Paper 2026/2287
Knuth–Yao masked (Gaussian) sampling
Abstract
Discrete Gaussian sampling remains one of the most delicate operations to protect against side-channel attacks in lattice-based cryptography. In this work, we present the first masked evaluation of the Knuth-Yao sampler, a generic building block for lattice-based schemes. Its random-walk formulation might seem fundamentally at odds with masking, since the walk's control flow depends precisely on the secret sample being produced. We show instead that its underlying tree structure is remarkably suited to it. Evaluated as a bitsliced Boolean circuit, the public tree prescribes an evaluation order requiring exactly L - 2 masked AND gadgets, where L is the total Hamming weight of the probability expansions of the target distribution. This makes the approach particularly effective for the narrow distributions used in lattice-based schemes. We provide a generic framework that compiles any finite-precision distribution into a masked C implementation with optimized linear-gate count. We use FrodoKEM and HAWK as case studies, and also compile the base samplers of Falcon and HAETAE. On ARM Cortex-M4, our sampler outperforms the state-of-the-art masked CDT approach for every distribution at masking orders 1 to 5, running up to 2.3 times as fast at order 1, even for distributions where it evaluates more non-linear gates. Finally, since the Fujisaki-Okamoto transform ties FrodoKEM to the exact randomness consumption of its specified sampler, we discuss the consequences of this constraint. We benchmarked an unmasked implementation and argue that the Knuth-Yao approach is competitive even without masking, while using identical input randomness.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Published by the IACR in TCHES 2027
- Keywords
- Side-channel analysisMaskingDiscrete Gaussian samplingKnuth--YaoLattice-based cryptography
- Contact author(s)
-
calvin abou-haidar @ protonmail com
clement hoffmann @ hotmail fr - History
- 2026-10-04: approved
- 2026-10-01: received
- See all versions
- Short URL
- https://ia.cr/2026/2287
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2287,
author = {Calvin Abou Haidar and Clément Hoffmann},
title = {Knuth–Yao masked (Gaussian) sampling},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2287},
year = {2026},
url = {https://eprint.iacr.org/2026/2287}
}