TY - GEN
T1 - Breaking Masked Kyber
T2 - 28th International Conference on Information Security and Cryptology, ICISC 2025
AU - Ding, Yaoling
AU - Xu, Haotong
AU - Luo, Chong
AU - Liu, Annyu
AU - Zhang, Zheyu
AU - Yu, Jing
AU - Wang, An
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2026.
PY - 2026
Y1 - 2026
N2 - As post-quantum cryptography becomes the cornerstone of future security systems, it is crucial to understand its practical resilience under present side-channel analysis. In this paper, we propose an effective side-channel analysis method for the poly_tomsg() function in the decapsulation of the first-order mask implementation of CRYSTALS-Kyber (the NIST-selected post-quantum key encapsulation mechanism). Unlike previous methods that target individual bits, our method targets a masked shared byte. By systematically evaluating multiple neural network architectures (MLP, CNN, ResNet), we find that residual learning has the best robustness under low signal-to-noise ratios. The method achieves up to 98% average accuracy by training a ResNet18 network, and is able to recover m from a single trace with a success rate of over 38%, outperforming classical template attacks without trace alignment. These findings reveal that even well-implemented Boolean masking can be defeated by neural-based profiling attacks, thus emphasizing the need for stronger countermeasures in post-quantum cryptographic implementations.
AB - As post-quantum cryptography becomes the cornerstone of future security systems, it is crucial to understand its practical resilience under present side-channel analysis. In this paper, we propose an effective side-channel analysis method for the poly_tomsg() function in the decapsulation of the first-order mask implementation of CRYSTALS-Kyber (the NIST-selected post-quantum key encapsulation mechanism). Unlike previous methods that target individual bits, our method targets a masked shared byte. By systematically evaluating multiple neural network architectures (MLP, CNN, ResNet), we find that residual learning has the best robustness under low signal-to-noise ratios. The method achieves up to 98% average accuracy by training a ResNet18 network, and is able to recover m from a single trace with a success rate of over 38%, outperforming classical template attacks without trace alignment. These findings reveal that even well-implemented Boolean masking can be defeated by neural-based profiling attacks, thus emphasizing the need for stronger countermeasures in post-quantum cryptographic implementations.
KW - CRYSTALS-Kyber
KW - Masking
KW - Neural networks
KW - Profiling attacks
KW - Side-channel analysis
UR - https://www.scopus.com/pages/publications/105040567108
U2 - 10.1007/978-981-95-8034-7_10
DO - 10.1007/978-981-95-8034-7_10
M3 - Conference contribution
AN - SCOPUS:105040567108
SN - 9789819580330
T3 - Lecture Notes in Computer Science
SP - 185
EP - 197
BT - Information Security and Cryptology – ICISC 2025 - 28th International Conference, Revised Selected Papers
A2 - Seo, Hwajeong
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 19 November 2025 through 21 November 2025
ER -