High-order masking of NTRU

Jean-Sebastien Coron, University of Luxembourg
François Gérard, University of Luxembourg
Matthias Trannoy, IDEMIA
Rina Zeitoun, IDEMIA

The main protection against side-channel attacks consists in computing every function with multiple shares via the masking countermeasure. While the masking countermeasure was originally developed for securing block-ciphers such as AES, the protection of lattice-based cryptosystems is often more challenging, because of the diversity of the underlying algorithms. In this paper, we introduce new gadgets for the high-order masking of the NTRU cryptosystem, with security proofs in the classical ISW probing model. We then describe the first fully masked implementation of the NTRU Key Encapsulation Mechanism submitted to NIST, including the key generation. To assess the practicality of our countermeasures, we provide a concrete implementation on ARM Cortex-M3 architecture, and eventually a t-test leakage evaluation.

A minor revision of an IACR publication in TCHES 2023
High-order maskinglattice-based cryptographyNTRU
