Paper 2026/071

Codeword Masking Can Be Harmful Under Replay Attacks on HQC

Jaeho Jeon, DGIST
Yongseong Park
Jaeyeon Lee
Suseong Lee, DGIST
Donghyen Kim, DGIST
Young-Sik Kim, DGIST
Abstract

HQC, selected by NIST for standardization in 2025, was recently shown vulnerable to a replay attack recovering $\mathbf{v} - \mathbf{u}\cdot \mathbf{y}$, from which the long-term secret $\mathbf{y}$ was shown to be recoverable, and against which \emph{codeword masking} was proposed as the countermeasure. We revisit both and demonstrate that the countermeasure yields an opposite effect: on the target build, the unmasked replay attack is ineffective, whereas introducing codeword masking paradoxically enables its success. We present a new leakage venue in HQC, in the Reed--Muller encoder, and apply to it the post-decoding idea of recent work, turning HQC's own error correction into a side-channel budget that recovers the message: a single trace suffices, with only ${\sim}80$ profiling traces, and we confirm the same across the official implementations (the NIST reference and optimized code, and PQClean) at both \texttt{-O3} and \texttt{-Os}. We then improve the replay attack on $\mathbf{v} - \mathbf{u}\cdot \mathbf{y}$, raising its per-bit recovery probability; at the optimization level we study, that is still not enough for a practical attack. Codeword masking, adopted as the defense, supplies what replay could not: the random share erases the ambiguity that identical replays leave behind, and the extrapolated probability of recovering the whole $\mathbf{v} - \mathbf{u}\cdot \mathbf{y}$ rises from $10^{-555}$ to $1.0$. Increasing the masking order fails to mitigate the attack: we demonstrate identical recovery against a three-share implementation, without incurring additional profiling overhead for the adversary. Masking must therefore be designed against the optimization level and the device it is deployed on.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A minor revision of an IACR publication in ASIACRYPT 2026
Keywords
HQCHamming Quasi-CyclicPQCPost-Quantum CryptographyKEMEmbedded systemsside-channel attacks
Contact author(s)
dgwogh @ dgist ac kr
reo91004 @ dgist ac kr
ljy8733 @ dgist ac kr
mercury @ dgist ac kr
dhkim200426 @ dgist ac kr
ysk @ dgist ac kr
History
2026-09-17: last of 3 revisions
2026-01-16: received
See all versions
Short URL
https://ia.cr/2026/071
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/071,
      author = {Jaeho Jeon and Yongseong Park and Jaeyeon Lee and Suseong Lee and Donghyen Kim and Young-Sik Kim},
      title = {Codeword Masking Can Be Harmful Under Replay Attacks on {HQC}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/071},
      year = {2026},
      url = {https://eprint.iacr.org/2026/071}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.