Bypassing the Random-Probing Model in Masking Security Proofs
Julien Béguinot, Gianluca Brian, Loïc Masure
Abstract
Masking, i.e., computing over secret-shared data, is one of the main counter-measures against side-channel analysis, provably secure in the standard noisy-leakage model. However, all the state-of-the-art security proofs rely on a reduction to a more abstract model called random probing (Eurocrypt’14). As a result, the noise requirements of such proofs must scale with the field size of the circuit which, beyond not reflecting real-world physics of target devices, is often prohibitive, especially in the post-quantum era. That is why it is critical to find alternative strategies to the reduction to the random-probing model. In this paper, we establish for the first time a masking security proof bypassing this reduction, answering positively to the above question. Contrary to the common belief that directly working in the noisy-leakage model is not convenient, we show how to reach this goal by leveraging an extension of the Xor lemma. We also show how to leverage the IOS framework (CHES’21) in order to derive composable security directly in the noisy-leakage model. As a result, our bound relies on relaxed noise requirements characterized in a weaker metric than the so far state of the art (Crypto’24, ’19). Moreover, our new proof strategy allows us to derive a security bound for circuits masked with the first-order ISW compiler, for which the optimal noise requirement scales as , whereas proofs using the random-probing model work in a regime of . The latter contribution illustrates how some current design choices for masked implementations could be concretely affected: we exhibit two exemplary masked implementations such that the former one is more secure in the (more abstract) random-probing model, whereas the latter one is more secure in the (more realistic) noisy-leakage model.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d2f725d4-54d8-4483-a71f-25466cd8abc8Builds on18
- Random Probing Security: Verification, Composition, Expansion and New ConstructionsSonia Belaïd, Jean-Sébastien Coron, Emmanuel Prouff, Matthieu Rivain et al.CRYPTO 2020 · 30 citations
- Leakage-Resilience of the Shamir Secret-Sharing Scheme Against Physical-Bit LeakagesHemanta K. Maji, Hai H. Nguyen, Anat Paskin-Cherniavsky, Tom Suad et al.EUROCRYPT 2021 · 27 citations
- On the Power of Expansion: More Efficient Constructions in the Random Probing ModelSonia Belaïd, Matthieu Rivain, Abdul Rahman TalebEUROCRYPT 2021 · 22 citations
- On the Success Rate of Side-Channel Attacks on Masked Implementations: Information-Theoretical Bounds and Their Practical UsageAkira Ito, Rei Ueno, Naofumi HommaCCS 2022 · 18 citations
- Prouff and Rivain's Formal Security Proof of Masking, Revisited - Tight Bounds in the Noisy Leakage ModelLoïc Masure, François-Xavier StandaertCRYPTO 2023 · 10 citations
Related papers
- From Random Probing to Noisy Leakages Without Field-Size DependenceGianluca Brian, Stefan Dziembowski, Sebastian FaustEUROCRYPT 2024 · 6 citations
- Formal Security Proofs via Doeblin Coefficients: - Optimal Side-Channel Factorization from Noisy Leakage to Random ProbingJulien Béguinot, Wei Cheng, Sylvain Guilley, Olivier RioulCRYPTO 2024 · 7 citations
- Unifying Freedom and Separation for Tight Probing-Secure CompositionSonia Belaïd, Gaëtan Cassiers, Matthieu Rivain, Abdul Rahman TalebCRYPTO 2023 · 8 citations
- Tighter Security Notions for a Modular Approach to Private CircuitsBohan Wang, Juelin Zhang, Yu Yu, Weijia WangEUROCRYPT 2025 · 2 citations
- INDIANA - Verifying (Random) Probing Security Through Indistinguishability AnalysisChristof Beierle, Jakob Feldtkeller, Anna Guinet, Tim Güneysu et al.EUROCRYPT 2025 · 2 citations
