USENIX Security2024Top-tier venue
Divide and Surrender: Exploiting Variable Division Instruction Timing in HQC Key Recovery Attacks
Robin Leander Schröder, Stefan Gast, Qian Guo
Abstract
We uncover a critical side-channel vulnerability in the Hamming Quasi-Cyclic (HQC) round 4 optimized implementation arising due to the use of the modulo operator. In some cases, compilers optimize uses of the modulo operator with compile-time known divisors into constant-time Barrett reductions. However, this optimization is not guaranteed: for example, when a modulo operation is used in a loop the compiler may emit division (div) instructions which have variable execution time depending on the numerator. When the numerator depends on secret data, this may yield a timing side-channel. We name vulnerabilities of this kind Divide and Surrender (DaS) vulnerabilities. For processors supporting Simultaneous Multithreading (SMT) we propose a new approach called DIV-SMT which enables precisely measuring small division timing variations using scheduler and/or execution unit contention. We show that using only 100 such side-channel traces we can build a Plaintext-Checking (PC) oracle with above 90% accuracy. Our approach might also prove applicable to other instances of the DaS vulnerability, such as KyberSlash. We stress that exploitation with DIV-SMT requires co-location of the attacker on the same physical core as the victim. We then apply our methodology to HQC and present a novel way to recover HQC secret keys faster, achieving an 8-fold decrease in the number of idealized oracle queries when compared to previous approaches. Our new PC oracle attack uses our newly developed Zero Tester method to quickly determine whether an entire block of bits contains only zero-bits. The Zero Tester method enables the DIV-SMT powered attack on HQC-128 to complete in under 2 minutes on our targeted AMD Zen2 machine.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7d51bacf-601e-4c19-bbee-b6794d52ddf4Cited by top-tier papers5
- Key Recovery from Side-Channel Power Analysis Attacks on Non-SIMD HQC DecryptionNathan Maillet, Cyrius Nugier, Vincent Migliore, Jean-Christophe DeneuvilleCRYPTO 2025 · 4 citations
- Smooth, Integrated Proofs of Cryptographic Constant Time for Nondeterministic Programs and CompilersOwen Conoly, Andres Erbsen, Adam ChlipalaPLDI 2025 · 1 citation
- Unlocking the True Potential of Decryption Failure Oracles: A Hybrid Adaptive-LDPC Attack on ML-KEM Using Imperfect OraclesQian Guo, Denis Nabokov, Thomas JohanssonUSENIX Security 2026
- CounterSEVeillance: Performance-Counter Attacks on AMD SEV-SNPStefan Gast, Hannes Weissteiner, Robin Leander Schröder, Daniel GrussNDSS 2025
- TEEcorrelate: An Information-Preserving Defense against Performance-Counter Attacks on TEEsHannes Weissteiner, Fabian Rauscher, Robin Leander Schröder, Jonas Juffinger et al.USENIX Security 2025
Builds on6
- Port Contention for Fun and ProfitAlejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García et al.S&P 2019 · 240 citations
- A Key-Recovery Timing Attack on Post-quantum Primitives Using the Fujisaki-Okamoto Transformation and Its Application on FrodoKEMQian Guo, Thomas Johansson, Alexander NilssonCRYPTO 2020 · 84 citations
- SQUIP: Exploiting the Scheduler Queue Contention Side ChannelStefan Gast, Jonas Juffinger, Martin Schwarzl, Gururaj Saileshwar et al.S&P 2023
- SecSMT: Securing SMT Processors against Contention-Based Covert ChannelsMohammadkazem Taram, Xida Ren, Ashish Venkat, Dean M. TullsenUSENIX Security 2022
- AMD Prefetch Attacks through Power and TimeMoritz Lipp, Daniel Gruss, Michael SchwarzUSENIX Security 2022
Related papers
- Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-quantum CryptographyHaiyue Dong, Qian GuoCRYPTO 2026
- Single-Trace Key Recovery Attacks on HQC Using Valid and Invalid CiphertextsHaiyue Dong, Qian Guo, Denis NabokovEUROCRYPT 2026 · 2 citations
- It's About Time: Detecting Timing Side-Channel Vulnerabilities in High-Level Synthesis DesignsDenis Zuppiger, Katharina Ceesay-Seitz, Jiahui Xu, Lana Josipović et al.CCS 2026
- "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing AttacksJan Jancar, Marcel Fourné, Daniel De Almeida Braga, Mohamed Sabt et al.S&P 2022 · 61 citations
- Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86Yingchen Wang, Riccardo Paccagnella, Elizabeth Tang He, Hovav Shacham et al.USENIX Security 2022
