scieee AI-readable full text Open interactive document viewer

Multimodal IoT Device Authentication using Behavioral and Physical Unclonable Functions and Kyber Public Key Encryption

Román, Roberto; ARJONA, ROSARIO; Baturone, Iluminada

Abstract

Proper device identity management and authentication is a must for many Internet of Things (IoT) applications. Physical Unclonable Functions (PUFs) are a well-known solution for identifying IoT devices. However, they can be attacked using both intrusive and non-intrusive physical attacks. In this work, we propose a multimodal device authentication scheme using Behavioral and Physical Unclonable Functions (BPUFs), which is a more secure option than PUFs. Adequate server-side security is achieved because BPUF responses are processed in the encrypted domain using homomorphic encryption. Furthermore, helper data attacks are avoided and the solution is quantum-safe. The proposal has been evaluated on an ESP32 microcontroller considering the security against false acceptance attacks and the security level of the Kyber public key encryption used. Fixing the first security to more than 192 bits for the behavioral and physical functions, the execution times of the cryptographic operations range from 41.30 to 205.70 ms, working at 160 MHz, with communication bandwidths from 3,840 to 15,680 bytes, and non-volatile memory occupation from 800 to 1,568 bytes.

Full text

Multimodal IoT Device Authentication using Behavioral and Physical Unclonable Functions and Kyber Public Key Encryption Roberto Román, Rosario Arjona, Iluminada Baturone Instituto de Microelectrónica de Sevilla (IMSE-CNM) University of Seville, CSIC Seville, Spain {roman, arjona, lumi}@imse-cnm.csic.es Abstract— Proper device identity management and authentication is a must for many Internet of Things (IoT) applications. Physical Unclonable Functions (PUFs) are a wellknown solution for identifying IoT devices. However, they can be attacked using both intrusive and non-intrusive physical attacks. In this work, we propose a multimodal device authentication scheme using Behavioral and Physical Unclonable Functions (BPUFs), which is a more secure option than PUFs. Adequate server-side security is achieved because BPUF responses are processed in the encrypted domain using homomorphic encryption. Furthermore, helper data attacks are avoided and the solution is quantum-safe. The proposal has been evaluated on an ESP32 microcontroller considering the security against false acceptance attacks and the security level of the Kyber public key encryption used. Fixing the first security to more than 192 bits for the behavioral and physical functions, the execution times of the cryptographic operations range from 41.30 to 205.70 ms, working at 160 MHz, with communication bandwidths from 3,840 to 15,680 bytes, and non-volatile memory occupation from 800 to 1,568 bytes. Keywords—Device authentication, Hardware security, Physical unclonable functions, Behavioral unclonable functions, Post-quantum cryptography, Kyber I. INTRODUCTION Since Internet of Things (IoT) devices have access to sensitive information and can impact their immediate environment, it is critical to properly authenticate them, i.e., verify their identity and know if a rogue device, such as a counterfeit device, is in the field. Physical Unclonable Functions (PUFs) are a well-known solution for device authentication. In PUF circuits, random variations in the manufacturing process of a circuit are mapped into a bit string that can be used as identifier. The number of challengeresponse pairs (CRPs) determines whether a PUF is weak or strong. Weak PUFs can support a relatively small number of CRPs, while strong PUFs can support a much larger number. However, invasive as well as non-invasive attacks are being discovered against physical responses of PUFs [1]-[3]. Thus, an attacker can supplant the identity of the device using a forged response. To remediate this, Behavioral and Physical Unclonable Functions (BPUFs) were introduced in [4]. They use an additional response called behavioral response that is computed using a set of physical responses. They are harder to attack since they use a dynamic behavior of a circuit instead of just the physical response. Hence, BPUFs can be viewed as a good construction for multimodal authentication. Due to the advent of quantum computers, the data interchanged with the device during the authentication process should be protected with quantum-resistant primitives. Regarding public key encryption, Kyber Public Key Encryption (Kyber PKE), whose security is based on the Module Learning With Errors (M-LWE) problem, is very suitable for IoT devices by its performance. The work in [5] proposes a protocol using weak BPUFs with Kyber Key Encapsulation Mechanism (KEM). The behavioral response, besides being obfuscated, is encrypted by the device using the ephemeral key agreed with the remote server after the KEM. The obfuscated behavioral response is obtained by XORing the behavioral response with a pseudorandom string derived from a key reconstructed with a fresh physical response and the helper data stored at enrollment. A problem of this protocol is its vulnerability to helper-data attacks and low server-side security [6]. An interesting homomorphic property of Kyber PKE was introduced in [7]. This property is used in [8] to create a private and unimodal authentication scheme for IoT devices with weak PUFs that does not require helper data and processes sensitive data in an encrypted domain. This paper extends the protocol presented in [8], making it multimodal by using a BPUF. Thus, the solution has higher security, since a behavioral response must be attacked in addition to a physical response. Experimental results are given to illustrate the security against a false acceptance attack and the performance in terms of execution time, bandwidth, and non-volatile memory requirements of the IoT device. The paper is structured as follows. Preliminaries are presented in Section II. Section III presents the proposed solution in this work. Experimental results are shown in Section IV. Finally, Section V concludes the paper. II. PRELIMINARIES Behavioral and Physical Unclonable Functions (BPUFs) were first introduced in [4]. Given a BPUF circuit, two functions are distinguished: the Physical Unclonable Function (PUF) and the Behavioral Unclonable Function (BUF). For the measurement 𝑚, the 𝑏-th bit 𝑢[𝑏] of the physical response 𝑢 is defined as 𝑢  [ 𝑏 ] = 󰇥 1 𝑖𝑓 𝑃𝑈𝐹 𝑢𝑛𝑖𝑡 𝑏 𝑠𝑎𝑡𝑖𝑠𝑓𝑖𝑒𝑠 𝑎 𝑐𝑜𝑛𝑑𝑖𝑡𝑖𝑜𝑛 0 𝑜𝑡 ℎ 𝑒𝑟𝑤𝑖𝑠𝑒 (1) and, given 𝑅+1 physical responses, the 𝑏-th bit 𝑣[𝑏] of the behavioral response 𝑣 is computed as 𝑣  [ 𝑏 ] =  1 𝑖𝑓   𝑢  [ 𝑏 ] ⊕ 𝑢  [ 𝑏 ]  > 0   0 𝑜𝑡 ℎ 𝑒𝑟𝑤𝑖𝑠𝑒 (2) where ⊕ is the XOR operation. In the case of an SRAM BPUF, the physical response is formed by the start-up values of a portion of the SRAM, and the behavioral response is formed by measuring the stability of those values after 𝑅 start-ups. Physical and behavioral responses can be used as device identifiers with the tuple 𝐼𝐷=(𝑢,𝑣). In an enrollment phase, a reference physical and behavioral responses 𝑢 and 𝑣 are stored, and, in an authentication phase 𝑖, new responses 𝑢 and 𝑣 are generated and compared with the stored ones. Two physical responses can be compared using the Hamming distance as 𝐻𝐷 ( 𝑢  , 𝑢  ) = 𝐻𝑊 ( 𝑢  ⊕ 𝑢  ) (3) where 𝐻𝑊 is the Hamming weight function. On the other hand, it has been shown in [4] that behavioral responses have a better distinguishability using the Jaccard distance. Since the Hamming weight cannot be computed in the encrypted domain with our proposal, we use an approximated Jaccard distance as 𝐽𝐷  ( 𝑣  , 𝑣  ) = 2 𝐻𝐷 ( 𝑣  , 𝑣  ) ( 𝐻𝐷 ( 𝑣  , 𝑣  ) + 2 𝐺 ) ⁄ (5) where 𝐺 is a constant obtained in a characterization process as the expected Hamming weight of a behavioral response. In the authentication phase, the device identifier is verified if 𝐻𝐷(𝑢,𝑢)≤𝐻𝐷 and 𝐽𝐷(𝑣0,𝑣𝑖)≤𝐽𝐷𝑀𝐴𝑋. The value 𝐻𝐷 is obtained as explained in [8]. To obtain the value of 𝐽𝐷, we first rewrite the expression (5) as 𝐽𝐷  ( 𝑣  , 𝑣  ) = 2 ( 1 + 2 ( 𝐺 / 𝑒 ) ) ⁄ (6) where 𝑒 is the number of errors between 𝑣 and 𝑣. If 𝐸 is the random variable associated with 𝑒, we assume that the probability that a genuine behavioral response contains more than 𝑒 errors is given by 𝑃  ( 𝐸 > 𝑒  ) = 1 −   𝑁 𝑖       𝑝   ( 1 − 𝑝   )    (7) where 𝑁 is the number of bits in the responses and 𝑝 is the bit error probability in the genuine responses, which can be obtained experimentally using the average fractional Hamming distance between the genuine behavioral responses. In this way, 𝑒 can be chosen to achieve 𝑃(𝐸>𝑒)< 𝜖, where 𝜖 is the allowed false rejection rate of the behavioral response, and can be used in (6) to calculate the 𝐽𝐷 value. Given that the attacker can know the Hamming weight of the reference behavioral response 𝑀, the size 𝑁, and the value of 𝐽𝐷, the probability of success of a false acceptance attack is given by a cumulative hypergeometric distribution that is maximum when the Hamming weight of the responses that s/he tries is 𝑛. The details about this attack probability can be seen in [4]. Concerning the preliminaries about the cryptographic operations employed in our proposal, Kyber PKE is defined by key generation, encryption and decryption algorithms. The three algorithms can be found in [9]. The key generation algorithm (𝐾𝑌𝐵𝐸𝑅.𝑃𝐾𝐸.𝑘𝑒𝑦𝑔𝑒𝑛()) generates a secret key 𝑠𝑘=𝒔 and a public key 𝑝𝑘=(𝒕,𝜌). The encryption algorithm (𝐾𝑌𝐵𝐸𝑅.𝑃𝐾𝐸.𝑒𝑛𝑐𝑟𝑦𝑝𝑡(𝑚,𝑝𝑘)) uses the public key 𝑝𝑘 to encrypt a plaintext message 𝑚, and generates a ciphertext 𝑐=(𝒖,𝑣). The message is represented as a polynomial with coefficients in {0,1}. The encryption scheme (𝐾𝑌𝐵𝐸𝑅.𝑃𝐾𝐸.𝑑𝑒𝑐𝑟𝑦𝑝𝑡(𝑐,𝑠𝑘)) takes a ciphertext 𝑐 and the secret key 𝑠𝑘 and returns the message 𝑚. The work in [7] found that the Kyber PKE satisfies the following homomorphic property given two ciphertexts 𝑐 and 𝑐 of two messages 𝑚 and 𝑚: 𝐾𝑌𝐵𝐸𝑅 . 𝑃𝐾𝐸 . 𝑑𝑒𝑐𝑟𝑦𝑝𝑡 ( 𝑃𝑂𝐿𝑌 . 𝑠𝑢𝑏𝑠𝑡𝑟𝑎𝑐𝑡 ( 𝑐  , 𝑐  ) ) = 𝑚  ⊕ 𝑚  (8) where the function 𝑃𝑂𝐿𝑌.𝑠𝑢𝑏𝑠𝑡𝑟𝑎𝑐𝑡(𝑐,𝑐) performs the coefficient-wise subtractions between the ciphertexts, that is, 𝒖𝟏−𝒖𝟐 and 𝑣−𝑣. It is assumed that the ciphertexts are decompressed and the result is recompressed. Thus, with this homomorphic property, an XOR operation between two plaintexts can be performed between two strings in the encrypted domain. III. PROPOSED SOLUTION FOR MULTIMODAL DEVICE AUTHENTICATION A. Assumptions We distinguish three parties in the scheme. One party is the IoT device (DEV) whose authenticity needs to be verified in the field. The other parties are two servers responsible for managing the identity of DEV: the Database Server (DBS), which stores the information needed to authenticate DEV in a private and secure manner, and the Authentication Server (AS), which proves the authenticity of DEV. DBS and AS are considered to behave honestly. We assume that the communication channels are secure between DBS and DEV, AS and DEV, and between DBS and AS. For simplicity, and because we are focusing on device authentication, we will not show this. Also, we assume that DEV has a BPUF, which generates proper physical and behavioral responses. 𝐵𝑃𝑈𝐹.𝑔𝑒𝑡𝑃𝑈𝐹𝑟𝑒𝑠𝑝() and 𝐵𝑃𝑈𝐹.𝑔𝑒𝑡𝐵𝑈𝐹𝑟𝑒𝑠𝑝() are the functions for generating these responses. In general, both responses come from different challenges. Also, DEV should have a True Random Number Generator (TRNG). We assume that AS knows the threshold distance 𝐻𝐷 of the physical response and the threshold distance 𝐽𝐷 of the behavioral response, which is securely provided by the device manufacturer. Also, AS has already executed the Kyber key generation algorithm and has the secret key 𝑆𝐾 and the public key 𝑃𝐾. B. Enrollment phase In the enrollment phase, the identity of DEV is registered by DBS. The enrollment phase is performed only once, and it should be done in a controlled and secure manner. First, DBS gives to DEV the challenges of the physical and behavioral responses (𝑐, 𝑐), the public key 𝑃𝐾, and its identifier 𝐼𝐷, which is chosen by AS. Given the received challenges, DEV generates the physical response 𝑢 and the behavioral response 𝑣. Then, DEV uses the Kyber encryption algorithm and 𝑃𝐾 to encrypt the physical and behavioral responses, resulting in the protected physical response 𝑈 and the protected behavioral response 𝑉. Finally, DEV sends 𝑈 and 𝑉 to DBS to be stored. DEV stores 𝐼𝐷 along with 𝑃𝐾. C. Authentication phase In the authentication phase, DEV is in the field and ready to operate. In this phase, AS wants to verify the identity of DEV for an authentication 𝑖. This is done through the steps shown in Figure 1. Firstly, AS generates a pair of nonces 𝑛 and 𝑛 to guarantee the freshness of the process and to prevent a possible impersonation of DBS and DEV. Then, AS sends to DBS a request to start the authentication phase and the identifier of DEV, 𝐼𝐷. The AS also sends to DEV a request to perform an authentication, 𝐼𝐷 and the nonces 𝑛 and 𝑛. DBS sends to DEV the challenges to the BPUF of the device, 𝑐 and 𝑐. DEV samples a fresh physical response 𝑢 and a fresh behavioral response 𝑣, which are XORed with the nonces 𝑛 and 𝑛, respectively. The values 𝑢⊕𝑛 and 𝑣⊕𝑛 are encrypted using Kyber encryption algorithm, and the public key 𝑃𝐾, resulting in 𝑈 and 𝑉. These values are sent to DBS. Then, DBS performs the 𝑃𝑂𝐿𝑌.𝑠𝑢𝑏𝑠𝑡𝑟𝑎𝑐𝑡 operation between the reference and fresh physical response 𝑈 and 𝑈, and between the reference and fresh behavioral responses 𝑉 and 𝑉. The results are the encrypted differences 𝐷 and 𝐷, which are sent to AS. Finally, AS decrypts the differences, performs the XOR with the nonces, resulting in 𝑑 and 𝑑, and obtains the Hamming distance between 𝑢 and 𝑢, and the approximated Jaccard distance between 𝑣 and 𝑣. These distances are compared with the thresholds 𝐻𝐷 and 𝐽𝐷 to check if the device is successfully authenticated. D. Features of the proposal The device uses two responses to authenticate itself instead of just one, resulting in a stronger authentication. Also, the responses are never seen in plaintext due to the use of homomorphic encryption. So, if the authentication server is attacked, the attacker cannot see the responses directly. In addition, helper-data attacks are completely avoided since no helper data are used in the protocol. Even more, we argue that behavioral responses are more difficult to clone than physical responses using an invasive attack. This is because behavioral responses are sensitive to the reliability of a set of physical responses. If an invasive attack is performed, it would affect the reliability of the circuit, which would change the behavioral response. Also, the proposal is ready for the quantum-era because we use Kyber public key encryption. In addition, a device can use a single CRP to authenticate to many database and authentication servers because the response is never seen in clear and they are unlinkable. [7]. IV. EXPERIMENTAL RESULTS Regarding the experimental results, in this work we focus on the IoT device. A Pycom WiPy 3.0 board with an Espressif ESP32 microcontroller was chosen to evaluate the proposal. The board has 8 MB of external flash memory. The ESP32 microcontroller has 512 kB of internal SRAM. A clock frequency of 160 MHz was chosen for the experiments. The internal TRNG of the ESP32 was used to generate the required random numbers of the proposal. We use the ESP32 internal SRAM as the SRAM BPUF and characterized it by using 25,593 bytes and 7 boards and taking 2000 measurements from each board with a 5-second delay between measurements using the deep sleep mode. The evaluation of the behavioral responses was carried out using three values of 𝑅, 10, 20 and 40, and three different response sizes, 768, 1,024 and 2,048 bits. We evaluated our proposal using the reference implementation of Kyber found in [10]. A. Parameter selection and security evaluation Table I shows the values of the average intra approximated Jaccard distance and the average inter approximated Jaccard distance as a function of the parameter 𝑅 and the size of the behavioral responses. Note that these are the Jaccard approximated distances reformulated in Section II. It can be seen that the size does not significantly affect these values. However, the difference between the average intra and inter distances increases slightly as 𝑅 increases. 𝐺 represents the average Hamming weight in the behavioral responses. The maximum number of allowed errors in an authentication 𝑒 and the threshold 𝐽𝐷 have been evaluated as explained in Section II. They are shown in Table I. It can be seen that 𝑒 is slightly lower as 𝑅 increases. The maximum probability of a successful false acceptance attack, (𝑃𝑟𝑜𝑏.𝑎𝑡𝑡𝑎𝑐𝑘) referred in Section II has been evaluated, adapted to the approximated Jaccard distance used in this paper. The values are also shown in Table I together with the corresponding optimal values that the attacker should select for the Hamming weight of the trial (𝑛) and the lowest number of successes or 1’s that the attacker hit (𝑠) employed to calculate 𝑃𝑟𝑜𝑏.𝑎𝑡𝑡𝑎𝑐𝑘. Bit security, calculated as 𝑙𝑜𝑔(1/𝑃𝑟𝑜𝑏.𝑎𝑡𝑡𝑎𝑐𝑘) is also shown in Table I. These values can be used to select appropriate values of 𝑅 and behavioral response sizes. In this case, if a bit security higher than 192 is desired, the values of 2,048 bits, 1,024 bits and 768 bits are depicted for 𝑅 values of 10, 20 and 40, respectively. For physical responses, the choice of 𝐻𝐷 and the bit security can be seen evaluated in [8]. A size of 512 bits can be Fig. 1. Steps performed at the authentication phase. chosen to achieve a bit security above 192 bits, which should use a value of 56 for 𝐻𝐷. B. Performance of the proposal The performance of the proposal was evaluated as a function of the behavioral response parameter 𝑅 and the Kyber instance. The response sizes were chosen according to the desired bit security of 192 bits for both responses. Of course, this security can be decreased for many applications. Table II shows the results of the communication bandwidth and the execution time of the cryptographic operations of the device. The results are considering both physical and behavioral responses. Bandwidth values range from 3,840 to 15,680 bytes, and cryptographic execution times range from 41.30 to 205.70 ms, depending on the selected 𝑅 and Kyber instance. Higher values are for an 𝑅 value of 10. However, a lower 𝑅 value requires fewer responses to form a behavioral response, thus saving time during the ESP32’s deep sleep. Note that no calculations are performed during deep sleep, so it is not expected to consume much power. Regarding the nonvolatile memory required for the device, it is related to the size of the public key (which is 800, 1,184 or 1,568 bytes), depending on the used Kyber instance. The size of the identifier depends on the application, but it can be of 32 bytes. V. CONCLUSIONS In this work, we propose a multimodal device authentication scheme based on physical and behavioral unclonable functions. The proposal has a very high security not only because the security provided by each response is added but also because the responses are processed in the encrypted domain thanks to the homomorphic encryption. Also, helper-data attacks are avoided. The solution is ready for the quantum era by using Kyber public key encryption scheme. Experimental results on an ESP32 microcontroller show that high security against false acceptance attacks is achieved with low execution times for the cryptographic operations. Concerning non-volatile storage, the requirements are low. ACKNOWLEDGEMENTS This research was conducted thanks to Grants PDC2023– 145873-I00, CPP2022–009796, and PID2023-150809OB-I00 funded by MICIU/AEI/10.13039/ 501100011033 and the “European Union NextGenerationEU/PRTR”, thanks to the LICORICE Project with Grant Agreement No. 101168311 under the EU Horizon Europe, and thanks to the grant USECHIP (TSI-069100-2023-001) of PERTE Chip Chair program funded by European Union – Next Generation EU. The work of Roberto Román was supported by VI Plan Propio de Investigación y Transferencia, Universidad de Sevilla. REFERENCES [1] C. Helfmeier, C. Boit, D. Nedospasov and J. -P. Seifert, “Cloning Physically Unclonable Functions,” in 2013 IEEE International Symposium on Hardware-Oriented Security and Trust (HOST), Austin, TX, USA, 2013, pp. 1-6. [2] C. Helfmeier, C. Boit, D. Nedospasov, S. Tajik and J. -P. Seifert, “Physical vulnerabilities of Physically Unclonable Functions,” in 2014 Design, Automation & Test in Europe Conference & Exhibition (DATE), Dresden, Germany, 2014, pp. 1-4. [3] B. M. S. Bahar Talukder, F. Ferdaus and M. T. Rahman, “MemoryBased PUFs are Vulnerable as Well: A Non-Invasive Attack Against SRAM PUFs,” IEEE Transactions on Information Forensics and Security, vol. 16, pp. 4035-4049, 2021. [4] M. A. Prada-Delgado and I. Baturone, “Behavioral and Physical Unclonable Functions (BPUFs): SRAM Example,” IEEE Access, vol. 9, pp. 23751-23763, 2021. [5] R. Román, R. Arjona and I. Baturone, “Post-quantum Secure Communication with IoT Devices Using Kyber and SRAM Behavioral and Physical Unclonable Functions,” in: Attacks and Defenses for the Internet-of-Things: 5th International Workshop (ADIoT), Springer Nature, Switzerland, 2022, pp. 72–83. [6] T. Becker, “Robust Fuzzy Extractors and Helper Data Manipulation Attacks Revisited: Theory versus Practice,” in IEEE Transactions on Dependable and Secure Computing, vol. 16, no. 5, pp. 783-795, 2019. [7] R. Román, R. Arjona, P. López-González and I. Baturone, “A Quantum-Resistant Face Template Protection Scheme using Kyber and Saber Public Key Encryption Algorithms,” in 2022 International Conference of the Biometrics Special Interest Group (BIOSIG), Darmstadt, Germany, 2022, pp. 1-5. [8] R. Román, R. Arjona and I. Baturone, “A quantum-safe authentication scheme for IoT devices using homomorphic encryption and weak physical unclonable functions with no helper data”, Internet of Things, Elsevier, vol. 28, no. 101389, 2024. [9] J. Bos et al., “CRYSTALS–Kyber: A CCA-secure module-latticebased KEM,” in Proc. IEEE Eur. Symp. Secur. Privacy, Apr. 2018, pp. 353-367. [10] Github, pq-crystals. Accessed: February 12, 2025. [Online]. Available: https://github.com/pq-crystals/kyber TABLE I. PARAMETER SELECTION AND SECURITY EVALUATION (HIGHLIGHTED IN GREY, FOR A BIT SECURITY HIGHER THAN 192) 𝑹 Size (bits) 𝑱𝑫 𝒂𝒑𝒑 , 𝒏𝒕𝒓𝒂               𝑱𝑫 𝒂𝒑𝒑 , 𝒏𝒕𝒆𝒓               𝑮 𝒆 𝑴𝑨𝑿 𝑱𝑫 𝑴𝑨𝑿 𝒏 𝒐𝒑𝒕𝒊𝒎𝒂𝒍 𝒔 𝒂𝒕𝒕𝒂𝒄𝒌 Prob. attack Bit security 10 768 0.3602 0.9206 111.3586 86 0.5571 30 27 3.0160 ‧10 -21 68 1,024 0.3605 0.9208 148.4655 108 0.5334 48 43 2.0526 ‧10 -33 108 2,048 0.3609 0.9212 296.9194 191 0.4867 128 116 4.9130 ‧10 -92 303 20 768 0.2792 0.9026 135.1027 79 0.4525 69 62 4.9149 ‧10 -45 147 1,024 0.2795 0.9028 180.125 99 0.4311 98 89 5.8316 ‧10 -66 216 2,048 0.2797 0.9030 360.2377 174 0.3891 223 204 1.6605 ‧10 -155 514 40 768 0.2256 0.8859 156.3017 74 0.3828 99 90 4.5027 ‧10 -63 207 1,024 0.2257 0.8860 208.3925 92 0.3616 139 127 1.5300 ‧10 -90 298 2,048 0.2259 0.8862 416.7716 161 0.3238 303 279 4.3141 ‧10 -205 678 TABLE II. PERFORMANCE OF THE PROPOSAL 𝑹 Kyber instance Bandwidth (bytes) Exec. times (ms) 10 KYBER512 7,680 82.60 KYBER768 10,880 135.40 KYBER1024 15,680 205.70 20 KYBER512 4,608 49.56 KYBER768 6,528 81.24 KYBER1024 9,408 123.42 40 KYBER512 3,840 41.30 KYBER768 5,440 67.70 KYBER1024 7,840 102.85