Paper 2026/2287

Knuth–Yao masked (Gaussian) sampling

Calvin Abou Haidar, NTT Social Informatics Laboratories
Clément Hoffmann, NTT Social Informatics Laboratories
Abstract

Discrete Gaussian sampling remains one of the most delicate operations to protect against side-channel attacks in lattice-based cryptography. In this work, we present the first masked evaluation of the Knuth-Yao sampler, a generic building block for lattice-based schemes. Its random-walk formulation might seem fundamentally at odds with masking, since the walk's control flow depends precisely on the secret sample being produced. We show instead that its underlying tree structure is remarkably suited to it. Evaluated as a bitsliced Boolean circuit, the public tree prescribes an evaluation order requiring exactly L - 2 masked AND gadgets, where L is the total Hamming weight of the probability expansions of the target distribution. This makes the approach particularly effective for the narrow distributions used in lattice-based schemes. We provide a generic framework that compiles any finite-precision distribution into a masked C implementation with optimized linear-gate count. We use FrodoKEM and HAWK as case studies, and also compile the base samplers of Falcon and HAETAE. On ARM Cortex-M4, our sampler outperforms the state-of-the-art masked CDT approach for every distribution at masking orders 1 to 5, running up to 2.3 times as fast at order 1, even for distributions where it evaluates more non-linear gates. Finally, since the Fujisaki-Okamoto transform ties FrodoKEM to the exact randomness consumption of its specified sampler, we discuss the consequences of this constraint. We benchmarked an unmasked implementation and argue that the Knuth-Yao approach is competitive even without masking, while using identical input randomness.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published by the IACR in TCHES 2027
Keywords
Side-channel analysisMaskingDiscrete Gaussian samplingKnuth--YaoLattice-based cryptography
Contact author(s)
calvin abou-haidar @ protonmail com
clement hoffmann @ hotmail fr
History
2026-10-04: approved
2026-10-01: received
See all versions
Short URL
https://ia.cr/2026/2287
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2287,
      author = {Calvin Abou Haidar and Clément Hoffmann},
      title = {Knuth–Yao masked (Gaussian) sampling},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2287},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2287}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.