View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Hardware
  2. Quantum
January 8, 2024updated 10 Jan 2024 5:08pm

Implementation vulnerabilities reported for post-quantum encryption algorithm

The flaws impact several Kyber key encapsulation mechanisms for quantum-safe encryption endorsed by NIST.

By Greg Noone

Two implementation vulnerabilities have been reported in the Kyber key encapsulation mechanism (KEM), an encryption standard designed to protect networks against future attacks by quantum computers. Collectively referred to as “KyberSlash,” these flaws could lead to attackers discovering encryption keys. 

An AI-generated image of a green crystal, used to illustrate a story about the Kyber encryption protocol.
So named after the fictional crystals that power lightsabers in “Star Wars,” implementations of Kyber KEM have been embraced by several organisations as a method of securing their communications against future decryption by quantum computers. (Photo by Shutterstock)

The vulnerabilities, known as KyberSlash 1 and KyberSlash 2, consist of timing-based attacks wherein attackers observe how long Kyber performs specific division operations in its decapsulation process, according to BleepingComputer, which broke the story. “Timing attacks of this nature are a derivative of broader ‘side channel’ attacks, which can be used to undermine any type of encryption, including both classical and post-quantum algorithms,” Andersen Cheng, founder of Post-Quantum, explained to Tech Monitor. “With this type of attack, the adversaries send fake (and known) ciphertext and measure how long it takes to decipher. They can then infer the timings for each attempt and reverse engineer the actual key-pair.”

The flaws were reported to Kyber’s development team by Franziskus Kiefer, Goutam Tamvada and Karthikeyan Bhargavan, all researchers at cybersecurity firm Cryspen, on 1 December. A patch was immediately issued for the encryption standard, but as it wasn’t labelled as a security issue, Cryspen began to proactively inform projects that they needed to apply the fix from 15 December. 

Versions of the Kyber post-quantum encryption standard have been adopted by Google, Signal and Mullvad VPN, though the latter has since confirmed that its services are not impacted by the vulnerability.

Post-quantum encryption rush

Kyber was first submitted for review to the US National Institute of Standards and Technology (NIST) in 2017, as part of a competition convened by the organisation to test and finalise an encryption standard capable of defending networks against future attacks by a quantum computer. Though a machine with the requisite number of qubits capable of using Shor’s algorithm to break RSA encryption and similar standards has yet to be developed, recent breakthroughs in scaling quantum computers and mounting speculation about “Harvest Now, Decrypt Later” attacks have led to increased interest in adopting post-quantum standards by governments and major corporations. 

Several algorithms entered into NIST’s competition have been proven vulnerable to conventional attacks. These include the standards Rainbow and SIKE, the latter of which was defeated by researchers at KU Leuven in 2022 in under an hour using a classical computer. The official implementation of Kyber, CRYSTALS-Kyber, was also undermined in February 2023 using highly complex deep learning-based side-channel attacks by a team from Sweden’s KTH Royal Institute of Technology. Nevertheless, the algorithm was one of several for which NIST released draft standards last summer, intending to finalise its competition later this year. 

Kyber vulnerabilities

In the meantime, several major organisations have adopted versions of the Kyber KEM. In August 2023, Google announced its implementation of Kyber-768 as part of a hybrid mechanism to secure the transport layer security traffic on its Chrome browser. Similarly in September, Signal adopted Kyber-1024 in combination with an elliptic curve key agreement protocol to help secure its “Signal Protocol,” which is also used to guarantee end-to-end encryption in WhatsApp and Google messages. 

Content from our partners
Scan and deliver
GenAI cybersecurity: "A super-human analyst, with a brain the size of a planet."
Cloud, AI, and cyber security – highlights from DTX Manchester

This hybrid approach to using post-quantum encryption standards is meant to ensure that network traffic is protected from attack should new vulnerabilities in post-quantum standards be discovered. Since the KyberSlash vulnerabilities were uncovered, the team behind the discovery claim that patches have now been implemented by the Kyber development team and by AWS. A GitHub library created by Kudelski Security was also listed by the team. When Tech Monitor contacted the cybersecurity firm, it confirmed that the code listed was not used in any of its commercial products and should not be used in production, but that it had nevertheless implemented a patch for the KyberSlash vulnerabilities in a new version of the library.

Nevertheless, Cheng considers it an important step forward for the post-quantum encryption community that its focus on flaws has moved on from vulnerabilities in the mathematics underpinning the standards toward implementation attacks. “It will be the responsibility of each organisation implementing new encryption to ensure the implementation is robust,” says Cheng. “That’s why it is so important that teams working on the migration to post-quantum encryption have deep engineering understanding and ideally, existing experience in deploying the cryptographic algorithms. “

Read more: IBM reveals new modular quantum computing system

Topics in this article :
Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.