Paper 2025/2088

UP TO 50% OFF: Efficient Implementation of Polynomial Masking

Jorge Andresen, University of Luebeck
Paula Arnold, University of Luebeck
Sebastian Berndt, Technische Hochschule Lübeck, University of Luebeck
Thomas Eisenbarth, University of Luebeck
Sebastian Faust, Technical University of Darmstadt
Marc Gourjon, Max Planck Institute for Security and Privacy
Eric Landthaler, University of Luebeck
Elena Micheli, Technical University of Darmstadt
Maximilian Orlt, UCLouvain, Technical University of Darmstadt
Pajam Pauls, University of Luebeck
Kathrin Wirschem, Technical University of Darmstadt
Liang Zhao, Technical University of Darmstadt
Abstract

While passive probing attacks and active fault attacks have been studied for multiple decades, research has only started to consider combined attacks that use both probes and faults relatively recently. During this period, polynomial masking became a promising, provably secure countermeasure to protect cryptographic computations against such combined attacks. Unlike other countermeasures, such as duplicated additive masking, polynomial masking can be implemented using a linear number of shares, as shown by Berndt et al. at CRYPTO '23. Based upon this fact, Arnold et al. noted at CHES '24 that polynomial masking is particularly well-suited for parallel computation. This characteristic is especially effective in scenarios involving multiple circuits with identical structures, such as the 16 SBoxes in AES. Just recently, Faust et al. showed at CHES '25 that one can also incorporate the technique of packed secret sharing into these masking schemes, given that the state-of-the-art polynomial masking scheme is secure against combined attacks. In this work, we present provably secure advancements regarding this state-of-the-art scheme in both computational and randomness efficiency, reducing the randomness complexity by up to 50% and the computational complexity even more by going from a quadratic term to a linear one for many parameters. Moreover, we present the first implementation of a polynomial masking scheme against combined attacks along with an extensive experimental evaluation for a wide range of parameters and configurations as well as a statistical leakage detection to evaluate the security of the implementation on an Arm Cortex-M processor. Our implementation is publicly available to encourage further research in practical combined resilience.

Note: This is the full version.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
A minor revision of an IACR publication in TCHES 2026
DOI
10.46586/tches.v2026.i1.688-731
Keywords
Combined AttacksPolynomial MaskingLeakage and Fault Resilience
Contact author(s)
jorge andresen @ student uni-luebeck de
p arnold @ uni-luebeck de
sebastian berndt @ th-luebeck de
thomas eisenbarth @ uni-luebeck de
sebastian faust @ tu-darmstadt de
marc gourjon @ mpi-sp org
eric landthaler @ student uni-luebeck de
elena micheli @ tu-darmstadt de
maximilian orlt @ uclouvain be
p pauls @ uni-luebeck de
kathrin wirschem @ tu-darmstadt de
liang zhao @ tu-darmstadt de
History
2026-06-08: revised
2025-11-13: received
See all versions
Short URL
https://ia.cr/2025/2088
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2088,
      author = {Jorge Andresen and Paula Arnold and Sebastian Berndt and Thomas Eisenbarth and Sebastian Faust and Marc Gourjon and Eric Landthaler and Elena Micheli and Maximilian Orlt and Pajam Pauls and Kathrin Wirschem and Liang Zhao},
      title = {{UP} {TO} 50% {OFF}: Efficient Implementation of Polynomial Masking},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2088},
      year = {2025},
      doi = {10.46586/tches.v2026.i1.688-731},
      url = {https://eprint.iacr.org/2025/2088}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.