BEGIN:VEVENT
SUMMARY:Fast Verification of Masking Schemes in Characteristic Two
Damien Vergnaud
Nicolas Bordes et Pierre Karpman
CCEPTED
DESCRIPTION:We revisit the matrix model for non-interference (NI) probing
security of masking gadgets introduced by Belaïd et al. at CRYPTO 2017. T
his leads to two main results.
1) We generalise the theorems on which th
is model is based\, so as to be able to apply them to masking schemes over
any finite field -- in particular F_2 -- and to be able to analyse the st
rong non-interference (SNI) security notion. We also follow Faust et al. (
TCHES 2018) to additionally consider a robust probing model that takes har
dware defects such as glitches into account.
2) We exploit this improved
model to implement a very efficient verification algorithm that improves
the performance of state-of-the-art software by three orders of magnitude.
We show applications to variants of NI and SNI multiplication gadgets fro
m Barthe et al. (EUROCRYPT 2017) which we verify to be secure up to order
11 after a significant parallel computation effort\, whereas the previous
largest proven order was 7; SNI refreshing gadgets (ibid.); and NI multipl
ication gadgets from Gross et al. (TIS@CCS 2016) secure in presence of gli
tches. We also reduce the randomness cost of some existing gadgets\, notab
ly for the implementation-friendly case of 8 shares\, improving here the p
revious best results by 17% (resp. 19%) for SNI multiplication (resp. refr
eshing).
20211126T110000
Salle 405, couloir 24-25, 4 place Jussieu - 75005 Paris
