arXiv · 2604.03813
Partial Number Theoretic Transform Masking in Post-Quantum Cryptography (PQC) Hardware: A Security Margin Analysis
Abstract
Adams Bridge, a hardware accelerator for ML-DSA and ML-KEM designed for the Caliptra root of trust, masks 1 of its Inverse Number Theoretic Transform (INTT) layers and relies on shuffling for the remainder, claiming per-butterfly Correlation Power Analysis (CPA) complexities of 2^46 (ML-DSA) and 2^96 (ML-KEM). We evaluate these claims across seven tracks with confidence-rated evidence. Register-Transfer Level (RTL) analysis confirms the design's Random Start Index (RSI) shuffling provides 6 bits of entropy per layer (64 orderings), not the 296 bits of a full random permutation. Under corrected test stimulus, the masked INTT round's butterfly register group fails first-order Test Vector Leakage Assessment (TVLA) at the RTL level, inverting the earlier verdict; the security margins are not re-derived from that result. A soft-analytical attack pipeline demonstrates a 37-bit attack-model gap, not a reduction in total work: it follows from the RSI structure alone, is independent of BP gains and measured SNR, and achieves no key recovery. Full-scale BP on the complete ML-KEM INTT factor graph achieves 100% coefficient recovery at SNRxN = 3,000; that graph decomposes into two independent 128-coefficient components. Layer-ablation over all 35 four-layer subsets shows observation topology sets the trace budget for BP convergence, not necessary conditions: input-adjacency and gap raise that budget by up to roughly 10x and by roughly 4x; output-anchoring and layer count are not priced. Four spread layers recover the full key in 78 of 80 seeds at SNRxN = 5,000; four consecutive need ~100x that. Masking 3 consecutive mid-layers (43% overhead) defers full recovery to SNRxN = 20,000 rather than preventing it; partial masking bounds attacker cost. We contribute an audit methodology assembled from established practice into a reproducible critique of partially masked NTT accelerators.
Explore related subjects
Keep this discovery
Ray Iskander, Khaled Kirah. 2026-04-04. Partial Number Theoretic Transform Masking in Post-Quantum Cryptography (PQC) Hardware: A Security Margin Analysis. https://arxiv.org/abs/2604.03813
Cite the original work for its findings. Save a collection to share your selection of sources.
Discover connections
Connections use source metadata and explicit phrase matches, not verified experimental comparisons.