Paper 2026/2015

A Unified Analysis of Refresh Gadgets in the Random Probing Model

Sonia Belaïd, CryptoExperts (France)
Victor Normand, CryptoExperts (France), École Normale Supérieure - PSL
Matthieu Rivain, CryptoExperts (France)
Abstract

Masking is a standard countermeasure against side-channel attacks on embedded cryptographic implementations. Its security is commonly analyzed in the random probing model, which offers a useful trade-off between realistic leakage assumptions and tractable security proofs. Recent years have seen the emergence of several masking compilers based on compositional security frameworks such as general/cardinal random probing composability (RPC). Most of these approaches rely on dedicated refresh gadgets whose structure is often tightly coupled to the targeted security analysis. In this work, we investigate the impact of refresh gadgets on the random probing security of masking compilers within the recent general/cardinal RPC frameworks. We formalize two broad families of refresh gadgets, namely direct and zero encoding-based refreshes, define ideal constructions for both families under explicit randomness and uniformity conditions, and extend the compositional analysis of zero encoding-based refreshes. We then introduce an atomic refresh function capturing the core operation underlying most refresh gadgets from the literature. This abstraction allows us to express and analyze existing constructions within a unified framework, derive their cardinal/general RPC envelopes, and obtain analytical formulas for several of them. Finally, we compare ideal and concrete refresh gadgets on masked implementations of AES and Raccoon. Our results provide a systematic comparison of the security-complexity trade-offs achieved by current refresh strategies.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
A major revision of an IACR publication in ASIACRYPT 2026
Keywords
MaskingRandom Probing SecurityRefresh Gadgets
Contact author(s)
sonia belaid @ cryptoexperts com
victor normand @ cryptoexperts com
matthieu rivain @ cryptoexperts com
History
2026-09-14: approved
2026-09-14: received
See all versions
Short URL
https://ia.cr/2026/2015
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2015,
      author = {Sonia Belaïd and Victor Normand and Matthieu Rivain},
      title = {A Unified Analysis of Refresh Gadgets in the Random Probing Model},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2015},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2015}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.