Breaking optimized HQC : the first cache-timing full decryption oracle key-recovery attack in post-quantum cryptography
(2026) In Lecture Notes in Computer Science 16803. p.224-255- Abstract
- Hamming Quasi-Cyclic (HQC) has been selected by NIST for standardization in the post-quantum landscape. As deployment approaches, implementation security becomes as critical as mathematical hardness. In this work, we demonstrate that source-level constant-time coding is not a standalone guarantee: the compiled binary must inherently preserve this behavior.
We identify a severe compiler-induced vulnerability within the official AVX2-optimized implementation of HQC, despite its claims of being constant-time. Although the C source code relies on secure, mask-based conditional selection, certain compiler optimizations rewrite this logic systematically. This transformation silently introduces secret-dependent control flow into the... (More) - Hamming Quasi-Cyclic (HQC) has been selected by NIST for standardization in the post-quantum landscape. As deployment approaches, implementation security becomes as critical as mathematical hardness. In this work, we demonstrate that source-level constant-time coding is not a standalone guarantee: the compiled binary must inherently preserve this behavior.
We identify a severe compiler-induced vulnerability within the official AVX2-optimized implementation of HQC, despite its claims of being constant-time. Although the C source code relies on secure, mask-based conditional selection, certain compiler optimizations rewrite this logic systematically. This transformation silently introduces secret-dependent control flow into the inner Reed-Muller decoding process, resulting in secret-dependent cache access patterns.
Exploiting this vulnerability, we mount, to the best of our knowledge, the first cache-timing Full-Decryption-style oracle attack against a post-quantum cryptosystem. Using Flush+Reload on shared libraries, an unprivileged co-located adversary can extract fine-grained predicates of the decoder’s internal state. To achieve full key recovery, we develop a novel, reliability-aware Soft Information Set Decoding (Soft-ISD) post-processing framework. Leveraging a GPU-accelerated meet-in-the-middle strategy optimized for heterogeneous platforms (including Apple Silicon), we demonstrate end-to-end secret key recovery for hqc-1 with less than 10 s of online trace collection. (Less)
Please use this url to cite or link to this publication:
https://lup.lub.lu.se/record/9fc2ceef-38ad-4e3c-991e-c8d9f9e939e2
- author
- Dong, Haiyue
LU
and Guo, Qian
LU
- organization
- publishing date
- 2026
- type
- Chapter in Book/Report/Conference proceeding
- publication status
- published
- subject
- host publication
- Advances in Cryptology – CRYPTO 2026 : 46th Annual International Cryptology Conference Santa Barbara, CA, USA, August 17–20, 2026 Proceedings, Part IV - 46th Annual International Cryptology Conference Santa Barbara, CA, USA, August 17–20, 2026 Proceedings, Part IV
- series title
- Lecture Notes in Computer Science
- editor
- Heninger, Nadia and Rosulek, Mike
- volume
- 16803
- pages
- 224 - 255
- publisher
- Springer
- ISSN
- 1611-3349
- 0302-9743
- ISBN
- 978-3-032-35398-6
- 978-3-032-35397-9
- DOI
- 10.1007/978-3-032-35398-6_8
- language
- English
- LU publication?
- yes
- id
- 9fc2ceef-38ad-4e3c-991e-c8d9f9e939e2
- date added to LUP
- 2026-08-17 13:07:59
- date last changed
- 2026-09-03 03:14:10
@inbook{9fc2ceef-38ad-4e3c-991e-c8d9f9e939e2,
abstract = {{Hamming Quasi-Cyclic (HQC) has been selected by NIST for standardization in the post-quantum landscape. As deployment approaches, implementation security becomes as critical as mathematical hardness. In this work, we demonstrate that source-level constant-time coding is not a standalone guarantee: the compiled binary must inherently preserve this behavior.<br/><br/>We identify a severe compiler-induced vulnerability within the official AVX2-optimized implementation of HQC, despite its claims of being constant-time. Although the C source code relies on secure, mask-based conditional selection, certain compiler optimizations rewrite this logic systematically. This transformation silently introduces secret-dependent control flow into the inner Reed-Muller decoding process, resulting in secret-dependent cache access patterns.<br/><br/>Exploiting this vulnerability, we mount, to the best of our knowledge, the first cache-timing Full-Decryption-style oracle attack against a post-quantum cryptosystem. Using Flush+Reload on shared libraries, an unprivileged co-located adversary can extract fine-grained predicates of the decoder’s internal state. To achieve full key recovery, we develop a novel, reliability-aware Soft Information Set Decoding (Soft-ISD) post-processing framework. Leveraging a GPU-accelerated meet-in-the-middle strategy optimized for heterogeneous platforms (including Apple Silicon), we demonstrate end-to-end secret key recovery for hqc-1 with less than 10 s of online trace collection.}},
author = {{Dong, Haiyue and Guo, Qian}},
booktitle = {{Advances in Cryptology – CRYPTO 2026 : 46th Annual International Cryptology Conference Santa Barbara, CA, USA, August 17–20, 2026 Proceedings, Part IV}},
editor = {{Heninger, Nadia and Rosulek, Mike}},
isbn = {{978-3-032-35398-6}},
issn = {{1611-3349}},
language = {{eng}},
pages = {{224--255}},
publisher = {{Springer}},
series = {{Lecture Notes in Computer Science}},
title = {{Breaking optimized HQC : the first cache-timing full decryption oracle key-recovery attack in post-quantum cryptography}},
url = {{http://dx.doi.org/10.1007/978-3-032-35398-6_8}},
doi = {{10.1007/978-3-032-35398-6_8}},
volume = {{16803}},
year = {{2026}},
}