Sep 2026· IACR Transactions on Cryptographic Hardware and Embedded Systems· 0 citations· 20 references
TL;DR
This work proposes CCHPC1.1, an arbitrary-order masked gadget construction that improves Constant-Cycle Hardware Private Circuits (CCHPC) while preserving security in the Robust but Relaxed (RR) d-probing model and under the Probe- Isolating Non-Interference (PINI) composability notion.
Abstract
Boolean masking is a widely used countermeasure to protect hardware implementations against side-channel attacks. However, combining security with low latency remains challenging, since in many composed masked designs the latency increases with the number of cascaded non-linear operations. Constant-cycle masking schemes address this limitation by maintaining a fixed evaluation latency for a given security order d, independent of the number of non-linear functions. In this work, we propose CCHPC1.1, an arbitrary-order masked gadget construction that improves Constant-Cycle Hardware Private Circuits (CCHPC) while preserving security in the Robust but Relaxed (RR) d-probing model and under the Probe- Isolating Non-Interference (PINI) composability notion. Building on these gadget-level improvements, we further propose architecture-level optimizations that reduce the overall costs of Dual-Rail Pre-charge (DRP) logic in constant-cycle schemes, namely LUT-based Masked Dual-Rail with Pre-charge Logic (LMDPL) and CCHPC. We integrate these optimizations into a low-latency Advanced Encryption Standard (AES) core with 10+d clock cycles of total latency by extending the existing duality concept into duality+, enabling consecutive evaluation cycles at reduced area cost. Overall, our optimized design reduces the area of this low-latency cipher core by at least 44.98% for first-order security, with increasing area savings for higher security orders.
Masking is an essential countermeasure against side-channel attacks, yet implementing secure and low-latency hardware masking remains challenging. In particular, although OPINI provides strong composability guarantees for single-cycle iterative architectures, the prior low-latency OPINI gadget, HPC4, is limited to two-...
Li-Xuan Wu, Yan-Hong Fan, Guo-Wei Liu et al.· IACR Transactions on Cryptog...· 0 citations
With the widespread adoption of Field Programmable Gate Arrays (FPGAs) in security-critical industries such as defense and telecommunications, ensuring the confidentiality of sensitive data processed by these devices has become paramount. Side-Channel Analysis (SCA) poses a significant threat, necessitating the protect...
Nicolai Müller, Daniel Lammers, Simon Osterheider et al.· IACR Transactions on Cryptog...· 0 citations
This work focuses on detecting (low-level) vulnerabilities in masked FPGA designs through experimental and tool-assisted evaluation and shows how to formally abstract, unveil, and mitigate such leakages, thereby enabling a security-aware FPGA design flow that spans from the behavioral to the physical level.
Nicolai Müller, Daniel Lammers, Simon Osterheider et al.· IACR Cryptology ePrint Archi...· 0 citations
Raccoon, presented at CRYPTO 2024, is a provably secure lattice-based signature scheme featuring an O(d log d) masking overhead. Although it did not advance beyond the first-round of NIST’s additional call for post-quantum digital signatures, Raccoon remains a promising candidate due to its low masking overhead and str...
Jun-Hao Huang, Yi-Teng Sun, Ji-Peng Zhang et al.· IACR Transactions on Cryptog...· 0 citations
With the continuous advancement of side-channel attack techniques, the demand for high-order masking has been steadily increasing. However, as the masking order grows, the area overhead quickly becomes a critical bottleneck for cryptographic primitives in the IoT environment. Classical arbitrary-order masking schemes,...
Chao-Ran Wang, Mei-Qin Wang, Li-Xuan Wu et al.· IACR Transactions on Cryptog...· 0 citations