"publisher","first-page":"142","DOI":"10.13154\/tches.v2018.i1.142-174","volume":"2018","author":"T Oder","year":"2018","unstructured":"Oder, T., Schneider, T., P\u00f6ppelmann, T., G\u00fcneysu, T.: Practical CCA2-secure and masked ring-LWE implementation. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2018(1), 142\u2013174 (2018). https:\/\/doi.org\/10.13154\/tches.v2018.i1.142-174","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"issue":"4","key":"315_CR43","doi-asserted-by":"publisher","first-page":"337","DOI":"10.46586\/tches.v2020.i4.337-364","volume":"2020","author":"G Perin","year":"2020","unstructured":"Perin, G., Chmielewski, \u0141, Picek, S.: Strength in numbers: improving generalization with ensembles in machine learning-based profiled side-channel analysis. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2020(4), 337\u2013364 (2020)","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"315_CR44","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1007\/978-3-319-66787-4_25","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2017","author":"R Primas","year":"2017","unstructured":"Primas, R., Pessl, P., Mangard, S.: Single-trace side-channel attacks on masked lattice-based encryption. In: Fischer, W., Homma, N. (eds.) Cryptographic Hardware and Embedded Systems - CHES 2017, pp. 513\u2013533. Springer International Publishing, Cham (2017)"},{"key":"315_CR45","unstructured":"Ravi, P., Bhasin, S., Roy, S.S., Chattopadhyay, A.: On exploiting message leakage in (few) NIST PQC candidates for practical message recovery and key recovery attacks. Cryptology ePrint Archive, Report 2020\/1559 (2020). https:\/\/eprint.iacr.org\/2020\/1559"},{"key":"315_CR46","doi-asserted-by":"crossref","unstructured":"Ravi, P., Deb, S., Baksi, A., Chattopadhyay, A., Bhasin, S., Mendelson, A.: on threat of hardware trojan to post-quantum lattice-based schemes: a key recovery attack on saber and beyond. In: Batina, L., Picek, S., Mondal, M. (eds.) Security, Privacy, and Applied Cryptography Engineering, pp. 81\u2013103. Springer International Publishing, Cham (2022)","DOI":"10.1007\/978-3-030-95085-9_5"},{"issue":"3","key":"315_CR47","doi-asserted-by":"publisher","first-page":"307","DOI":"10.13154\/tches.v2020.i3.307-335","volume":"2020","author":"P Ravi","year":"2020","unstructured":"Ravi, P., Roy, S.S., Chattopadhyay, A., Bhasin, S.: Generic side-channel attacks on CCA-secure lattice-based PKE and KEMs. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2020(3), 307\u2013335 (2020). https:\/\/doi.org\/10.13154\/tches.v2020.i3.307-335","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"315_CR48","doi-asserted-by":"crossref","unstructured":"Reparaz, O., de Clercq, R., Roy, S.S., Vercauteren, F., Verbauwhede, I.: Additively homomorphic ring-LWE masking. In: Post-Quantum Cryptography, pp. 233\u2013244. Springer (2016)","DOI":"10.1007\/978-3-319-29360-8_15"},{"key":"315_CR49","doi-asserted-by":"crossref","unstructured":"Reparaz, O., Roy, S.S., Vercauteren, F., Verbauwhede, I.: A masked ring-LWE implementation. In: International Workshop on Cryptographic Hardware and Embedded Systems, pp. 683\u2013702. Springer (2015)","DOI":"10.1007\/978-3-662-48324-4_34"},{"key":"315_CR50","doi-asserted-by":"crossref","unstructured":"Schneider, T., Paglialonga, C., Oder, T., G\u00fcneysu, T.: Efficiently masking binomial sampling at arbitrary orders for lattice-based crypto. In: Public-Key Cryptography \u2013 PKC 2019, pp. 534\u2013564. Springer International Publishing (2019)","DOI":"10.1007\/978-3-030-17259-6_18"},{"issue":"2","key":"315_CR51","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1137\/S0036144598347011","volume":"41","author":"Peter W Shor","year":"1999","unstructured":"Shor, Peter W.: Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM Rev. 41(2), 303\u2013332 (1999)","journal-title":"SIAM Rev."},{"key":"315_CR52","unstructured":"Sim, B-Y, Kwon, J., Lee, J., Kim, I-J., Lee, T., Han, J., Yoon, H., Cho, J., Han, D-G.: Single-trace attacks on the message encoding of lattice-based KEMs. Cryptology ePrint Archive, Report 2020\/992 (2020). https:\/\/eprint.iacr.org\/2020\/992"},{"key":"315_CR53","unstructured":"Timon, B.: Non-profiled deep learning-based side-channel attacks. Cryptology ePrint Archive, Paper 2018\/196 (2018). https:\/\/eprint.iacr.org\/2018\/196"},{"issue":"1","key":"315_CR54","doi-asserted-by":"publisher","first-page":"296","DOI":"10.46586\/tches.v2022.i1.296-322","volume":"2022","author":"R Ueno","year":"2021","unstructured":"Ueno, R., Xagawa, K., Tanaka, Y., Ito, A., Takahashi, J., Homma, N.: Curse of re-encryption: a generic power\/EM analysis on post-quantum KEMs. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2022(1), 296\u2013322 (2021). https:\/\/doi.org\/10.46586\/tches.v2022.i1.296-322","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"315_CR55","doi-asserted-by":"crossref","unstructured":"Ueno, R., Xagawa, K., Tanaka, Y., Ito, A., Takahashi, J., Homma, N.: Curse of re-encryption: a generic power\/EM analysis on post-quantum KEMs. Cryptology ePrint Archive, Report 2021\/849 (2021)","DOI":"10.46586\/tches.v2022.i1.296-322"},{"key":"315_CR56","doi-asserted-by":"crossref","unstructured":"Veyrat-Charvillon, N., Medwed, M., Kerckhof, S., Standaert, F-X.: Shuffling against side-channel attacks: a comprehensive study with cautionary note. In: Wang, X., Sako, K. (eds.) Advances in Cryptology \u2013 ASIACRYPT 2012, pp. 740\u2013757. Springer, Berlin, Heidelberg (2012)","DOI":"10.1007\/978-3-642-34961-4_44"},{"key":"315_CR57","doi-asserted-by":"crossref","unstructured":"Wang, H., Dubrova, E.: Tandem deep learning side-channel attack against FPGA implementation of AES. In: Proceedings of IEEE International Symposium on Smart Electronic Systems (iSES), pp. 147\u2013150 (2020)","DOI":"10.1109\/iSES50453.2020.00041"},{"key":"315_CR58","doi-asserted-by":"crossref","unstructured":"Wang, J., Cao, W., Chen, H., Li, H.: Practical side-channel attack on masked message encoding in latticed-based KEM. Cryptology ePrint Archive, Paper 2022\/859 (2022). https:\/\/eprint.iacr.org\/2022\/859","DOI":"10.1109\/TrustCom56396.2022.00122"},{"key":"315_CR59","doi-asserted-by":"crossref","unstructured":"Wang, R., Ngo, K., Dubrova, E.: A message recovery attack on LWE \/ LWR-based PKE \/ KEMs using amplitude-modulated EM emanations (2022)","DOI":"10.1007\/978-3-031-29371-9_22"},{"key":"315_CR60","doi-asserted-by":"crossref","unstructured":"Wang, R., Ngo, K., Dubrova, E.: Side-channel analysis of Saber KEM using amplitude-modulated EM emanations. In: 2022 25th Euromicro Conference on Digital System Design (DSD), pp. 488\u2013495. IEEE (2022). https:\/\/doi.org\/10.1109\/DSD57027.2022.00071","DOI":"10.1109\/DSD57027.2022.00071"},{"key":"315_CR61","doi-asserted-by":"crossref","unstructured":"Welch, B.L.: The generalization of \u2019student\u2019s\u2019 problem when several different population variances are involved. Biometrika 34(1-2), 28\u201335 (1947). http:\/\/www.jstor.org\/stable\/2332510","DOI":"10.1093\/biomet\/34.1-2.28"},{"key":"315_CR62","doi-asserted-by":"crossref","unstructured":"Xu, Z., Pemberton, O., Roy, S.S., Oswald, D., Yao, W., Zheng, Z.: Magnifying side-channel leakage of lattice-based cryptosystems with chosen ciphertexts: the case study of kyber. Tech. Rep. (2020). https:\/\/doi.org\/10.1109\/TC.2021.3122997","DOI":"10.1109\/TC.2021.3122997"},{"key":"315_CR63","doi-asserted-by":"crossref","unstructured":"Yu, Y., Moraitis, M., Dubrova, E.: Why deep learning makes it difficult to keep secrets in FPGAs. In: Proceedings of Workshop on DYnamic and Novel Advances in Machine Learning and Intelligent Cyber Security (DYNAMICS \u201920) (2020). https:\/\/doi.org\/10.1145\/3477997.3478001","DOI":"10.1145\/3477997.3478001"}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-023-00315-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13389-023-00315-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-023-00315-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,23]],"date-time":"2023-11-23T12:19:57Z","timestamp":1700741997000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13389-023-00315-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,25]]},"references-count":63,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,11]]}},"alternative-id":["315"],"URL":"https:\/\/doi.org\/10.1007\/s13389-023-00315-3","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"type":"print","value":"2190-8508"},{"type":"electronic","value":"2190-8516"}],"subject":[],"published":{"date-parts":[[2023,4,25]]},"assertion":[{"value":"12 June 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 February 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 April 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}