{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T18:40:01Z","timestamp":1745347201990,"version":"3.40.4"},"reference-count":46,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,4,2]],"date-time":"2025-04-02T00:00:00Z","timestamp":1743552000000},"content-version":"vor","delay-in-days":1,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100004270","name":"Royal Institute of Technology","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100004270","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2025,4]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>NIST has recently selected CRYSTALS-Kyber as a new public key encryption and key establishment algorithm to be standardized. This makes it important to evaluate the resistance of CRYSTALS-Kyber implementations to side-channel attacks. Software implementations of CRYSTALS-Kyber have already been thoroughly analysed. The discovered vulnerabilities have helped improve subsequently released versions and promoted stronger countermeasures against side-channel attacks. In this paper, we present the first attack on a protected hardware implementation of CRYSTALS-Kyber. We demonstrate a practical message (shared key) recovery attack on the first-order masked FPGA implementation of Kyber-512 by Kamucheka et al. (2022) using power analysis based on the Hamming distance leakage model. The presented attack exploits a vulnerability located in the masked message decoding function executed during the decryption step of decapsulation. The message recovery is performed using a profiled deep learning-assisted method which extracts the message directly, without explicitly retrieving each share. By repeating the same decapsulation multiple times, it is possible to increase the success rate of full shared key recovery to 99%. We also analyse the feasibility of recovering shared keys during encapsulation and propose a countermeasure against the presented attack that is also applicable to FPGA implementations of other cryptographic algorithms.<\/jats:p>","DOI":"10.1007\/s13389-025-00375-7","type":"journal-article","created":{"date-parts":[[2025,4,4]],"date-time":"2025-04-04T14:41:51Z","timestamp":1743777711000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A side-channel attack on a masked hardware implementation of CRYSTALS-Kyber"],"prefix":"10.1007","volume":"15","author":[{"given":"Yanning","family":"Ji","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elena","family":"Dubrova","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,4,2]]},"reference":[{"key":"375_CR1","unstructured":"[n.\u00a0d.]: CW-Analyzer Tool-Wiki. https:\/\/wiki.newae.com\/CW-Analyzer_Tool"},{"key":"375_CR2","unstructured":"Announcing the Commercial National Security Algorithm Suite 2.0. https:\/\/media.defense.gov\/2022\/Sep\/07\/2003071834\/-1\/-1\/0\/CSA_CNSA_2.0_ALGORITHMS_.PDF (2022)"},{"key":"375_CR3","doi-asserted-by":"crossref","unstructured":"Agrawal, D., Archambeault, B., Rao, J.R., Rohatgi, P.: The EM Side-Channel(s). In Crypt. Hardware and Embedded Systems, pp. 29\u201345 (2003)","DOI":"10.1007\/3-540-36400-5_4"},{"key":"375_CR4","unstructured":"Avanzi, R., Bos, J., Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V., Schanck, J.M., Schwabe, P., Seiler, G., Stehl\u00e9, D.: CRYSTALS-Kyber algorithm specifications and supporting documentation (2021). https:\/\/pq-crystals.org\/kyber\/data\/kyber-specification-round3-20210131.pdf"},{"key":"375_CR5","doi-asserted-by":"crossref","unstructured":"Azouaoui, M., Kuzovkova, Y., Schneider, T., van Vredendaal, C.: Post-quantum authenticated encryption against chosen-ciphertext side-channel attacks. Cryptology ePrint archive, Paper 2022\/916 (2022)","DOI":"10.46586\/tches.v2022.i4.372-396"},{"key":"375_CR6","doi-asserted-by":"crossref","unstructured":"Backlund, L., Ngo, K., Gartner, J., Dubrova, E.: Secret key recovery attacks on masked and shuffled implementations of CRYSTALS-Kyber and Saber. Cryptology ePrint Archive, Paper 2022\/1692 (2022)","DOI":"10.1007\/978-3-031-41181-6_9"},{"key":"375_CR7","unstructured":"Becker, G.T, Kumar, R.: Active and passive side-channel attacks on delay based PUF designs. Cryptology ePrint Archive (2014)"},{"issue":"4","key":"375_CR8","first-page":"4","volume":"16","author":"N Belleville","year":"2018","unstructured":"Belleville, N., Courousse, D., Heydemann, K., Charles, H.-P.: Automated software protection for the masses against side-channel attacks. ACM Trans. Archit. Code Optim. 16(4), 4 (2018)","journal-title":"ACM Trans. Archit. Code Optim."},{"key":"375_CR9","doi-asserted-by":"crossref","unstructured":"Bhasin, S., Chattopadhyay, A., Heuser, A., Jap, D., Picek, S., Ranjan Shrivastwa, R.: Mind the portability: a warriors guide through realistic profiled side-channel analysis. In: Network and Distributed System Security Symposium (2020)","DOI":"10.14722\/ndss.2020.24390"},{"key":"375_CR10","doi-asserted-by":"crossref","unstructured":"Bos, J.W., Gourjon, M., Renes, J., Schneider, T., van Vredendaal, C.: Masking Kyber: first- and higher-order implementations. In: IACR Trans. Crypt. Hardware and Embedded Systems, 4 Aug 2021, pp. 173\u2013214 (2021)","DOI":"10.46586\/tches.v2021.i4.173-214"},{"key":"375_CR11","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1007\/978-3-030-23696-0_11","volume-title":"Progress in Cryptology - AFRICACRYPT 2019","author":"L Botros","year":"2019","unstructured":"Botros, L., Kannwischer, M.J., Schwabe, P.: Memory-efficient high-speed implementation of Kyber on Cortex-M4. In: Buchmann, J., Nitaj, A., Rachidi, T. (eds.) Progress in Cryptology - AFRICACRYPT 2019, pp. 209\u2013228. Springer, Cham (2019)"},{"key":"375_CR12","doi-asserted-by":"crossref","unstructured":"Chari, S., Jutla, C.S., Rao, J.R., Rohatgi, P.: Towards sound approaches to counteract power-analysis attacks. In: Advances in Cryptology\u2014CRYPTO\u201999, vol. 1666, pp. 398\u2013412. Springer (1999)","DOI":"10.1007\/3-540-48405-1_26"},{"key":"375_CR13","doi-asserted-by":"crossref","unstructured":"Chinbat, M., Wu, L., Zhang, X., Batsukh, A., Yang, Y., Wu, L.: Evaluating side-channel attack vulnerabilities in post-quantum CRYSTALS-Kyber hardware based on simple power analysis. In: 2023 IEEE 17th International Conference on Anti-counterfeiting, Security, and Identification (ASID), pp. 46\u201349. IEEE (2023)","DOI":"10.1109\/ASID60355.2023.10426450"},{"key":"375_CR14","first-page":"156","volume-title":"Crypt. Hardware and Embedded Systems","author":"J-S Coron","year":"2009","unstructured":"Coron, J.-S., Kizhvatov, I.: An efficient method for random delay generation in embedded software. In: Crypt. Hardware and Embedded Systems, pp. 156\u2013170. Springer, Berlin (2009)"},{"key":"375_CR15","unstructured":"D\u2019Anvers, J.-P., Van Beirendonck, M., Verbauwhede, I.: Revisiting higher-order masked comparison for lattice-based cryptography: algorithms and bit-sliced implementations. Cryptology ePrint Archive, Paper 2022\/110 (2022)"},{"key":"375_CR16","doi-asserted-by":"crossref","unstructured":"Dubrova, E., Ngo, K., Gartner, J., Wang, R.: Breaking a Fifth-Order Masked Implementation of CRYSTALS-Kyber by copy-paste. In: Proc. of the 10th ACM Asia Public-Key Cryptography Workshop (APKC 2023) (2023)","DOI":"10.1145\/3591866.3593072"},{"key":"375_CR17","doi-asserted-by":"crossref","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. In: Annual International Cryptology Conference, pp. 537\u2013554. Springer (1999)","DOI":"10.1007\/3-540-48405-1_34"},{"key":"375_CR18","unstructured":"Goodwill, G., Jun, B., Jaffe, J., Rohatgi, P.: A testing methodology for side\u2013channel resistance validation. In: NIST Non-Invasive Attack Testing Workshop, vol. 7, pp. 115\u2013136 (2011)"},{"key":"375_CR19","doi-asserted-by":"crossref","unstructured":"Gross, H., Mangard, S., Korak, T.: Domain-oriented masking: compact masked hardware implementations with arbitrary protection order. Cryptology ePrint Archive, Paper 2016\/486, pp. 3\u20133 (2016)","DOI":"10.1145\/2996366.2996426"},{"issue":"11","key":"375_CR20","doi-asserted-by":"publisher","first-page":"4505","DOI":"10.1109\/TCSI.2023.3306347","volume":"70","author":"W Guo","year":"2023","unstructured":"Guo, W., Li, S.: Highly-efficient hardware architecture for CRYSTALS-Kyber with a novel conflict-free memory access pattern. IEEE Trans. Circuits Syst. I Regular Papers 70(11), 4505\u20134515 (2023)","journal-title":"IEEE Trans. Circuits Syst. I Regular Papers"},{"key":"375_CR21","doi-asserted-by":"crossref","unstructured":"Hoffmann, C., Libert, B., Momin, C., Peters, T., Standaert, F.-X.: Towards leakage-resistant post-quantum CCA-secure public key encryption. Cryptology ePrint Archive, Paper 2022\/873 (2022)","DOI":"10.1007\/978-3-031-31368-4_5"},{"issue":"17","key":"375_CR22","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1587\/elex.17.20200234","volume":"17","author":"Y Huang","year":"2020","unstructured":"Huang, Y., Huang, M., Lei, Z.W.: A pure hardware implementation of CRYSTALS-Kyber PQC algorithm through resource reuse. IEICE Electron. Exp. 17(17), 1\u20136 (2020)","journal-title":"IEICE Electron. Exp."},{"key":"375_CR23","unstructured":"Jati, A., Gupta, N., Chattopadhyay, A., Sanadhya, S.K.: A configurable CRYSTALS-Kyber hardware implementation with side-channel protection. Cryptology ePrint Archive, Paper 2021\/1189 (2021)"},{"key":"375_CR24","doi-asserted-by":"crossref","unstructured":"Ji, Y., Wang, R., Ngo, K., Dubrova, E., Backlund, L.: A side-channel attack on a hardware implementation of CRYSTALS-Kyber. In: 2023 IEEE European Test Symposium (ETS\u201923) (2023)","DOI":"10.1109\/ETS56758.2023.10174000"},{"key":"375_CR25","unstructured":"Kamucheka, T., Fahr, M., Teague, T., Nelson, A., Andrews, D.: Power-based side channel attack analysis on PQC algorithms. Cryptology ePrint Archive, Paper 2021\/1021 (2021)"},{"key":"375_CR26","doi-asserted-by":"crossref","unstructured":"Kamucheka, T., Nelson, A., Andrews, D., Huang, M.: A masked pure-hardware implementation of Kyber cryptographic algorithm. In: 2022 International Conference on Field-Programmable Technology (ICFPT). IEEE (2022)","DOI":"10.1109\/ICFPT56656.2022.9974404"},{"key":"375_CR27","doi-asserted-by":"crossref","unstructured":"Kocher, P., Jaffe, J., Jun, B.: Differential power analysis. In: Advances in Cryptology\u2014CRYPTO\u201999, pp. 388\u2013397. Springer, Berlin (1999)","DOI":"10.1007\/3-540-48405-1_25"},{"key":"375_CR28","doi-asserted-by":"crossref","unstructured":"Kocher, P.C.: Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In: Advances in cryptology\u2014CRYPTO\u201996, Neal Koblitz, pp. 104\u2013113. Springer, Berlin (1996)","DOI":"10.1007\/3-540-68697-5_9"},{"key":"375_CR29","unstructured":"Kocher, P.C., Jaffe, J., Jun, B.: Using unpredictable information to minimize leakage from smartcards and other cryptosystems. US Patent 6,327,661 (n.\u00a0d.)"},{"key":"375_CR30","doi-asserted-by":"crossref","unstructured":"Ma, H., Pan, S., Gao, Y., He, J., Zhao, Y., Jin, Y.: Vulnerable PQC against side channel analysis-a case study on Kyber. In: 2022 Asian HardwareOriented Security and Trust Symposium (AsianHOST), pp. 1\u20136. IEEE (2022)","DOI":"10.1109\/AsianHOST56390.2022.10022165"},{"key":"375_CR31","doi-asserted-by":"crossref","unstructured":"Maghrebi, H., Servant, V., Bringer, J.: There is wisdom in harnessing the strengths of your enemy: customized encoding to thwart side-channel attacks. In: Fast Software Encryption, pp. 223\u2013243 (2016)","DOI":"10.1007\/978-3-662-52993-5_12"},{"key":"375_CR32","unstructured":"Moody, D.: Status report on the third round of the NIST post-quantum cryptography standardization process. Nistir 8309, pp. 1\u201327 (2022). https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2022\/NIST.IR.8413.pdf"},{"key":"375_CR33","doi-asserted-by":"crossref","unstructured":"Moraitis, M., Ji, Y., Brisfors, M., Dubrova, E., Lindskog, N., Englund, H.: Securing CRYSTALS-Kyber in FPGA using duplication and clock randomization. IEEE Design Test (2023)","DOI":"10.1109\/MDAT.2023.3298805"},{"key":"375_CR34","doi-asserted-by":"crossref","unstructured":"Ngo, K., Dubrova, E.: Side-channel analysis of the random number generator in STM32 MCUs. In: Proc. of the Great Lakes Symposium on VLSI (GLSVLSI\u201922) (2022)","DOI":"10.1145\/3526241.3530324"},{"key":"375_CR35","doi-asserted-by":"crossref","unstructured":"Ngo, K., Dubrova, E., Guo, Q., Johansson, T.: A side-channel attack on a masked IND-CCA secure Saber KEM implementation. In: IACR Trans. on Cryptographic Hardware and Embedded Systems, pp. 676\u2013707 (2021)","DOI":"10.46586\/tches.v2021.i4.676-707"},{"key":"375_CR36","doi-asserted-by":"crossref","unstructured":"Nikova, S., Rechberger, C., Rijmen, V.: Threshold implementations against side-channel attacks and glitches. In: International Conference on Information and Communications Security, pp. 529\u2013545. Springer (2006)","DOI":"10.1007\/11935308_38"},{"key":"375_CR37","doi-asserted-by":"crossref","unstructured":"Rodriguez, R.C., Bruguier, F., Valea, E., Benoit, P.: Correlation electromagnetic analysis on an FPGA implementation of CRYSTALS-Kyber. Cryptology ePrint Archive, Paper 2022\/1361 (2022)","DOI":"10.1109\/PRIME58259.2023.10161764"},{"key":"375_CR38","doi-asserted-by":"crossref","unstructured":"Shang, L., Kaviani, A.S., Bathala, K.: Dynamic power consumption in Virtex$$^{TM}$$-II FPGA family. In: Proceedings of the 2002 ACM\/SIGDA 10th International Symposium on Field-Programmable Gate Arrays. 157\u2013164 (2002)","DOI":"10.1145\/503048.503072"},{"key":"375_CR39","doi-asserted-by":"crossref","unstructured":"Shen, M., Cheng, C., Zhang, X., Guo, Q., Jiang, T.: Find the bad apples: an efficient method for perfect key recovery under imperfect SCA oracles\u2014a case study of Kyber. Cryptology ePrint Archive, Paper 2022\/563 (2022)","DOI":"10.46586\/tches.v2023.i1.89-112"},{"key":"375_CR40","doi-asserted-by":"crossref","unstructured":"Takarabt, S., Guilley, S., Souissi, Y., Karray, K., Sauvage, L., Mathieu, Y.: Formal evaluation and construction of glitch-resistant masked functions. In: IEEE International Symposium on Hardware Oriented Security and Trust (HOST\u20192021), pp. 304\u2013313 (2021)","DOI":"10.1109\/HOST49136.2021.9702272"},{"issue":"2022","key":"375_CR41","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1109\/OJCS.2022.3198073","volume":"3","author":"T-T Tsai","year":"2022","unstructured":"Tsai, T.-T., Huang, S.-S., Tseng, Y.-M., Chuang, Y.-H., Hung, Y.-H.: Leakage-resilient certificate-based authenticated key exchange protocol. IEEE Open J. Comput. Soc. 3(2022), 137\u2013148 (2022)","journal-title":"IEEE Open J. Comput. Soc."},{"key":"375_CR42","doi-asserted-by":"crossref","unstructured":"Ueno, R., Xagawa, K., Tanaka, Y., Ito, A., Takahashi, J., Homma, N.: Curse of re-encryption: a generic power\/EM analysis on post-quantum KEMs. In: IACR Tran. on Cryptographic Hardware and Embedded Systems 2022, 1 Nov 2021, pp. 296\u2013322 (2021)","DOI":"10.46586\/tches.v2022.i1.296-322"},{"key":"375_CR43","doi-asserted-by":"crossref","unstructured":"Veyrat-Charvillon, et al.: Shuffling against side-channel attacks: a comprehensive study with cautionary note. In: Advances in Cryptology - ASIACRYPT 2012, pp. 740\u2013757. Springer, Berlin Heidelberg (2012)","DOI":"10.1007\/978-3-642-34961-4_44"},{"key":"375_CR44","doi-asserted-by":"crossref","unstructured":"Wang, H., Forsmark, S., Brisfors, M., Dubrova, E.: Multi-source training deep learning side-channel attacks. In: IEEE 50th International Symposium on Multiple-Valued Logic (ISMVL\u20192020) (2020)","DOI":"10.1109\/ISMVL49045.2020.00-29"},{"issue":"1\u20132","key":"375_CR45","first-page":"28","volume":"34","author":"BL Welch","year":"1947","unstructured":"Welch, B.L.: The generalization of \u2018Student\u2019s\u2019 problem when several different population variances are involved. Biometrika 34(1\u20132), 28\u201335 (1947)","journal-title":"Biometrika"},{"key":"375_CR46","doi-asserted-by":"crossref","unstructured":"Xing, Y., Li, S.: A compact hardware implementation of CCA-secure key exchange mechanism CRYSTALS-Kyber on FPGA. In: IACR Transactions on Cryptographic Hardware and Embedded Systems 2021, pp. 328\u2013356 (2021)","DOI":"10.46586\/tches.v2021.i2.328-356"}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-025-00375-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13389-025-00375-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-025-00375-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T18:10:12Z","timestamp":1745345412000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13389-025-00375-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4]]},"references-count":46,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,4]]}},"alternative-id":["375"],"URL":"https:\/\/doi.org\/10.1007\/s13389-025-00375-7","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"type":"print","value":"2190-8508"},{"type":"electronic","value":"2190-8516"}],"subject":[],"published":{"date-parts":[[2025,4]]},"assertion":[{"value":"27 July 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 March 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 April 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"7"}}