PQ-WB-KEM: Toward a White-Box Construction of ML-KEM-768 with Arithmetic Masking for M2M Communications

Machine-to-machine and Internet of Things endpoints operate in physically accessible environments, motivating decapsulation-path hardening against an adversary with full code access. We present PQ-WB-KEM, a feasibility study that is, to our knowledge, the first systematic exploration of the table-based white-box design space for a NIST-standardized lattice key-encapsulation mechanism (ML-KEM-768, FIPS 203); prior white-box post-quantum work targets hash-based SPHINCS+ and multivariate hidden field equations (HFE; 256 GB), while the only earlier lattice-based white-box is custom and non-standardized. Because the base multiply runs in the number-theoretic transform (NTT) domain, where the secret operand s^=NTT(s) is full-range over Zq, coefficient smallness does not shrink the tables. We map the design space with two verified lookup-only constructions: a shared full multiply table (Construction A, a measured 22.16 MB base, 25.57 MB core) and per-component tables with the secret baked in (Construction B, 7.67 MB base, 11.08 MB core), with the base tables being about 11,600× (A) and 33,400× (B) smaller than the 2022 256 GB HFE white box. Three-share arithmetic masking drives the measured first-order differential computation analysis (DCA) correlation to near the noise floor (ρmax=0.011, versus 0.85 unmasked). The projected deployment overhead is ≈47×, anchored on the native-C protected primitive measured with its mask-generation random number generator (RNG) randomness included (4.30×, times an ≈11× embedded cache factor); the RNG-excluded harness yields the 17× lower bound. We delimit scope honestly: against the full white-box adversary this construction does not achieve key confidentiality because the base multiply forms the clear product coordinates p0,p1 before masking and these yield linear equations for the secret; every positive result holds only against strictly weaker adversaries, and the work maps the lattice white-box design space rather than delivering a fully white-box key-encapsulation mechanism.

Authors

Institutions

Publication Details

Journal
Mathematics
Published
2026-08-26
DOI
https://doi.org/10.3390/math14173072
Primary Topic
Cryptographic Implementations and Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

PQ-WB-KEM: Toward a White-Box Construction of ML-KEM-768 with Arithmetic Masking for M2M Communications

Uğur Coruh
Mathematics
Cryptographic Implementations and Security
article

PQ-WB-KEM: Toward a White-Box Construction of ML-KEM-768 with Arithmetic Masking for M2M Communications

Uğur Coruh
article en

Abstract

Machine-to-machine and Internet of Things endpoints operate in physically accessible environments, motivating decapsulation-path hardening against an adversary with full code access. We present PQ-WB-KEM, a feasibility study that is, to our knowledge, the first systematic exploration of the table-based white-box design space for a NIST-standardized lattice key-encapsulation mechanism (ML-KEM-768, FIPS 203); prior white-box post-quantum work targets hash-based SPHINCS+ and multivariate hidden field equations (HFE; 256 GB), while the only earlier lattice-based white-box is custom and non-standardized. Because the base multiply runs in the number-theoretic transform (NTT) domain, where the secret operand s^=NTT(s) is full-range over Zq, coefficient smallness does not shrink the tables. We map the design space with two verified lookup-only constructions: a shared full multiply table (Construction A, a measured 22.16 MB base, 25.57 MB core) and per-component tables with the secret baked in (Construction B, 7.67 MB base, 11.08 MB core), with the base tables being about 11,600× (A) and 33,400× (B) smaller than the 2022 256 GB HFE white box. Three-share arithmetic masking drives the measured first-order differential computation analysis (DCA) correlation to near the noise floor (ρmax=0.011, versus 0.85 unmasked). The projected deployment overhead is ≈47×, anchored on the native-C protected primitive measured with its mask-generation random number generator (RNG) randomness included (4.30×, times an ≈11× embedded cache factor); the RNG-excluded harness yields the 17× lower bound. We delimit scope honestly: against the full white-box adversary this construction does not achieve key confidentiality because the base multiply forms the clear product coordinates p0,p1 before masking and these yield linear equations for the secret; every positive result holds only against strictly weaker adversaries, and the work maps the lattice white-box design space rather than delivering a fully white-box key-encapsulation mechanism.

MathematicsVol. 14(17)
Recep Tayyip Erdoğan University (TR)
Openalex Percentile: Top 7%
Cryptographic Implementations and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.