Expert Training
Post-Quantum Cryptography (PQC) Physical Threats
Physical attacks against PQC implementations are no longer theoretical. Over 2 days of hands-on side-channel analysis and fault injection against ML-KEM and ML-DSA, learn to go from attack theory to live key recovery on real targets.
agenda
Training Program
ā MORNING: 09:00 AM - 12:00 PM
ML-KEM internals and physical attack theory
- From LWE to Module-LWE
Review of original Learning With Errors (LWE) schemes, focusing on the heavy computational overhead of matrix multiplications and bloated key/ciphertext sizes. Analysis of how Kyber optimizes this through Module-LWE (ML-LWE) structures. - Polynomial Multiplication Acceleration
Deep dive into the Number Theoretic Transform (NTT), exploring how it reduces polynomial multiplication complexity from quadratic O(n²) to quasi-linear O(n log n). - Security Architecture & Pitfalls
Structural exploration of the Fujisaki-Okamoto (FO) transform, utilized to convert a Chosen Plaintext Attack secure Public Key Encryption (IND-CPA PKE) scheme into a Chosen Ciphertext Attack secure Key Encapsulation Mechanism (IND-CCA KEM). - Physical Attack Landscape
Detailed review of Simple Power Analysis (SPA) targeting message conversion routines, Correlation Power Analysis (CPA) targeting pointwise products within the NTT domain, and Fault Injection (FI) models focusing on the zeroization of NTT twiddle constants.
š AFTERNOON: 12:00 PM - 05:00 PM
Hands-on SCA and FI on ML-KEM
- Exercise 1: Side-Channel Analysis (SCA) on Kyber Chosen Ciphertext Attack
Objective: Manipulate ciphertexts to observe and exploit shared key leakage during the decryption and decompression phases. - Exercise 2: Fault Injection (FI) on Kyber Key Generation
āObjective: Simulate precise hardware faults within the key generation phase to analyze how internal code architecture fault propagation compromises system security.
ā MORNING: 09:00 AM - 12:00 PM
CRYSTALS-Dilithium (ML-DSA) & Advanced Analysis
- Dilithium Architecture
Analysis of the "Fiat-Shamir with Aborts" framework and its specific, physical hardware-level threat vectors. - Advanced Side-Channel Analysis (SCA)
Core training on Online Template Attacks (OTA) and Soft Analytical SCA (SASCA) using factor graphs and belief propagation to extract cryptographic keys from exceptionally noisy or masked implementations. - Advanced Fault Injection (FI) Models
Exploration of Differential Fault Analysis (DFA) targeting deterministic signature schemes, alongside Signature Correction attacks (recovering a single bit-flip injected into a secret coefficient by iteratively correcting the signature until validation passes).
š AFTERNOON: 12:00 PM - 05:00 PM
Practical Application & Conclusion
- Exercise 1: Correlation Power Analysis (CPA) on Dilithium NTT
āObjective: Analyze physical power traces, identify critical Points of Interest (PoIs), and successfully extract secret coefficients from the NTT polynomial multiplication step. - Exercise 2: "Zeroize NTT" Fault Injection Attack
āObjective: Inject targeted faults to force internal variables to zero, resulting in forgeable signatures and catastrophic key leakage.
Why us
Over 10 Years of Hands-On Expertise.
Effective security testing comes from the combination of the right tools, deep technical knowledge, and the people who know how to apply them. eShard has spent over 10 years developing all three, and our coaching programs put that same expertise directly in your hands.
Our blog






