Tighter Security Notions for a Modular Approach to Private Circuits
Bohan Wang, Juelin Zhang, Yu Yu, Weijia Wang
Abstract
To counteract side-channel attacks, a masking scheme splits each intermediate variable into shares and transforms each elementary operation (e.g., field addition and multiplication) to the masked correspondence called gadget, such that intrinsic noise in the leakages renders secret recovery infeasible in practice. A simple and efficient security notion is the probing model ensuring that any shares are independently distributed from the secret input. One requirement of the probing model is the noise in the leakages should increase with the number of shares, largely restricting the side-channel security in the low-noise scenario. Another security notion for masking, called the random probing model, allows each variable to leak with a probability . While this model reflects the physical reality of side channels much better, it brings significant overhead. At Crypto 2018, Ananth et al. proposed a modular approach that can provide random probing security for any security level by expanding small base gadgets with share recursively, such that the tolerable leakage probability decreases with while the security increases exponentially with the recursion depth of expansion. Then, Belaïd et al. provided a formal security definition called Random Probing Expandability (RPE) and an explicit framework using the modular approach to construct masking schemes at Crypto 2020.
In this paper, we investigate how to tighten the RPE definition via allowing the dependent failure probabilities of multiple inputs, which results in a new definition called related RPE. It can be directly used for the expansion of multiplication gates and reduce the complexity of the base multiplication gadget from proposed at Asiacrypt 2021 to and maintain the same security level. Furthermore, we describe a method to expand any gates (rather than only multiplication) with the related RPE gadgets. Besides, we denote another new RPE definition called Multiple inputs RPE used for the expansion of multiple-input gates composed with any gates. Utilizing these methods, we reduce the complexity of 3-share circuit compiler to , where is the size of the unprotected circuit and the protection failure probability of the global circuit is . In comparison, the complexity of the state-of-the-art work, proposed at Eurocrypt 2021, is for the same value of . Additionally, we provide the construction of a 5-share circuit compiler with a complexity .
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6ce40494-c6af-479a-9874-b81ec7fa421eCited by top-tier papers1
Ask how each one uses itRelated papers
- On the Power of Expansion: More Efficient Constructions in the Random Probing ModelSonia Belaïd, Matthieu Rivain, Abdul Rahman TalebEUROCRYPT 2021 · 22 citations
- Random Probing Security: Verification, Composition, Expansion and New ConstructionsSonia Belaïd, Jean-Sébastien Coron, Emmanuel Prouff, Matthieu Rivain et al.CRYPTO 2020 · 30 citations
- New Techniques for Random Probing Security and Application to Raccoon Signature SchemeSonia Belaïd, Matthieu Rivain, Mélissa RossiEUROCRYPT 2025 · 5 citations
- From Random Probing to Noisy Leakages Without Field-Size DependenceGianluca Brian, Stefan Dziembowski, Sebastian FaustEUROCRYPT 2024 · 6 citations
- Formal Security Proofs via Doeblin Coefficients: - Optimal Side-Channel Factorization from Noisy Leakage to Random ProbingJulien Béguinot, Wei Cheng, Sylvain Guilley, Olivier RioulCRYPTO 2024 · 7 citations
