Finding and Protecting the Weakest Link - On Side-Channel Attacks on in Masked ML-DSA
Julius Hermelink, Kai-Chun Ning, Richard Petri
Abstract
NIST standardized ML-KEM and ML-DSA as post-quantum key exchanges and digital signatures. Both schemes have already seen analysis with respect to side-channels, and first fully masked implementations of ML-DSA have been published. Previous attacks focused on unprotected implementations or assumed only hiding countermeasures to be in-place. Thus, in contrast to ML-KEM, the threat of side-channel attacks for protected ML-DSA implementations is mostly unclear.
In this work, we analyze the side-channel vulnerability of masked ML-DSA implementations. We first systematically assess the vulnerability of several potential points of attacks in different leakage models using information theory. Then, we explain how an adversary could launch first, second, and higher-order attacks using a recently presented framework for side-channel information in lattice-based schemes. In this context, we propose a filtering technique that allows the framework to solve for the secret key from a large number of hints; this had previously been prevented by numerical instabilities. We simulate the presented attacks and discuss the relation to the information-theoretic analysis.
Finally, we carry out relevant attacks on physical devices, discuss recent masked implementations, and instantiate a countermeasure against the most threatening attacks. The countermeasure mitigates the attacks with the highest noise-tolerance while having very little overhead. The results on the physical devices validate our simulations.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get bdbabb86-c431-49e3-8345-a584f49ec47bRelated papers
- The Insecurity of Masked Comparisons: SCAs on ML-KEM's FO-TransformJulius Hermelink, Kai-Chun Ning, Richard Petri, Emanuele StriederCCS 2024 · 3 citations
- When Module Lattice Leaks: Horizontal Fusion Attacks on ML-DSA ImplementationYuhan Zhao, Dalin He, Wei Cheng, Yuejun Liu et al.CCS 2026
- Uncompressing Dilithium's Public KeyPaco Azevedo Oliveira, Andersson Calle Viera, Benoît Cogliati, Louis GoubinCRYPTO 2025 · 10 citations
- Side-Channel Attacks on BLISS Lattice-Based Signatures: Exploiting Branch Tracing against strongSwan and Electromagnetic Emanations in MicrocontrollersThomas Espitau, Pierre-Alain Fouque, Benoît Gérard, Mehdi TibouchiCCS 2017 · 145 citations
- Unlocking the True Potential of Decryption Failure Oracles: A Hybrid Adaptive-LDPC Attack on ML-KEM Using Imperfect OraclesQian Guo, Denis Nabokov, Thomas JohanssonUSENIX Security 2026
