{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T13:11:23Z","timestamp":1785417083003,"version":"3.56.0"},"reference-count":25,"publisher":"International Association for Cryptologic Research","issue":"2","license":[{"start":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T00:00:00Z","timestamp":1744070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,6,2]]},"abstract":"<jats:p>\n                    Classic McEliece was one of the code-based Key Encapsulation Mechanism finalists in the NIST post-quantum cryptography standardization process. Several key-recovery side-channel attacks on the decapsulation algorithm have already been published. However none of them discusses the feasibility and\/or efficiency of the attack in the case of noisy side-channel acquisitions. In this paper, we address this issue by proposing two improvements on the recent key-recovery attack published by Dr\u0103goi et al.. First, we introduce an error correction algorithm for the lists of Hamming weights obtained by side-channel measurements, based on the assumption, validated experimentally, that the error on a recovered Hamming weight is bounded to\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>\u00b1<\/mml:mi>\n                        <mml:mn>1<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    . We then offer a comparison between two decoding efficiency metrics, the theoretical minimal error correction capability and an empirical average correction probability. We show that the minimal error correction capability, widely used for linear codes, is not suitable for the (non-linear) code formed by the lists of Hamming weights. Conversely, experimental results show that out of 1 million random erroneous lists of\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>2<\/mml:mn>\n                        <mml:mi>t<\/mml:mi>\n                        <mml:mo>=<\/mml:mo>\n                        <mml:mn>128<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    Hamming weights, only 2 could not be corrected by the proposed algorithm. This shows that the probability of successfully decoding a list of erroneous Hamming weights is very high, regardless of the error weight. In addition to this algorithm, we describe how the secret Goppa polynomial\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>g<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    , recovered during the first step of the attack, can be exploited to reduce both the time and space complexity of recovering the secret permuted support\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>\u2112<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    .\n                  <\/jats:p>","DOI":"10.62056\/ahmpgyl7s","type":"journal-article","created":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T17:09:09Z","timestamp":1751908149000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":1,"title":["Optimizing Key Recovery in Classic McEliece: Advanced Error Correction for Noisy Side-Channel Measurements"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-5282-7571","authenticated-orcid":false,"given":"Nicolas","family":"Vallet","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0028p8r67","id-type":"ROR","asserted-by":"publisher"}],"name":"Universit\u00e9 Jean Monnet Saint-Etienne, CNRS, Institut d Optique Graduate School, Laboratoire Hubert Curien UMR 5516, F-42023","place":["Saint-\u00c9tienne, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6708-868X","authenticated-orcid":false,"given":"Pierre-Louis","family":"Cayrel","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0028p8r67","id-type":"ROR","asserted-by":"publisher"}],"name":"Universit\u00e9 Jean Monnet Saint-Etienne, CNRS, Institut d Optique Graduate School, Laboratoire Hubert Curien UMR 5516, F-42023","place":["Saint-\u00c9tienne, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6028-3028","authenticated-orcid":false,"given":"Brice","family":"Colombier","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0028p8r67","id-type":"ROR","asserted-by":"publisher"}],"name":"Universit\u00e9 Jean Monnet Saint-Etienne, CNRS, Institut d Optique Graduate School, Laboratoire Hubert Curien UMR 5516, F-42023","place":["Saint-\u00c9tienne, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8673-9097","authenticated-orcid":false,"given":"Vlad-Florin","family":"Dr\u0103goi","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05w5rsy15","id-type":"ROR","asserted-by":"publisher"}],"name":"Faculty of Exact Sciences, Aurel Vlaicu University of Arad","place":["Arad, Romania"]},{"id":[{"id":"https:\/\/ror.org\/01f1vfy95","id-type":"ROR","asserted-by":"publisher"}],"name":"LITIS, University of Rouen Normandie","place":["Saint-\u00c9tienne du Rouvray, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3874-7527","authenticated-orcid":false,"given":"Vincent","family":"Grosso","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0028p8r67","id-type":"ROR","asserted-by":"publisher"}],"name":"Universit\u00e9 Jean Monnet Saint-Etienne, CNRS, Institut d Optique Graduate School, Laboratoire Hubert Curien UMR 5516, F-42023","place":["Saint-\u00c9tienne, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,7,7]]},"reference":[{"key":"ref1:nist_fips203_2024","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.FIPS.203","volume-title":"FIPS203 Module-Lattice-Based Key-Encapsulation Mechanism\n  Standard","author":"National Institute of Standards","year":"2024"},{"key":"ref2:nist_fips204_2024","volume-title":"FIPS204 Module-Lattice-Based Digital Signature Standard","author":"National Institute of Standards","year":"2024"},{"key":"ref3:nist_fips205_2024","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.FIPS.205","volume-title":"FIPS205 Stateless Hash-Based Digital Signature Standard","author":"National Institute of Standards","year":"2024"},{"key":"ref4:NISTPQC:FALCON22","volume-title":"FALCON","author":"Thomas Prest","year":"2022"},{"key":"ref5:NISTPQC-R4:BIKE22","volume-title":"BIKE","author":"Nicolas Aragon","year":"2022"},{"key":"ref6:NISTPQC-R4:ClassicMcEliece22","volume-title":"Classic McEliece","author":"Martin R. Albrecht","year":"2022"},{"key":"ref7:NISTPQC-R4:HQC22","volume-title":"HQC","author":"Carlos Aguilar-Melchor","year":"2022"},{"key":"ref8:NISTPQC-R3:FrodoKEM20","volume-title":"FrodoKEM","author":"Michael Naehrig","year":"2020"},{"key":"ref9:TCHES:BCMNY25","doi-asserted-by":"publisher","first-page":"94","DOI":"10.46586\/tches.v2025.i2.94-125","article-title":"Leaky McEliece: Secret Key Recovery From Highly Erroneous\n  Side-Channel Information","volume":"2025","author":"Marcus Brinkmann","year":"2025","journal-title":"IACR TCHES"},{"key":"ref10:AFRICACRYPT:SCDDBKGC23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1007\/978-3-031-37679-5_5","article-title":"A Side-Channel Attack Against Classic McEliece When\n  Loading the Goppa Polynomial","volume":"14064","author":"Boly Seck","year":"2023"},{"key":"ref11:TCHES:GuoJohJoh22","doi-asserted-by":"publisher","first-page":"800","DOI":"10.46586\/tches.v2022.i4.800-827","article-title":"A Key-Recovery Side-Channel Attack on Classic McEliece\n  Implementations","volume":"2022","author":"Qian Guo","year":"2022","journal-title":"IACR TCHES"},{"key":"ref12:TCHES:DCVCV25","doi-asserted-by":"publisher","first-page":"367","DOI":"10.46586\/tches.v2025.i1.367-391","article-title":"Full Key-Recovery Cubic-Time Template Attack on Classic\n  McEliece Decapsulation","volume":"2025","author":"Vlad-Florin Dr\u0103goi","year":"2025","journal-title":"IACR TCHES","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref13:COSADE:OFlChe14","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1007\/978-3-319-10175-0_17","article-title":"ChipWhisperer: An Open-Source Platform for Hardware\n  Embedded Security Research","volume":"8622","author":"Colin O'Flynn","year":"2014"},{"key":"ref14:CHES:ChaRaoRoh02","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1007\/3-540-36400-5_3","article-title":"Template Attacks","volume":"2523","author":"Suresh Chari","year":"2003"},{"key":"ref15:DBLP:journals\/tit\/Sendrier00","doi-asserted-by":"publisher","first-page":"1193","DOI":"10.1109\/18.850662","article-title":"Finding the permutation between equivalent linear codes: The\n  support splitting algorithm","volume":"46","author":"Nicolas Sendrier","year":"2000","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref16:Ber2024","doi-asserted-by":"publisher","DOI":"10.62056\/angy4fe-3","article-title":"Understanding binary-Goppa decoding","volume":"1","author":"Daniel J. Bernstein","year":"2024","journal-title":"IACR Communications in Cryptology","ISSN":"https:\/\/id.crossref.org\/issn\/3006-5496","issn-type":"electronic"},{"key":"ref17:WISA:MMPS09","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/978-3-642-10838-9_15","article-title":"A Comparative Study of Mutual Information Analysis under a\n  Gaussian Assumption","volume":"5932","author":"Amir Moradi","year":"2009"},{"key":"ref18:SAC:Rivain08","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/978-3-642-04159-4_11","article-title":"On the Exact Success Rate of Side Channel Analysis in the\n  Gaussian Model","volume":"5381","author":"Matthieu Rivain","year":"2009"},{"key":"ref19:CHES:HeuRioGui14","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1007\/978-3-662-44709-3_4","article-title":"Good Is Not Good Enough - Deriving Optimal Distinguishers\n  from Communication Theory","volume":"8731","author":"Annelie Heuser","year":"2014"},{"key":"ref20:DBLP:phd\/ethos\/Choudary14","volume-title":"Efficient multivariate statistical techniques for extracting\n  secrets from electronic devices","author":"Omar-Salim Choudary","year":"2014"},{"key":"ref21:CHES:StaArc08","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"411","DOI":"10.1007\/978-3-540-85053-3_26","article-title":"Using Subspace-Based Template Attacks to Compare and Combine\n  Power and Electromagnetic Information Leakages","volume":"5154","author":"Fran\u00e7ois-Xavier Standaert","year":"2008"},{"key":"ref22:McEliece78","first-page":"114","volume-title":"A public-key cryptosystem based on algebraic coding theory","author":"Robert J. McEliece","year":"1978"},{"key":"ref23:Niederreiter86","first-page":"159","article-title":"Knapsack-Type Cryptosystems and Algebraic Coding Theory","volume":"15","author":"H. Niederreiter","year":"1986","journal-title":"Problems of Control and Information Theory"},{"key":"ref24:sidelnikov1992insecurity","doi-asserted-by":"publisher","first-page":"439","DOI":"10.1515\/dma.1992.2.4.439","article-title":"On insecurity of cryptosystems based on generalized\n  Reed-Solomon codes","volume":"2","author":"VM Sidelnikov","year":"1992","journal-title":"Discrete Math. AppL"},{"key":"ref25:DBLP:journals\/tit\/LiDW94","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1109\/18.272496","article-title":"On the equivalence of McEliece's and Niederreiter's\n  public-key cryptosystems","volume":"40","author":"Yuanxing Li","year":"1994","journal-title":"IEEE Trans. Inf. Theory"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T17:10:07Z","timestamp":1751908207000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/2\/26"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,7]]},"references-count":25,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,7,7]]}},"URL":"https:\/\/doi.org\/10.62056\/ahmpgyl7s","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,7]]},"assertion":[{"value":"2025-04-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-06-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-2-65"}}