Paper 2025/1608
Multi-Value Plaintext-Checking and Full-Decryption Oracle-Based Attacks on HQC from Offline Templates
Abstract
The Hamming Quasi-Cyclic (HQC) key encapsulation mechanism (KEM), recently selected by NIST for standardization in the Post-Quantum Cryptography (PQC) process, distinguishes itself through its efficiency, robust design based on hard decoding problems in coding theory, and well-characterized decryption failure rates. Despite its selection, practical security concerns arise from implementation threats, particularly those exploiting plaintext-checking (PC) oracles. While multi-value PC (MV-PC) and full decryption (FD) oracle attacks have been extensively studied in the context of lattice-based cryptography, their applicability to code-based schemes like HQC has remained relatively unexplored. In this work, we present the first MV-PC and FD oracle attacks targeting code-based KEMs, specifically on HQC. Our MV-PC attack significantly reduces the required oracle queries compared to previous PC oracle-based methods and holds implications for side-channel, key-mismatch, and fault-injection attacks. Our FD attack exhibits remarkable efficiency in trace complexity, achieving secret key recovery for hqc-128 with just two queries to a perfect oracle, and four queries for hqc-192 and hqc-256. Simulations further demonstrate the robustness of our MV-PC and FD oracle attacks against imperfect oracle responses. We experimentally validate the new attacks on an ARM Cortex-M4 microcontroller, highlighting the critical need for robust countermeasures. In particular, on such a platform, substantial leakage during operations like syndrome computation poses significant challenges to the efficiency of masking techniques in mitigating FD oracle attacks.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Published by the IACR in TCHES 2025
- DOI
- 10.46586/tches.v2025.i4.254-289
- Keywords
- Code-based cryptographySide-channel attacksHQCPlaintext-checking oracle
- Contact author(s)
-
chelseadong202 @ gmail com
qian guo @ eit lth se - History
- 2025-09-11: approved
- 2025-09-07: received
- See all versions
- Short URL
- https://ia.cr/2025/1608
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1608,
author = {Haiyue Dong and Qian Guo},
title = {Multi-Value Plaintext-Checking and Full-Decryption Oracle-Based Attacks on {HQC} from Offline Templates},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1608},
year = {2025},
doi = {10.46586/tches.v2025.i4.254-289},
url = {https://eprint.iacr.org/2025/1608}
}