Partial Key Exposure Attacks on BIKE, Rainbow and NTRU
Andre Esser, Alexander May, Javier A. Verbel, Weiqiang Wen
Abstract
In a so-called partial key exposure attack one obtains some information about the secret key, e.g. via some side-channel leakage. This information might be a certain fraction of the secret key bits (erasure model) or some erroneous version of the secret key (error model). The goal is to recover the secret key from the leaked information.
There is a common belief that, as opposed to e.g. the RSA cryptosystem, most post-quantum cryptosystems are usually resistant against partial key exposure attacks. We strongly question this belief by constructing partial key exposure attacks on code-based, multivariate, and latticebased schemes (BIKE, Rainbow and NTRU). Our attacks exploit the redundancy that modern PQ cryptosystems inherently use for efficiency reasons. The application and development of techniques from information set decoding plays a crucial role for achieving our results.
On the theoretical side, we show non-trivial information leakage bounds that allow for a polynomial time key recovery attack. As an example, for all schemes the knowledge of a constant fraction of the secret key bits suffices to reconstruct the full key in polynomial time.
Even if we no longer insist on polynomial time attacks, most of our attacks extend well and remain feasible up to large erasure and error rates. In the case of BIKE for example we obtain attack complexities around 60 bits when half of the secret key bits are erased, or a quarter of the secret key bits are faulty.
Our results show that even highly error-prone key leakage of modern PQ cryptosystems may lead to full secret key recoveries.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on3
- LWE with Side Information: Attacks and Concrete Security EstimationDana Dachman-Soled, Léo Ducas, Huijing Gong, Mélissa RossiCRYPTO 2020 · 162 citations
- Side-Channel Attacks on BLISS Lattice-Based Signatures: Exploiting Branch Tracing against strongSwan and Electromagnetic Emanations in MicrocontrollersThomas Espitau, Pierre-Alain Fouque, Benoît Gérard, Mehdi TibouchiCCS 2017 · 145 citations
- How to Meet Ternary LWE KeysAlexander MayCRYPTO 2021 · 36 citations
Related papers
- A Little LESS Secure - Side-Channel Attacks Exploiting Randomness LeakageDina Hesse, Elisabeth Krahmer, Yi-Fu Lai, Jonas MeersCRYPTO 2026
- PQ-Hammer: End-to-End Key Recovery Attacks on Post-Quantum Cryptography Using RowhammerSamy Amer, Yingchen Wang, Hunter Kippen, Thinh Dang et al.S&P 2025
- Approximate Divisor Multiples - Factoring with Only a Third of the Secret CRT-ExponentsAlexander May, Julian Nowakowski, Santanu SarkarEUROCRYPT 2022 · 11 citations
- HAWK with Hint: Algebraic Key Recovery from Side-Channel LeakageByoungchan Chi, Changmin Lee, Inhun LeeCCS 2026
- Exploring Decryption Failures of BIKE: New Class of Weak Keys and Key Recovery AttacksTianrui Wang, Anyu Wang, Xiaoyun WangCRYPTO 2023 · 9 citations
