Leakage Assessment and Correlation Power Analysis of the MAYO Secret Linear Map on a Cortex-M4: A Reproducible Case Study and a Validated First-Order Countermeasure
Abstract
1. Introduction
Contributions
- A non-profiled, first-order leakage baseline for the MAYO secret map. The MAYO secret operation over is isolated as a reference-faithful reduced target, reusing the MAYO-C arithmetic verbatim so that the measured leakage is faithful to the reference while fitting the ∼48 KB SRAM on which full MAYO-1 signing does not run. On this target, non-specific TVLA yields and a secret-dependent fixed-versus-fixed test with 12,298/20,000 points failing (Section 5 and Section 7).
- A distinguisher that resolves the confounds of a linear map, with its assumptions made explicit. The multiplicative-identity input-load alias and temporal row-mixing are identified and removed by partial correlation with points-of-interest windowing, recovering first-row nibbles and collapsing the row from 168 to 24 candidates, with the key dependence of that figure measured over 20 independent random keys (median 287 candidates, mean rank 3.21 against chance 8.50). The accompanying identity-disambiguation rule, its threshold-invariance interval, the significance of the reduction against a null model, and its dependence on the particular test key are all quantified, and the full-matrix cost is reported as a measured residual of 2374 over the 39 rows carrying exploitable leakage (per-row 9.60 bits, 40.4% of nibbles recovered outright) and an extrapolated full-matrix cost of ≈2749 (Section 6.4, Section 7 and Section 7.3).
- A first-order countermeasure evaluated on the same bench, with a methodology for near-threshold assessment. A masked and row-shuffled map reduces the peak fixed-versus-fixed statistic to with 0/24,000 failing points at a measured 2.22× cycle cost, while masking alone still leaks at . Reaching a defensible verdict at this effect size required drift-free block-interleaved acquisition and explicit null behavior for both the t and criteria, which is reported as a transferable methodology. Firmware, capture and analysis code and all raw traces are released as a public artifact [13] (Section 6.6 and Section 8).
2. Background
2.1. MAYO and the Secret Linear Map
2.2. Leakage Assessment (TVLA)
2.3. Correlation Power Analysis (CPA)
3. The PQ-NEXT Framework and the Placement of This Study
4. Related Work
4.1. Attacks on MAYO
4.2. Countermeasures
4.3. Differentiation from Prior Work
5. Target Analysis and Threat Model
5.1. Isolating the Sensitive Primitive
5.2. Feasibility Constraint and the Reduced Target
5.3. Threat Model
6. Materials and Methods
6.1. Device Under Test and Instrumentation
trigger_high();__asm__ volatile("" ::: "memory");mat_mul(O, x, Ox, o, v, 1);__asm__ volatile("" ::: "memory");trigger_low();
6.2. Capture Configuration
6.3. Leakage-Assessment Procedure
6.4. CPA Distinguisher and Confound Handling
- Multiplicative-identity input-load alias. Because in , the hypothesis predicts exactly , which coincides with the strong, pervasive leakage of the public input being (re)loaded from memory on every row. A global-maximum CPA therefore returns for every nibble—correct only where the true nibble happens to be 1. This alias is removed by partial correlation, i.e., by linearly regressing out of the traces before correlating, annihilating the predictor.
- Temporal row-mixing. Each public multiplies for all 78 rows, so a full-trace search mixes contributions from many rows. Within the 5000-sample window the first row’s eight products are separated in time at a fixed cadence, empirically samples. Therefore, each nibble is correlated only within a tight window around its point of interest.
6.5. Statistical Rigor of the Assessment
6.6. Decision Criteria and Their Null Behavior
7. Results
7.1. Leakage Assessment
7.2. Correlation Power Analysis
Statistical Significance and Dependence on the Particular Test Key
7.3. Beyond the First Row: Full-Key Argument
8. A First-Order Countermeasure and Its Evaluation
8.1. Design: Masking and Shuffling
- Temporal share separation. The two share products and are computed in two separate passes, and the shares are recombined only after the measured (trigger-bracketed) region, so no sample manipulates and back-to-back (which would leak their Hamming distance ).
- Row shuffling. Each share pass evaluates the output rows in an independent uniformly random order (two Fisher–Yates permutations from an on-device xorshift32 generator), so any residual per-row leakage is diluted across 78 time slots, and no fixed sample corresponds to a fixed secret row.
- Fresh randomness. Masks and permutations are regenerated every invocation, outside the trigger, so leakage of the mask itself does not enter the measured window.
8.2. Measured Overhead
8.3. Leakage Evaluation
9. Discussion
9.1. Why the First-Order Model Saturates
9.2. From Assessment to Countermeasure: What Was Measured and What Remains
- Integration into full signing. Here the map is isolated for measurement; folding the shared output into the vinegar addition (so the vinegar acts as a further share) and re-assessing within full mayo_sign is the deployment step.
- Cross-parameter and cross-scheme coverage. Repeat on MAYO-2 (, change the map geometry) and extend the same reduced-target methodology to the other embedded multivariate candidates, for which hardware-evaluated masking is likewise absent.
9.3. Limitations
10. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| CPA | Correlation Power Analysis |
| DPA | Differential Power Analysis |
| GE | Gaussian Elimination/Guessing Entropy (as indicated in context) |
| Galois Field with 16 Elements | |
| MAYO | Whipped Oil-and-Vinegar Post-Quantum Signature Scheme |
| NIST | National Institute of Standards and Technology |
| POI | Point of Interest |
| PQC | Post-Quantum Cryptography |
| SCA | Side-Channel Analysis |
| SNR | Signal-to-Noise Ratio |
| TtD | Traces-to-Detection |
| TVLA | Test Vector Leakage Assessment |
| UOV | Unbalanced Oil and Vinegar |
References
- National Institute of Standards and Technology. Post-Quantum Cryptography: Digital Signature Schemes—Call for Additional Signatures; NIST: Gaithersburg, MD, USA, 2023. Available online: https://csrc.nist.gov/projects/pqc-dig-sig (accessed on 25 July 2026).
- Beullens, W. MAYO: Practical Post-Quantum Signatures from Oil-and-Vinegar Maps. In Selected Areas in Cryptography (SAC 2021); Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2022; Volume 13203, pp. 355–376. [Google Scholar]
- Beullens, W.; Campos, F.; Celi, S.; Hess, B.; Kannwischer, M.J. MAYO: Specification Document, Round-2 Version; 2025. Available online: https://pqmayo.org/assets/specs/mayo-round2.pdf (accessed on 12 August 2026).
- Sayari, O.; Marzougui, S.; Aulbach, T.; Krämer, J.; Seifert, J.-P. HaMAYO: A Fault-Tolerant Reconfigurable Hardware Implementation of the MAYO Signature Scheme. In Constructive Side-Channel Analysis and Secure Design (COSADE 2024); Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2024; Volume 14595. [Google Scholar]
- Hirner, F.; Streibl, M.; Mert, A.C.; Sinha Roy, S. Whipping the Multivariate-Based MAYO Signature Scheme Using Hardware Platforms. In Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS); ACM: New York, NY, USA, 2024; pp. 3421–3435. [Google Scholar]
- Aulbach, T.; Marzougui, S.; Seifert, J.-P.; Ulitzsch, V.Q. MAYo or MAY-not: Exploring Implementation Security of the Post-Quantum Signature Scheme MAYO Against Physical Attacks. In Workshop on Fault Detection and Tolerance in Cryptography (FDTC 2024); IEEE: Piscataway, NJ, USA, 2024; pp. 28–33. [Google Scholar]
- Jendral, S.; Dubrova, E. MAYO Key Recovery by Fixing Vinegar Seeds. IACR Commun. Cryptol. 2024, 1, 17. [Google Scholar] [CrossRef] [Scilit]
- Jendral, S.; Dubrova, E. Single-Trace Side-Channel Attacks on MAYO Exploiting Leaky Modular Multiplication. Cryptology ePrint Archive, Paper 2024/1850. 2024. Available online: https://eprint.iacr.org/2024/1850 (accessed on 7 September 2026).
- Jendral, S.; Dubrova, E. Single-Trace Side-Channel Attacks on MAYO Exploiting Leaky Modular Multiplication. In QRSEC ’25: Proceedings of the 2025 1st Workshop on Quantum-Resistant Cryptography and Security; ACM: New York, NY, USA, 2026; pp. 21–30. [Google Scholar] [CrossRef] [Scilit]
- Vishwaajith, N.K.; Ganguly, A.; Pal, D.; Yap, T.; Mondal, P.; Kundu, S.; Saha, S.; Bhasin, S.; Verbauwhede, I.; Karmakar, A. SCA-MQDSA: Side-Channel Analysis of Multivariate Digital Signature Implementations. Cryptology ePrint Archive, Paper 2026/228. 2026. Available online: https://eprint.iacr.org/2026/228 (accessed on 7 September 2026).
- Aulbach, T.; Campos, F.; Krämer, J. SoK: On the Physical Security of UOV-Based Signature Schemes. In Post-Quantum Cryptography (PQCrypto 2025); Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2025; Volume 15577, pp. 199–231. [Google Scholar]
- Norga, Q.; Kundu, S.; Ojha, U.K.; Ganguly, A.; Karmakar, A.; Verbauwhede, I. Masking Gaussian Elimination at Arbitrary Order, with Application to Multivariate- and Code-Based PQC. In Topics in Cryptology—CT-RSA 2025; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2025. [Google Scholar]
- Lampropoulou, V.; Economopoulos, A.; Kourtis, M.-A.; Xilouris, G.; Niemiec, M.; Opiłka, F. PQ-NEXT: MAYO Secret Linear Map on Cortex-M4: Power Side-Channel Traces for Unprotected and Protected Implementations [Data Set]; Zenodo: Geneva, Switzerland, 2026. [Google Scholar] [CrossRef]
- Tosun, T.; Oswald, E.; Savaş, E. Non-Profiled Higher-Order Side-Channel Attacks against Lattice-Based Post-Quantum Cryptography. IACR Commun. Cryptol. 2025, 2, 31. [Google Scholar] [CrossRef] [Scilit]
- Goodwill, G.; Jun, B.; Jaffe, J.; Rohatgi, P. A Testing Methodology for Side-Channel Resistance Validation. In NIST Non-Invasive Attack Testing Workshop (NIAT); NIST: Gaithersburg, MD, USA, 2011. [Google Scholar]
- Schneider, T.; Moradi, A. Leakage Assessment Methodology—A Clear Roadmap for Side-Channel Evaluations. In Cryptographic Hardware and Embedded Systems (CHES 2015); Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2015; Volume 9293, pp. 495–513. [Google Scholar]
- Brier, E.; Clavier, C.; Olivier, F. Correlation Power Analysis with a Leakage Model. In Cryptographic Hardware and Embedded Systems (CHES 2004); Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2004; Volume 3156, pp. 16–29. [Google Scholar]
- PQ-NEXT: Post-Quantum Networks for Energy-Efficient Transitions. Horizon Europe Research and Innovation Action, Grant Agreement No. 101225759, 2025–2028. Available online: https://pqnext.eu (accessed on 9 August 2026).
- PQ-REACT: Post-Quantum Cryptography Framework for Energy Aware Contexts. Horizon Europe Research and Innovation Action, Grant Agreement No. 101119547, 2023–2026. Available online: https://pqreact.eu (accessed on 9 August 2026).
- Abdelmonem, M.; Batina, L.; Chatterjee, D.; Dankbaar, V.; Raddum, H. Splitting the MAYO: A Component-Wise Fault Injection Attack on Randomized MAYO. Cryptology ePrint Archive, Paper 2025/2163, 2025. Available online: https://eprint.iacr.org/2025/2163 (accessed on 7 September 2026).
- Aulbach, T.; Campos, F.; Krämer, J.; Samardjiska, S.; Stöttinger, M. Separating Oil and Vinegar with a Single Trace: Side-Channel Assisted Kipnis–Shamir Attack on UOV. IACR Trans. Cryptogr. Hardw. Embedded Syst. 2023, 2023, 221–245. [Google Scholar]
- Kundu, S.; Norga, Q.; Karmakar, A.; Ojha, U.K.; Ganguly, A.; Verbauwhede, I. mUOV: Masking the Unbalanced Oil and Vinegar Digital Signature Scheme at First- and Higher-Order. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS); ACM: New York, NY, USA, 2025; pp. 1994–2008. [Google Scholar]
- Coron, J.-S.; Gérard, F.; Zhang, B. Masked Solving of Linear Equations System and Application to UOV Signatures. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2026, 2026, 51–72. [Google Scholar] [CrossRef] [Scilit]
- Krieger, F.; Czuprynko, M.; Sinha Roy, S. Lightweight Hardware Accelerator for the UOV Signature Scheme with Oil Space Blinding. Cryptology ePrint Archive, Paper 2026/1451. 2026. Available online: https://eprint.iacr.org/2026/1451 (accessed on 7 September 2026).
- Moradi, A.; Richter, B.; Schneider, T.; Standaert, F.-X. Leakage Detection with the χ2-Test. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2018, 2018, 209–237. [Google Scholar]





| Element of This Study | PQ-NEXT Layer/WP/Task | Serves |
|---|---|---|
| TVLA leakage assessment of | Network Security layer, side-channel/fault mitigation (T2.3) | Hardened, leakage-evaluated implementations |
| CPA key-recovery baseline | Benchmarking of PQC resilience & quality (WP3) | Algorithm maturity/standardization input (EO1) |
| Masking-and-evaluation roadmap | Crypto-agility module, Maintenance Tools (T2.2) | Concrete countermeasure target |
| Reference-faithful reduced target | PQC Algorithm Catalog, multivariate family (T2.1) | Cross-parameter/cross-scheme coverage |
| Constrained Cortex-M4 focus | Adaptation to resource-constrained devices (SN#8) | Good-practice hardware demonstrator (EO5) |
| Work | Target (Operation) | Platform | Prof.? | # Traces | Metric | Attack/Defense |
|---|---|---|---|---|---|---|
| Jendral–Dubrova [8,9] | MAYO (modular mult.) | Cortex-M4 | Prof. (DL) | single trace | SR 99.9%/91.6% | Attack |
| SCA-MQDSA [10] | UOV/MAYO/QR-UOV/ SNOVA | ChipWhisperer, STM32F3 | Non-prof. | single exec. | key recovery | Attack |
| Separating Oil and Vinegar [21] | UOV (central-map inversion) | ChipWhisperer, STM32F3 | Non-prof. | single trace | key recovery | Attack |
| SoK UOV physical sec. [11] | UOV and MAYO (signing subroutines) | Cortex-M4 (NUCLEO-L4R5ZI) | — | — | TVLA (prot. vs. unprot.) | Defense (masking + fault) |
| Masking GE [12] | UOV/MAYO/SNOVA/QR-UOV (Gaussian elim.) | Cortex-M4 | — | — | probing-model proof | Defense (∼ M4) |
| mUOV [22] | UOV (dot-product, mat.–vec.) | Cortex-M4 | — | — | probing-model proof | Defense ( sign) |
| Coron et al. [23] | UOV (linear-system solve) | C (probing) | — | — | probing-model proof | Defense (≥ vs. GE) |
| Krieger et al. [24] | UOV (oil-space blinding) | FPGA | — | — | runtime/area | Defense (<30% runtime) |
| This work | MAYO ( over ) | ChipWhisperer, STM32F3 | Non-prof. | (CPA), /class (TVLA) | GE// | Attack and defense (2.22×) |
| Test | Run | Traces/Class | Peak | Points > 4.5 |
|---|---|---|---|---|
| Fixed-vs-random | Smoke | 60 | 14.20 | 847/5000 |
| Fixed-vs-random | Full | 1000 | 52.88 | 2747/5000 |
| Fixed-vs-fixed | Full | 500 | 195.7 | 12,298/20,000 |
| Nibble j | POI (Sample) | Recovered | True | Rank |
|---|---|---|---|---|
| 0 | 130 | 0 × 6 | 0 × 3 | 2 |
| 1 | 230 | 0 × A | 0 × A | 1 |
| 2 | 330 | 0 × 1 | 0 × 1 | 1 |
| 3 | 430 | 0 × 8 | 0 × 8 | 1 |
| 4 | 530 | 0 × E | 0 × F | 4 |
| 5 | 630 | 0 × 6 | 0 × 6 | 1 |
| 6 | 730 | 0 × 6 | 0 × D | 3 |
| 7 | 830 | 0 × 4 | 0 × 4 | 1 |
| Recovered row | ||||
| Ground truth | ||||
| Metric | Value |
|---|---|
| Exact top-1 nibbles | 5/8 |
| Per-nibble true-key ranks | |
| Mean true-key rank | 1.75/16 (random = 8.5) |
| Row-0 key-space reduction |
| Metric | Random Keys (n = 20) | Structured Test Key |
|---|---|---|
| Exact top-1 nibbles | 3.90/8 (range 1–6) | 5/8 |
| Mean true-key rank | (chance 8.50) | 1.75 |
| Residual candidates | median 287 (min 24, max ) | 24 |
| candidates | 4.58 |
| Implementation | Cycles | Overhead |
|---|---|---|
| Unprotected | 16,242 | 1.00× |
| Masked (two shares) | 35,565 | 2.19× |
| Masked + shuffled | 36,130 | 2.22× |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Lampropoulou, V.; Economopoulos, A.; Kourtis, M.-A.; Xilouris, G.; Niemiec, M.; Opiłka, F. Leakage Assessment and Correlation Power Analysis of the MAYO Secret Linear Map on a Cortex-M4: A Reproducible Case Study and a Validated First-Order Countermeasure. Cryptography 2026, 10, 68. https://doi.org/10.3390/cryptography10050068
Lampropoulou V, Economopoulos A, Kourtis M-A, Xilouris G, Niemiec M, Opiłka F. Leakage Assessment and Correlation Power Analysis of the MAYO Secret Linear Map on a Cortex-M4: A Reproducible Case Study and a Validated First-Order Countermeasure. Cryptography. 2026; 10(5):68. https://doi.org/10.3390/cryptography10050068
Chicago/Turabian StyleLampropoulou, Virginia, Achilleas Economopoulos, Michail-Alexandros Kourtis, George Xilouris, Marcin Niemiec, and Filip Opiłka. 2026. "Leakage Assessment and Correlation Power Analysis of the MAYO Secret Linear Map on a Cortex-M4: A Reproducible Case Study and a Validated First-Order Countermeasure" Cryptography 10, no. 5: 68. https://doi.org/10.3390/cryptography10050068
APA StyleLampropoulou, V., Economopoulos, A., Kourtis, M.-A., Xilouris, G., Niemiec, M., & Opiłka, F. (2026). Leakage Assessment and Correlation Power Analysis of the MAYO Secret Linear Map on a Cortex-M4: A Reproducible Case Study and a Validated First-Order Countermeasure. Cryptography, 10(5), 68. https://doi.org/10.3390/cryptography10050068

