A Template attack for decryption key recovery on the NTT accelerator of PQC ML-KEM

Abstract Quantum computers threaten traditional cryptography, making the development of quantum-secure cryptographic schemes essential. Module-Lattice–based Key-Encapsulation Mechanism (ML-KEM), recently standardized by NIST for post-quantum public-key encryption, plays a critical role in enabling quantum-resistant key establishment. Its design relies heavily on the Number Theoretic Transform (NTT) for efficient polynomial computations. This paper presents a profiling-based template side-channel attack targeting an unprotected NTT accelerator for ML-KEM-768 and ML-KEM-1024 implementations. We implement a complete forward NTT accelerator on FPGA and collect power traces from its execution, while side-channel measurements focus on the first NTT round. Using Test Vector Leakage Assessment (TVLA), we extract pair-specific points of interest corresponding to individual coefficient-pair computations. These points are then used to construct profiling templates based on principal component analysis (PCA) and Mahalanobis-distance classification. Experimental results show that the proposed attack achieves consistently high classification accuracy across all 128 coefficient pairs, with accuracies ranging from 96.93 to 97.97%. By aggregating likelihoods across multiple traces, we demonstrate reliable recovery of a complete secret polynomial, requiring an average of approximately 27 traces. These results confirm that even lightweight or sequential NTT designs are highly vulnerable to profiling-based side-channel attacks and must be secured before deployment in post-quantum cryptographic systems.

Authors

Publication Details

Journal
Cybersecurity
Published
2026-10-08
DOI
https://doi.org/10.1186/s42400-026-00675-3
Primary Topic
Cryptographic Implementations and Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

A Template attack for decryption key recovery on the NTT accelerator of PQC ML-KEM

Munkhbaatar Chinbat, Munkhnar Khulan, Liji Wu, Xiangmin Zhang
Cybersecurity
Cryptographic Implementations and Security
article

A Template attack for decryption key recovery on the NTT accelerator of PQC ML-KEM

Munkhbaatar Chinbat, Munkhnar Khulan, Liji Wu, Xiangmin Zhang
article en

Abstract

Abstract Quantum computers threaten traditional cryptography, making the development of quantum-secure cryptographic schemes essential. Module-Lattice–based Key-Encapsulation Mechanism (ML-KEM), recently standardized by NIST for post-quantum public-key encryption, plays a critical role in enabling quantum-resistant key establishment. Its design relies heavily on the Number Theoretic Transform (NTT) for efficient polynomial computations. This paper presents a profiling-based template side-channel attack targeting an unprotected NTT accelerator for ML-KEM-768 and ML-KEM-1024 implementations. We implement a complete forward NTT accelerator on FPGA and collect power traces from its execution, while side-channel measurements focus on the first NTT round. Using Test Vector Leakage Assessment (TVLA), we extract pair-specific points of interest corresponding to individual coefficient-pair computations. These points are then used to construct profiling templates based on principal component analysis (PCA) and Mahalanobis-distance classification. Experimental results show that the proposed attack achieves consistently high classification accuracy across all 128 coefficient pairs, with accuracies ranging from 96.93 to 97.97%. By aggregating likelihoods across multiple traces, we demonstrate reliable recovery of a complete secret polynomial, requiring an average of approximately 27 traces. These results confirm that even lightweight or sequential NTT designs are highly vulnerable to profiling-based side-channel attacks and must be secured before deployment in post-quantum cryptographic systems.

CybersecurityVol. 9(1)
Openalex Percentile: Top 12%
Cryptographic Implementations and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.