Reportskem-07 · Constant-time review

BRQC (kem-07)

CandidateBRQC
FamilyCode-based (rank metric)
ArchiveBRQC.zip (SHA-256: 2c76bdd4e4df7829bf22fa4949a3c744b9af692425f6f2e5fae5317d41e366ae)

kem-07-1: Secret-derived decoder pivots select memory addresses

SeverityMedium
Scopeside-channel
StatusConfirmed
AffectedReference implementations, all three parameter sets
DiscoveryModerate
ExploitationLocal cache observer; key recovery not demonstrated
CreditMarkku-Juhani O. Saarinen markku-juhani.saarinen@tuni.fi, with AI assistance
Date2026-09-23

BRQC decryption computes v-u*y using private y and the public ciphertext (src/brqc.c:277-288). The Gabidulin decoder chooses pivot next from discrepancies in that word, then uses next as the load/store index of u0 and u1 (src/gabidulin.c:185-201). Those addresses vary with a secret-key-derived intermediate. The final KEM ciphertext comparison is masked, but it executes after this leakage. No complete key recovery or remote timing channel is demonstrated.

Reproducing

Commands below run in a checkout of the ngcc-harness repository with the candidate built (see its README).

Inspect src/kem.c:214, src/brqc.c:277-288, and src/gabidulin.c:185-201 under Implementations/Reference_Implementation/BRQC-128/; the same pivot code is present in BRQC-256/512. See constant_time.md for the fuller trace.