Hardware Security

2-Day Training: Can your PQC implementation be challenged?

Fernanda Delestre
|
-
|
Aug 2026
Back to all articles
SHARE

With the formalization of the NIST Post-Quantum Cryptography (PQC) standards, the focus of cryptographic engineering shifts from algorithmic security to implementation robustness. For embedded software engineers, hardware specialists, security analysts, and cryptographers, evaluating these new standards against physical attack vectors is now a critical requirement.

To address this, we have opened registration for a specialized 2-day online training program focused entirely on the physical vulnerabilities of CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA). The curriculum bridges theoretical mechanics with practical hardware-level exploitation.

Program Structure and Methodology

The training runs completely online from 9 AM to 5 PM. It is structured into theoretical analysis in the morning and autonomous, hands-on exploitation in the afternoon utilizing the esDynamic platform.

Day 1: ML-KEM Architecture and Fundamental Vulnerabilities

We begin with the mathematical transition from original LWE schemes to Module-LWE. The theory isolates the Number Theoretic Transform (NTT), analyzing how reducing polynomial multiplication complexity to $O(n \log n)$ introduces specific side-channel leakage models. We also examine the structural pitfalls of the Fujisaki-Okamoto (FO) transform during message conversion.

  • Practical Application: Participants utilize Jupyter Notebooks and NumPy to execute Side-Channel Analysis (SCA) on chosen ciphertexts and simulate precision Fault Injection (FI) attacks targeting the key generation architecture.

Day 2: ML-DSA and Advanced Exploitation Techniques

Day two transitions to digital signature vulnerabilities, analyzing the hardware-level threat vectors inherent in the "Fiat-Shamir with Aborts" framework. The theory covers advanced exploitation models, including Online Template Attacks (OTA), Soft Analytical SCA (SASCA) using belief propagation, and Differential Fault Analysis (DFA).

  • Practical Application: The labs focus on Correlation Power Analysis (CPA) to extract secret coefficients from the Dilithium NTT polynomial multiplication step. Participants will also execute a targeted "Zeroize NTT" fault attack to force internal variables to zero, demonstrating signature forgery and key leakage.

Prerequisites and Registration

This is an advanced technical program. Participants must have familiarity with Python (NumPy) and a foundational understanding of public-key cryptography and side-channel analysis baselines.

Upcoming Sessions:

  • October 27 & 28th
  • November 17 & 18th

Equip your team with the practical skills required to validate and secure the post-quantum transition against physical threats. Limited spots.

💸 Early bird registration closes October 1.

Register here: https://www.eventbrite.fr/e/post-quantum-cryptography-pqc