Effective and Efficient Masking with Low Noise Using Small-Mersenne-Prime Ciphers
Loïc Masure, Pierrick Méaux, Thorben Moos, François-Xavier Standaert
Abstract
Embedded devices used in security applications are natural targets for physical attacks. Thus, enhancing their side-channel resistance is an important research challenge. A standard solution for this purpose is the use of Boolean masking schemes, as they are well adapted to current block ciphers with efficient bitslice representations. Boolean masking guarantees that the security of an implementation grows exponentially in the number of shares under the assumption that leakages are sufficiently noisy (and independent). Unfortunately, it has been shown that this noise assumption is hardly met on low-end devices. In this paper, we therefore investigate techniques to mask cryptographic algorithms in such a way that their resistance can survive an almost complete lack of noise. Building on seed theoretical results of Dziembowski et al., we put forward that arithmetic encodings in prime fields can reach this goal. We first exhibit the gains that such encodings lead to thanks to a simulated information theoretic analysis of their leakage (with up to six shares). We then provide figures showing that on platforms where optimized arithmetic adders and multipliers are readily available (i.e., most MCUs and FPGAs), performing masked operations in small to medium Mersenne-prime fields as opposed to binary extension fields will not lead to notable implementation overheads. We compile these observations into a new AES-like block cipher, called AES-prime, which is well-suited to illustrate the remarkable advantages of masking in prime fields. We also confirm the practical relevance of our findings by evaluating concrete software (ARM Cortex-M3) and hardware (Xilinx Spartan-6) implementations. Our experimental results show that security gains over Boolean masking (and, more generally, binary encodings) can reach orders of magnitude despite the same amount of information being leaked per share.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 944ccdbc-aa9d-426b-915f-8996f050debfCited by top-tier papers4
- The Algebraic FreeLunch: Efficient Gröbner Basis Attacks Against Arithmetization-Oriented PrimitivesAugustin Bariant, Aurélien Boeuf, Axel Lemoine, Irati Manterola Ayala et al.CRYPTO 2024 · 17 citations
- Connecting Leakage-Resilient Secret Sharing to Practice: Scaling Trends and Physical Dependencies of Prime Field MaskingSebastian Faust, Loïc Masure, Elena Micheli, Maximilian Orlt et al.EUROCRYPT 2024 · 8 citations
- Generalized Feistel Ciphers for Efficient Prime Field MaskingLorenzo Grassi, Loïc Masure, Pierrick Méaux, Thorben Moos et al.EUROCRYPT 2024 · 4 citations
- On Borrowed Time - Preventing Static Side-Channel AnalysisRobert Dumitru, Thorben Moos, Andrew Wabnitz, Yuval YaromNDSS 2025
Builds on5
- Strong Non-Interference and Type-Directed Higher-Order MaskingGilles Barthe, Sonia Belaïd, François Dupressoir, Pierre-Alain Fouque et al.CCS 2016 · 302 citations
- On a Generalization of Substitution-Permutation Networks: The HADES Design StrategyLorenzo Grassi, Reinhard Lüftenegger, Christian Rechberger, Dragos Rotaru et al.EUROCRYPT 2020 · 77 citations
- Ciminion: Symmetric Encryption Based on Toffoli-Gates over Large Finite FieldsChristoph Dobraunig, Lorenzo Grassi, Anna Guinet, Daniël KuijstersEUROCRYPT 2021 · 64 citations
- Real-World Snapshots vs. Theory: Questioning the t-Probing Security ModelThilo Krachenfels, Fatemeh Ganji, Amir Moradi, Shahin Tajik et al.S&P 2021 · 42 citations
- On the Success Rate of Side-Channel Attacks on Masked Implementations: Information-Theoretical Bounds and Their Practical UsageAkira Ito, Rei Ueno, Naofumi HommaCCS 2022 · 18 citations
Related papers
- A Formal Security Proof of Masking - Reduction from Strong Noisy Leakage to Probing Model Without Random Probing and Application to LR PrimitiveRei Ueno, Akiko Inoue, Kazuhiko Minematsu, Akira Ito et al.CRYPTO 2026
- A Thorough Evaluation of RAMBAMDaniel Lammers, Amir Moradi, Nicolai Müller, Aein Rezaei ShahmirzadiCCS 2023 · 1 citation
- Prouff and Rivain's Formal Security Proof of Masking, Revisited - Tight Bounds in the Noisy Leakage ModelLoïc Masure, François-Xavier StandaertCRYPTO 2023 · 10 citations
- From Random Probing to Noisy Leakages Without Field-Size DependenceGianluca Brian, Stefan Dziembowski, Sebastian FaustEUROCRYPT 2024 · 6 citations
- Mode-Level vs. Implementation-Level Physical Security in Symmetric Cryptography - A Practical Guide Through the Leakage-Resistance JungleDavide Bellizia, Olivier Bronchain, Gaëtan Cassiers, Vincent Grosso et al.CRYPTO 2020 · 38 citations
