Side-Channel-Resistant Post-Quantum Digital Signatures with Verkle Trees, Lattice-Based Vector Commitments, and Quantum True Random Number Generators
Maksim Iavich1, Nursulu Kapalova2, Kunbolat Algazy2,*
1 Department of Computer Science, Caucasus University, Tbilisi, Georgia
2 Information Security Laboratory, Institute of Information and Computational Technologies, Almaty, Kazakhstan
* Corresponding Author: Kunbolat Algazy. Email:
Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.085904
Received 20 May 2026; Accepted 14 July 2026; Published online 03 August 2026
Abstract
Lattice-based post-quantum cryptographic standards such as Module-Lattice Key Encapsulation Mechanism (ML-KEM) and Module-Lattice-Based Digital Signature Algorithm (ML-DSA) have demonstrated documented susceptibility to power-based side-channel attacks even when protected by higher-order arithmetic masking. Concurrently, hash-based and Verkle-tree digital signature schemes lack a systematic analysis of their physical-layer attack surface. This paper closes both gaps by introducing a Verkle-tree digital signature scheme incorporating multiple complementary countermeasures: (i) arithmetic masking of lattice-based Short Integer Solution (SIS) vector commitments, (ii) a counter-mode deterministic random bit generator (CTR_DRBG) seeded by a hardware quantum random number generator (QRNG), and (iii) an implementation framework experimentally validated on ChipWhisperer-Nano and ChipWhisperer-Husky embedded platforms. We leverage ID Quantique Quantis PCIe, ID Quantique Quantum Appliance, and CryptoLabs USB QRNG modules as entropy sources; their certified output distributions are characterized and formally incorporated into the key-generation security proof. We analyze the susceptibility of existing post-quantum lattice schemes to correlation power analysis (CPA), higher-order CPA (HOCPA), and single-trace soft-analytical attacks (SASCA), and we qualitatively discuss why deep-learning side-channel attacks (DLSCA) face additional structural challenges against our Verkle-SIS construction. We demonstrate that the structural properties of Verkle trees, combined with on-demand key generation and QRNG-seeded mask refreshing, measurably reduce the physical attack surface compared with standard NTT-based polynomial multiplication targets. Full Existential Unforgeability under Chosen Message Attack (EUF-CMA) security is proven in the quantum random oracle model (QROM) under the SIS hardness assumption. Our ChipWhisperer measurements confirm that first- through third-order CPA attacks against the SIS commitment step require at least
23×103 traces to exceed a 50% success rate, compared with 700–2400 traces sufficient to break equivalently masked Dilithium implementations. While QRNG seeding provides measurable improvements in mask-refreshing quality over classical hardware entropy sources, it is one component of a layered protection strategy and does not by itself guarantee side-channel resistance.
Keywords
Post-quantum cryptography; side-channel analysis; Verkle tree; lattice-based vector commitments; quantum random number generator; ChipWhisperer; masking; correlation power analysis; CTR_DRBG; EUF-CMA