Paper 2026/2278

Masked CROSS: Masking the CROSS Digital Signature Scheme at Arbitrary Order

Khan Keren Mengwi, University of Bamenda
Puja Mondal, Indian Institute of Technology Kanpur
Achille Ecladore Tchahou Tchendjeu, University of Bamenda
Emmanuel Fouotsa, University of Bamenda
Suparna Kundu, KU Leuven
Abstract

CROSS is a code-based signature scheme built on the Restricted Syndrome Decoding Problem and is a second-round candidate in NIST's additional digital signature standardization process. Recent work shows that its reference implementation is vulnerable to side-channel analysis, allowing an attacker to recover the long-term secret key from a single power trace. No masking countermeasure has so far been designed for CROSS's restricted-syndrome framework, leaving its practical side-channel resistance unresolved. In this work, we present a full sensitivity analysis and a gadget-based masking schedule ($G_0-G_8$) for the CROSS signing algorithm of the R-SDP(G) variant. One gadget in this schedule, the restriction-lift exponentiation, has no counterpart in prior masked multivariate- or lattice-based signatures: it masks $g^{\bar{\mathbf v}[i]}$ via table lookup, share-serial conversion, and ISW-multiplication sub-gadgets rather than via a fixed linear or bilinear map. We rigorously prove $t_{\mathrm{mask}}$-probing security for each gadget individually and for their full composition, using the NI, SNI, and NIo frameworks. We implement the resulting masked signer for an arbitrary number of shares $d$ and evaluate it on an x86-64 platform, measuring cycle overheads of $21.73\times$ at first order and $78.05\times$ at second order relative to the unmasked baseline. At first order, our masked CROSS is cheaper than a comparably masked Dilithium-2 ($38\times$), but Dilithium-2 overtakes it at second order ($70\times$). This crossover cost is driven by the $O(d^3)$ chained-ISW cost of $G_3$/$G_7$ compared to Dilithium's cheaper $O(d^2)$ scaling.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
Post-Quantum CryptographyDigital SignatureCROSSSide-Channel AttackSecure implementationsMasking
Contact author(s)
khankeren @ uniba cm
pujamondal @ cse iitk ac in
tchahoutchendjeu @ gmail com
emmanuelfouotsa @ yahoo fr
suparna kundu @ esat kuleuven be
History
2026-10-03: approved
2026-09-30: received
See all versions
Short URL
https://ia.cr/2026/2278
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2278,
      author = {Khan Keren Mengwi and Puja Mondal and Achille Ecladore Tchahou Tchendjeu and Emmanuel Fouotsa and Suparna Kundu},
      title = {Masked {CROSS}: Masking the {CROSS} Digital Signature Scheme at Arbitrary Order},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2278},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2278}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.