Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-quantum Cryptography
Haiyue Dong, Qian Guo
摘要
Hamming Quasi-Cyclic (HQC) has been selected by NIST for standardization in the post-quantum landscape. As deployment approaches, implementation security becomes as critical as mathematical hardness. In this work, we demonstrate that source-level constant-time coding is not a standalone guarantee: the compiled binary must inherently preserve this behavior. We identify a severe compiler-induced vulnerability within the official AVX2-optimized implementation of HQC, despite its claims of being constant-time. Although the C source code relies on secure, mask-based conditional selection, certain compiler optimizations rewrite this logic systematically. This transformation silently introduces secret-dependent control flow into the inner Reed-Muller decoding process, resulting in secret-dependent cache access patterns. Exploiting this vulnerability, we mount, to the best of our knowledge, the first cache-timing Full-Decryption-style oracle attack against a post-quantum cryptosystem. Using Flush+Reload on shared libraries, an unprivileged co-located adversary can extract fine-grained predicates of the decoder’s internal state. To achieve full key recovery, we develop a novel, reliability-aware Soft Information Set Decoding (Soft-ISD) post-processing framework. Leveraging a GPU-accelerated meet-in-the-middle strategy optimized for heterogeneous platforms (including Apple Silicon), we demonstrate end-to-end secret key recovery for hqc-1 with less than 10 s of online trace collection.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Key Recovery from Side-Channel Power Analysis Attacks on Non-SIMD HQC DecryptionNathan Maillet, Cyrius Nugier, Vincent Migliore, Jean-Christophe DeneuvilleCRYPTO 2025 · 被引用 4 次
- Single-Trace Key Recovery Attacks on HQC Using Valid and Invalid CiphertextsHaiyue Dong, Qian Guo, Denis NabokovEUROCRYPT 2026 · 被引用 2 次
- Divide and Surrender: Exploiting Variable Division Instruction Timing in HQC Key Recovery AttacksRobin Leander Schröder, Stefan Gast, Qian GuoUSENIX Security 2024 · 被引用 12 次
- Binsec/Rel: Efficient Relational Symbolic Execution for Constant-Time at Binary-LevelLesly-Ann Daniel, Sébastien Bardin, Tamara RezkS&P 2020 · 被引用 76 次
- Typing High-Speed Cryptography against Spectre v1Basavesh Ammanaghatta Shivakumar, Gilles Barthe, Benjamin Grégoire, Vincent Laporte 等S&P 2023
