01▲Slicing Bits and Cutting Costs in CDT Sampling: High-Order Masking of FrodoKEM's Gaussian Sampler, Revisited eprint.iacr.org Masked Gaussian sampling gets expensive fast; this paper trims FrodoKEM CDT costs with bitslicing for arbitrary orders.bitslicingcryptographyeprintgaussian-samplingimplementation-securitylatticemaskingpqc2 pts/nullptr12/2 days ago/discuss
02▲Maskaglia: A New, Efficient Approach to Masked Discrete Gaussian Sampling eprint.iacr.org Rejection sampling, the old side-channel workhorse, beats CDT here with fewer masked ANDs for lattice Gaussians (incl. HAWK).discrete-gaussian-samplinglatticelinkedinmaskingpqcprivacyside-channelsignatures1 pt/ringlwe/16 hours ago/discuss
03▲[acc,masking] Add first-order masked ML-DSA key generation and signing github.com First-order masked ML-DSA keygen/signing for Pavona ACC, reusing masked KMAC and aiming at DPA resistance?dpalatticelinkedinmaskingpqcside-channelsignatures0 pts/nonce23/24 minutes ago/discuss
04▲Hardware Private Cubic Circuits eprint.iacr.org HPCC gives single-cycle masked 3-input multiplies and 2-cycle AES S-boxes in the PINI glitch model.cipher-sboxeprintfinite-fieldshardwaremaskingpiniside-channel10 pts/nonce99/6 days ago/discuss
05▲A Second-Order Side-Channel Attack on Masked Kyber768 | Ledger Donjon donjon.ledger.com First-order masking still folds to second-order CPA on masked Kyber768 on Cortex-M4, with leakage models and SNR plots.cpacryptanalysiskyberlatticeleakage-analysislinkedinmaskingml-kempqcsecond-orderside-channel4 pts/pavelk/9 days ago/1 comment
06▲Hardening ML-KEM for Pavona's ACC zerorisc.com First-order masked ML-KEM for Pavona's ACC fits under 22 KB DMEM and costs 2.6x to 3.4x, because side channels insist.hardwarehashimplementationkeccaklatticelinkedinmaskingpqcside-channel0 pts/proverbill/19 days ago/2 comments
07▲[acc,masking] Add masked ML-KEM decaps and keygen, plus masking gadgets by pqcfox · Pull Request #230 · pavona/pavona github.com PR adds fully masked ML-KEM decaps/keygen plus masking gadgets for Pavona's crypto coprocessor, with the usual register fuss.hardwarelatticelinkedinmaskingml-kempqcside-channel0 pts/tara_stderr/26 days ago/5 comments
08▲Changing of the Guards with Two Shares - Security Flaws, Corrrections, and Application to Low-Latency AES eprint.iacr.org Paper finds a flaw in Changing of the Guards masking, patches it, and gets first-order AES with 20-cycle latency and no fresh randomness.aeseprinthardwaremaskingrandomness-reductionsecurity-flawside-channel0 pts/ines/28 days ago/3 comments