Lune

EUROCRYPT2026Top-tier venue

On the Security of Linear Secret Sharing with General Noisy Side-Channel Leakage

Utkarsh Gupta, Hessam Mahdavifar

2026Year
1Citations
1Top-tier citations

Abstract

Secret sharing is a foundational cryptographic primitive for sharing keys in distributed systems. In a classical (n,t)(n,t)-threshold setting, it involves a dealer who has a secret, a set of nn users to whom shares of the secret are sent, and a threshold tt which is the minimum number of shares required to recover the secret. These schemes offer an all-or-nothing security approach where less than tt shares reveal no information about the secret. But these guarantees are threatened by side-channel attacks which can leak partial information from each share. Initiated by Benhamouda et al. (Crypto'18), the security of linear secret sharing schemes has been studied for bounded leakage attack models, which assume that the adversary can leak bounded functions of each share. However, this model does not translate into real-world attacks, as physical side-channels are inherently noisy. The δ\delta-noisy channel model, proposed by Prouff and Rivain (Eurocrypt’13), is a general leakage framework which captures the noisy behavior of side-channels. In this work, we study the security of linear secret sharing schemes with δ\delta-noisy leakage, and show bounds on the mutual information (MI) and statistical bias (ΔTV\Delta^{\mathrm{TV}}) security metrics. Our results are based on the Fourier analytical framework, first used by Benhamouda et al. (Crypto'18), adapted to the δ\delta-noisy leakage model. To give security bounds, we introduce a security parameter η≤min⁡{1,2δ}\eta\le \min{\{1,2\delta\}}, determined by the Fourier linear biases of the posterior distributions of the leaked secret shares. Then, the Poisson summation formula enables us to bound the ratio between the observed leakage for some given secret, and leakage under independence as (1±ηt)(1\pm \eta^t). This is then used to show a) (n,t≥τ(n+1))(n,t \ge \tau (n+1))-threshold schemes over Fq\mathbb{F}_q have at most O(q−t(γ+1−1/τ))\mathcal{O}(q^{-t(\gamma+1-1/\tau)}) leakage, given η≤q−γ\eta \le q^{-\gamma}; and consequently b) for (n,n)(n,n)-threshold schemes the guessing advantage is at most (q−1)⋅ηn≤(q−1)⋅(2δ)n(q-1) \cdot \eta^n \le (q-1)\cdot (2 \delta)^n. This work can be viewed as a next step towards closing the gap between theory and practice in leakage resilient cryptography.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 8e650940-797a-4bd2-af85-46411df46ae6

Cited by top-tier papers1

Ask how each one uses it

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines