[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-140256-105":59,"doc-detail-140256-en":130},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":123,"head_meta":125,"extra_data":127,"updated_unix":129},105,"en","effective-and-efficient-masking-with-low-noise-using-small-mersenne-prime-ciphers","E􀀋ective and E􀀎cient Masking with Low Noise using Small-Mersenne-Prime Ciphers","","Embedded devices in security applications are frequent targets for physical side-channel attacks, making side-channel resistance a key research challenge. Boolean masking schemes can provide strong guarantees by increasing security exponentially with the number of shares when leakage is sufficiently noisy and independent. However, on low-end devices this noise assumption often fails. The study proposes prime-field arithmetic encodings and evaluates an AES-prime cipher, showing major security gains with low-noise leakage and limited overhead on common MCUs and FPGAs, validated by Cortex-M3 and Xilinx Spartan-6 implementations.",{"@graph":69,"@context":122},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/effective-and-efficient-masking-with-low-noise-using-small-mersenne-prime-ciphers/140256/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/effective-and-efficient-masking-with-low-noise-using-small-mersenne-prime-ciphers/140256.png","ImageObject",300,407,{"name":92,"@type":93},"นรินทร์","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-09-11","2026-08-24",true,{"@type":102,"interactionType":103,"userInteractionCount":81},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118],{"name":109,"@type":110,"acceptedAnswer":111},"Why does Boolean masking weaken on low-end embedded devices?","Question",{"text":112,"@type":113},"Because the theoretical security relies on leakage being sufficiently noisy and independent, assumptions that are often not met on low-end platforms.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"What is the paper’s main idea to achieve secure low-noise masking?",{"text":117,"@type":113},"Use arithmetic encodings in prime fields (based on prime-order group results), aiming to preserve resistance even when noise is almost absent.",{"name":119,"@type":110,"acceptedAnswer":120},"How are the proposed techniques validated experimentally?",{"text":121,"@type":113},"By evaluating software and hardware implementations, including ARM Cortex-M3 and Xilinx Spartan-6, and comparing security gains and practical overheads versus Boolean masking.","https://schema.org",{"og:url":83,"og:type":124,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":126,"canonical":83},"index,follow",{"doc_id":128,"site_id":62},140256,1787571353,{"code":4,"msg":5,"data":131},{"doc_id":128,"user_id":132,"nickname":92,"user_avatar":133,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":81,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":139,"language":140,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":67,"update_tm":129,"read_time":144},2336475104957,"https://ap-avatar.wpscdn.com/avatar/22000c4c6bd8a5076e1?x-image-process=image/resize,m_fixed,w_180,h_180&k=1787554080175789136","E􀀋ective and E􀀎cient Masking with Low Noise using Small-Mersenne-Prime Ciphers  \nLo􀁿􀀐c Masure 1[0000􀀀0003􀀀2978􀀀4067], Pierrick M􀀓eaux2[0000􀀀0001􀀀5733􀀀4341],  \nThorben Moos 1[0000􀀀0003􀀀3809􀀀9803], Fran􀀘cois-Xavier  \nStandaert 1[0000􀀀0001􀀀7444􀀀0285]  \n1 Crypto Group, ICTEAM Institute, UCLouvain, Louvain-la-Neuve, Belgium.  \n2 Luxembourg University, SnT, Luxembourg.  \nAbstract. Embedded devices used in security applications are natural targets for physical attacks. Thus, enhancing their side-channel resistance is an important research challenge. A standard solution for this purpose is the use of Boolean masking schemes, as they are well adapted to current block ciphers with e􀀎cient bitslice representations. Boolean masking guarantees that the security of an implementation grows exponentially in the number of shares under the assumption that leakages are su􀀎 -ciently noisy (and independent) . Unfortunately, it has been shown that this noise assumption is hardly met on low-end devices. In this paper, we therefore investigate techniques to mask cryptographic algorithms in such a way that their resistance can survive an almost complete lack of noise. Building on seed theoretical results of Dziembowski et al., we put forward that arithmetic encodings in prime 􀀌elds can reach this goal. We  \n􀀌rst exhibit the gains that such encodings lead to thanks to a simulated information theoretic analysis of their leakage (with up to six shares) . We then provide 􀀌gures showing that on platforms where optimized arithmetic adders and multipliers are readily available (i.e., most MCUs and FPGAs), performing masked operations in small to medium Mersenneprime 􀀌elds as opposed to binary extension 􀀌elds will not lead to notable implementation overheads. We compile these observations into a new AES-like block cipher, called AES-prime, which is well-suited to illustrate the remarkable advantages of masking in prime 􀀌elds. We also con􀀌rm the practical relevance of our 􀀌ndings by evaluating concrete software (ARM Cortex-M3) and hardware (Xilinx Spartan-6) implementations.  \nOur experimental results show that security gains over Boolean masking (and, more generally, binary encodings) can reach orders of magnitude despite the same amount of information being leaked per share.  \n1 Introduction  \nResearch question. Masking is an important countermeasure against sidechannel attacks. Introduced in [46,27], it has attracted signi􀀌cant attention thanks to the strong security guarantees it can provide [53,76 ,36 ,37] . Since leading to e􀀎cient implementations in software [79, 13], bitslice software [47,49] and hardware [50,23], additive (Boolean) masking is for now the most investigated type of encoding. Concretely, assuming that the shares' leakage is su􀀎ciently  \nnoisy and independent, Boolean masking can amplify the noise of an implementation (and therefore its security) exponentially in the number of shares.  \nYet, and despite these strong theoretical guarantees, ensuring the noise and independence conditions may not be easy in practice. The independence issue is a well investigated one. Physical defaults such as glitches [61,62] or transitions [30,8] can cause leakage about re-combined shares. Fortunately, these defaults can be circumvented (at some cost) thanks to well understood design techniques [72,44 ,24] . To the best of our knowledge, the noise issue is for now a less investigated one. Concrete results of so-called horizontal attacks such as [12,20] showed that a lack of noise can lead to devastating attacks against Boolean masking. Improved security against horizontal attacks has been captured with the notion of noise rate [5,25] . But gadgets with limited noise rate only reduce the number of manipulations of the shares (in order to prevent reducing the noise by averaging) . Therefore, they have limited impact when the noise level of an implementation is already small without averaging, as it is for example the case for small embedded devices (e.g., 32-","cbCaim6Gow1Wp8jW","https://ap.wps.com/l/cbCaim6Gow1Wp8jW","pdf",1299439,32,"English","# Abstract\n# 1 Introduction\n## Research question\n## Seed results","[{\"question\":\"Why does Boolean masking weaken on low-end embedded devices?\",\"answer\":\"Because the theoretical security relies on leakage being sufficiently noisy and independent, assumptions that are often not met on low-end platforms.\"},{\"question\":\"What is the paper’s main idea to achieve secure low-noise masking?\",\"answer\":\"Use arithmetic encodings in prime fields (based on prime-order group results), aiming to preserve resistance even when noise is almost absent.\"},{\"question\":\"How are the proposed techniques validated experimentally?\",\"answer\":\"By evaluating software and hardware implementations, including ARM Cortex-M3 and Xilinx Spartan-6, and comparing security gains and practical overheads versus Boolean masking.\"}]","E􀀋ective and E􀀎cient Masking with Low Noise using Small-Mersenne-Prime Ciphers | PDF",81]