Research

Watch · narrated whiteboard episodesL3

Implementation Security of Post-Quantum Cryptography: Constant-Time and Side Channels

A mathematically secure scheme still leaks through its implementation. Post-quantum cryptography introduces new side-channel surfaces - sampling, the number-theoretic transform, rejection - that classical crypto never had. This series is the attacker's-eye tour: the threat model, the decapsulation timing oracle, power and electromagnetic attacks, masking countermeasures, and how to verify constant-time. Grounded in the side-channel literature and NIST KEM guidance.

Murali Chillakuru·5 episodes
  1. 20 min Episode 1The Side-Channel Threat Model for Post-Quantum CryptographyA moderator and a hardware-security expert establish why post-quantum implementations leak — what a side channel is, why a mathematically secure algorithm can still be broken, the new leakage surfaces post-quantum schemes bring, the spectrum of attacker capabilities, profiled versus non-profiled attacks, and why threat modeling comes first.
  2. 21 min Episode 2Timing and the Decapsulation Oracle: When Non-Constant-Time Handling Leaks the PlaintextA moderator and a hardware-security expert trace a real post-quantum attack end to end — where secrets flow in decapsulation, what a decryption oracle is, how timing turns a device into a plaintext-checking oracle, how that oracle recovers the full secret key, where the timing actually leaks, and how constant-time code closes it.
  3. 21 min Episode 3Power and Electromagnetic Attacks on the NTT and the SamplerA moderator and a hardware-security expert dissect physical side-channel attacks on lattice cryptography — how correlation power analysis works, why single-trace attacks make post-quantum schemes uniquely exposed, why the number-theoretic transform and the noise sampler are prime targets, and what all this demands of countermeasures.
  4. 22 min Episode 4Masking and Countermeasures: Arithmetic-to-Boolean Shares and the Cost of Provable ResistanceA moderator and a hardware-security expert explain the primary defense against power analysis — how masking splits a secret into random shares so no wire carries it, how that defeats correlation, the two mask types and their conversion problem, masking order and its steep overhead, provable resistance and the glitch caveat, plus shuffling and what agent hardware should demand.
  5. 23 min Episode 5Verifying Constant-Time: Tooling and Methodology to Demonstrate a Leak-Free ImplementationIn the implementation-security finale, a moderator and a hardware-security expert cover how you actually verify that post-quantum code doesn't leak — statistical timing tests, formal and static analysis, dynamic tracking and power leakage assessment, a practical methodology with a CI gate, the limits of verification, and what AI agents should demand.