Skip to main content

Lund University Publications

LUND UNIVERSITY LIBRARIES

Breaking optimized HQC : the first cache-timing full decryption oracle key-recovery attack in post-quantum cryptography

Dong, Haiyue LU orcid and Guo, Qian LU (2026) In Lecture Notes in Computer Science 16803. p.224-255
Abstract
Hamming Quasi-Cyclic (HQC) has been selected by NIST for standardization in the post-quantum landscape. As deployment approaches, implementation security becomes as critical as mathematical hardness. In this work, we demonstrate that source-level constant-time coding is not a standalone guarantee: the compiled binary must inherently preserve this behavior.

We identify a severe compiler-induced vulnerability within the official AVX2-optimized implementation of HQC, despite its claims of being constant-time. Although the C source code relies on secure, mask-based conditional selection, certain compiler optimizations rewrite this logic systematically. This transformation silently introduces secret-dependent control flow into the... (More)
Hamming Quasi-Cyclic (HQC) has been selected by NIST for standardization in the post-quantum landscape. As deployment approaches, implementation security becomes as critical as mathematical hardness. In this work, we demonstrate that source-level constant-time coding is not a standalone guarantee: the compiled binary must inherently preserve this behavior.

We identify a severe compiler-induced vulnerability within the official AVX2-optimized implementation of HQC, despite its claims of being constant-time. Although the C source code relies on secure, mask-based conditional selection, certain compiler optimizations rewrite this logic systematically. This transformation silently introduces secret-dependent control flow into the inner Reed-Muller decoding process, resulting in secret-dependent cache access patterns.

Exploiting this vulnerability, we mount, to the best of our knowledge, the first cache-timing Full-Decryption-style oracle attack against a post-quantum cryptosystem. Using Flush+Reload on shared libraries, an unprivileged co-located adversary can extract fine-grained predicates of the decoder’s internal state. To achieve full key recovery, we develop a novel, reliability-aware Soft Information Set Decoding (Soft-ISD) post-processing framework. Leveraging a GPU-accelerated meet-in-the-middle strategy optimized for heterogeneous platforms (including Apple Silicon), we demonstrate end-to-end secret key recovery for hqc-1 with less than 10 s of online trace collection. (Less)
Please use this url to cite or link to this publication:
author
and
organization
publishing date
type
Chapter in Book/Report/Conference proceeding
publication status
published
subject
host publication
Advances in Cryptology – CRYPTO 2026 : 46th Annual International Cryptology Conference Santa Barbara, CA, USA, August 17–20, 2026 Proceedings, Part IV - 46th Annual International Cryptology Conference Santa Barbara, CA, USA, August 17–20, 2026 Proceedings, Part IV
series title
Lecture Notes in Computer Science
editor
Heninger, Nadia and Rosulek, Mike
volume
16803
pages
224 - 255
publisher
Springer
ISSN
1611-3349
0302-9743
ISBN
978-3-032-35398-6
978-3-032-35397-9
DOI
10.1007/978-3-032-35398-6_8
language
English
LU publication?
yes
id
9fc2ceef-38ad-4e3c-991e-c8d9f9e939e2
date added to LUP
2026-08-17 13:07:59
date last changed
2026-09-03 03:14:10
@inbook{9fc2ceef-38ad-4e3c-991e-c8d9f9e939e2,
  abstract     = {{Hamming Quasi-Cyclic (HQC) has been selected by NIST for standardization in the post-quantum landscape. As deployment approaches, implementation security becomes as critical as mathematical hardness. In this work, we demonstrate that source-level constant-time coding is not a standalone guarantee: the compiled binary must inherently preserve this behavior.<br/><br/>We identify a severe compiler-induced vulnerability within the official AVX2-optimized implementation of HQC, despite its claims of being constant-time. Although the C source code relies on secure, mask-based conditional selection, certain compiler optimizations rewrite this logic systematically. This transformation silently introduces secret-dependent control flow into the inner Reed-Muller decoding process, resulting in secret-dependent cache access patterns.<br/><br/>Exploiting this vulnerability, we mount, to the best of our knowledge, the first cache-timing Full-Decryption-style oracle attack against a post-quantum cryptosystem. Using Flush+Reload on shared libraries, an unprivileged co-located adversary can extract fine-grained predicates of the decoder’s internal state. To achieve full key recovery, we develop a novel, reliability-aware Soft Information Set Decoding (Soft-ISD) post-processing framework. Leveraging a GPU-accelerated meet-in-the-middle strategy optimized for heterogeneous platforms (including Apple Silicon), we demonstrate end-to-end secret key recovery for hqc-1 with less than 10 s of online trace collection.}},
  author       = {{Dong, Haiyue and Guo, Qian}},
  booktitle    = {{Advances in Cryptology – CRYPTO 2026 : 46th Annual International Cryptology Conference Santa Barbara, CA, USA, August 17–20, 2026 Proceedings, Part IV}},
  editor       = {{Heninger, Nadia and Rosulek, Mike}},
  isbn         = {{978-3-032-35398-6}},
  issn         = {{1611-3349}},
  language     = {{eng}},
  pages        = {{224--255}},
  publisher    = {{Springer}},
  series       = {{Lecture Notes in Computer Science}},
  title        = {{Breaking optimized HQC : the first cache-timing full decryption oracle key-recovery attack in post-quantum cryptography}},
  url          = {{http://dx.doi.org/10.1007/978-3-032-35398-6_8}},
  doi          = {{10.1007/978-3-032-35398-6_8}},
  volume       = {{16803}},
  year         = {{2026}},
}