Paper 2026/2015
A Unified Analysis of Refresh Gadgets in the Random Probing Model
Abstract
Masking is a standard countermeasure against side-channel attacks on embedded cryptographic implementations. Its security is commonly analyzed in the random probing model, which offers a useful trade-off between realistic leakage assumptions and tractable security proofs. Recent years have seen the emergence of several masking compilers based on compositional security frameworks such as general/cardinal random probing composability (RPC). Most of these approaches rely on dedicated refresh gadgets whose structure is often tightly coupled to the targeted security analysis. In this work, we investigate the impact of refresh gadgets on the random probing security of masking compilers within the recent general/cardinal RPC frameworks. We formalize two broad families of refresh gadgets, namely direct and zero encoding-based refreshes, define ideal constructions for both families under explicit randomness and uniformity conditions, and extend the compositional analysis of zero encoding-based refreshes. We then introduce an atomic refresh function capturing the core operation underlying most refresh gadgets from the literature. This abstraction allows us to express and analyze existing constructions within a unified framework, derive their cardinal/general RPC envelopes, and obtain analytical formulas for several of them. Finally, we compare ideal and concrete refresh gadgets on masked implementations of AES and Raccoon. Our results provide a systematic comparison of the security-complexity trade-offs achieved by current refresh strategies.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- A major revision of an IACR publication in ASIACRYPT 2026
- Keywords
- MaskingRandom Probing SecurityRefresh Gadgets
- Contact author(s)
-
sonia belaid @ cryptoexperts com
victor normand @ cryptoexperts com
matthieu rivain @ cryptoexperts com - History
- 2026-09-14: approved
- 2026-09-14: received
- See all versions
- Short URL
- https://ia.cr/2026/2015
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2015,
author = {Sonia Belaïd and Victor Normand and Matthieu Rivain},
title = {A Unified Analysis of Refresh Gadgets in the Random Probing Model},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2015},
year = {2026},
url = {https://eprint.iacr.org/2026/2015}
}