The lattice-based cryptography problems are known to be secure against the quantum computing attacks, till date no known quantum algorithm is able to solve these hard problems in lattices. Their naive implementations on embedded devices are, however, vulnerable to side-channel analysis (SCA) attacks with full key recovery possible via power/EM leakage analysis. This work analyses and attacks the power side channel leakage in the baseline hardware architecture of schoolbook polynomial multiplication, that is an essential component of most of the lattice based cryptography implementations. We first undertake a horizontal correlation power analysis (HCPA) method, optimized to work independent of the precise attack location specification in the schoolbook polynomial multiplier power leakage profile. Inspite of the inherent difficulties in HCPA, the attack is extremely efficient; with an 99.90% accuracy of recovering any one sub secret-key using only a single trace. Next we undertake the vertical correlation power analysis (VCPA) attack on the schoolbook polynomial multiplier power leakage profile, that requires larger number of power traces to analyze the correlation. Finally, we propose a novel combined correlation power analysis (CCPA) method that combines the strengths of both the VCPA and the HCPA to further improve the attacking capability of HCPA. We report a complete secret key recovery with a 100% accuracy by using only 4 power traces.
Most cryptographic systems are secure in theory; however, the implementation of cryptographic system on embedded devices can be attacked by analyzing the power consumption of specific operation to reveal the key. The classic vertical correlation power analysis (CPA) attack requires a large number of power traces for analysis. Using transient secret-key scheme significantly weakens such an attack as insufficient data could be obtained. On the other hand, the horizontal CPA requires at least a single power trace and can make full use of multiple intermediate values to analyze the correlation of power consumption. In this work, we devised a horizontal CPA attack on schoolbook polynomial multiplication of hardware-implemented lattice-based cryptosystem without precise location. The accuracy of correctly recovering any one sub secret-key using only a single trace is 99.90%, and the accuracy of correctly recovering the secret-key is 76.41%. The powerful attack capability of horizontal CPA exposes the vulnerability of unprotected schoolbook polynomial multiplication against the attack of side-channel analysis (SCA).