PQ-WB-KEM: Toward a White-Box Construction of ML-KEM-768 with Arithmetic Masking for M2M Communications
MATHEMATICS, cilt.14, sa.17, 2026 (SCI-Expanded, Scopus)
- Yayın Türü: Makale / Tam Makale
- Cilt numarası: 14 Sayı: 17
- Basım Tarihi: 2026
- Doi Numarası: 10.3390/math14173072
- Dergi Adı: MATHEMATICS
- Derginin Tarandığı İndeksler: Science Citation Index Expanded (SCI-EXPANDED), Scopus, Aerospace Database, zbMATH, Directory of Open Access Journals, Academic Search Ultimate (EBSCO), Materials Science & Engineering Collection (ProQuest), Technology Collection (ProQuest)
- Recep Tayyip Erdoğan Üniversitesi Adresli: Evet
Özet
Machine-to-machine and Internet of Things endpoints operate in physically accessible environments, motivating decapsulation-path hardening against an adversary with full code access. We present PQ-WB-KEM, a feasibility study that is, to our knowledge, the first systematic exploration of the table-based white-box design space for a NIST-standardized lattice key-encapsulation mechanism (ML-KEM-768, FIPS 203); prior white-box post-quantum work targets hash-based SPHINCS+ and multivariate hidden field equations (HFE; 256 GB), while the only earlier lattice-based white-box is custom and non-standardized. Because the base multiply runs in the number-theoretic transform (NTT) domain, where the secret operand s<^>=NTT(s) is full-range over Zq , coefficient smallness does not shrink the tables. We map the design space with two verified lookup-only constructions: a shared full multiply table (Construction A, a measured 22.16 MB base, 25.57 MB core) and per-component tables with the secret baked in (Construction B, 7.67 MB base, 11.08 MB core), with the base tables being about 11,600 & times; (A) and 33,400 & times; (B) smaller than the 2022 256 GB HFE white box. Three-share arithmetic masking drives the measured first-order differential computation analysis (DCA) correlation to near the noise floor ( rho max=0.011 , versus 0.85 unmasked). The projected deployment overhead is approximate to 47 & times;, anchored on the native-C protected primitive measured with its mask-generation random number generator (RNG) randomness included ( 4.30 & times; , times an approximate to 11 & times; embedded cache factor); the RNG-excluded harness yields the 17 & times; lower bound. We delimit scope honestly: against the full white-box adversary this construction does not achieve key confidentiality because the base multiply forms the clear product coordinates p0,p1 before masking and these yield linear equations for the secret; every positive result holds only against strictly weaker adversaries, and the work maps the lattice white-box design space rather than delivering a fully white-box key-encapsulation mechanism.