Exploiting Load/Store Leakage of Sparse Vectors for Key Recovery in HQC

πŸ“… 2026-07-21
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This work addresses the NIST-standardized HQC cryptosystem and uncovers an asymmetric side-channel leakage in its reference implementation on the Cortex-M4 platform, stemming from compiler-generated assembly code. Specifically, electromagnetic emanations differ between the high and low 32-bit halves of 64-bit words due to register spilling. Leveraging this observation, we propose the first zero-word distinguisher, which efficiently identifies zero positions in the secret key vector from only 500–5000 electromagnetic traces and converts them into decoding hints. Applied to the HQC-1 parameter set, our method successfully recovers 88.7% of zero words, reducing the key recovery complexity to approximately $2^{46}$ operations. This establishes a novel side-channel attack avenue that exploits both the inherent sparsity of the secret structure and compiler-induced implementation artifacts.
πŸ“ Abstract
Hamming Quasi-Cyclic (HQC) is a code-based key encapsulation mechanism selected by NIST for standardization, making its resistance to implementation attacks critically important. We present a side-channel attack that exploits load/store leakage in the manipulation of HQC's sparse secret vectors. Analysing Cortex-M4 assembly generated from the reference implementation, we identify a leakage surface in which the low and high 32-bit halves of each 64-bit word leak with different strengths, due to compiler-generated register spilling. We exploit this leakage to construct a simple zero-word distinguisher classifying machine words of the secret vector as zero or nonzero from electromagnetic measurements. The recovered zero positions are then translated into decoding hints, reducing HQC key recovery to a shortened syndrome-decoding problem. We analyse the resulting decoding complexity for all HQC parameter sets: at 32-bit granularity an expected 88.7% of the machine words of y are zero for HQC-1, cutting the decoding to $\approx$ 2 46 bit operations. Experiments on a Cortex-M4 validate the predicted low/high-half asymmetry-approximately 500 traces for the stronger low-half channel and 5,000 for the weaker high-half channeland recover the zero words of an HQC-1 key at 32-bit granularity. Finally, we discuss practical countermeasures that eliminate the sparsity exploited by the attack.
Problem

Research questions and friction points this paper is trying to address.

side-channel attack
load/store leakage
sparse vectors
key recovery
HQC
Innovation

Methods, ideas, or system contributions that make the work stand out.

side-channel attack
sparse vector leakage
register spilling
syndrome decoding
HQC
πŸ’Ό Related Jobs
No related jobs found.
G
Gustavo Banegas
LIX, Inria, CNRS, Γ‰cole Polytechnique, Institut Polytechnique de Paris, France
Benjamin Smith
Benjamin Smith
Professor of Radiation Oncology, The University of Texas MD Anderson Cancer Center
Radiation oncologybreast cancerhealth services research
J
Jad Zahreddine
LIX, Inria, CNRS, Γ‰cole Polytechnique, Institut Polytechnique de Paris, France; eShard, France