Pierre-Augustin Berthet - Ciphertext Malleability in Lattice-Based KEMs as a Countermeasure to Side Channel Analysis

fi:14339 - Fundamenta Informaticae, December 27, 2025, Volume 194, Issue 4: Central European Conference on Cryptology 2024 - https://doi.org/10.46298/fi.14339
Ciphertext Malleability in Lattice-Based KEMs as a Countermeasure to Side Channel AnalysisArticle

Authors: Pierre-Augustin Berthet

    Due to developments in quantum computing, classical asymmetric cryptography is at risk of being breached. Consequently, new Post-Quantum Cryptography (PQC) primitives using lattices are studied. Another point of scrutiny is the resilience of these new primitives to Side Channel Analysis (SCA), where an attacker can study physical leakages. In this work we discuss a SCA vulnerability due to the ciphertext malleability of some PQC primitives exposed by a work from Ravi et al. We propose a novel countermeasure to this vulnerability exploiting the same ciphertext malleability and discuss its practical application to several PQC primitives. We also extend the seminal work of Ravi et al. by detailing their attack on the different security levels of a post-quantum Key Encapsulation Mechanism (KEM), namely FrodoKEM. We also provide a generalisation of their attack to different parameters which could be used in future similar primitives.

    29 pages total, 26 pages excluding references, 8 figures. This paper is an extension of a work presented at CECC 2024 under the title "A Countermeasure To Side Channel Message Recovery Attacks Using Chosen-Ciphertext Against ML-KEM". It has been selected by the CECC 2024 program chairs for submission at a special edition of the Fundamenta Informaticae journal


    Volume: Volume 194, Issue 4: Central European Conference on Cryptology 2024
    Published on: December 27, 2025
    Accepted on: August 8, 2025
    Submitted on: September 26, 2024
    Keywords: Cryptography and Security, 94A60, E.3.3