Side-Channel Masking with Pseudo-Random Generator
Jean-Sébastien Coron, Aurélien Greuet, Rina Zeitoun
Abstract
High-order masking countermeasures against side-channel attacks usually require plenty of randomness during their execution. For security against t probes, the classical ISW countermeasure requires O(t^2 s) random bits, where s is the circuit size. However running a True Random Number Generator (TRNG) can be costly in practice and become a bottleneck on embedded devices. In [IKL+13] the authors introduced the notion of robust pseudo-random number generator (PRG), which must remain secure even against an adversary who can probe at most t wires. They showed that when embedding a robust PRG within a private circuit, the number of random bits can be reduced to O(t^4), that is independent of the circuit size s (up to a logarithmic factor). Using bipartite expander graphs, this can be further reduced to O(t^(3+eps)); however the resulting construction is unpractical.
In this paper we describe a practical construction where the number of random bits is only O(t^2) for security against t probes, without expander graphs; moreover the running time of each pseudo-random generation goes down from O(t^4) to O(t). Our technique consists in using multiple independent PRGs instead of a single one. We show that for ISW circuits, the robustness property of the PRG is not required anymore, which leads to simple and efficient constructions. For example, for AES we only need 48 bytes of randomness to get second-order security (t=2), instead of 2880 in the original Rivain-Prouff countermeasure; when implemented on an ARM-based embedded device with a relatively slow TRNG, we obtain a 50% speed-up compared to Rivain-Prouff.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a738068e-7d84-4efd-9e24-aecb51458f16Cited by top-tier papers4
- Second-Order Low-Randomness d + 1 Hardware Sharing of the AESSiemen Dhooghe, Aein Rezaei Shahmirzadi, Amir MoradiCCS 2022 · 9 citations
- Tight Bounds on the Randomness Complexity of Secure Multiparty ComputationVipul Goyal, Yuval Ishai, Yifan SongCRYPTO 2022 · 2 citations
- Amortizing Randomness Cost: Efficient Masked Implementation of SDitH Signatures with Common SharesGuowei Liu, Weijia Wang, Lixuan Wu, Chaoran Wang et al.USENIX Security 2026
- microSCALE: Static Analysis for Microarchitectural Side-channel Leakage EvaluationAkshay Kumar E, Pranav Krishna N, Annapurna Valiveti, Pallavi Borkar et al.USENIX Security 2026
Related papers
- Secure Wire Shuffling in the Probing ModelJean-Sébastien Coron, Lorenzo SpignoliCRYPTO 2021 · 13 citations
- Private Circuits with Quasilinear RandomnessVipul Goyal, Yuval Ishai, Yifan SongEUROCRYPT 2022 · 4 citations
- Random Probing Security: Verification, Composition, Expansion and New ConstructionsSonia Belaïd, Jean-Sébastien Coron, Emmanuel Prouff, Matthieu Rivain et al.CRYPTO 2020 · 30 citations
- PERSEUS - Probabilistic Evaluation of Random Probing SEcurity Using Efficient SamplingSonia Belaïd, Gaëtan CassiersEUROCRYPT 2026
- On the Power of Expansion: More Efficient Constructions in the Random Probing ModelSonia Belaïd, Matthieu Rivain, Abdul Rahman TalebEUROCRYPT 2021 · 22 citations
