PQ-WB-KEM: Toward a White-Box Construction of ML-KEM-768 with Arithmetic Masking for M2M Communications
Abstract
1. Introduction
| Work | PQC Type | NIST Std | Size | Practical |
|---|---|---|---|---|
| Bicakci [11] | Hash-based | FIPS 205 | Medium | Moderate |
| Galissant (ePrint 2022) [12] | Multivariate | None | 256 GB | No |
| Galissant (CASCADE 2025) [15] | Multivariate | None | 94–752 MB | No |
| Barthelemy (ePrint 2020) [16] | Lattice (custom) | None | <20 MB | PoC |
| This work | Lattice | FIPS 203 | 11–26 MB | Yes (proj.) |
| Algorithm 1 Base-Multiply Table Lookup for NTT Component i (Construction B; masking applied to outputs) |
|
2. Related Work
3. Background and Motivation
3.1. ML-KEM Parameters and Structure
3.2. NTT Domain Structure
3.3. Threat Model Hierarchy
3.4. Differential Computation Analysis
3.5. Precise White-Box Attacker Model
4. The Proposed PQ-WB-KEM Construction
4.1. Architecture Overview
4.2. Coefficient-Pair Multiplication Tables
| Component | A (Shared) | B (Baked) | Basis |
|---|---|---|---|
| Base-multiply tables * | 22.16 MB | 7.67 MB | Measured |
| Output-encoding sublayer | 3.41 MB | 3.41 MB | Measured |
| Measured core | 25.57 MB | 11.08 MB | Measured |
| Coefficient shuffle (, ) | 3 KB | 3 KB | Measured |
| Masking support | 0 | 0 | runtime |
| Deployment total | 25.58 MB | 11.08 MB | Measured |

4.3. Three-Share Arithmetic Masking
4.4. Freedom from Division-Timing Leakage in the Protected Base Multiply
| Algorithm 2 Protected Decapsulation: composition of the secret-key path |
|
4.5. Putting It Together: Protected Decapsulation
5. Security Analysis
5.1. Achieved Security Properties
5.2. Limitations and Open Attacks
5.3. Why Only Decapsulation Is Protected
6. Performance Evaluation
6.1. Implementation Details
6.2. Performance Results
| Operation | x86-64 liboqs | ARM64 QEMU () |
|---|---|---|
| KeyGen | 0.137 ms | ms |
| Encaps | 0.161 ms | ms |
| Decaps | 0.194 ms | ms |
| Metric | Value | Notes |
|---|---|---|
| Overhead factor | ≈47× (proj.) | native protected primitive × ≈11× cache; with the RNG-excluded lower bound |
| Est. WB decaps (x86-64 host) | ≈10 ms (7–14) | Based on 0.213 ms × 47, ±35% band; no ARM-device measurement |
| Storage | 11–26 MB | Construction B/A measured core |
| Working Set | ns/Access | Penalty vs. L1 |
|---|---|---|
| 16 KB (L1) | 1.6 | 1.0× |
| 256 KB (L2) | 4.9 | ≈3× |
| 2 MB (L2 edge) | 10.3 | ≈6× |
| 7.67 MB (tables) | 102.6 | ≈63× |
| 36 MB (L3 edge) | 111.2 | ≈69× |
| 64 MB (DRAM) | 114.7 | ≈71× |
6.3. DCA Resistance Evaluation
6.4. Algebraic Attack Resistance
6.5. Memory Overhead Justification
6.6. Performance vs. Security Trade-Off
6.7. ML-KEM Parameter Scaling Analysis
| Parameter | ML-KEM-512 | ML-KEM-768 | ML-KEM-1024 |
|---|---|---|---|
| Module rank k | 2 | 3 | 4 |
| NIST Level | 1 | 3 | 5 |
| NTT factors (constant) | 128 | 128 | 128 |
| Component mult. () | 256 | 384 | 512 |
| Construction-B core (est.) | ≈9 MB | ≈11 MB | ≈14 MB |
| Decaps overhead | ≈30× | ≈47× | ≈64× |
| Decaps time (est.) | 4–9 ms | 7–14 ms | 9–18 ms |
| Target RAM | ≥64 MB | ≥64 MB | ≥64 MB |
6.8. Summary of Results
7. Conclusions and Future Work
7.1. Contributions and Practical Limits
7.2. Open Problems and Future Work
Supplementary Materials
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Chow, S.; Eisen, P.; Johnson, H.; van Oorschot, P.C. White-Box Cryptography and an AES Implementation. In Proceedings of the SAC; Nyberg, K., Heys, H., Eds.; Springer: Berlin/Heidelberg, Germany, 2002; pp. 250–270. [Google Scholar] [CrossRef] [Scilit]
- Chow, S.; Eisen, P.; Johnson, H.; van Oorschot, P.C. A White-Box DES Implementation for DRM Applications. In Proceedings of the ACM DRM Workshop; Feigenbaum, J., Ed.; Springer: Berlin/Heidelberg, Germany, 2002; pp. 1–15. [Google Scholar] [CrossRef] [Scilit]
- Coruh, U.; Bayat, O. Hybrid Secure Authentication and Key Exchange Scheme for M2M Home Networks. Secur. Commun. Netw. 2018, 2018, 6563089. [Google Scholar] [CrossRef] [Scilit]
- Bos, J.W.; Hubain, C.; Michiels, W.; Teuwen, P. Differential Computation Analysis: Hiding Your White-Box Designs Is Not Enough. In Proceedings of the CHES; Gierlichs, B., Poschmann, A., Eds.; Springer: Berlin/Heidelberg, Germany, 2016; pp. 215–236. [Google Scholar] [CrossRef] [Scilit]
- Rivain, M. White-Box Cryptography. In Encyclopedia of Cryptography, Security and Privacy; Jajodia, S., Samarati, P., Yung, M., Eds.; Springer: Berlin/Heidelberg, Germany, 2023. [Google Scholar] [CrossRef] [Scilit]
- Liu, T.; Ramachandran, G.; Jurdak, R. Post-Quantum Cryptography for Internet of Things: A Survey on Performance and Optimization. arXiv 2024, arXiv:2401.17538. [Google Scholar] [CrossRef] [Scilit]
- FIPS 203; Module-Lattice-Based Key-Encapsulation Mechanism Standard. National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024. [CrossRef] [Scilit]
- FIPS 204; Module-Lattice-Based Digital Signature Standard. National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024. [CrossRef] [Scilit]
- FIPS 205; Stateless Hash-Based Digital Signature Standard. National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024. [CrossRef] [Scilit]
- Moody, D.; Perlner, R.; Regenscheid, A.; Robinson, A.; Cooper, D. Transition to Post-Quantum Cryptography Standards; NIST Internal Report, NIST IR 8547 ipd; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024. [Google Scholar] [CrossRef] [Scilit]
- Bicakci, K.; Ulker, K.; Uzunay, Y.; Şahin, H.T.; Gündoğan, M.S. Quantum-Resistance Meets White-Box Cryptography: How to Implement Hash-Based Signatures Against White-Box Attackers? IACR Commun. Cryptol. 2024, 1, 1–21. [Google Scholar] [CrossRef] [Scilit]
- Galissant, P.; Goubin, L. Resisting Key-Extraction and Code-Compression: A Secure Implementation of the HFE Signature Scheme in the White-Box Model. Cryptol. ePrint Arch. 2022, 138, 1–28. [Google Scholar]
- Bernstein, D.J.; Bhargavan, K.; Bhasin, S.; Chattopadhyay, A.; Chia, T.K.; Kannwischer, M.J.; Kiefer, F.; Paiva, T.B.; Ravi, P.; Tamvada, G. KyberSlash: Exploiting Secret-Dependent Division Timings in Kyber Implementations. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2025, 2025, 209–234. [Google Scholar] [CrossRef] [Scilit]
- Pay, D.; Standaert, F.X. Keep it Simple: Refreshing the NTT of Kyber’s Decapsulation to Prevent Plaintext-Checking Side-Channel Attacks. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2026, 2026, 472–499. [Google Scholar] [CrossRef] [Scilit]
- Galissant, P.; Goubin, L. White-Box Implementation Techniques for the HFE Family. In Proceedings of the CASCADE; Rivain, M., Sasdrich, P., Eds.; Springer: Cham, Switzerland, 2025; pp. 261–288. [Google Scholar] [CrossRef] [Scilit]
- Barthelemy, L. Toward an Asymmetric White-Box Proposal. Cryptol. ePrint Arch. 2020, 893, 1–18. [Google Scholar]
- Alpirez Bock, E.; Brzuska, C.; Lai, R.W.F. On Provable White-Box Security in the Strong Incompressibility Model. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2023, 2023, 167–187. [Google Scholar] [CrossRef] [Scilit]
- Billet, O.; Gilbert, H.; Ech-Chatbi, C. Cryptanalysis of a White Box AES Implementation. In Proceedings of the SAC; Handschuh, H., Hasan, M.A., Eds.; Springer: Berlin/Heidelberg, Germany, 2004; pp. 227–240. [Google Scholar] [CrossRef] [Scilit]
- Wyseur, B.; Michiels, W.; Gorissen, P.; Preneel, B. Cryptanalysis of White-Box DES Implementations with Arbitrary External Encodings. In Proceedings of the SAC; Adams, C., Miri, A., Wiener, M., Eds.; Springer: Berlin/Heidelberg, Germany, 2007; pp. 264–277. [Google Scholar] [CrossRef] [Scilit]
- Goubin, L.; Masereel, J.M.; Quisquater, M. Cryptanalysis of White Box DES Implementations. In Proceedings of the SAC; Adams, C., Miri, A., Wiener, M., Eds.; Springer: Berlin/Heidelberg, Germany, 2007; pp. 278–295. [Google Scholar] [CrossRef] [Scilit]
- WhibOx Contest. CHES 2024 Challenge (WhibOx Contest). 2024. Available online: https://whibox.io/contests/2024/ (accessed on 13 August 2026).
- Barbu, G.; Beullens, W.; Dottax, E.; Giraud, C.; Houzelot, A.; Li, C.; Mahzoun, M.; Ranea, A.; Xie, J. ECDSA White-Box Implementations: Attacks and Designs from CHES 2021 Challenge. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2022, 2022, 527–552. [Google Scholar] [CrossRef] [Scilit]
- Delerablée, C.; Lepoint, T.; Paillier, P.; Rivain, M. White-Box Security Notions for Symmetric Encryption Schemes. In Proceedings of the SAC; Lange, T., Lauter, K., Lisoněk, P., Eds.; Springer: Berlin/Heidelberg, Germany, 2013; pp. 247–264. [Google Scholar] [CrossRef] [Scilit]
- Bogdanov, A.; Isobe, T. White-Box Cryptography Revisited: Space-Hard Ciphers. In Proceedings of the ACM CCS; ACM: New York, NY, USA, 2015; pp. 1058–1069. [Google Scholar] [CrossRef] [Scilit]
- Fouque, P.A.; Karpman, P.; Kirchner, P.; Minaud, B. Efficient and Provable White-Box Primitives. In Proceedings of the ASIACRYPT; Cheon, J.H., Takagi, T., Eds.; Springer: Berlin/Heidelberg, Germany, 2016; pp. 159–188. [Google Scholar] [CrossRef] [Scilit]
- Biryukov, A.; Bouillaguet, C.; Khovratovich, D. Cryptographic Schemes Based on the ASASA Structure: Black-Box, White-Box, and Public-Key (Extended Abstract). In Proceedings of the ASIACRYPT; Sarkar, P., Iwata, T., Eds.; Springer: Berlin/Heidelberg, Germany, 2014; pp. 63–84. [Google Scholar] [CrossRef] [Scilit]
- Bos, J.W.; Gourjon, M.; Renes, J.; Schneider, T.; van Vredendaal, C. Masking Kyber: First- and Higher-Order Implementations. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2021, 2021, 173–214. [Google Scholar] [CrossRef] [Scilit]
- Heinz, D.; Kannwischer, M.J.; Land, G.; Pöppelmann, T.; Schwabe, P.; Sprenkels, A. First-Order Masked Kyber on ARM Cortex-M4. Cryptol. ePrint Arch. 2022, 058, 1–11. [Google Scholar]
- Coron, J.S.; Gérard, F.; Trannoy, M.; Zeitoun, R. Improved Gadgets for the High-Order Masking of Dilithium. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2023, 2023, 110–145. [Google Scholar] [CrossRef] [Scilit]
- Belaïd, S.; Benadjila, R.; Devevey, J.; Guerreau, M.; Legavre, T.; Martinelli, A.; Ricosset, T.; Rivain, M.; Rossi, M. ML-DSA Masking Sweetened with SUCRE: Shuffle-and-Unmask Countermeasure for REjection Sampling. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2026, 2026, 618–659. [Google Scholar] [CrossRef] [Scilit]
- Li, Z.; Xu, J.; Song, J.; Xu, H.; Jia, Y.; Zou, Y.; Hu, L. Improved Attacks Against Lattice-Based KEMs Using Hints from Hertzbleed. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2025, 2025, 463–485. [Google Scholar] [CrossRef] [Scilit]
- Ravi, P.; Sinha Roy, S.; Chattopadhyay, A.; Bhasin, S. Generic Side-Channel Attacks on CCA-Secure Lattice-Based PKE and KEMs. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2020, 2020, 307–335. [Google Scholar] [CrossRef]
- Rajendran, G.; Ravi, P.; D’Anvers, J.P.; Bhasin, S.; Chattopadhyay, A. Pushing the Limits of Generic Side-Channel Attacks on LWE-Based KEMs—Parallel PC Oracle Attacks on Kyber KEM and Beyond. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2023, 2023, 418–446. [Google Scholar] [CrossRef] [Scilit]
- Du, J.; Wang, Z.; Yu, A. Revisiting the Masking Strategy: A Side-Channel Attack on CRYSTALS-Kyber. IEEE Trans. Inf. Forensics Secur. 2025, 20, 3387–3399. [Google Scholar] [CrossRef] [Scilit]
- Berzati, A.; Calle Viera, A.; Chartouny, M.; Vigilant, D. Simple Power Analysis Assisted Chosen Cipher-Text Attack on ML-KEM. In Proceedings of the CASCADE; Rivain, M., Sasdrich, P., Eds.; Springer: Cham, Switzerland, 2025; pp. 3–26. [Google Scholar] [CrossRef] [Scilit]
- Dubrova, E.; Ngo, K.; Gärtner, J.; Wang, R. Breaking a Fifth-Order Masked Implementation of CRYSTALS-Kyber by Copy-Paste. In Proceedings of the APKC; ACM: New York, NY, USA, 2023; pp. 10–20. [Google Scholar] [CrossRef] [Scilit]
- Kundu, S.; Chowdhury, S.; Saha, S.; Karmakar, A.; Mukhopadhyay, D.; Verbauwhede, I. Carry Your Fault: A Fault Propagation Attack on Side-Channel Protected LWE-Based KEM. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2024, 2024, 844–869. [Google Scholar] [CrossRef] [Scilit]
- Berthet, P.A.; Rougeolle, Y.; Tavernier, C.; Sauvage, L. Advances in Reed-Solomon Code-Based Masking and Application to ML-KEM. IACR Commun. Cryptol. 2025, 2, 1–32. [Google Scholar] [CrossRef] [Scilit]
- Carlet, C.; Daif, A.; Guilley, S.; Tavernier, C. Quasi-Linear Masking against SCA and FIA, with Cost Amortization. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2024, 2024, 398–432. [Google Scholar] [CrossRef] [Scilit]
- Bos, J.; Ducas, L.; Kiltz, E.; Lepoint, T.; Lyubashevsky, V.; Schanck, J.M.; Schwabe, P.; Seiler, G.; Stehlé, D. CRYSTALS-Kyber: A CCA-Secure Module-Lattice-Based KEM. In Proceedings of the IEEE EuroS&P; IEEE: Piscataway, NJ, USA, 2018; pp. 353–367. [Google Scholar] [CrossRef] [Scilit]
- Lyubashevsky, V.; Peikert, C.; Regev, O. On Ideal Lattices and Learning with Errors over Rings. In Proceedings of the EUROCRYPT; Gilbert, H., Ed.; Springer: Berlin/Heidelberg, Germany, 2010; pp. 1–23. [Google Scholar] [CrossRef] [Scilit]
- Langlois, A.; Stehlé, D. Worst-Case to Average-Case Reductions for Module Lattices. Des. Codes Cryptogr. 2015, 75, 565–599. [Google Scholar] [CrossRef] [Scilit]
- Peikert, C. A Decade of Lattice Cryptography. Found. Trends Theor. Comput. Sci. 2016, 10, 283–424. [Google Scholar] [CrossRef] [Scilit]
- Bronchain, O.; Cassiers, G. Bitslicing Arithmetic/Boolean Masking Conversions for Fun and Profit: With Application to Lattice-Based KEMs. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2022, 2022, 553–588. [Google Scholar] [CrossRef] [Scilit]
- Coron, J.S.; Großschädl, J.; Tibouchi, M.; Vadnala, P.K. Conversion from Arithmetic to Boolean Masking with Logarithmic Complexity. In Proceedings of the FSE; Leander, G., Ed.; Springer: Berlin/Heidelberg, Germany, 2015; pp. 130–149. [Google Scholar] [CrossRef] [Scilit]
- Coron, J.S.; Gérard, F.; Montoya, S.; Zeitoun, R. High-Order Table-Based Conversion Algorithms and Masking Lattice-Based Encryption. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2022, 2022, 1–40. [Google Scholar] [CrossRef] [Scilit]
- Fujisaki, E.; Okamoto, T. Secure Integration of Asymmetric and Symmetric Encryption Schemes. In Proceedings of the CRYPTO; Wiener, M., Ed.; Springer: Berlin/Heidelberg, Germany, 1999; pp. 537–554. [Google Scholar] [CrossRef] [Scilit]
- Ishai, Y.; Sahai, A.; Wagner, D. Private Circuits: Securing Hardware Against Probing Attacks. In Proceedings of the CRYPTO; Boneh, D., Ed.; Springer: Berlin/Heidelberg, Germany, 2003; pp. 463–481. [Google Scholar] [CrossRef] [Scilit]
- Charlès, A.; Udovenko, A. LPN-Based Attacks in the White-Box Setting. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2023, 2023, 318–343. [Google Scholar] [CrossRef] [Scilit]
- Open Quantum Safe Project. liboqs: Open-Source C Library for Quantum-Safe Cryptographic Algorithms. 2024. Available online: https://openquantumsafe.org/liboqs/ (accessed on 13 August 2026).
- Stebila, D.; Mosca, M. Post-Quantum Key Exchange for the Internet and the Open Quantum Safe Project. In Proceedings of the SAC; Avanzi, R., Heys, H., Eds.; Springer: Cham, Switzerland, 2016; pp. 14–37. [Google Scholar] [CrossRef] [Scilit]
- Biryukov, A.; Udovenko, A. Attacks and Countermeasures for White-Box Designs. In Proceedings of the ASIACRYPT; Peyrin, T., Galbraith, S., Eds.; Springer: Cham, Switzerland, 2018; pp. 373–402. [Google Scholar] [CrossRef] [Scilit]
- ARM Limited. ARM Security Technology: Building a Secure System Using TrustZone Technology; Technical Report PRD29-GENC-009492C; ARM Limited: Cambridge, UK, 2009. [Google Scholar]
- Costan, V.; Devadas, S. Intel SGX Explained. Cryptol. ePrint Arch. 2016, 86, 1–118. [Google Scholar] [CrossRef] [Scilit]
- Zhou, Y.; Wang, W.; Sun, Y.; Yu, Y. Rejected Signatures’ Challenges Pose New Challenges: Key Recovery of CRYSTALS-Dilithium via Side-Channel Attacks. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2025, 2025, 817–847. [Google Scholar] [CrossRef] [Scilit]
- Stefanov, E.; van Dijk, M.; Shi, E.; Fletcher, C.; Ren, L.; Yu, X.; Devadas, S. Path ORAM: An Extremely Simple Oblivious RAM Protocol. In Proceedings of the ACM CCS; ACM: New York, NY, USA, 2013; pp. 299–310. [Google Scholar] [CrossRef] [Scilit]


| Parameter | Value | Description |
|---|---|---|
| n | 256 | Polynomial degree |
| q | 3329 | Prime modulus |
| k | 3 | Module rank |
| 2, 2 | lefted binomial distribution parameters | |
| 1184 B | Public key size | |
| 1088 B | Ciphertext size | |
| 32 B | Shared secret |
| Aspect | Bicakci [11] | Galissant [12] | This Work |
|---|---|---|---|
| PQC family | Hash-based | Multivariate | Lattice |
| Algorithm | SPHINCS+ | HFE | ML-KEM-768 |
| NIST standard | FIPS 205 | None | FIPS 203 |
| Implementation size | Medium | 256 GB | 11–26 MB |
| Practical deployment | Moderate | No | Yes (proj.) |
| Signature/CT size | ≈8–50 KB | N/A | 1088 B |
| Algebraic attack risk | Low | High | High (unprotected vs. informed adversary) |
| Masking-independence (standard) | No | N/A | Yes (Theorem 2) |
| Implementation | Traces | Attack | |
|---|---|---|---|
| Unmasked | 1000 | 0.866 | Success |
| Unmasked | 10,000 | 0.853 | Success |
| 3-share masked | 1000 | 0.031 | Fail |
| 3-share masked | 5000 | 0.005 | Fail |
| 3-share masked | 10,000 | 0.011 | Fail |
| Implementation | Queries | Success | Error |
|---|---|---|---|
| Unprotected | 1–2 | 100% | 0.0 |
| Protected (mixing + shuffle) | 100 | 0% * | 30,683.7 |
| Metric | Windows (Portable) | WSL/Linux |
|---|---|---|
| Protected-primitive overhead (×, RNG excl.) | ||
| Algebraic mixing overhead (×) | ||
| Algebraic shuffling overhead (×) | ||
| Algebraic full overhead (×) | ||
| liboqs decaps (ms) | — * |
| Platform | RAM | 26 MB % | Suitable |
|---|---|---|---|
| Raspberry Pi 4 | 4 GB | 0.6% | Yes |
| Automotive ECU | 512 MB–2 GB | 1.2–5.0% | Yes |
| Edge server | 16+ GB | <0.2% | Yes |
| Industrial gateway | 256 MB–1 GB | 2.5–10.0% | Yes |
| IoT sensor | 32–256 KB | N/A | No |
| # | Result | Type | Exp. | Verification |
|---|---|---|---|---|
| 1 | NTT Factorization | Struct. | ✓ | SageMath |
| 2 | NTT-domain secret range | Obs. | ✓ | Python |
| 3 | Masking Security | Pos. | ✓ | Python/DCA |
| 4 | DCA Complexity | Cor. | – | Analytical |
| 5 | Constant-Time Ops | Pos. | ✓ | Structural |
| 6 | Encoding key entropy | Struct. | – | Analytical |
| 7 | Cond. algebraic security | Cond. | ✓ | Premise open (Section 7.2) |
| Theorem | Metric | Value | Status |
|---|---|---|---|
| Theorem 2 (share obs.) | 3-share (10 K traces) | 0.011 | Pass |
| Correlation near noise floor () | Pass | ||
| RNG sanity check | Share uniformity (mean p) | 0.50 | Pass |
| Theorem 3 (Timing) | No secret-dependent branch | True | Pass |
| No data-dependent division/reduction | True | Pass | |
| Theorem 1 (NTT) | True | Pass | |
| True | Pass | ||
| True | Pass | ||
| 128 irreducible factors | True | Pass |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Coruh, U. PQ-WB-KEM: Toward a White-Box Construction of ML-KEM-768 with Arithmetic Masking for M2M Communications. Mathematics 2026, 14, 3072. https://doi.org/10.3390/math14173072
Coruh U. PQ-WB-KEM: Toward a White-Box Construction of ML-KEM-768 with Arithmetic Masking for M2M Communications. Mathematics. 2026; 14(17):3072. https://doi.org/10.3390/math14173072
Chicago/Turabian StyleCoruh, Uğur. 2026. "PQ-WB-KEM: Toward a White-Box Construction of ML-KEM-768 with Arithmetic Masking for M2M Communications" Mathematics 14, no. 17: 3072. https://doi.org/10.3390/math14173072
APA StyleCoruh, U. (2026). PQ-WB-KEM: Toward a White-Box Construction of ML-KEM-768 with Arithmetic Masking for M2M Communications. Mathematics, 14(17), 3072. https://doi.org/10.3390/math14173072
