{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T14:46:02Z","timestamp":1776955562953,"version":"3.51.4"},"reference-count":22,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2022,10,18]],"date-time":"2022-10-18T00:00:00Z","timestamp":1666051200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>The side-channel security of lattice-based post-quantum cryptography has gained extensive attention since the standardization of post-quantum cryptography. Based on the leakage mechanism in the decapsulation stage of LWE\/LWR-based post-quantum cryptography, a message recovery method, with templates and cyclic message rotation targeting the message decoding operation, was proposed. The templates were constructed for the intermediate state based on the Hamming weight model and cyclic message rotation was used to construct special ciphertexts. Using the power leakage during operation, secret messages in the LWE\/LWR-based schemes were recovered. The proposed method was verified on CRYSTAL-Kyber. The experimental results demonstrated that this method could successfully recover the secret messages used in the encapsulation stage, thereby recovering the shared key. Compared with existing methods, the power traces required for templates and attack were both reduced. The success rate was significantly increased under the low SNR, indicating a better performance with lower recovery cost. The message recovery success rate could reach 99.6% with sufficient SNR.<\/jats:p>","DOI":"10.3390\/e24101489","type":"journal-article","created":{"date-parts":[[2022,10,18]],"date-time":"2022-10-18T21:18:02Z","timestamp":1666127882000},"page":"1489","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Template Attack of LWE\/LWR-Based Schemes with Cyclic Message Rotation"],"prefix":"10.3390","volume":"24","author":[{"given":"Yajing","family":"Chang","sequence":"first","affiliation":[{"name":"College of Cryptography Engineering, Information Engineering University, Zhengzhou 450001, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yingjian","family":"Yan","sequence":"additional","affiliation":[{"name":"College of Cryptography Engineering, Information Engineering University, Zhengzhou 450001, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chunsheng","family":"Zhu","sequence":"additional","affiliation":[{"name":"College of Cryptography Engineering, Information Engineering University, Zhengzhou 450001, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pengfei","family":"Guo","sequence":"additional","affiliation":[{"name":"College of Cryptography Engineering, Information Engineering University, Zhengzhou 450001, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,10,18]]},"reference":[{"key":"ref_1","unstructured":"NIST (2021, January 03). Post-Quantum Cryptography: Post-Quantum Cryptography Standardization, Available online: https:\/\/csrc.nist.gov\/Projects\/Post-Quantum-Cryptography\/Post-Quantum-Cryptography-Standardization."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Kocher, P., Jaffe, J., and Jun, B. (1999). Differential Power Analysis. Advances in Cryptology\u2014CRYPTO\u2019 99. CRYPTO 1999. Lecture Notes in Computer Science, Springer.","DOI":"10.1007\/3-540-48405-1_25"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1568318.1568324","article-title":"On lattices, learning with errors, random linear codes, and cryptography","volume":"56","author":"Regev","year":"2009","journal-title":"J. ACM"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Banerjee, A., Peikert, C., and Rosen, A. (1999). Pseudorandom Functions and Lattices. Advances in Cryptology\u2014EUROCRYPT 2012, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-642-29011-4_42"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Primas, R., Pessl, P., and Mangard, S. (2017). Single-Trace Side-Channel Attacks on Masked Lattice-Based Encryption. Cryptographic Hardware and Embedded Systems\u2014CHES 2017. CHES 2017, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-319-66787-4_25"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Pessl, P., and Primas, R. (2019). More Practical Single-Trace Attacks on the Number Theoretic Transform. Progress in Cryptology\u2014LATINCRYPT 2019. LATINCRYPT 2019, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-030-30530-7_7"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3476799","article-title":"Horizontal Side-Channel Vulnerabilities of Post-Quantum Key Exchange and Encapsulation Protocols","volume":"20","author":"Aydin","year":"2021","journal-title":"ACM Trans. Embed. Comput. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"307","DOI":"10.46586\/tches.v2020.i3.307-335","article-title":"Generic Side-channel attacks on CCA-secure lattice-based PKE and KEMs","volume":"3","author":"Ravi","year":"2020","journal-title":"IACR Transac. Cryptogr. Hardw. Embed. Syst."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"88","DOI":"10.46586\/tches.v2021.i4.88-113","article-title":"Chosen Ciphertext k-Trace Attacks on Masked CCA2 Secure Kyber","volume":"4","author":"Hamburg","year":"2021","journal-title":"IACR Transac. Cryptogr. Hardw. Embed. Syst."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"676","DOI":"10.46586\/tches.v2021.i4.676-707","article-title":"A Side-Channel Attack on a Masked IND-CCA Secure Saber KEM Implementation","volume":"4","author":"Ngo","year":"2021","journal-title":"IACR Transac. Cryptogr. Hardw. Embed. Syst."},{"key":"ref_11","unstructured":"Ravi, P., Bhasin, S., and Sinha Roy, S. (2021, December 23). Drop by Drop You Break the Rock\u2014Exploiting Generic Vulnerabilities in Lattice-Based PKE\/KEMs Using EM-Based Physical Attacks. Available online: https:\/\/eprint.iacr.org\/2020\/549."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Amiet, D., Curiger, A., Leuenberger, L., and Zbinden, P. (2020). Defeating NEWHOPE with a Single Trace. Post-Quantum Cryptography. PQCrypto 2020, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-030-44223-1_11"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"183175","DOI":"10.1109\/ACCESS.2020.3029521","article-title":"Single-Trace Attacks on Message Encoding in Lattice-Based KEMs","volume":"8","author":"Sim","year":"2020","journal-title":"IEEE Access"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"684","DOI":"10.1109\/TIFS.2021.3139268","article-title":"On Exploiting Message Leakage in (Few) NIST PQC Candidates for Practical Message Recovery Attacks","volume":"17","author":"Ravi","year":"2022","journal-title":"IEEE Transac. Inform. Forensics Secur."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3292548","article-title":"Post-Quantum Lattice-Based Cryptography Implementations: A Survey","volume":"51","author":"Nejatollahi","year":"2019","journal-title":"ACM Comput. Surv."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2535925","article-title":"On Ideal Lattices and Learning with Errors over Rings","volume":"60","author":"Lyubashevsky","year":"2013","journal-title":"J. ACM"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1007\/s00145-011-9114-1","article-title":"Secure Integration of Asymmetric and Symmetric Encryption Schemes","volume":"26","author":"Fujisaki","year":"2013","journal-title":"J. Cryptol."},{"key":"ref_18","first-page":"115","article-title":"A testing methodology for side channel resistance validation","volume":"17","author":"Goodwill","year":"2011","journal-title":"Proc. NIAT"},{"key":"ref_19","unstructured":"Bhasin, S., Danger, J.L., Guilley, S., and Najm, Z. (2014, January 13\u201316). NICV: Normalized inter-class variance for detection of side-channel leakage. Proceedings of the 2014 International Symposium on Electromagnetic Compatibility, Tokyo, Japan."},{"key":"ref_20","unstructured":"Schwabe, P., Avanzi, R., and Bos, J. (2021, May 08). CRYSTALS\u2014CRYSTAL-Kyber\u2014Algorithm Specifications And Supporting Documentation. Available online: https:\/\/pq-crystals.org\/kyber\/index.shtml."},{"key":"ref_21","unstructured":"Kannwischer, M.J., Rijneveld, J., and Schwabe, P. (2022, September 18). PQM4: Post-Quantum Crypto Library for the ARM Cortex-M4. Available online: http:\/\/github.com\/mupq\/pqm4."},{"key":"ref_22","unstructured":"NewAE Technology Inc. (2022, May 06). Chipwhisperer. Available online: http:\/\/rtfm.newae.com."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/24\/10\/1489\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:56:53Z","timestamp":1760144213000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/24\/10\/1489"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,18]]},"references-count":22,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2022,10]]}},"alternative-id":["e24101489"],"URL":"https:\/\/doi.org\/10.3390\/e24101489","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,10,18]]}}}