Paper 2025/873

Improvement of Side-Channel Attacks on Mitaka

Vladimir Sarde, Cryptography & Security Group, IDEMIA Secure Transactions, Pessac, France, Laboratoire de Mathématiques de Versailles, UVSQ, CNRS, Université Paris-Saclay, 78035 Versailles, France
Nicolas Debande, Cryptography & Security Group, IDEMIA Secure Transactions, Pessac, France
Abstract

Mitaka is a variant of Falcon, which is one of the three postquantum signature schemes selected by the NIST for standardization. Introduced in 2021, Mitaka offers a simpler, parallelizable, and maskable version of Falcon. Our article focuses on its physical security, and our results are threefold. Firstly, we enhance a known profiled side-channel attack on an unprotected Mitaka implementation by a factor of 512. Secondly, we analyze the masked implementation of Mitaka described in the reference article, which incorporates a different sampler and a protective gadget. We expose the first side-channel flaw on this sampler. This flaw enables to break the masked implementation with a first-order side-channel attack. In this scenario, the key can be recovered using only three times more traces compared to the attack on the unprotected implementation. Finally, we discuss and recommend new countermeasures to mitigate these attacks.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Minor revision. CASCADE
Keywords
Post-quantum cryptographySignature schemeMitakaSidechannel analysisLattice
Contact author(s)
vladimir sarde @ idemia com
nicolas debande @ idemia com
History
2025-05-19: approved
2025-05-16: received
See all versions
Short URL
https://ia.cr/2025/873
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2025/873,
      author = {Vladimir Sarde and Nicolas Debande},
      title = {Improvement of Side-Channel Attacks on Mitaka},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/873},
      year = {2025},
      url = {https://eprint.iacr.org/2025/873}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.