Conception Digital Wave Form

Rethinking TVLA for PQC: Toward Meaningful Leakage Detection

As post-quantum cryptography (PQC) begins to mature, hardware security evaluators are facing a familiar challenge in a new form: how do we detect side-channel leakage when the traditional assumptions no longer apply?

TVLA (Test Vector Leakage Assessment) has long been regarded as a reliable first-line technique for detecting side-channel leakage. However, in the context of post-quantum cryptography, its foundational assumptions begin to falter. What happens when traditional fixed-versus-random input strategies no longer align with the structure of computations? When operations like the Number-Theoretic Transform (NTT) dominate the algorithm’s behavior? Or when key material is inherently randomized and structured, rather than static and uniform?

This is where our perspective on TVLA needs to evolve—not just technically, but philosophically.

Why Traditional TVLA Needs Rethinking in PQC

TVLA is based on statistical analysis, most commonly using Welch’s t-test to compare physical side-channel traces (such as power or electromagnetic emissions) collected under fixed and random input conditions. When properly implemented and interpreted, it can indicate whether a device exhibits statistically significant leakage.

This method has shown strong effectiveness in symmetric cryptography, particularly with algorithms like AES, where internal intermediates—such as key-dependent S-box outputs—align well with the fixed-versus-random input model. Under these conditions, leakage can be meaningfully detected across many independent operations.

However, TVLA has important limitations. It does not guarantee the absence of leakage—only that none was detected under a specific test configuration. It is inherently sensitive to trace quality, noise, and the choice of input vectors. Moreover, it is primarily designed to detect first-order leakage; higher-order or structured leakages (as in masked or post-quantum implementations) may go undetected unless explicitly targeted with more advanced statistical models and preprocessing.

In contrast, PQC algorithms often don't fit the conventional model. Consider lattice-based schemes like Kyber or Dilithium. These algorithms involve complex algebraic structures, randomized key generation, and transformation-heavy computations such as the Number-Theoretic Transform (NTT). In these schemes:

Applying TVLA in this context using traditional test vectors could produce results that are either inconclusive or misleading.

TVLA in the ISO 17825:2024 Update

The recently updated ISO/IEC 17825:2024 standard acknowledges these challenges. It expands on the original 2016 version by introducing:

These updates are critical. They formalize a broader understanding that side-channel analysis cannot be one-size-fits-all. And more importantly, they validate what evaluators in the field have already begun to experience: the need to adapt TVLA to meet the realities of modern cryptography.

A PQC-Aware Approach to Leakage Detection

So, what does a more PQC-aware TVLA approach look like in practice?

1. Flexible Test Vectors

Rather than relying on fixed vs. random plaintexts or keys, test vectors should be constructed to stimulate specific internal operations. This could include targeting polynomial multiplications, modular reductions, or the NTT stages themselves. The goal is to surface leakage in computations that, while not directly key-dependent in the classical sense, could still reveal exploitable correlations.

2. Leakage Modeling Beyond the Key

In many PQC schemes, the concept of a "static key" does not apply in the traditional sense. Implementations may use ephemeral keys or randomized key encapsulation. As such, leakage detection must shift focus toward intermediate state leakage, even when that leakage isn’t directly correlated with a reused secret.

3. Higher-Order Analysis by Default

PQC implementations are more likely to incorporate masking, blinding, or domain separation techniques. As a result, first-order leakage may be absent while higher-order leakage persists. This makes second- or even third-order TVLA testing a necessary baseline rather than an optional extension.

4. Algorithm-Specific Leakage Hypotheses

Rather than applying generic tests, evaluators should build leakage hypotheses around the specific structure and flow of the algorithm under review. This includes understanding how randomness, key scheduling, and transform domains like the NTT interact in practice.

Why This Shift Matters

The transition to post-quantum cryptography (PQC) introduces not only new algorithmic primitives but also fundamentally different computational behaviors that challenge established security evaluation methodologies. Leakage detection methodologies that were once effective for symmetric ciphers must evolve to remain relevant. If we continue to apply traditional TVLA without adaptation, we risk two major issues:

In either case, the result is a misalignment between the test method and the actual security posture of the implementation.

A New Baseline for Hardware Security

As post-quantum cryptographic algorithms transition from theory to hardware deployment, TVLA must be re-envisioned—not as a rigid, one-size-fits-all standard, but as a flexible, context-sensitive methodology. The revisions introduced in ISO 17825:2024 represent a meaningful step toward this goal. However, the true advancement will depend on how practitioners interpret, implement, and operationalize these principles across diverse post-quantum platforms and threat models.

Side-channel analysis isn’t going away. It’s becoming more important—and more complex. And as cryptographic designs grow more intricate, so too must our tools for testing them.

The future of hardware cryptography is quantum-resistant, randomized, and transform-heavy. Our testing strategies must reflect that reality. TVLA still has a vital role to play in securing post-quantum hardware implementations. But only if we allow it to evolve. This isn’t about replacing the old model. It’s about refining it—to remain meaningful, rigorous, and relevant for the next generation of cryptographic security.

Keysight provides solutions and services to help our clients deliver secure, compliant, and future-ready products. For more information on our PQC offering, visit this page or reach out to our team at [email protected].

Related Posts

limit
3