Paper 2026/208

eVer: Universal and Automated Verification of Side-Channel Security for Additive, Inner Product, Polynomial and General Code-Based Masking

Marc Gourjon, Max Planck Institute for Security and Privacy
Maximilian Orlt, Université catholique de Louvain
Pajam Pauls, University of Luebeck
Alexander Treff, University of Luebeck
Abstract

Automated verification of side-channel security is essential as countermeasures and protected schemes grow in complexity, and as developers increasingly rely on LLMs to generate security-critical code. In these settings, independent verification serves as a dependable security check, assuring the absence of security vulnerabilities. However, existing verification tools support only a narrow class of masking countermeasures due to fundamental technical limitations. For example, current tools fail to verify many instances of masking countermeasures, as well as entire classes of polynomial, inner-product, or code-based masking schemes in general. These practical countermeasures and schemes are particularly interesting as many of them offer stronger resistance to practical side-channel attacks, yet they remain out of reach of formal verification. We close this gap with a sound, field-agnostic verification approach that, for the first time, automatically checks standard side-channel security notions for all common masking schemes, including polynomial, inner-product, and all variants of code-based masking. In addition to addressing the inherently distinct algebraic structure of these schemes, our method relies on a new proof rule within a general proof system for establishing the joint probabilistic independence of expressions. We implement our approach in the tool eVer and evaluate it on masked algorithms previously beyond the reach of automated verification, including BGW, LaOla, inner-product, and general code-based-masked multiplication algorithms.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
formal verificationlanguage-based securityside-channelmaskingprobabilistic equivalence
Contact author(s)
marc gourjon @ mpi-sp org
maximilian orlt @ uclouvain be
p pauls @ uni-luebeck de
a treff @ uni-luebeck de
History
2026-02-11: approved
2026-02-09: received
See all versions
Short URL
https://ia.cr/2026/208
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/208,
      author = {Marc Gourjon and Maximilian Orlt and Pajam Pauls and Alexander Treff},
      title = {{eVer}: Universal and Automated Verification of Side-Channel Security for Additive, Inner Product, Polynomial and General Code-Based Masking},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/208},
      year = {2026},
      url = {https://eprint.iacr.org/2026/208}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.