Paper 2026/2248
ML-DSA masking sweetened with SUCRE: Shuffle-and-Unmask Countermeasure for REjection sampling
Abstract
We present SUCRE, a novel countermeasure designed to physically protect the rejection sampling step of ML-DSA, one of the post-quantum signature schemes standardized by NIST. At the core of SUCRE is a masking gadget that securely unmasks a vector while simultaneously applying a random permutation of its coefficients. This lightweight mechanism preserves the vector’s infinity norm, enabling rejection sampling to proceed as usual without requiring any complex mask conversions. We formally prove that a $d$-probing adversary can learn at most some permuted rejected values---information which, we show, should remain insufficient to endanger the security of the signature scheme. This security argument relies on a new variant of the Module Learning with Rounding (MLWR) assumption, for which we provide a dedicated concrete security analysis to assess its hardness relative to the standard MLWR assumption. Our implementation of SUCRE achieves a significant performance improvement over previous masked non-bitsliced implementations of rejection sampling---delivering four to six times faster execution than Coron et al. (TCHES 2024)---albeit at the cost of increased memory usage. Since the rejection step accounts for approximately 25% of the total runtime in masked ML-DSA implementations, and given the expected adoption of ML-DSA on embedded platforms, this speedup could significantly enhance efficiency in real-world applications.
Note: This version of the article corrects an issue in the definition of the πnt-MLWR assumption, which is discussed in Section 1.4.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- A minor revision of an IACR publication in TCHES 2026
- DOI
- https://doi.org/10.46586/tches.v2026.i1.618-659
- Keywords
- ML-DSADilithiumMaskingModule Learning With RoundingSCA countermeasureLatticesPermutation
- Contact author(s)
-
sonia belaid @ cryptoexperts com
ryad benadjila @ cryptoexperts com
julien devevey @ ssi gouv fr
morgane guerreau @ pqshield com
thomas legavre @ lip6 fr
ange martinelli @ ssi gouv fr
thomas ricosset @ thalesgroup com
matthieu rivain @ cryptoexpert com
melissa rossi @ cryptoexpert com - History
- 2026-09-30: approved
- 2026-09-28: received
- See all versions
- Short URL
- https://ia.cr/2026/2248
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2248,
author = {Sonia Belaïd and Ryad Benadjila and Julien Devevey and Morgane Guerreau and Thomas Legavre and Ange Martinelli and Thomas Ricosset and Matthieu Rivain and Mélissa Rossi},
title = {{ML}-{DSA} masking sweetened with {SUCRE}: Shuffle-and-Unmask Countermeasure for {REjection} sampling},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2248},
year = {2026},
doi = {https://doi.org/10.46586/tches.v2026.i1.618-659},
url = {https://eprint.iacr.org/2026/2248}
}