Our report presents several improvements to the dual lattice attack, which induce a noticeable reduction in the security estimation forKyber, Saber and Dilithium, bringing them below the required threshold. The report does not intend to provide a complete analysis of all post-quantum candidates, nor to recommend usage of specific algorithms.
Our report presents several improvements to the dual lattice attack, which induce a noticeable reduction in the security estimation forKyber, Saber and Dilithium, bringing them below the required threshold. The report does not intend to provide a complete analysis of all post-quantum candidates, nor to recommend usage of specific algorithms.

Furthermore, visual representations like the one above help us fully grasp the concept of Kyber Sabre Lacing For Improved Send-For-Detail Accuracy.
View recent discussion. Abstract: After three rounds of post-quantum cryptography (PQC) strict evaluations conducted by NIST, CRYSTALS-Kyberwas successfully selected in July 2022 and standardized in August 2024. It becomes urgent to further evaluateKyber'sphysical security for the upcoming deployment phase. In this brief, we present animprovedtwo-step attack onKyberto quickly recover ...

Furthermore, visual representations like the one above help us fully grasp the concept of Kyber Sabre Lacing For Improved Send-For-Detail Accuracy.
Forinstance, that failure probability ofKyberis below 2 −140 [4], namelyKyberis ϵ -correct with ϵ < 2 −140. In the following, we briefly describe some mathematical notations used inKyber, Saber, and SK-MLWR. The three KEMs share some common mathematical backgrounds because they all belong to the class of lattice-based KEMs.

The fact that all the mismatch attacks onKyberand Saber follow this approach is due to the distribution of the \ (s_i\) values. For another distribution, such as the uniform distribution, this would of course not be a sensible strategy.