{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T11:27:41Z","timestamp":1757590061239,"version":"3.41.2"},"reference-count":67,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,7,3]],"date-time":"2024-07-03T00:00:00Z","timestamp":1719964800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,9,2]]},"abstract":"<jats:p>Most of the previous attacks on Dilithium exploit side-channel information which is leaked during the computation of the polynomial multiplication cs1, where s1 is a small-norm secret and c is a verifier's challenge. In this paper, we present a new attack utilizing leakage during secret key unpacking in the signing algorithm. The unpacking is also used in other post-quantum cryptographic algorithms, including Kyber, because inputs and outputs of their API functions are byte arrays. Exploiting leakage during unpacking is more challenging than exploiting leakage during the computation of cs1 since c varies for each signing, while the unpacked secret key remains constant. Therefore, post-processing is required in the latter case to recover a full secret key. We present two variants of post-processing. In the first one, a half of the coefficients of the secret s1 and the error s2 is recovered by profiled deep learning-assisted power analysis and the rest is derived by solving linear equations based on t = As1 + s2, where A and t are parts of the public key. This case assumes knowledge of the least significant bits of t,  t0. The second variant uses lattice reduction to derive s1 without the knowledge of t0. However, it needs a larger portion of s1 to be recovered by power analysis. We evaluate both variants on an ARM Cortex-M4 implementation of Dilithium-2. The experiments show that the attack assuming the knowledge of t0 can recover s1 from a single trace captured from a different from profiling device with a non-negligible probability. <\/jats:p>","DOI":"10.62056\/a0fh89n4e","type":"journal-article","created":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T15:13:33Z","timestamp":1728314013000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":1,"title":["Unpacking Needs Protection"],"prefix":"10.62056","author":[{"given":"Ruize","family":"Wang","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/026vcq606","id-type":"ROR","asserted-by":"publisher"}],"name":"KTH Royal Institute of Technology","place":["Stockholm, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9842-2038","authenticated-orcid":false,"given":"Kalle","family":"Ngo","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/026vcq606","id-type":"ROR","asserted-by":"publisher"}],"name":"KTH Royal Institute of Technology","place":["Stockholm, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3724-2914","authenticated-orcid":false,"given":"Joel","family":"G\u00e4rtner","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/026vcq606","id-type":"ROR","asserted-by":"publisher"}],"name":"KTH Royal Institute of Technology","place":["Stockholm, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7382-9408","authenticated-orcid":false,"given":"Elena","family":"Dubrova","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/026vcq606","id-type":"ROR","asserted-by":"publisher"}],"name":"KTH Royal Institute of Technology","place":["Stockholm, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"48349","published-online":{"date-parts":[[2024,10,7]]},"reference":[{"volume-title":"CRYSTALS-Dilithium Algorithm Specifications and Supporting\n  Documentation","year":"2021","author":"Shi Bai","key":"ref1:dilithiumSpecV3"},{"key":"ref2:Moody2022","doi-asserted-by":"publisher","first-page":"1","DOI":"10.6028\/NIST.IR.8413","article-title":"Status Report on the Third Round of the NIST Post-Quantum\n  Cryptography Standardization Process","author":"Dustin Moody","year":"2022","journal-title":"Nistir 8309"},{"volume-title":"Announcing the Commercial National Security Algorithm Suite\n  2.0","year":"2022","key":"ref3:nsa_cnsa"},{"volume-title":"pqm4: Testing and Benchmarking NIST PQC on ARM\n  Cortex-M4","year":"2019","author":"Matthias J. Kannwischer","key":"ref4:cryptoeprint:2019\/844"},{"key":"ref5:Ko96","isbn-type":"print","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","article-title":"Timing Attacks on Implementations of Diffie-Hellman,\n  RSA, DSS, and Other Systems","author":"Paul C. Kocher","year":"1996","ISBN":"https:\/\/id.crossref.org\/isbn\/3540615121"},{"key":"ref6:Ko99","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","article-title":"Differential Power Analysis","author":"Paul Kocher","year":"1999"},{"key":"ref7:ChJRR99","doi-asserted-by":"publisher","first-page":"398","DOI":"10.1007\/3-540-48405-1_26","article-title":"Towards Sound Approaches to Counteract Power-Analysis\n  Attacks","volume":"1666","author":"Suresh Chari","year":"1999"},{"key":"ref8:VeMF12","isbn-type":"print","doi-asserted-by":"publisher","first-page":"740","DOI":"10.1007\/978-3-642-34961-4_44","article-title":"Shuffling against Side-Channel Attacks: A Comprehensive\n  Study with Cautionary Note","author":"Veyrat-Charvillon","year":"2012","ISBN":"https:\/\/id.crossref.org\/isbn\/9783642349614"},{"volume-title":"Side-channel Assisted Existential Forgery Attack on\n  Dilithium - A NIST PQC candidate","year":"2018","author":"Prasanna Ravi","key":"ref9:ravi2018partialSecrets"},{"key":"ref10:Bruinderink_Pessl_2018","doi-asserted-by":"publisher","first-page":"21","DOI":"10.13154\/tches.v2018.i3.21-43","article-title":"Differential fault attacks on deterministic lattice\n  signatures","author":"Leon Groot Bruinderink","year":"2018","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref11:han2021single","doi-asserted-by":"publisher","first-page":"166283","DOI":"10.1109\/ACCESS.2021.3135600","article-title":"Single-trace attack on NIST round 3 candidate Dilithium\n  using machine learning-based profiling","volume":"9","author":"Jaeseung Han","year":"2021","journal-title":"IEEE Access"},{"key":"ref12:chen_iccd2021","doi-asserted-by":"publisher","first-page":"583","DOI":"10.1109\/ICCD53106.2021.00094","article-title":"An Efficient Non-Profiled Side-Channel Attack on the\n  CRYSTALS-Dilithium Post-Quantum Signature","author":"Zhaohui Chen","year":"2021"},{"volume-title":"Profiling Side-Channel Attacks on Dilithium: A Small\n  Bit-Fiddling Leak Breaks It All","year":"2022","author":"Soundes Marzougui","key":"ref13:marzougui2022"},{"key":"ref14:berzati2023","doi-asserted-by":"publisher","first-page":"188","DOI":"10.46586\/tches.v2023.i4.188-210","article-title":"Exploiting intermediate value leakage in Dilithium: a\n  template-based approach","volume":"2023","author":"Alexandre Berzati","year":"2023","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref15:bronchain2023exploiting","doi-asserted-by":"publisher","first-page":"359","DOI":"10.46586\/tches.v2024.i2.359-383","article-title":"Exploiting small-norm polynomial multiplication with\n  physical attacks: Application to CRYSTALS-Dilithium","author":"Olivier Bronchain","year":"2024","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"volume-title":"Migration to quantum-resistant algorithms in mobile\n  networks","year":"2023","author":"John Mattsson","key":"ref16:Er23"},{"key":"ref17:fips204","article-title":"FIPS 204 (Draft): Module-Lattice-Based Digital Signature\n  Standard","author":"PUB FIPS","year":"2023","journal-title":"National Institute of Standards and Technology"},{"key":"ref18:oliveira2024uncompressing","article-title":"Uncompressing Dilithium's public key","author":"Paco Azevedo Oliveira","year":"2024","journal-title":"Cryptology ePrint Archive"},{"volume-title":"Round 1 Official Comment: CRYSTALS-Dilithium","year":"2018","author":"Vadim Lyubashevsky","key":"ref19:dil_comment"},{"key":"ref20:abdulrahman2022faster","doi-asserted-by":"publisher","first-page":"853","DOI":"10.1007\/978-3-031-09234-3_42","article-title":"Faster Kyber and Dilithium on the Cortex-M4","author":"Amin Abdulrahman","year":"2022"},{"key":"ref21:lyubashevsky2009fiat","doi-asserted-by":"publisher","first-page":"598","DOI":"10.1007\/978-3-642-10366-7_35","article-title":"Fiat-Shamir with aborts: Applications to lattice and\n  factoring-based signatures","author":"Vadim Lyubashevsky","year":"2009"},{"key":"ref22:archambeau2006template","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11894063_1","article-title":"Template attacks in principal subspaces","author":"C\u00e9dric Archambeau","year":"2006"},{"key":"ref23:camurati2018screaming","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1145\/3243734.3243802","article-title":"Screaming channels: When electromagnetic side channels meet\n  radio transceivers","author":"Giovanni Camurati","year":"2018"},{"key":"ref24:HoGA18","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1109\/DSD.2019.00041","article-title":"Circumventing uniqueness of XOR arbiter PUFs","author":"Caio Hoffman","year":"2019"},{"key":"ref25:MaR16","isbn-type":"print","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-49445-6_1","article-title":"Breaking Cryptographic Implementations Using Deep Learning\n  Techniques","author":"Houssem Maghrebi","year":"2016","ISBN":"https:\/\/id.crossref.org\/isbn\/9783319494456"},{"key":"ref26:CaDP18","isbn-type":"print","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1007\/978-3-319-66787-4_3","article-title":"Convolutional Neural Networks with Data Augmentation Against\n  Jitter-Based Countermeasures","author":"Eleonora Cagli","year":"2017","ISBN":"https:\/\/id.crossref.org\/isbn\/9783319667874"},{"key":"ref27:Kim18","doi-asserted-by":"publisher","first-page":"148","DOI":"10.13154\/tches.v2019.i3.148-179","article-title":"Make Some Noise. Unleashing the Power of Convolutional\n  Neural Networks for Profiled Side-channel Analysis","volume":"2019","author":"Jaehun Kim","year":"2019","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref28:BrFD20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68487-7_9","article-title":"How Deep Learning Helps Compromising USIM","author":"Martin Brisfors","year":"2020"},{"key":"ref29:Tim18","doi-asserted-by":"publisher","first-page":"107","DOI":"10.13154\/tches.v2019.i2.107-131","article-title":"Non-profiled deep learning-based side-channel attacks with\n  sensitivity analysis","author":"Benjamin Timon","year":"2019","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref30:BrCP04","isbn-type":"print","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/978-3-540-28632-5_2","article-title":"Correlation Power Analysis with a Leakage Model","author":"Eric Brier","year":"2004","ISBN":"https:\/\/id.crossref.org\/isbn\/9783540286325"},{"key":"ref31:SimPH22","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3179683","article-title":"Chosen-ciphertext Clustering Attack on CRYSTALS-KYBER\n  using the Side-channel Leakage of Barrett Reduction","author":"Bo-Yeon Sim","year":"2022","journal-title":"IEEE Internet of Things Journal"},{"key":"ref32:C:DDGR20_custom","isbn-type":"print","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-030-56880-1_12","article-title":"LWE with Side Information: Attacks and Concrete Security\n  Estimation","volume":"12171","author":"Dana Dachman-Soled","year":"2020","ISBN":"https:\/\/id.crossref.org\/isbn\/9783030568801"},{"key":"ref33:1982-lenstra-lll","doi-asserted-by":"crossref","first-page":"515","DOI":"10.1007\/BF01457454","article-title":"Factoring polynomials with rational coefficients","volume":"261","author":"Arjen K. Lenstra","year":"1982","journal-title":"Mathematische Annalen"},{"key":"ref34:SE94","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/BF01581144","article-title":"Lattice basis reduction: Improved practical algorithms and\n  solving subset sum problems","volume":"66","author":"Claus-Peter Schnorr","year":"1994","journal-title":"Mathematical programming"},{"key":"ref35:bdgl16","series-title":"SODA '16","isbn-type":"print","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1137\/1.9781611974331.ch2","article-title":"New Directions in Nearest Neighbor Searching with\n  Applications to Lattice Sieving","author":"Anja Becker","year":"2016","ISBN":"https:\/\/id.crossref.org\/isbn\/9781611974331"},{"volume-title":"R\u00e9duction de r\u00e9seau et s\u00e9curit\u00e9 concrete du\n  chiffrement completement homomorphe","year":"2013","author":"Yuanmi Chen","key":"ref36:Chen2013"},{"key":"ref37:concrete-lwe","doi-asserted-by":"publisher","DOI":"10.1515\/jmc-2015-0016","article-title":"On the concrete hardness of Learning with Errors","volume":"9","author":"Martin Albrecht","year":"2015","journal-title":"Journal of Mathematical Cryptology"},{"key":"ref38:10.1007\/978-3-030-60939-9_19","isbn-type":"print","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1007\/978-3-030-60939-9_19","article-title":"Profiling Dilithium Digital Signature Traces for\n  Correlation Differential Side Channel Attacks","author":"Apostolos P. Fournaris","year":"2020","ISBN":"https:\/\/id.crossref.org\/isbn\/9783030609399"},{"key":"ref39:Migliore2019","doi-asserted-by":"publisher","first-page":"344","DOI":"10.1007\/978-3-030-21568-2_17","article-title":"Masking Dilithium: Efficient implementation and\n  side-channel evaluation","author":"Vincent Migliore","year":"2019"},{"key":"ref40:steffen2023breaking","doi-asserted-by":"publisher","first-page":"688","DOI":"10.1007\/978-3-031-40003-2_25","article-title":"Breaking and protecting the Crystal: Side-channel analysis\n  of Dilithium in hardware","author":"Hauke Steffen","year":"2023"},{"key":"ref41:LiZS20","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TIFS.2020.3045904","article-title":"On the Security of Lattice-Based Fiat-Shamir Signatures\n  in the Presence of Randomness Leakage","volume":"PP","author":"Yuejun Liu","year":"2020","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"ref42:9924203","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TIFS.2022.3215913","article-title":"Practical Public Template Attacks on CRYSTALS-Dilithium\n  With Randomness Leakages","volume":"18","author":"Zehua Qiao","year":"2023","journal-title":"IEEE Transactions on Information Forensics and Security"},{"volume-title":"When NTT Meets SIS: Efficient Side-channel Attacks on\n  Dilithium and Kyber","year":"2023","author":"Zehua Qiao","key":"ref43:Qiao2023"},{"volume-title":"A Side-Channel Assisted Attack on NTRU","year":"2021","author":"Amund Askeland","key":"ref44:amund21"},{"key":"ref45:do2019role","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1016\/j.cose.2018.12.002","article-title":"The role of the adversary model in applied security\n  research","volume":"81","author":"Quang Do","year":"2019","journal-title":"Computers & Security"},{"key":"ref46:SiKLKL20","doi-asserted-by":"publisher","first-page":"183175","DOI":"10.1109\/ACCESS.2020.3029521","article-title":"Single-trace attacks on message encoding in lattice-based\n  KEMs","volume":"8","author":"Bo-Yeon Sim","year":"2020","journal-title":"IEEE Access"},{"key":"ref47:wang2020multi","doi-asserted-by":"publisher","DOI":"10.1109\/ISMVL49045.2020.00-29","article-title":"Multi-source training deep learning side-channel attacks","author":"Huanyu Wang","year":"2020"},{"volume-title":"ChipWhisperer","author":"NewAE Technology Inc.","key":"ref48:cw"},{"author":"CW308 UFO Board","key":"ref49:cw308"},{"author":"CW308T-STM32F4 target board","key":"ref50:cw308target"},{"key":"ref51:huanyudiver","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/NORCHIP.2019.8906945","article-title":"How Diversity Affects Deep-Learning Side-Channel Attacks","author":"Huanyu Wang","year":"2019"},{"key":"ref52:DuNG22","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1145\/3591866.3593072","article-title":"Breaking a fifth-order masked implementation of\n  CRYSTALS-Kyber by copy-paste","author":"Elena Dubrova","year":"2023"},{"key":"ref53:brisfors2022not","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1007\/978-3-031-30122-3_3","article-title":"Do not rely on clock randomization: A side-channel attack on\n  a protected hardware implementation of AES","author":"Martin Brisfors","year":"2022"},{"volume-title":"Darmstadt SVP Challenges","year":"2010","author":"Michael Schneider","key":"ref54:svp-challenge"},{"key":"ref55:coron23masked","doi-asserted-by":"publisher","first-page":"110","DOI":"10.46586\/tches.v2023.i4.110-145","article-title":"Improved gadgets for the high-order masking of Dilithium","volume":"2023","author":"Jean-S\u00e9bastien Coron","year":"2023","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref56:azouaoui2023protecting","doi-asserted-by":"publisher","first-page":"58","DOI":"10.46586\/tches.v2023.i4.58-79","article-title":"Protecting Dilithium against Leakage: Revisited\n  Sensitivity Analysis and Improved Implementations","volume":"2023","author":"Melissa Azouaoui","year":"2023","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref57:wangtandem","doi-asserted-by":"publisher","first-page":"373","DOI":"10.1007\/s42979-021-00755-w","article-title":"Tandem deep learning side-channel attack on FPGA\n  implementation of AES","volume":"2","author":"Huanyu Wang","year":"2021","journal-title":"SN Computer Science"},{"key":"ref58:PeCP20","doi-asserted-by":"publisher","first-page":"337","DOI":"10.13154\/tches.v2020.i4.337-364","article-title":"Strength in numbers: Improving generalization with ensembles\n  in machine learning-based profiled side-channel analysis","author":"Guilherme Perin","year":"2020","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref59:NgD22a","doi-asserted-by":"publisher","DOI":"10.1145\/3526241.3530324","article-title":"Side-Channel Analysis of the Random Number Generator in\n  STM32 MCUs","author":"Kalle Ngo","year":"2022"},{"key":"ref60:PiSK18","isbn-type":"print","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1007\/978-3-030-05072-6_10","article-title":"On the Performance of Convolutional Neural Networks for\n  Side-Channel Analysis","author":"Stjepan Picek","year":"2018","ISBN":"https:\/\/id.crossref.org\/isbn\/9783030050726"},{"volume-title":"Advanced Side-Channel Analysis of USIMs, Bluetooth SoCs\n  and MCUs","year":"2021","author":"Martin Brisfors","key":"ref61:Br21"},{"key":"ref62:Hajra_Chowdhury_Mukhopadhyay_2023","doi-asserted-by":"publisher","first-page":"336","DOI":"10.46586\/tches.v2024.i1.336-374","article-title":"EstraNet: An Efficient Shift-Invariant Transformer Network\n  for Side-Channel Analysis","volume":"2024","author":"Suvadeep Hajra","year":"2024","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref63:WuP20","doi-asserted-by":"publisher","first-page":"389","DOI":"10.13154\/tches.v2020.i4.389-415","article-title":"Remove some noise: On pre-processing of side-channel\n  measurements with autoencoders","author":"Lichao Wu","year":"2020","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref64:cryptoeprint:2023\/551","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1007\/978-3-031-54773-7_5","article-title":"Breaking DPA-protected Kyber via the pair-pointwise\n  multiplication","author":"Estuardo Alpirez Bock","year":"2024"},{"key":"ref65:BaNGD22","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/978-3-031-41181-6_9","article-title":"Secret Key Recovery Attack on Masked and Shuffled\n  Implementations of CRYSTALS-Kyber and Saber","author":"Linus Backlund","year":"2023"},{"volume-title":"A Single-Trace Message Recovery Attack on a Masked and\n  Shuffled Implementation of CRYSTALS-Kyber","year":"2023","author":"S\u00f6nke Jendral","key":"ref66:JeNWD23"},{"key":"ref67:MaSB16","isbn-type":"print","doi-asserted-by":"publisher","first-page":"223","DOI":"10.1007\/978-3-662-52993-5_12","article-title":"There Is Wisdom in Harnessing the Strengths of Your Enemy:\n  Customized Encoding to Thwart Side-Channel Attacks","author":"Houssem Maghrebi","year":"2016","ISBN":"https:\/\/id.crossref.org\/isbn\/9783662529935"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T21:28:13Z","timestamp":1733866093000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/3\/12"}},"subtitle":["A Single-Trace Secret Key Recovery Attack on Dilithium"],"short-title":[],"issued":{"date-parts":[[2024,10,7]]},"references-count":67,"URL":"https:\/\/doi.org\/10.62056\/a0fh89n4e","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"type":"electronic","value":"3006-5496"}],"subject":[],"published":{"date-parts":[[2024,10,7]]},"assertion":[{"value":"2024-07-03","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-3-34"}}