Skip to content
Open access

Area Efficiency in Constant-Cycle Schemes

Sep 2026 · IACR Transactions on Cryptographic Hardware and Embedded Systems · 0 citations · 20 references

TL;DR

This work proposes CCHPC1.1, an arbitrary-order masked gadget construction that improves Constant-Cycle Hardware Private Circuits (CCHPC) while preserving security in the Robust but Relaxed (RR) d-probing model and under the Probe- Isolating Non-Interference (PINI) composability notion.

Abstract

Boolean masking is a widely used countermeasure to protect hardware implementations against side-channel attacks. However, combining security with low latency remains challenging, since in many composed masked designs the latency increases with the number of cascaded non-linear operations. Constant-cycle masking schemes address this limitation by maintaining a fixed evaluation latency for a given security order d, independent of the number of non-linear functions. In this work, we propose CCHPC1.1, an arbitrary-order masked gadget construction that improves Constant-Cycle Hardware Private Circuits (CCHPC) while preserving security in the Robust but Relaxed (RR) d-probing model and under the Probe- Isolating Non-Interference (PINI) composability notion. Building on these gadget-level improvements, we further propose architecture-level optimizations that reduce the overall costs of Dual-Rail Pre-charge (DRP) logic in constant-cycle schemes, namely LUT-based Masked Dual-Rail with Pre-charge Logic (LMDPL) and CCHPC. We integrate these optimizations into a low-latency Advanced Encryption Standard (AES) core with 10+d clock cycles of total latency by extending the existing duality concept into duality+, enabling consecutive evaluation cycles at reduced area cost. Overall, our optimized design reduces the area of this low-latency cipher core by at least 44.98% for first-order security, with increasing area savings for higher security orders.

Read PDF

Similar papers

Open access Sep 2026

Low-Latency Low-Randomness First-Order OPINI Gadgets and Their Formal Verification

Masking is an essential countermeasure against side-channel attacks, yet implementing secure and low-latency hardware masking remains challenging. In particular, although OPINI provides strong composability guarantees for single-cycle iterative architectures, the prior low-latency OPINI gadget, HPC4, is limited to two-...

Li-Xuan Wu, Yan-Hong Fan, Guo-Wei Liu et al. · 0 citations
Open access Sep 2026

Coupling Leakage in Theory and Practice

With the widespread adoption of Field Programmable Gate Arrays (FPGAs) in security-critical industries such as defense and telecommunications, ensuring the confidentiality of sensitive data processed by these devices has become paramount. Side-Channel Analysis (SCA) poses a significant threat, necessitating the protect...

Nicolai Müller, Daniel Lammers, Simon Osterheider et al. · 0 citations
2026

Coupling Leakage in Theory and Practice - Unveiling (Post-PnR) Security Flaws in Masked FPGA-Mapped Designs

This work focuses on detecting (low-level) vulnerabilities in masked FPGA designs through experimental and tool-assisted evaluation and shows how to formally abstract, unveil, and mitigate such leakages, thereby enabling a security-aware FPGA design flow that spans from the behavioral to the physical level.

Nicolai Müller, Daniel Lammers, Simon Osterheider et al. · 0 citations
Open access Sep 2026

Efficient and Compact High-order Masking Raccoon on Memory Constrained Devices

Raccoon, presented at CRYPTO 2024, is a provably secure lattice-based signature scheme featuring an O(d log d) masking overhead. Although it did not advance beyond the first-round of NIST’s additional call for post-quantum digital signatures, Raccoon remains a promising candidate due to its low masking overhead and str...

Jun-Hao Huang, Yi-Teng Sun, Ji-Peng Zhang et al. · 0 citations
Open access Sep 2026

Breaking the Area Limit of Composable Gadgets

With the continuous advancement of side-channel attack techniques, the demand for high-order masking has been steadily increasing. However, as the masking order grows, the area overhead quickly becomes a critical bottleneck for cryptographic primitives in the IoT environment. Classical arbitrary-order masking schemes,...

Chao-Ran Wang, Mei-Qin Wang, Li-Xuan Wu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.