Paper 2023/1220

Advances in Reed-Solomon Code-Based Masking and Application to ML-KEM

Pierre-Augustin Berthet, Télécom Paris, Hensoldt SAS France
Yoan Rougeolle, Hensoldt SAS France
Cédric Tavernier, Hensoldt SAS France
Laurent Sauvage, Télécom Paris
Abstract

Physical attacks such as Side-Channel Analysis (SCA) or Fault Injection Attacks (FIA) can recover sensitive data from cryptographic primitives otherwise thought theoretically secure. To counter such threats, generic countermeasures such as masking are studied. In this work, we provide some advances on one particular form of masking, Reed-Solomon Code-Based Masking (RS-CBM). Although its application to the AES primitive with Boolean logic has been investigated, we propose arithmetic gadgets and constrained conversions from arithmetic to boolean logic and back. We also investigate Cost-Amortisation (CA), a method to encode several sensitive data into one masked code word, and propose techniques to swap between an un-amortised masking and an amortised one. Security is experimentally verified by performing a Test Vector Leakage Assessment (TVLA) on a SAM4S target thanks to a Chipwhisperer Husky. We also provide formal proofs of security in the SNI model. Finally, we apply our gadgets to a post-quantum Key Encapsulation Mechanism (KEM), ML-KEM. Notably, we propose a full arithmetisation of the masked calculations of the message compression and of the ciphertext comparison of ML-KEM.

Note: Revision 4: Editorial line changed. Focus is now on the contributions regarding Reed-Solomon Code-Based Masking. ML-KEM is used as an application example.

Metadata
Available format(s)
PDF
Publication info
Preprint.
Keywords
Side-Channel AnalysisMaskingReed-Solomon Code-Based MaskingCost-AmortisationPost-Quantum CryptographyML-KEM
Contact author(s)
berthet @ telecom-paris fr
yoan rougeolle @ hensoldt net
cedric tavernier @ hensoldt net
laurent sauvage @ telecom-paris fr
History
2025-08-26: last of 4 revisions
2023-08-11: received
See all versions
Short URL
https://ia.cr/2023/1220
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2023/1220,
      author = {Pierre-Augustin Berthet and Yoan Rougeolle and Cédric Tavernier and Laurent Sauvage},
      title = {Advances in Reed-Solomon Code-Based Masking and Application to {ML}-{KEM}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2023/1220},
      year = {2023},
      url = {https://eprint.iacr.org/2023/1220}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.