USENIX Security2026Top-tier venue
Amortizing Randomness Cost: Efficient Masked Implementation of SDitH Signatures with Common Shares
Guowei Liu, Weijia Wang, Lixuan Wu, Chaoran Wang, Yanhong Fan, Jinliang Wang, Meiqin Wang
Abstract
MPC-in-the-Head (MPCitH) signatures are attractive for postquantum deployment, but they are structurally vulnerable to side-channel leakage: verification opens almost all simulated views, so any leakage correlated with the remaining unopened view(s) can be amplified and exploited to recover the witness. Among the MPCitH-based signature candidates considered in NIST's additional-signature round, Syndrome-Decodingin-the-Head (SDitH)-Hypercube is particularly susceptible to this concern, since its signing process combines: (i) offline last-party completion involving nonlinear arithmetic computations, (ii) online Baum-Nof (BN) arithmetic checking, and (iii) Keccak sponge calls that generate or absorb secretbearing values.
To the best of our knowledge, this is the first protocolcompatible masked implementation-level protection architecture for SDitH-Hypercube on Cortex-M4. Our implementation combines three techniques, each protecting one attackcritical hotspot: (i) Common Shares to amortize the masking randomness required by masked multiplications in the offline phase, (ii) a Sec/Pub typing discipline that reconstructs transcript-public and verifier-reconstructible values early to avoid costly Sec×Sec gadgets in the online BN kernels, and (iii) selective masked Keccak backends applied only to secretbearing sponge call sites.
On the L1 parameter set, Common Shares reduces arithmetic masking randomness from 8.37 KiB/signature of the Strong Non-Interference (SNI) profile to 16 B/signature, while the Sec/Pub-typed optimization removes 3,264 B/signature from the online BN kernels. When Keccak is masked, masking randomness is dominated by the sponge: 41,118.75 KiB/signature with DOM-Keccak and 82,237.50 KiB/signature with SNI-Keccak, motivating selective masked hashing and tunable backends. We implement a low-stack reference signer and all protected signers on Cortex-M4. Across protected profiles, signing takes 913.7-1,542.0 Mcycles (1.84×-3.10× over the * Corresponding Author. reference), and fits within 155.6 KiB flash, 136.7 KiB static RAM, and 7.96 KiB signing stack. A 1M-trace first-order fixed-vs-random Test Vector Leakage Assessment (TVLA) experiment on Cortex-M4 no longer detects the previously observed leakage peaks after protection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on4
- Strong Non-Interference and Type-Directed Higher-Order MaskingGilles Barthe, Sonia Belaïd, François Dupressoir, Pierre-Alain Fouque et al.CCS 2016 · 302 citations
- Syndrome Decoding in the Head: Shorter Signatures from Zero-Knowledge ProofsThibauld Feneuil, Antoine Joux, Matthieu RivainCRYPTO 2022 · 73 citations
- Side-Channel Masking with Pseudo-Random GeneratorJean-Sébastien Coron, Aurélien Greuet, Rina ZeitounEUROCRYPT 2020 · 29 citations
- SNI-in-the-head: Protecting MPC-in-the-head Protocols against Side-channel AnalysisOkan Seker, Sebastian Berndt, Luca Wilke, Thomas EisenbarthCCS 2020
Related papers
- On Round Elimination for Special-Sound Multi-round Identification and the Generality of the Hypercube for MPCitHAndreas Hülsing, David Joseph, Christian Majenz, Anand Kumar NarayananCRYPTO 2024 · 2 citations
- The Return of the SDitHCarlos Aguilar Melchor, Nicolas Gama, James Howe, Andreas Hülsing et al.EUROCRYPT 2023 · 40 citations
- AIM: Symmetric Primitive for Shorter Signatures with Stronger SecuritySeongkwang Kim, Jincheol Ha, Mincheol Son, ByeongHak Lee et al.CCS 2023 · 19 citations
- Short Signatures from Regular Syndrome Decoding in the HeadEliana Carozza, Geoffroy Couteau, Antoine JouxEUROCRYPT 2023 · 25 citations
- Accelerating SLH-DSA by Two Orders of Magnitude with a Single Hash UnitMarkku-Juhani O. SaarinenCRYPTO 2024 · 18 citations
