Paper 2025/1577

Template and CPA Side Channel Attacks on the Kyber/ML-KEM Pair-Pointwise Multiplication

Sedric Nkotto, SRC Security Research & Consulting GmbH
Abstract

Kyber a.k.a ML-KEM is a quantum-safe Key Encapsulation Mechanism, that has been standardized by NIST under FIPS-203 and will definitely in the coming years be implemented in several commercial products. Following fors instance this report https://radar.cloudflare.com/adoption-and-usage?dateRange=52w, one can notice that since the end of 2024, the post-quantum encrypted share of the HTTPS request traffics has been increasing and is about to reach 50% now. However, the resilience of implementations against side channel attacks is still an open and practical concern. One of the drawbacks of the ongoing side channel analysis research related to PQC schemes is the availability of open-source datasets. Luckily some open-source datasets start popping up. For instance, the one recently published by Rezaeezade et al. in the paper 2025/811. This dataset captures power consumption during a pair-pointwise multiplication occurring in the course of ML-KEM decapsulation process and involving the decapsulation (sub)key and ciphertexts. In this paper we present both a profiled (template) and an unprofiled (CPA) side channel attacks targeting that pair-pointwise multiplication, which yield, in both cases, a complete recovery of the decapsulation secret (sub)key.

Note: Compared to the previous one, this version of the paper improves the Template attack with Linear Discriminant Analysis (LDA). As a result, the number of required traces drops from about 300 traces to a maximum of 40 traces to recover the secret key

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Template Side-Channel AttackLinear Discriminant AnalysisCPA AttackPost Quantum CryptographyKyberML-KEM
Contact author(s)
sedric nkotto @ src-gmbh de
History
2026-02-05: last of 6 revisions
2025-09-02: received
See all versions
Short URL
https://ia.cr/2025/1577
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1577,
      author = {Sedric Nkotto},
      title = {Template and {CPA} Side Channel Attacks on the  Kyber/{ML}-{KEM} Pair-Pointwise Multiplication},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1577},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1577}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.