Chosen-Ciphertext Clustering Attack on CRYSTALS-KYBER Using the Side-Channel Leakage of Barrett Reduction

被引:7
|
作者
Sim, Bo-Yeon [1 ]
Park, Aesun [2 ]
Han, Dong-Guk [3 ]
机构
[1] Elect & Telecommun Res Inst, Dept Intelligent Convergence Res Lab, Daejeon 34129, South Korea
[2] Def Secur Support Command, Dept Informat Secur Unit, Gwacheon 13820, South Korea
[3] Kookmin Univ, Dept Informat Secur Cryptol & Math, Seoul 02707, South Korea
关键词
Barrett reduction; chosen-ciphertext attack (CCA); key decapsulation mechanism; lattice-based cryptography; side-channel attack (SCA);
D O I
10.1109/JIOT.2022.3179683
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This study proposes a chosen-ciphertext sidechannel attack against a lattice-based key encapsulation mechanism (KEM), the third-round candidate of the national institute of standards and technology (NIST) standardization project. Unlike existing attacks that target operations, such as inverse NTT and message encoding/decoding, we target Barrett reduction in the decapsulation phase of CRYSTALS - KYBER to obtain a secret key. We show that a sensitive variable-dependent leakage of Barrett reduction exposes an entire secret key. The results of experiments conducted on the ARM Cortex-M4 microcontroller accomplish a success rate of 100%. We only need six chosen ciphertexts for KYBER512 and KYBER768 and eight chosen ciphertexts for KYBER1024. We also show that the m4 scheme of the pqm4 library, an implementation with the ARM Cortex-M4 specific optimization (typically in assembly), is vulnerable to the proposed attack. In this scheme, six, nine, and twelve chosen ciphertexts are required for KYBER512, KYBER768, and KYBER1024, respectively.
引用
收藏
页码:21382 / 21397
页数:16
相关论文
共 17 条
  • [1] A Side-Channel Attack on a Hardware Implementation of CRYSTALS-Kyber
    Ji, Yanning
    Wang, Ruize
    Ngo, Kalle
    Dubrova, Elena
    Backlund, Linus
    2023 IEEE EUROPEAN TEST SYMPOSIUM, ETS, 2023,
  • [2] A side-channel attack on a masked hardware implementation of CRYSTALS-Kyber
    Ji, Yanning
    Dubrova, Elena
    JOURNAL OF CRYPTOGRAPHIC ENGINEERING, 2025, 15 (01)
  • [3] A Side-Channel Attack on a Masked Hardware Implementation of CRYSTALS-Kyber
    Ji, Yanning
    Dubrova, Elena
    PROCEEDINGS OF THE 2023 WORKSHOP ON ATTACKS AND SOLUTIONS IN HARDWARE SECURITY, ASHES 2023, 2023, : 27 - 37
  • [4] A comprehensive side-channel leakage assessment of CRYSTALS-Kyber in IIoT
    Huang, Zitian
    Wang, Huanyu
    Cao, Bijia
    He, Dalin
    Wang, Junnian
    INTERNET OF THINGS, 2024, 27
  • [5] A Side-Channel Attack on a Higher-Order Masked CRYSTALS-Kyber Implementation
    Wang, Ruize
    Brisfors, Martin
    Dubrova, Elena
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, ACNS 2024, PT III, 2024, 14585 : 301 - 324
  • [6] A Configurable CRYSTALS-Kyber Hardware Implementation with Side-Channel Protection
    Jati, Arpan
    Gupta, Naina
    Chattopadhyay, Anupam
    Sanadhya, Somitra Kumar
    ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2024, 23 (02)
  • [7] Reveal the Invisible Secret: Chosen-Ciphertext Side-Channel Attacks on NTRU
    Xu, Zhuang
    Pemberton, Owen
    Oswald, David
    Zheng, Zhiming
    SMART CARD RESEARCH AND ADVANCED APPLICATIONS, CARDIS 2022, 2023, 13820 : 227 - 247
  • [8] Post-Quantum Authenticated Encryption against Chosen-Ciphertext Side-Channel Attacks
    Azouaoui M.
    Kuzovkova Y.
    Schneider T.
    van Vredendaal C.
    IACR Transactions on Cryptographic Hardware and Embedded Systems, 2022, 2022 (04): : 372 - 396
  • [9] Side-Channel Analysis of CRYSTALS-Kyber and A Novel Low-Cost Countermeasure
    Hamoudi, Meziane
    Korchi, Amina Bel
    Guilley, Sylvain
    Takarabt, Sofiane
    Karray, Khaled
    Souissi, Youssef
    SECURITY AND PRIVACY, ICSP 2021, 2021, 1497 : 30 - 46
  • [10] A New Key Recovery Side-Channel Attack on HQC with Chosen Ciphertext
    Goy, Guillaume
    Loiseau, Antoine
    Gaborit, Philippe
    POST-QUANTUM CRYPTOGRAPHY (PQCRYPTO 2022), 2022, 13512 : 353 - 371