{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T07:48:57Z","timestamp":1782719337055,"version":"3.54.5"},"reference-count":17,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T00:00:00Z","timestamp":1782691200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T00:00:00Z","timestamp":1782691200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"State Cryptography Administration of China","award":["2025NCSF02044"],"award-info":[{"award-number":["2025NCSF02044"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1007\/s13389-026-00398-8","type":"journal-article","created":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T07:36:03Z","timestamp":1782718563000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Countermeasures against side-channel attacks in FrodoKEM: an implementation study"],"prefix":"10.1007","volume":"16","author":[{"given":"Aoyang","family":"Zhou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haiying","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingdeng","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bin","family":"Hu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,29]]},"reference":[{"key":"398_CR1","doi-asserted-by":"publisher","DOI":"10.1137\/S0097539795293172","author":"PW Shor","year":"1997","unstructured":"Shor, P.W.: Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum. Computer (1997). https:\/\/doi.org\/10.1137\/S0097539795293172","journal-title":"Computer"},{"key":"398_CR2","doi-asserted-by":"publisher","unstructured":"Regev, O.: On lattices, learning with errors, random linear codes, and cryptography. J. ACM 56(6), 1\u201340 (2009). https:\/\/doi.org\/10.1145\/1568318.1568324","DOI":"10.1145\/1568318.1568324"},{"key":"398_CR3","doi-asserted-by":"publisher","unstructured":"Bos, J., Costello, C., Ducas, L., Mironov, I., Naehrig, M., Nikolaenko, V., Raghunathan, A., Stebila, D.: Frodo: Take off the ring! practical, quantum-secure key exchange from lwe. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. CCS \u201916, pp. 1006\u20131018. Association for Computing Machinery, New York, NY, USA (2016). https:\/\/doi.org\/10.1145\/2976749.2978425","DOI":"10.1145\/2976749.2978425"},{"issue":"10","key":"398_CR4","doi-asserted-by":"publisher","first-page":"1809","DOI":"10.3390\/app8101809","volume":"8","author":"S Kim","year":"2018","unstructured":"Kim, S., Hong, S.: Single Trace Analysis on Constant Time CDT Sampler and Its Countermeasure. Appl. Sci. 8(10), 1809 (2018). https:\/\/doi.org\/10.3390\/app8101809","journal-title":"Appl. Sci."},{"key":"398_CR5","doi-asserted-by":"publisher","first-page":"216","DOI":"10.1007\/978-3-030-10970-7_10","volume-title":"Selected Areas in Cryptography - SAC 2018","author":"JW Bos","year":"2019","unstructured":"Bos, J.W., Friedberger, S., Martinoli, M., Oswald, E., Stam, M.: Assessing the feasibility of single trace power analysis of frodo. In: Cid, C., Jacobson, M.J., Jr. (eds.) Selected Areas in Cryptography - SAC 2018, pp. 216\u2013234. Springer, Cham (2019)"},{"key":"398_CR6","doi-asserted-by":"publisher","first-page":"262","DOI":"10.1007\/978-3-030-60939-9_18","volume-title":"Embedded Computer Systems: Architectures, Modeling, and Simulation","author":"F Aydin","year":"2020","unstructured":"Aydin, F., Kashyap, P., Potluri, S., Franzon, P., Aysu, A.: Deepar-sca: Breaking parallel architectures of lattice cryptography via learning based side-channel attacks. In: Orailoglu, A., Jung, M., Reichenbach, M. (eds.) Embedded Computer Systems: Architectures, Modeling, and Simulation, pp. 262\u2013280. Springer, Cham (2020)"},{"key":"398_CR7","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-030-56880-1_13","volume-title":"Advances in Cryptology - CRYPTO 2020","author":"Q Guo","year":"2020","unstructured":"Guo, Q., Johansson, T., Nilsson, A.: A key-recovery timing attack on post-quantum primitives using the fujisaki-okamoto transformation and its application on frodokem. In: Micciancio, D., Ristenpart, T. (eds.) Advances in Cryptology - CRYPTO 2020, pp. 359\u2013386. Springer, Cham (2020)"},{"key":"398_CR8","doi-asserted-by":"publisher","unstructured":"Fahr, M., Kippen, H., Kwong, A., Dang, T., Lichtinger, J., Dachman-Soled, D., Genkin, D., Nelson, A., Perlner, R., Yerukhimovich, A., Apon, D.: When frodo flips: End-to-end key recovery on frodokem via rowhammer. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. CCS \u201922, pp. 979\u2013993. Association for Computing Machinery, New York, NY, USA (2022). https:\/\/doi.org\/10.1145\/3548606.3560673","DOI":"10.1145\/3548606.3560673"},{"key":"398_CR9","doi-asserted-by":"publisher","unstructured":"Kim, Y., Daly, R., Kim, J., Fallin, C., Lee, J.H., Lee, D., Wilkerson, C., Lai, K., Mutlu, O.: Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors. In: 2014 ACM\/IEEE 41st International Symposium on Computer Architecture (ISCA), pp. 361\u2013372. IEEE, Minneapolis, MN, USA (2014). https:\/\/doi.org\/10.1109\/ISCA.2014.6853210","DOI":"10.1109\/ISCA.2014.6853210"},{"issue":"8","key":"398_CR10","doi-asserted-by":"publisher","first-page":"1555","DOI":"10.1109\/TCAD.2019.2915318","volume":"39","author":"O Mutlu","year":"2020","unstructured":"Mutlu, O., Kim, J.S.: RowHammer: A Retrospective. IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 39(8), 1555\u20131571 (2020). https:\/\/doi.org\/10.1109\/TCAD.2019.2915318","journal-title":"IEEE Trans. Comput. Aided Des. Integr. Circuits Syst."},{"key":"398_CR11","unstructured":"Brasser, F., Davi, L., Gens, D., Liebchen, C., Sadeghi, A.-R.: CAn\u2019t touch this: Software-only mitigation against rowhammer attacks targeting kernel memory. In: 26th USENIX Security Symposium (USENIX Security 17), pp. 117\u2013130. USENIX Association, Vancouver, BC (2017)"},{"key":"398_CR12","doi-asserted-by":"publisher","unstructured":"Cojocar, L., Razavi, K., Giuffrida, C., Bos, H.: Exploiting Correcting Codes: On the Effectiveness of ECC Memory Against Rowhammer Attacks. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 55\u201371. IEEE, San Francisco, CA, USA (2019). https:\/\/doi.org\/10.1109\/SP.2019.00089","DOI":"10.1109\/SP.2019.00089"},{"key":"398_CR13","doi-asserted-by":"publisher","unstructured":"Frigo, P., Vannacc, E., Hassan, H., Der\u00a0Veen, V.V., Mutlu, O., Giuffrida, C., Bos, H., Razavi, K.: TRRespass: Exploiting the Many Sides of Target Row Refresh. In: 2020 IEEE Symposium on Security and Privacy (SP), pp. 747\u2013762. IEEE, San Francisco, CA, USA (2020). https:\/\/doi.org\/10.1109\/SP40000.2020.00090","DOI":"10.1109\/SP40000.2020.00090"},{"key":"398_CR14","doi-asserted-by":"publisher","unstructured":"P\u00f6ppelmann, T., G\u00fcneysu, T.: Towards Practical Lattice-Based Public-Key Encryption on Reconfigurable Hardware. In: Lange, T., Lauter, K., Lison\u011bk, P. (eds.) Selected Areas in Cryptography \u2013 SAC 2013 vol. 8282, pp. 68\u201385. Springer, Berlin, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-43414-7_4","DOI":"10.1007\/978-3-662-43414-7_4"},{"key":"398_CR15","doi-asserted-by":"publisher","unstructured":"Reparaz, O., Sinha\u00a0Roy, S., Vercauteren, F., Verbauwhede, I.: A Masked Ring-LWE Implementation. In: G\u00fcneysu, T., Handschuh, H. (eds.) Cryptographic Hardware and Embedded Systems \u2013 CHES 2015 vol. 9293, pp. 683\u2013702. Springer, Berlin, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48324-4_34","DOI":"10.1007\/978-3-662-48324-4_34"},{"key":"398_CR16","doi-asserted-by":"publisher","unstructured":"Barthe, G., Bela\u00efd, S., Espitau, T., Fouque, P.-A., Gr\u00e9goire, B., Rossi, M., Tibouchi, M.: Masking the GLP Lattice-Based Signature Scheme at Any Order. In: Advances in Cryptology \u2013 EUROCRYPT 2018 vol. 10821, pp. 354\u2013384. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78375-8_12","DOI":"10.1007\/978-3-319-78375-8_12"},{"key":"398_CR17","doi-asserted-by":"crossref","unstructured":"Eid, E., Greuet, A., Reboud, N., Zeitoun, R.: Efficient high-order masking of frodokem\u2019s cdt-based gaussian sampler. IACR Cryptol. ePrint Arch , 1308 (2025)","DOI":"10.46586\/tches.v2026.i2.868-892"}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-026-00398-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13389-026-00398-8","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-026-00398-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T07:36:09Z","timestamp":1782718569000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13389-026-00398-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,29]]},"references-count":17,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2026,9]]}},"alternative-id":["398"],"URL":"https:\/\/doi.org\/10.1007\/s13389-026-00398-8","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"value":"2190-8508","type":"print"},{"value":"2190-8516","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,29]]},"assertion":[{"value":"3 September 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 May 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that there are no conflicts of interest regarding the publication of this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable. This study does not involve human participants or animals.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"Not applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}}],"article-number":"10"}}