Paper 2025/2199
A Formal Security Proof of Masking: Reduction from Strong Noisy Leakage to Probing Model without Random Probing and Application to LR Primitive
Abstract
This paper provides upper bounds on the success rate (SR) of side-channel attacks (SCAs) on masked implementations. We present a formal security proof of additive masking over any finite abelian group—including Boolean and arithmetic maskings—through new reductions from strong noisy leakage (SNL) to the probing model. Unlike existing proofs relying on noisy leakage (NL) and random probing (RP), our proof introduces a novel security notion named leakage energy (LE), which enables a stronger bound. Our proof reveals the necessary and sufficient condition for asymptotic security of additive masking in both the NL and mutual information frameworks, which includes a resolution to an open problem in TCC 2016. Our claims are validated through numerical evaluations. As an application of our theorems, we propose a binary block-cipher based leakage-resilient primitive based on a variant of XEX, which claims $d$-th order SCA security of arithmetic masking by design under some assumptions, enabling efficient OCB-style authenticated encryption with implementation cost of $O(d)$.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- A minor revision of an IACR publication in CRYPTO 2026
- DOI
- 10.1007/978-3-032-35415-0_11
- Keywords
- Boolean maskingArithmetic maskingProbing modelNoisy leakageMutual informationLeakage resilienceXEX
- Contact author(s)
-
ueno rei 2e @ kyoto-u ac jp
a_inoue @ nec com
k-minematsu @ nec com
akira ito b1 @ tohoku ac jp
naofumi homma c8 @ tohoku ac jp - History
- 2026-08-13: last of 7 revisions
- 2025-12-04: received
- See all versions
- Short URL
- https://ia.cr/2025/2199
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/2199,
author = {Rei Ueno and Akiko Inoue and Kazuhiko Minematsu and Akira Ito and Naofumi Homma},
title = {A Formal Security Proof of Masking: Reduction from Strong Noisy Leakage to Probing Model without Random Probing and Application to {LR} Primitive},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2199},
year = {2025},
doi = {10.1007/978-3-032-35415-0_11},
url = {https://eprint.iacr.org/2025/2199}
}