Paper 2026/769
High-Order Masking for MQOM v2.1 Signing
Abstract
This paper presents the first high-order fully-shared masking construction for MQOM v2.1, a candidate in NIST's additional digital signature standardization process. We provide a baseline high-order masked signing design for MQOM v2.1, prove its security in the standard probing leakage model, and validate the implementation through a comprehensive TVLA campaign. To mitigate the online-time bottleneck in masked signing, we further introduce an optional Rijndael LUT-based acceleration mode that decouples offline precomputation from online signing. Although this accelerated mode incurs higher offline time and memory costs, it can run during idle periods and significantly reduce online signing latency. We implement and benchmark all 36 MQOM v2.1 signing variants over GF(2), GF(16), and GF(256), and report comprehensive performance and leakage-evaluation results for both the baseline and accelerated designs.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- fully-shared maskinghigh-order maskingMQOM v2.1side-channel17 securitysigningTVLA
- Contact author(s)
-
e88888812 @ gmail com
jiunpeng @ ntu edu tw
holinc @ gmail com
byyang @ iis sinica edu tw - History
- 2026-04-22: approved
- 2026-04-19: received
- See all versions
- Short URL
- https://ia.cr/2026/769
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/769,
author = {Yi-Lin Hung and Jiun-Peng Chen and Ho-Lin Chen and Bo-Yin Yang},
title = {High-Order Masking for {MQOM} v2.1 Signing},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/769},
year = {2026},
url = {https://eprint.iacr.org/2026/769}
}