Paper 2026/2248

ML-DSA masking sweetened with SUCRE: Shuffle-and-Unmask Countermeasure for REjection sampling

Sonia Belaïd, CryptoExperts
Ryad Benadjila, CryptoExperts
Julien Devevey, ANSSI
Morgane Guerreau, PQShield
Thomas Legavre, ANSSI, Thales, Sorbonne University, CNRS, LIP6
Ange Martinelli, ANSSI
Thomas Ricosset, Thales
Matthieu Rivain, CryptoExperts
Mélissa Rossi, CryptoExperts
Abstract

We present SUCRE, a novel countermeasure designed to physically protect the rejection sampling step of ML-DSA, one of the post-quantum signature schemes standardized by NIST. At the core of SUCRE is a masking gadget that securely unmasks a vector while simultaneously applying a random permutation of its coefficients. This lightweight mechanism preserves the vector’s infinity norm, enabling rejection sampling to proceed as usual without requiring any complex mask conversions. We formally prove that a $d$-probing adversary can learn at most some permuted rejected values---information which, we show, should remain insufficient to endanger the security of the signature scheme. This security argument relies on a new variant of the Module Learning with Rounding (MLWR) assumption, for which we provide a dedicated concrete security analysis to assess its hardness relative to the standard MLWR assumption. Our implementation of SUCRE achieves a significant performance improvement over previous masked non-bitsliced implementations of rejection sampling---delivering four to six times faster execution than Coron et al. (TCHES 2024)---albeit at the cost of increased memory usage. Since the rejection step accounts for approximately 25% of the total runtime in masked ML-DSA implementations, and given the expected adoption of ML-DSA on embedded platforms, this speedup could significantly enhance efficiency in real-world applications.

Note: This version of the article corrects an issue in the definition of the πnt-MLWR assumption, which is discussed in Section 1.4.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
A minor revision of an IACR publication in TCHES 2026
DOI
https://doi.org/10.46586/tches.v2026.i1.618-659
Keywords
ML-DSADilithiumMaskingModule Learning With RoundingSCA countermeasureLatticesPermutation
Contact author(s)
sonia belaid @ cryptoexperts com
ryad benadjila @ cryptoexperts com
julien devevey @ ssi gouv fr
morgane guerreau @ pqshield com
thomas legavre @ lip6 fr
ange martinelli @ ssi gouv fr
thomas ricosset @ thalesgroup com
matthieu rivain @ cryptoexpert com
melissa rossi @ cryptoexpert com
History
2026-09-30: approved
2026-09-28: received
See all versions
Short URL
https://ia.cr/2026/2248
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2248,
      author = {Sonia Belaïd and Ryad Benadjila and Julien Devevey and Morgane Guerreau and Thomas Legavre and Ange Martinelli and Thomas Ricosset and Matthieu Rivain and Mélissa Rossi},
      title = {{ML}-{DSA} masking sweetened with {SUCRE}: Shuffle-and-Unmask Countermeasure for {REjection} sampling},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2248},
      year = {2026},
      doi = {https://doi.org/10.46586/tches.v2026.i1.618-659},
      url = {https://eprint.iacr.org/2026/2248}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.