Side-channel attack improves key recovery on HQC encryption

OT-PCA: New Key-Recovery Plaintext-Checking Oracle Based Side-Channel Attacks on HQC with Offline Templates

Cryptography and Security

Summary

Encryption methods protect secret messages, but some attacks try to uncover keys by studying the way devices decrypt those messages. This paper shows a new attack method that uses a publicly accessible decoding feature and smart algorithms to get secret key details more efficiently. Their approach greatly reduces how many attempts are needed and still works well even if the attack isn’t perfectly accurate. They also tested it on a real device to show it works outside simulations.

What this means in practice

  • For security engineers: Assess weaknesses in HQC implementations by employing more efficient side-channel key recovery methods.
  • For embedded system developers: Improve hardware defenses by testing resistance of ARM Cortex-M4 platforms against known side-channel attacks like the one demonstrated.

Authors

Haiyue Dong, Qian Guo

Abstract

In this paper, we introduce OT-PCA, a novel approach for conducting Plaintext-Checking (PC) oracle based side-channel attacks, specifically designed for Hamming Quasi-Cyclic (HQC). By calling the publicly accessible HQC decoder, we build offline templates that enable efficient extraction of soft information for hundreds of secret positions with just a single PC oracle call. Our method addresses critical challenges in optimizing key-related information extraction, including maximizing decryption output entropy and ensuring error pattern independence, through the use of genetic-style algorithms. Extensive simulations demonstrate that our new attack method significantly reduces the required number of oracle calls, achieving a 2.4-fold decrease for hqc-128 and even greater reductions for hqc-192 and hqc-256 compared to current state-of-the-art methods. Notably, the attack shows strong resilience against inaccuracy in the PC oracle-when the oracle accuracy decreases to 95%, the reduction factor in oracle call requirements increases to 7.6 for hqc-128. Lastly, a real-world evaluation conducted using power analysis on a platform with an ARM Cortex-M4 microcontroller validates the practical applicability and effectiveness of our approach.