{"status":"ok","message-type":"work-list","message-version":"1.0.0","message":{"facets":{},"total-results":359,"items":[{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T21:34:52Z","timestamp":1778276092867,"version":"3.51.4"},"reference-count":36,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,7,4]],"date-time":"2024-07-04T00:00:00Z","timestamp":1720051200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,9,2]]},"abstract":"<jats:p>This paper presents a new side-channel attack (SCA) on unrolled implementations of stream ciphers, with a particular focus on Trivium. Most conventional SCAs predominantly concentrate on leakage of some first rounds prior to the sufficient diffusion of the secret key and initial vector (IV). However, recently, unrolled hardware implementation has become common and practical, which achieves higher throughput and energy efficiency compared to a round-based hardware. The applicability of conventional SCAs to such unrolled hardware is unclear because the leakage of the first rounds from unrolled hardware is hardly observed. In this paper, focusing on Trivium, we propose a novel SCA on unrolled stream cipher hardware, which can exploit leakage of rounds latter than 80, while existing SCAs exploited intermediate values earlier than 80 rounds. We first analyze the algebraic equations representing the intermediate values of these rounds and present the recursive restricted linear decomposition (RRLD) strategy. This approach uses correlation power analysis (CPA) to estimate the intermediate values of latter rounds. Furthermore, we present a chosen-IV strategy for a successful key recovery through linearization. We experimentally demonstrate that the proposed SCA achieves the key recovery of a 288-round unrolled Trivium hardware implementation using 360,000 traces. Finally, we evaluate the performance of unrolled Trivium hardware implementations to clarify the trade-off between performance and SCA (in)security. The proposed SCA requires 34.5 M traces for a key recovery of 384-round unrolled Trivium implementation and is not applicable to 576-round unrolled hardware. <\/jats:p>","DOI":"10.62056\/angy11zn4","type":"journal-article","created":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T15:13:33Z","timestamp":1728314013000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":1,"title":["Side-Channel Linearization Attack on Unrolled Trivium Hardware"],"prefix":"10.62056","author":[{"given":"Soichiro","family":"Kobayashi","sequence":"first","affiliation":[{"name":"Tohoku University","place":["2\u20131\u20131 Katahira, Aoba-ku, Sendai, 980-8577, Japan"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9754-6792","authenticated-orcid":false,"given":"Rei","family":"Ueno","sequence":"additional","affiliation":[{"name":"Kyoto University","place":["Yoshidahommachi, Kyoto, 606\u20138501, Japan"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6839-4777","authenticated-orcid":false,"given":"Yosuke","family":"Todo","sequence":"additional","affiliation":[{"name":"NTT Social Informatics Laboratories","place":["3\u20139\u201311 Midori-cho, Musashino-shi, Tokyo, 180-8535, Japan"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0864-3126","authenticated-orcid":false,"given":"Naofumi","family":"Homma","sequence":"additional","affiliation":[{"name":"Tohoku University","place":["2\u20131\u20131 Katahira, Aoba-ku, Sendai, 980-8577, Japan"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"48349","published-online":{"date-parts":[[2024,10,7]]},"reference":[{"key":"ref1:de2008trivium","doi-asserted-by":"crossref","first-page":"244","DOI":"10.1007\/978-3-540-68351-3_18","article-title":"Trivium","author":"Christophe De Canniere","year":"2008","journal-title":"New Stream Cipher Designs: The eSTREAM Finalists"},{"key":"ref2:canniere2006trivium","volume-title":"Trivium specifications","author":"Christophe De Canniere","year":"2006"},{"key":"ref3:iso","volume-title":"ISO\/IEC 29192-3:2012 Information technology\u2014Security\n  techniques\u2014Lightweight cryptography\u2014 Part 3: Stream ciphers"},{"key":"ref4:eSTREAM","volume-title":"The eSTREAM portfolio\u2014eSTREAM: the ECRYPT Stream\n  Cipher Project"},{"key":"ref5:ePrint:CMM+23","volume-title":"Randomness Generation for Secure Hardware Masking - Unrolled\n  Trivium to the Rescue","author":"Ga\u00ebtan Cassiers","year":"2023"},{"key":"ref6:banik2018towards","doi-asserted-by":"publisher","first-page":"1","DOI":"10.13154\/tosc.v2018.i2.1-19","article-title":"Towards low energy stream ciphers","author":"Subhadeep Banik","year":"2018","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"ref7:caforio2021perfect","doi-asserted-by":"publisher","first-page":"36","DOI":"10.46586\/tosc.v2021.i4.36-73","article-title":"Perfect Trees: Designing Energy-Optimal Symmetric Encryption\n  Primitives","author":"Andrea Caforio","year":"2021","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"ref8:fischer2006differential","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/11967668_17","article-title":"Differential Power Analysis of Stream Ciphers","author":"Wieland Fischer","year":"2006"},{"key":"ref9:strobel2009side","article-title":"Side channel analysis attacks on stream ciphers","author":"Daehyun Strobel","year":"2009","journal-title":"Masterarbeit Ruhr-Universit\u00e4t Bochum, Lehrstuhl Embedded\n  Security"},{"key":"ref10:jia2012correlation","doi-asserted-by":"publisher","first-page":"479","DOI":"10.1002\/sec.329","article-title":"Correlation power analysis of Trivium","volume":"5","author":"Yanyan Jia","year":"2012","journal-title":"Security and Communication Networks"},{"key":"ref11:tena2015dpa","doi-asserted-by":"publisher","first-page":"1846","DOI":"10.1109\/ISCAS.2015.7169016","article-title":"DPA vulnerability analysis on Trivium stream cipher using\n  an optimized power model","author":"Erica Tena-S\u00e1nchez","year":"2015"},{"key":"ref12:tena2015optimized","first-page":"1","article-title":"Optimized DPA attack on Trivium stream cipher using\n  correlation shape distinguishers","author":"Erica Tena-S\u00e1nchez","year":"2015"},{"key":"ref13:sim2021dapa","doi-asserted-by":"publisher","first-page":"169","DOI":"10.46586\/tches.v2021.i1.169-191","article-title":"DAPA: Differential Analysis aided Power Attack on\n  (Non-)Linear Feedback Shift Registers","author":"Siang Meng Sim","year":"2021","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref14:kumar2022side","doi-asserted-by":"publisher","first-page":"166","DOI":"10.46586\/tches.v2022.i2.166-191","article-title":"Side Channel Attack On Stream Ciphers: A Three-Step Approach\n  To State\/Key Recovery","author":"Satyam Kumar","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref15:CTRSA:BGSD10","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/978-3-642-11925-5_14","article-title":"Unrolling Cryptographic Circuits: A Simple Countermeasure\n  Against Side-Channel Attacks","author":"Shivam Bhasin","year":"2010"},{"key":"ref16:LightSec:YHA16","doi-asserted-by":"publisher","first-page":"148","DOI":"10.1007\/978-3-319-29078-2_9","article-title":"Improved Power Analysis on Unrolled Architecture and Its\n  Application to PRINCE Block Cipher","author":"Ville Yli-M\u00e4yry","year":"2016"},{"key":"ref17:AC:MS16","doi-asserted-by":"publisher","first-page":"517","DOI":"10.1007\/978-3-662-53887-6_19","article-title":"Side-Channel Analysis Protection and Low-Latency in Action","author":"Amir Moradi","year":"2016"},{"key":"ref18:TIFS:YUM+21","doi-asserted-by":"publisher","first-page":"1351","DOI":"10.1109\/TIFS.2020.3033441","article-title":"Diffusional Side-Channel Leakage From Unrolled Lightweight\n  Block Ciphers: A Case Study of Power Analysis on PRINCE","volume":"16","author":"Ville Yli-M\u00e4yry","year":"2021","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"ref19:CHES:MPO05","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1007\/11545262_12","article-title":"Successfully Attacking Masked AES Hardware\n  Implementations","author":"Stefan Mangard","year":"2005"},{"key":"ref20:TCHES:Moos20","doi-asserted-by":"publisher","first-page":"416","DOI":"10.13154\/tches.v2020.i4.416-442","article-title":"Unrolled Cryptography on Silicon: A Physical Security\n  Analysis","volume":"2020","author":"Thorben Moos","year":"2020","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref21:ISSITC:SA15","doi-asserted-by":"publisher","first-page":"253","DOI":"10.1007\/978-3-319-27179-8_18","article-title":"Secure Implementation of Stream Cipher: Trivium","author":"Dillibabu Shanmugam","year":"2015"},{"key":"ref22:ICECS:MHBM+18","doi-asserted-by":"publisher","first-page":"393","DOI":"10.1109\/ICECS.2018.8617892","article-title":"Energy-efficient Masking of the Trivium Stream Cipher","author":"Maxime Montoya","year":"2018"},{"key":"ref23:COSADE:HHN+13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/978-3-642-40026-1_11","article-title":"Chosen-IV Correlation Power Analysis on KCipher-2 and a\n  Countermeasure","volume":"7864","author":"Takafumi Hibiki","year":"2013"},{"key":"ref24:SEMS:KUH+2017","first-page":"113","article-title":"Practical Power Analysis on KCipher-2 Software on Low-End\n  Microcontrollers","author":"Wataru Kawai","year":"2017"},{"key":"ref25:WOOT:BZD+16","series-title":"WOOT'16","first-page":"15","article-title":"Nonce-disrespecting adversaries: practical forgery attacks\n  on GCM in TLS","author":"Hanno B\u00f6ck","year":"2016"},{"key":"ref26:TCHES:UHIM23","doi-asserted-by":"publisher","first-page":"264","DOI":"10.46586\/tches.v2024.i1.264-308","article-title":"Fallen Sanctuary: A Higher-Order and Leakage-Resilient\n  Rekeying Scheme","volume":"1","author":"Rei Ueno","year":"2023","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref27:Z3:dMB08","first-page":"337","article-title":"Z3: An Efficient SMT Solver","author":"Leonardo de Moura","year":"2008"},{"key":"ref28:Z3","volume-title":"Z3 API in Python","author":"Microsoft","year":"2023"},{"key":"ref29:CHES:FPS12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1007\/978-3-642-33027-8_13","article-title":"Practical Leakage-Resilient Symmetric Cryptography","volume":"7428","author":"Sebastian Faust","year":"2012"},{"key":"ref30:FSE:Prouff05","doi-asserted-by":"publisher","first-page":"424","DOI":"10.1007\/11502760_29","article-title":"DPA Attacks and S-Boxes","author":"Emmanuel Prouff","year":"2005"},{"key":"ref31:JCEN:FDLZ15","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-015-0107-0","article-title":"A statistics-based success rate model for DPA and CPA","volume":"5","author":"Yunsi Fei","year":"2015","journal-title":"Journal of Cryptographic Engineering"},{"key":"ref32:EC:DS09","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1007\/978-3-642-01001-9_16","article-title":"Cube Attacks on Tweakable Black Box Polynomials","author":"Itai Dinur","year":"2009"},{"key":"ref33:EC:HHLW24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-58716-0_13","article-title":"Massive Superpoly Recovery with a Meet-in-the-middle\n  Framework: Improved Cube Attacks on Trivium and Kreyvium","author":"Jiahui He","year":"2024"},{"key":"ref34:Picek-TCHES-2019","doi-asserted-by":"publisher","first-page":"209","DOI":"10.13154\/tches.v2019.i1.209-237","article-title":"The Curse of Class Imbalance and Conflicting Metrics with\n  Machine Learning for Side-channel Evaluations","author":"Stjepan Picek","year":"2019","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref35:ito-tifs-2021","doi-asserted-by":"publisher","first-page":"3790","DOI":"10.1109\/TIFS.2021.3092050","article-title":"Imbalanced Data Problems in Deep Learning-Based Side-Channel\n  Attacks: Analysis and Solution","volume":"16","author":"Akira Ito","year":"2021","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"ref36:Ito-eprint-2021","volume-title":"Toward Optimal Deep-Learning Based Side-Channel Attacks:\n  Probability Concentration Inequality Loss and Its Usage","author":"Akira Ito","year":"2021"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T21:28:15Z","timestamp":1733866095000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/3\/14"}},"issued":{"date-parts":[[2024,10,7]]},"references-count":36,"URL":"https:\/\/doi.org\/10.62056\/angy11zn4","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2024,10,7]]},"assertion":[{"value":"2024-07-04","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-3-41"},{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T12:54:31Z","timestamp":1785416071919,"version":"3.56.0"},"reference-count":41,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,7,8]],"date-time":"2024-07-08T00:00:00Z","timestamp":1720396800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,9,2]]},"abstract":"<jats:p>Software implementations of cryptographic algorithms often use masking schemes as a countermeasure against side channel attacks. A number of recent results show clearly the challenge of implementing masking schemes in such a way, that (unforeseen) micro-architectural effects do not cause masking flaws that undermine the intended security goal of an implementation. So far, utilising a higher-order version of the non-specific (fixed-vs-random) input test of the Test Vector Leakage Assessment (TVLA) framework has been the best option to identify such flaws. The drawbacks of this method are both its significant computation cost, as well as its inability to pinpoint which interaction of masking shares leads to the flaw. In this paper we propose a novel version, the fixed-vs-random shares test, to tackle both drawbacks. We explain our method and show its application to three case studies, where each time it outperforms its conventional TVLA counterpart. The drawback of our method is that it requires control over the shares, which, we argue, is practically feasible in the context of in-house evaluation and testing for software implementations.<\/jats:p>","DOI":"10.62056\/ab89ksdja","type":"journal-article","created":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T11:13:33Z","timestamp":1728299613000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":1,"title":["Efficiently Detecting Masking Flaws in Software Implementations"],"prefix":"10.62056","author":[{"given":"Nima","family":"Mahdion","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05q9m0937","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Klagenfurt","place":["Klagenfurt, Austria"],"department":["Digital Age Research Centre"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7502-3184","authenticated-orcid":false,"given":"Elisabeth","family":"Oswald","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05q9m0937","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Klagenfurt","place":["Klagenfurt, Austria"],"department":["Digital Age Research Centre"]},{"id":[{"id":"https:\/\/ror.org\/03angcq70","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Birmingham","place":["Birmingham, United Kingdom"],"department":["Computer Science"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2024,10,7]]},"reference":[{"key":"ref1:DBLP:conf\/crypto\/Kocher96","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","article-title":"Timing Attacks on Implementations of Diffie-Hellman, RSA,\n  DSS, and Other Systems","volume":"1109","author":"Paul C. Kocher","year":"1996"},{"key":"ref2:DBLP:conf\/ches\/BrierCO04","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/978-3-540-28632-5_2","article-title":"Correlation Power Analysis with a Leakage Model","volume":"3156","author":"Eric Brier","year":"2004"},{"key":"ref3:DBLP:conf\/ches\/ChariRR02","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1007\/3-540-36400-5_3","article-title":"Template Attacks","volume":"2523","author":"Suresh Chari","year":"2002"},{"key":"ref4:Goodwill11","first-page":"115","article-title":"A testing methodology for side-channel resistance\n  validation","volume":"7","author":"Benjamin Jun Gilbert Goodwill","year":"2011"},{"key":"ref5:DBLP:conf\/ches\/SchneiderM15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"495","DOI":"10.1007\/978-3-662-48324-4_25","article-title":"Leakage Assessment Methodology - A Clear Roadmap for\n  Side-Channel Evaluations","volume":"9293","author":"Tobias Schneider","year":"2015"},{"key":"ref6:FIPS140_3","volume-title":"Security Requirements for Cryptographic Modules (FIPS PUB\n  140-3)","year":"2019"},{"key":"ref7:CC","volume-title":"The Common Criteria for Information Technology Security\n  Evaluation","author":"Common Criteria","year":"2017"},{"key":"ref8:DBLP:conf\/eurocrypt\/DurvauxS16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"240","DOI":"10.1007\/978-3-662-49890-3_10","article-title":"From Improved Leakage Detection to the Detection of Points\n  of Interests in Leakage Traces","volume":"9665","author":"Fran\u00e7ois Durvaux","year":"2016"},{"key":"ref9:DBLP:conf\/cosade\/DingCE16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/978-3-319-43283-0_10","article-title":"Simpler, Faster, and More Robust T-Test Based Leakage\n  Detection","volume":"9689","author":"A. Adam Ding","year":"2016"},{"key":"ref10:DBLP:conf\/cardis\/Standaert18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/978-3-030-15462-2_5","article-title":"How (Not) to Use Welch's T-Test in Side-Channel Security\n  Evaluations","volume":"11389","author":"Fran\u00e7ois-Xavier Standaert","year":"2018"},{"key":"ref11:TCHES:MRSS18","doi-asserted-by":"publisher","first-page":"209","DOI":"10.13154\/tches.v2018.i1.209-237","article-title":"Leakage Detection with the $\\chi^2$-Test","volume":"2018","author":"Amir Moradi","year":"2018","journal-title":"IACR TCHES","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref12:EPRINT:ZhoQiaOu19","volume-title":"Leakage Detection with Kolmogorov-Smirnov Test","author":"Xinping Zhou","year":"2019"},{"key":"ref13:TCHES:BroSchSta19","doi-asserted-by":"publisher","first-page":"318","DOI":"10.13154\/tches.v2019.i2.318-345","article-title":"Multi-Tuple Leakage Detection and the Dependent Signal\n  Issue","volume":"2019","author":"Olivier Bronchain","year":"2019","journal-title":"IACR TCHES","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref14:TCHES:MooWegMor21","doi-asserted-by":"publisher","first-page":"552","DOI":"10.46586\/tches.v2021.i3.552-598","article-title":"DL-LA: Deep Learning Leakage Assessment","volume":"2021","author":"Thorben Moos","year":"2021","journal-title":"IACR TCHES","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref15:DBLP:journals\/scn\/YangJ21","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/6614702","article-title":"Side-Channel Leakage Detection with One-Way Analysis of\n  Variance","volume":"2021","author":"Wei Yang","year":"2021","journal-title":"Secur. Commun. Networks"},{"key":"ref16:DBLP:journals\/integration\/WangTWLT22","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1016\/J.VLSI.2022.06.013","article-title":"The Levene test based-leakage assessment","volume":"87","author":"Yaru Wang","year":"2022","journal-title":"Integr."},{"key":"ref17:ARM_ARCH","volume-title":"ARM Achitecture","author":"ARM"},{"key":"ref18:TCHES:MarPagWeb22","doi-asserted-by":"publisher","first-page":"175","DOI":"10.46586\/tches.v2022.i1.175-220","article-title":"MIRACLE: MIcRo-ArChitectural Leakage Evaluation A\n  study of micro-architectural power leakage across many devices","volume":"2022","author":"Ben Marshall","year":"2022","journal-title":"IACR TCHES"},{"key":"ref19:AC:MOBW13","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"486","DOI":"10.1007\/978-3-642-42033-7_25","article-title":"Does My Device Leak Information? An a priori Statistical\n  Power Analysis of Leakage Detection Tests","volume":"8269","author":"Luke Mather","year":"2013"},{"key":"ref20:EC:DurSta16","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"240","DOI":"10.1007\/978-3-662-49890-3_10","article-title":"From Improved Leakage Detection to the Detection of Points\n  of Interests in Leakage Traces","volume":"9665","author":"Fran\u00e7ois Durvaux","year":"2016"},{"key":"ref21:DBLP:conf\/cardis\/DingZDSF17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1007\/978-3-319-75208-2_7","article-title":"Towards Sound and Optimal Leakage Detection Procedure","volume":"10728","author":"A. Adam Ding","year":"2017"},{"key":"ref22:C:IshSahWag03","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-3-540-45146-4_27","article-title":"Private Circuits: Securing Hardware against Probing\n  Attacks","volume":"2729","author":"Yuval Ishai","year":"2003"},{"key":"ref23:DBLP:conf\/ccs\/GrossMK16","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/2996366.2996426","article-title":"Domain-Oriented Masking: Compact Masked Hardware\n  Implementations with Arbitrary Protection Order","author":"Hannes Gro\u00df","year":"2016"},{"key":"ref24:RSA:GroManKor17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1007\/978-3-319-52153-4_6","article-title":"An Efficient Side-Channel Protected AES Implementation\n  with Arbitrary Protection Order","volume":"10159","author":"Hannes Gro\u00df","year":"2017"},{"key":"ref25:DBLP:journals\/tc\/CassiersGLS21","doi-asserted-by":"publisher","first-page":"1677","DOI":"10.1109\/TC.2020.3022979","article-title":"Hardware Private Circuits: From Trivial Composition to Full\n  Verification","volume":"70","author":"Ga\u00ebtan Cassiers","year":"2021","journal-title":"IEEE Trans. Computers"},{"key":"ref26:scaleboard","volume-title":"SCALE: Side-Channel Attack Lab. Exercises","author":"Dan Page"},{"key":"ref27:Thumb16","volume-title":"Thumb-16-bit instruction set quick reference card","author":"ARM"},{"key":"ref28:EC:GouRiv17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"567","DOI":"10.1007\/978-3-319-56620-7_20","article-title":"How Fast Can Higher-Order Masking Be in Software?","volume":"10210","author":"Dahmun Goudarzi","year":"2017"},{"key":"ref29:student1908probable","doi-asserted-by":"publisher","first-page":"1","DOI":"10.2307\/2331554","article-title":"The probable error of a mean","author":"Student","year":"1908","journal-title":"Biometrika"},{"key":"ref30:jan2011optimal","doi-asserted-by":"publisher","first-page":"1014","DOI":"10.3758\/s13428-011-0095-7","article-title":"Optimal sample sizes for Welch\u2019s test under various\n  allocation and cost considerations","volume":"43","author":"Show-Li Jan","year":"2011","journal-title":"Behavior research methods"},{"key":"ref31:welch1947generalization","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1093\/biomet\/34.1-2.28","article-title":"The generalization of `Student's\u2019 problem when several\n  different population variances are involved","volume":"34","author":"B. L. Welch","year":"1947","journal-title":"Biometrika","ISSN":"https:\/\/id.crossref.org\/issn\/0006-3444","issn-type":"electronic"},{"key":"ref32:FSE:Reparaz16","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"204","DOI":"10.1007\/978-3-662-52993-5_11","article-title":"Detecting Flawed Masking Schemes with Leakage Detection\n  Tests","volume":"9783","author":"Oscar Reparaz","year":"2016"},{"key":"ref33:DBLP:conf\/cardis\/BalaschGGRS14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-319-16763-3_5","article-title":"On the Cost of Lazy Engineering for Masked Software\n  Implementations","volume":"8968","author":"Josep Balasch","year":"2014"},{"key":"ref34:AES-FIPS","volume-title":"Advanced Encryption Standard (AES)","year":"2001"},{"key":"ref35:DBLP:journals\/tc\/ProuffRB09","doi-asserted-by":"publisher","first-page":"799","DOI":"10.1109\/TC.2009.15","article-title":"Statistical Analysis of Second Order Differential Power\n  Analysis","volume":"58","author":"Emmanuel Prouff","year":"2009","journal-title":"IEEE Trans. Computers"},{"key":"ref36:CHES:RivPro10","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"413","DOI":"10.1007\/978-3-642-15031-9_28","article-title":"Provably Secure Higher-Order Masking of AES","volume":"6225","author":"Matthieu Rivain","year":"2010"},{"key":"ref37:ICICS:NikRecRij06","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"529","DOI":"10.1007\/11935308_38","article-title":"Threshold Implementations Against Side-Channel Attacks and\n  Glitches","volume":"4307","author":"Svetla Nikova","year":"2006"},{"key":"ref38:C:RBNGV15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"764","DOI":"10.1007\/978-3-662-47989-6_37","article-title":"Consolidating Masking Schemes","volume":"9215","author":"Oscar Reparaz","year":"2015"},{"key":"ref39:DBLP:conf\/eurocrypt\/GaoOP22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"284","DOI":"10.1007\/978-3-031-07082-2_11","article-title":"Towards Micro-architectural Leakage Simulators: Reverse\n  Engineering Micro-architectural Leakage Features Is Practical","volume":"13277","author":"Si Gao","year":"2022"},{"key":"ref40:CCS:KniMor22","doi-asserted-by":"publisher","first-page":"1799","DOI":"10.1145\/3548606.3559362","article-title":"Low-Latency Hardware Private Circuits","author":"David Knichel","year":"2022"},{"key":"ref41:CCS:FGMRSSS23","doi-asserted-by":"publisher","first-page":"990","DOI":"10.1145\/3576915.3623129","article-title":"Combined Private Circuits - Combined Security Refurbished","author":"Jakob Feldtkeller","year":"2023"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T16:28:36Z","timestamp":1733848116000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/3\/35"}},"issued":{"date-parts":[[2024,10,7]]},"references-count":41,"URL":"https:\/\/doi.org\/10.62056\/ab89ksdja","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2024,10,7]]},"assertion":[{"value":"2024-07-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-3-99"},{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T09:29:31Z","timestamp":1785403771254,"version":"3.56.0"},"reference-count":128,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T00:00:00Z","timestamp":1704758400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,6,4]]},"abstract":"<jats:p>\n                    Masking is a prominent strategy to protect cryptographic implementations against side-channel analysis. Its popularity arises from the exponential security gains that can be achieved for (approximately) quadratic resource utilization. Many variants of the countermeasure tailored for different optimization goals have been proposed. The common denominator among all of them is the implicit demand for robust and high entropy randomness. Simply assuming that uniformly distributed random bits are available, without taking the cost of their generation into account, leads to a poor understanding of the efficiency vs. security tradeoff of masked implementations. This is especially relevant in case of hardware masking schemes which are known to consume large amounts of random bits per cycle due to parallelism. Currently, there seems to be no consensus on how to most efficiently derive many pseudo-random bits per clock cycle from an initial seed and with properties suitable for masked hardware implementations. In this work, we evaluate a number of building blocks for this purpose and find that hardware-oriented stream ciphers like Trivium and its reduced-security variant Bivium\u00a0B outperform most competitors when implemented in an unrolled fashion. Unrolled implementations of these primitives enable the flexible generation of many bits per cycle, which is crucial for satisfying the large randomness demands of state-of-the-art masking schemes. According to our analysis, only Linear Feedback Shift Registers\u00a0(LFSRs), when also unrolled, are capable of producing long non-repetitive sequences of random-looking bits at a higher rate per cycle for the same or lower cost as Trivium and Bivium B. Yet, these instances do not provide black-box security as they generate only linear outputs. We experimentally demonstrate that using multiple output bits from an LFSR in the same masked implementation can violate probing security and even lead to harmful randomness cancellations. Circumventing these problems, and enabling an independent analysis of randomness generation and masking, requires the use of cryptographically stronger primitives like stream ciphers. As a result of our studies, we provide an evidence-based estimate for the cost of securely generating\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>n<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    fresh random bits per cycle. Depending on the desired level of black-box security and operating frequency, this cost can be as low as\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>20<\/mml:mn>\n                        <mml:mi>n<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    to\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>30<\/mml:mn>\n                        <mml:mi>n<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    ASIC gate equivalents\u00a0(GE) or\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>3<\/mml:mn>\n                        <mml:mi>n<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    to\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>4<\/mml:mn>\n                        <mml:mi>n<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    FPGA look-up tables\u00a0(LUTs), where\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>n<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    is the number of random bits required. Our results demonstrate that the cost per bit is (sometimes significantly) lower than estimated in previous works, incentivizing parallelism whenever exploitable. This provides further motivation to potentially move low randomness usage from a primary to a secondary design goal in hardware masking research.\n                  <\/jats:p>","DOI":"10.62056\/akdkp2fgx","type":"journal-article","created":{"date-parts":[[2024,7,8]],"date-time":"2024-07-08T11:52:04Z","timestamp":1720439524000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":12,"title":["Randomness Generation for Secure Hardware Masking \u2013 Unrolled Trivium to the Rescue"],"prefix":"10.62056","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5426-9345","authenticated-orcid":false,"given":"Ga\u00ebtan","family":"Cassiers","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02495e989","id-type":"ROR","asserted-by":"publisher"}],"name":"Crypto Group, ICTEAM Institute, UCLouvain","place":["Louvain-la-Neuve, 1348, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2978-4067","authenticated-orcid":false,"given":"Lo\u00efc","family":"Masure","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/013yean28","id-type":"ROR","asserted-by":"publisher"}],"name":"Universit\u00e9 de Montpellier, LIRMM, CNRS","place":["Montpellier, 34090, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Charles","family":"Momin","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02495e989","id-type":"ROR","asserted-by":"publisher"}],"name":"Crypto Group, ICTEAM Institute, UCLouvain","place":["Louvain-la-Neuve, 1348, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3809-9803","authenticated-orcid":false,"given":"Thorben","family":"Moos","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02495e989","id-type":"ROR","asserted-by":"publisher"}],"name":"Crypto Group, ICTEAM Institute, UCLouvain","place":["Louvain-la-Neuve, 1348, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4032-7433","authenticated-orcid":false,"given":"Amir","family":"Moradi","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05n911h24","id-type":"ROR","asserted-by":"publisher"}],"name":"TU Darmstadt","place":["Darmstadt, 64293, Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7444-0285","authenticated-orcid":false,"given":"Fran\u00e7ois-Xavier","family":"Standaert","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02495e989","id-type":"ROR","asserted-by":"publisher"}],"name":"Crypto Group, ICTEAM Institute, UCLouvain","place":["Louvain-la-Neuve, 1348, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2024,7,8]]},"reference":[{"key":"ref1:DBLP:conf\/crypto\/KocherJJ99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","article-title":"Differential Power Analysis","volume-title":"Advances in Cryptology - CRYPTO '99, 19th Annual\n  International Cryptology Conference, Santa Barbara, California, USA, August\n  15-19, 1999, Proceedings","volume":"1666","author":"Paul C. Kocher","year":"1999"},{"key":"ref2:DBLP:conf\/crypto\/ChariJRR99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"398","DOI":"10.1007\/3-540-48405-1_26","article-title":"Towards Sound Approaches to Counteract Power-Analysis\n  Attacks","volume-title":"Advances in Cryptology - CRYPTO '99, 19th Annual\n  International Cryptology Conference, Santa Barbara, California, USA, August\n  15-19, 1999, Proceedings","volume":"1666","author":"Suresh Chari","year":"1999"},{"key":"ref3:DBLP:conf\/eurocrypt\/ProuffR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/978-3-642-38348-9_9","article-title":"Masking against Side-Channel Attacks: A Formal Security\n  Proof","volume-title":"Advances in Cryptology - EUROCRYPT 2013, 32nd Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Athens, Greece, May 26-30, 2013. Proceedings","volume":"7881","author":"Emmanuel Prouff","year":"2013"},{"key":"ref4:DBLP:conf\/eurocrypt\/DucDF14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/978-3-642-55220-5_24","article-title":"Unifying Leakage Models: From Probing Attacks to Noisy\n  Leakage","volume-title":"Advances in Cryptology - EUROCRYPT 2014 - 33rd Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Copenhagen, Denmark, May 11-15, 2014. Proceedings","volume":"8441","author":"Alexandre Duc","year":"2014"},{"key":"ref5:DBLP:conf\/eurocrypt\/DucFS15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1007\/978-3-662-46800-5_16","article-title":"Making Masking Security Proofs Concrete - Or How to Evaluate\n  the Security of Any Leaking Device","volume-title":"Advances in Cryptology - EUROCRYPT 2015 - 34th Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Sofia, Bulgaria, April 26-30, 2015, Proceedings, Part I","volume":"9056","author":"Alexandre Duc","year":"2015"},{"key":"ref6:DBLP:conf\/crypto\/IshaiSW03","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-3-540-45146-4_27","article-title":"Private Circuits: Securing Hardware against Probing\n  Attacks","volume-title":"Advances in Cryptology - CRYPTO 2003, 23rd Annual\n  International Cryptology Conference, Santa Barbara, California, USA, August\n  17-21, 2003, Proceedings","volume":"2729","author":"Yuval Ishai","year":"2003"},{"key":"ref7:DBLP:conf\/ctrsa\/MangardPG05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"351","DOI":"10.1007\/978-3-540-30574-3_24","article-title":"Side-Channel Leakage of Masked CMOS Gates","volume-title":"Topics in Cryptology - CT-RSA 2005, The Cryptographers'\n  Track at the RSA Conference 2005, San Francisco, CA, USA, February 14-18,\n  2005, Proceedings","volume":"3376","author":"Stefan Mangard","year":"2005"},{"key":"ref8:DBLP:conf\/cosade\/CoronGPRRV12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1007\/978-3-642-29912-4_6","article-title":"Conversion of Security Proofs from One Leakage Model to\n  Another: A New Issue","volume-title":"Constructive Side-Channel Analysis and Secure Design - Third\n  International Workshop, COSADE 2012, Darmstadt, Germany, May 3-4, 2012.\n  Proceedings","volume":"7275","author":"Jean-S\u00e9bastien Coron","year":"2012"},{"key":"ref9:DBLP:conf\/cosade\/CnuddeBGNNR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-319-64647-3_1","article-title":"Does Coupling Affect the Security of Masked\n  Implementations?","volume-title":"Constructive Side-Channel Analysis and Secure Design - 8th\n  International Workshop, COSADE 2017, Paris, France, April 13-14, 2017,\n  Revised Selected Papers","volume":"10348","author":"Thomas De Cnudde","year":"2017"},{"key":"ref10:DBLP:conf\/icics\/NikovaRR06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"529","DOI":"10.1007\/11935308_38","article-title":"Threshold Implementations Against Side-Channel Attacks and\n  Glitches","volume-title":"Information and Communications Security, 8th International\n  Conference, ICICS 2006, Raleigh, NC, USA, December 4-7, 2006, Proceedings","volume":"4307","author":"Svetla Nikova","year":"2006"},{"key":"ref11:DBLP:conf\/icisc\/NikovaRS08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1007\/978-3-642-00730-9_14","article-title":"Secure Hardware Implementation of Non-linear Functions in\n  the Presence of Glitches","volume-title":"Information Security and Cryptology - ICISC 2008, 11th\n  International Conference, Seoul, Korea, December 3-5, 2008, Revised Selected\n  Papers","volume":"5461","author":"Svetla Nikova","year":"2008"},{"key":"ref12:DBLP:conf\/crypto\/ReparazBNGV15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"764","DOI":"10.1007\/978-3-662-47989-6_37","article-title":"Consolidating Masking Schemes","volume-title":"Advances in Cryptology - CRYPTO 2015 - 35th Annual\n  Cryptology Conference, Santa Barbara, CA, USA, August 16-20, 2015,\n  Proceedings, Part I","volume":"9215","author":"Oscar Reparaz","year":"2015"},{"key":"ref13:DBLP:conf\/ccs\/GrossMK16","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/2996366.2996426","article-title":"Domain-Oriented Masking: Compact Masked Hardware\n  Implementations with Arbitrary Protection Order","volume-title":"Proceedings of the ACM Workshop on Theory of\n  Implementation Security, TIS@CCS 2016 Vienna, Austria, October, 2016","author":"Hannes Gro\u00df","year":"2016"},{"key":"ref14:DBLP:conf\/ctrsa\/GrossMK17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1007\/978-3-319-52153-4_6","article-title":"An Efficient Side-Channel Protected AES Implementation\n  with Arbitrary Protection Order","volume-title":"Topics in Cryptology - CT-RSA 2017 - The Cryptographers'\n  Track at the RSA Conference 2017, San Francisco, CA, USA, February 14-17,\n  2017, Proceedings","volume":"10159","author":"Hannes Gro\u00df","year":"2017"},{"key":"ref15:DBLP:conf\/ches\/GrossM17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/978-3-319-66787-4_6","article-title":"Reconciling d+1 Masking in Hardware and Software","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2017 -\n  19th International Conference, Taipei, Taiwan, September 25-28, 2017,\n  Proceedings","volume":"10529","author":"Hannes Gro\u00df","year":"2017"},{"key":"ref16:DBLP:conf\/asiacrypt\/BilginGNNR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1007\/978-3-662-45608-8_18","article-title":"Higher-Order Threshold Implementations","volume-title":"Advances in Cryptology - ASIACRYPT 2014 - 20th\n  International Conference on the Theory and Application of Cryptology and\n  Information Security, Kaoshiung, Taiwan, R.O.C., December 7-11, 2014,\n  Proceedings, Part II","volume":"8874","author":"Beg\u00fcl Bilgin","year":"2014"},{"key":"ref17:DBLP:journals\/iacr\/Reparaz15","first-page":"1","article-title":"A note on the security of Higher-Order Threshold\n  Implementations","author":"Oscar Reparaz","year":"2015","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref18:DBLP:conf\/ccs\/BartheBDFGSZ16","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1145\/2976749.2978427","article-title":"Strong Non-Interference and Type-Directed Higher-Order\n  Masking","volume-title":"Proceedings of the 2016 ACM SIGSAC Conference on\n  Computer and Communications Security, Vienna, Austria, October 24-28, 2016","author":"Gilles Barthe","year":"2016"},{"key":"ref19:DBLP:journals\/tches\/FaustGPPS18","doi-asserted-by":"publisher","first-page":"89","DOI":"10.13154\/tches.v2018.i3.89-120","article-title":"Composable Masking Schemes in the Presence of Physical\n  Defaults & the Robust Probing Model","volume":"2018","author":"Sebastian Faust","year":"2018","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref20:DBLP:journals\/tches\/MoosMSS19","doi-asserted-by":"publisher","first-page":"256","DOI":"10.13154\/tches.v2019.i2.256-292","article-title":"Glitch-Resistant Masking Revisited or Why Proofs in the\n  Robust Probing Model are Needed","volume":"2019","author":"Thorben Moos","year":"2019","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref21:DBLP:journals\/tifs\/CassiersS20","doi-asserted-by":"publisher","first-page":"2542","DOI":"10.1109\/TIFS.2020.2971153","article-title":"Trivially and Efficiently Composing Masked Gadgets With\n  Probe Isolating Non-Interference","volume":"15","author":"Ga\u00ebtan Cassiers","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref22:DBLP:journals\/tc\/CassiersGLS21","doi-asserted-by":"publisher","first-page":"1677","DOI":"10.1109\/TC.2020.3022979","article-title":"Hardware Private Circuits: From Trivial Composition to Full\n  Verification","volume":"70","author":"Ga\u00ebtan Cassiers","year":"2021","journal-title":"IEEE Trans. Computers"},{"key":"ref23:DBLP:conf\/ccs\/Knichel022","doi-asserted-by":"publisher","first-page":"1799","DOI":"10.1145\/3548606.3559362","article-title":"Low-Latency Hardware Private Circuits","volume-title":"Proceedings of the 2022 ACM SIGSAC Conference on\n  Computer and Communications Security, CCS 2022, Los Angeles, CA, USA,\n  November 7-11, 2022","author":"David Knichel","year":"2022"},{"key":"ref24:DBLP:journals\/tches\/KnichelM22","doi-asserted-by":"publisher","first-page":"114","DOI":"10.46586\/tches.v2022.i3.114-140","article-title":"Composable Gadgets with Reused Fresh Masks First-Order\n  Probing-Secure Hardware Circuits with only 6 Fresh Masks","volume":"2022","author":"David Knichel","year":"2022","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref25:DBLP:conf\/asiacrypt\/KnichelS020","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"787","DOI":"10.1007\/978-3-030-64837-4_26","article-title":"SILVER - Statistical Independence and Leakage\n  Verification","volume-title":"Advances in Cryptology - ASIACRYPT 2020 - 26th\n  International Conference on the Theory and Application of Cryptology and\n  Information Security, Daejeon, South Korea, December 7-11, 2020, Proceedings,\n  Part I","volume":"12491","author":"David Knichel","year":"2020"},{"key":"ref26:DBLP:journals\/tches\/KnichelMMS22","doi-asserted-by":"publisher","first-page":"589","DOI":"10.46586\/tches.v2022.i1.589-629","article-title":"Automated Generation of Masked Hardware","volume":"2022","author":"David Knichel","year":"2022","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref27:DBLP:journals\/tches\/CassiersS21","doi-asserted-by":"publisher","first-page":"136","DOI":"10.46586\/TCHES.V2021.I2.136-158","article-title":"Provably Secure Hardware Masking in the Transition- and\n  Glitch-Robust Probing Model: Better Safe than Sorry","volume":"2021","author":"Ga\u00ebtan Cassiers","year":"2021","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref28:DBLP:journals\/tches\/KnichelSM22","doi-asserted-by":"publisher","first-page":"323","DOI":"10.46586\/tches.v2022.i1.323-344","article-title":"Generic Hardware Private Circuits Towards Automated\n  Generation of Composable Secure Gadgets","volume":"2022","author":"David Knichel","year":"2022","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref29:DBLP:conf\/cosade\/MominCS22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/978-3-030-99766-3_12","article-title":"Handcrafting: Improving Automated Masking in Hardware with\n  Manual Optimizations","volume-title":"Constructive Side-Channel Analysis and Secure Design - 13th\n  International Workshop, COSADE 2022, Leuven, Belgium, April 11-12, 2022,\n  Proceedings","volume":"13211","author":"Charles Momin","year":"2022"},{"key":"ref30:DBLP:conf\/eurocrypt\/BelaidBPPTV16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"616","DOI":"10.1007\/978-3-662-49896-5_22","article-title":"Randomness Complexity of Private Circuits for\n  Multiplication","volume-title":"Advances in Cryptology - EUROCRYPT 2016 - 35th Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Vienna, Austria, May 8-12, 2016, Proceedings, Part II","volume":"9666","author":"Sonia Bela\u00efd","year":"2016"},{"key":"ref31:DBLP:conf\/indocrypt\/JouxD06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1007\/11941378_31","article-title":"Galois LFSR, Embedded Devices and Side Channel Weaknesses","volume-title":"Progress in Cryptology - INDOCRYPT 2006, 7th International\n  Conference on Cryptology in India, Kolkata, India, December 11-13, 2006,\n  Proceedings","volume":"4329","author":"Antoine Joux","year":"2006"},{"key":"ref32:DBLP:conf\/indocrypt\/BurmanMV07","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"384","DOI":"10.1007\/978-3-540-77026-8_30","article-title":"LFSR Based Stream Ciphers Are Vulnerable to Power\n  Attacks","volume-title":"Progress in Cryptology - INDOCRYPT 2007, 8th International\n  Conference on Cryptology in India, Chennai, India, December 9-13, 2007,\n  Proceedings","volume":"4859","author":"Sanjay Burman","year":"2007"},{"key":"ref33:DBLP:conf\/space\/ChakrabortyMM14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1007\/978-3-319-12060-7_2","article-title":"Fibonacci LFSR vs. Galois LFSR: Which is More Vulnerable\n  to Power Attacks?","volume-title":"Security, Privacy, and Applied Cryptography Engineering -\n  4th International Conference, SPACE 2014, Pune, India, October 18-22, 2014.\n  Proceedings","volume":"8804","author":"Abhishek Chakraborty","year":"2014"},{"key":"ref34:DBLP:conf\/secrypt\/MeranehCBM022","doi-asserted-by":"publisher","first-page":"25","DOI":"10.5220\/0011135300003283","article-title":"Blind Side Channel on the Elephant LFSR","volume-title":"Proceedings of the 19th International Conference on Security\n  and Cryptography, SECRYPT 2022, Lisbon, Portugal, July 11-13, 2022","author":"Awaleh Houssein Meraneh","year":"2022"},{"key":"ref35:NIST_Statistical_Test_Suite","article-title":"A Statistical Test Suite for Random and Pseudorandom Number\n  Generators for Cryptographic Applications - Rev. 1a","author":"Lawrence E. Bassham","year":"2010","journal-title":"NIST Special Publication (SP) 800-22"},{"key":"ref36:DBLP:conf\/ches\/GrossoSF13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"400","DOI":"10.1007\/978-3-642-40349-1_23","article-title":"Masking vs. Multiparty Computation: How Large Is the Gap for\n  AES?","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2013 -\n  15th International Workshop, Santa Barbara, CA, USA, August 20-23, 2013.\n  Proceedings","volume":"8086","author":"Vincent Grosso","year":"2013"},{"key":"ref37:DBLP:conf\/cardis\/GrossoSP13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-319-08302-5_3","article-title":"Low Entropy Masking Schemes, Revisited","volume-title":"Smart Card Research and Advanced Applications - 12th\n  International Conference, CARDIS 2013, Berlin, Germany, November 27-29,\n  2013. Revised Selected Papers","volume":"8419","author":"Vincent Grosso","year":"2013"},{"key":"ref38:DBLP:conf\/cardis\/YeE13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1007\/978-3-319-08302-5_4","article-title":"On the Vulnerability of Low Entropy Masking Schemes","volume-title":"Smart Card Research and Advanced Applications - 12th\n  International Conference, CARDIS 2013, Berlin, Germany, November 27-29,\n  2013. Revised Selected Papers","volume":"8419","author":"Xin Ye","year":"2013"},{"key":"ref39:DBLP:books\/daglib\/0023872","isbn-type":"print","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04101-3","article-title":"Understanding Cryptography - A Textbook for Students and\n  Practitioners","author":"Christof Paar","year":"2010","ISBN":"https:\/\/id.crossref.org\/isbn\/9783642041006"},{"key":"ref40:DBLP:conf\/africacrypt\/BilginGNNR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/978-3-319-06734-6_17","article-title":"A More Efficient AES Threshold Implementation","volume-title":"Progress in Cryptology - AFRICACRYPT 2014 - 7th\n  International Conference on Cryptology in Africa, Marrakesh, Morocco, May\n  28-30, 2014. Proceedings","volume":"8469","author":"Beg\u00fcl Bilgin","year":"2014"},{"key":"ref41:DBLP:journals\/tc\/UenoHMMMNBMGD20","doi-asserted-by":"publisher","first-page":"534","DOI":"10.1109\/TC.2019.2957355","article-title":"High Throughput\/Gate AES Hardware Architectures Based on\n  Datapath Compression","volume":"69","author":"Rei Ueno","year":"2020","journal-title":"IEEE Trans. Computers"},{"key":"ref42:DBLP:conf\/ches\/CnuddeRBNNR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"194","DOI":"10.1007\/978-3-662-53140-2_10","article-title":"Masking AES with d+1 Shares in Hardware","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2016 -\n  18th International Conference, Santa Barbara, CA, USA, August 17-19, 2016,\n  Proceedings","volume":"9813","author":"Thomas De Cnudde","year":"2016"},{"key":"ref43:DBLP:conf\/asiacrypt\/BorghoffCGKKKLNPRRTY12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1007\/978-3-642-34961-4_14","article-title":"PRINCE - A Low-Latency Block Cipher for Pervasive\n  Computing Applications - Extended Abstract","volume-title":"Advances in Cryptology - ASIACRYPT 2012 - 18th\n  International Conference on the Theory and Application of Cryptology and\n  Information Security, Beijing, China, December 2-6, 2012. Proceedings","volume":"7658","author":"Julia Borghoff","year":"2012"},{"key":"ref44:DBLP:journals\/tches\/SasdrichBHM20","doi-asserted-by":"publisher","first-page":"300","DOI":"10.13154\/tches.v2020.i2.300-326","article-title":"Low-Latency Hardware Masking with Application to AES","volume":"2020","author":"Pascal Sasdrich","year":"2020","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref45:DBLP:conf\/ches\/BertoniDPA10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-642-15031-9_3","article-title":"Sponge-Based Pseudo-Random Number Generators","volume-title":"Cryptographic Hardware and Embedded Systems, CHES 2010,\n  12th International Workshop, Santa Barbara, CA, USA, August 17-20, 2010.\n  Proceedings","volume":"6225","author":"Guido Bertoni","year":"2010"},{"key":"ref46:DBLP:conf\/eurocrypt\/BertoniDPA13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1007\/978-3-642-38348-9_19","article-title":"Keccak","volume-title":"Advances in Cryptology - EUROCRYPT 2013, 32nd Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Athens, Greece, May 26-30, 2013. Proceedings","volume":"7881","author":"Guido Bertoni","year":"2013"},{"key":"ref47:DBLP:conf\/rfidsec\/KavunY10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"258","DOI":"10.1007\/978-3-642-16822-2_20","article-title":"A Lightweight Implementation of Keccak Hash Function for\n  Radio-Frequency Identification Applications","volume-title":"Radio Frequency Identification: Security and Privacy Issues\n  - 6th International Workshop, RFIDSec 2010, Istanbul, Turkey, June 8-9, 2010,\n  Revised Selected Papers","volume":"6370","author":"Elif Bilge Kavun","year":"2010"},{"key":"ref48:DBLP:journals\/tches\/Meyer0W18","doi-asserted-by":"publisher","first-page":"596","DOI":"10.13154\/tches.v2018.i3.596-626","article-title":"Spin Me Right Round Rotational Symmetry for FPGA-Specific\n  AES","volume":"2018","author":"Lauren De Meyer","year":"2018","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref49:DBLP:journals\/tches\/Moos19","doi-asserted-by":"publisher","first-page":"202","DOI":"10.13154\/tches.v2019.i3.202-232","article-title":"Static Power SCA of Sub-100 nm CMOS ASICs and the\n  Insecurity of Masking Schemes in Low-Noise Environments","volume":"2019","author":"Thorben Moos","year":"2019","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref50:DBLP:journals\/tches\/ShahmirzadiM21a","doi-asserted-by":"publisher","first-page":"708","DOI":"10.46586\/tches.v2021.i3.708-755","article-title":"Second-Order SCA Security with almost no Fresh\n  Randomness","volume":"2021","author":"Aein Rezaei Shahmirzadi","year":"2021","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref51:DBLP:conf\/cardis\/Picek0RVWCM16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1007\/978-3-319-54669-8_13","article-title":"PRNGs for Masking Applications and Their Mapping to\n  Evolvable Hardware","volume-title":"Smart Card Research and Advanced Applications - 15th\n  International Conference, CARDIS 2016, Cannes, France, November 7-9, 2016,\n  Revised Selected Papers","volume":"10146","author":"Stjepan Picek","year":"2016"},{"key":"ref52:DBLP:journals\/tches\/MeyerRB18","doi-asserted-by":"publisher","first-page":"431","DOI":"10.13154\/tches.v2018.i3.431-468","article-title":"Multiplicative Masking for AES in Hardware","volume":"2018","author":"Lauren De Meyer","year":"2018","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref53:DBLP:journals\/tches\/0001RGMV18","doi-asserted-by":"publisher","first-page":"267","DOI":"10.13154\/tches.v2018.i3.267-292","article-title":"ES-TRNG: A High-throughput, Low-area True Random Number\n  Generator based on Edge Sampling","volume":"2018","author":"Bohan Yang","year":"2018","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref54:NISTLWC","article-title":"Lightweight Cryptography","author":"National Institute of Standards","year":"2017"},{"key":"ref55:ESTREAM","article-title":"eSTREAM: the ECRYPT Stream Cipher Project","author":"European Network of Excellence in Cryptology (ECRYPT)","year":"2004"},{"key":"ref56:DBLP:journals\/tosc\/DaemenMMR20","doi-asserted-by":"publisher","first-page":"262","DOI":"10.13154\/tosc.v2020.iS1.262-294","article-title":"The Subterranean 2.0 Cipher Suite","volume":"2020","author":"Joan Daemen","year":"2020","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref57:DBLP:journals\/iacr\/AagaardZ21","first-page":"49","article-title":"ASIC Benchmarking of Round 2 Candidates in the NIST\n  Lightweight Cryptography Standardization Process: (Preliminary Results)","author":"Mark D. Aagaard","year":"2021","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref58:DBLP:conf\/ches\/BernsteinKLMMN017","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"299","DOI":"10.1007\/978-3-319-66787-4_15","article-title":"Gimli : A Cross-Platform Permutation","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2017 -\n  19th International Conference, Taipei, Taiwan, September 25-28, 2017,\n  Proceedings","volume":"10529","author":"Daniel J. Bernstein","year":"2017"},{"key":"ref59:DBLP:journals\/tches\/LeanderMMR21","doi-asserted-by":"publisher","first-page":"510","DOI":"10.46586\/tches.v2021.i4.510-545","article-title":"The SPEEDY Family of Block Ciphers Engineering an Ultra\n  Low-Latency Cipher from Gate Level for Secure Processor Architectures","volume":"2021","author":"Gregor Leander","year":"2021","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref60:DBLP:conf\/isw\/Canniere06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1007\/11836810_13","article-title":"Trivium: A Stream Cipher Construction Inspired by Block\n  Cipher Design Principles","volume-title":"Information Security, 9th International Conference, ISC\n  2006, Samos Island, Greece, August 30 - September 2, 2006, Proceedings","volume":"4176","author":"Christophe De Canni\u00e8re","year":"2006"},{"key":"ref61:DBLP:series\/lncs\/CanniereP08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"244","DOI":"10.1007\/978-3-540-68351-3_18","article-title":"Trivium","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"Christophe De Canni\u00e8re","year":"2008"},{"key":"ref62:raddum2006cryptanalytic","article-title":"Cryptanalytic results on Trivium","author":"Havard Raddum","year":"2006","journal-title":"eSTREAM, ECRYPT Stream Cipher Project, Report 2006\/039"},{"key":"ref63:DBLP:conf\/fse\/CanteautCFLNPS16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1007\/978-3-662-52993-5_16","article-title":"Stream Ciphers: A Practical Solution for Efficient\n  Homomorphic-Ciphertext Compression","volume-title":"Fast Software Encryption - 23rd International Conference,\n  FSE 2016, Bochum, Germany, March 20-23, 2016, Revised Selected Papers","volume":"9783","author":"Anne Canteaut","year":"2016"},{"key":"ref64:DBLP:journals\/ijwmc\/HellJM07","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1504\/IJWMC.2007.013798","article-title":"Grain: a stream cipher for constrained environments","volume":"2","author":"Martin Hell","year":"2007","journal-title":"Int. J. Wirel. Mob. Comput."},{"key":"ref65:DBLP:conf\/isit\/Hell0MM06","doi-asserted-by":"publisher","first-page":"1614","DOI":"10.1109\/ISIT.2006.261549","article-title":"A Stream Cipher Proposal: Grain-128","volume-title":"Proceedings 2006 IEEE International Symposium on\n  Information Theory, ISIT 2006, The Westin Seattle, Seattle, Washington,\n  USA, July 9-14, 2006","author":"Martin Hell","year":"2006"},{"key":"ref66:DBLP:series\/lncs\/BabbageD08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1007\/978-3-540-68351-3_15","article-title":"The MICKEY Stream Ciphers","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"Steve Babbage","year":"2008"},{"key":"ref67:DBLP:series\/lncs\/GoodB08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/978-3-540-68351-3_19","article-title":"ASIC Hardware Performance","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"Tim Good","year":"2008"},{"key":"ref68:Grkaynak2006HardwareEO","article-title":"Hardware Evaluation of Estream Candidates","author":"Frank K. G\u00fcrkaynak","year":"2006"},{"key":"ref69:Bulens2007FPGAIO","article-title":"FPGA Implementations of eSTREAM Phase-2 Focus Candidates\n  with Hardware Profile","author":"Philippe Bulens","year":"2007"},{"key":"ref70:Gaj2007ComparisonOH","article-title":"Comparison of hardware performance of selected Phase II\n  eSTREAM candidates","author":"Kris Gaj","year":"2007"},{"key":"ref71:Rogawski2007HardwareEO","article-title":"Hardware evaluation of eSTREAM Candidates: Grain, Lex,\n  Mickey128, Salsa20 and Trivium","author":"Marcin Rogawski","year":"2007"},{"key":"ref72:Hwang2008ComparisonOF","article-title":"Comparison of FPGA-Targeted Hardware Implementations of\n  eSTREAM Stream Cipher Candidates","author":"David Hwang","year":"2008"},{"key":"ref73:DBLP:journals\/mam\/KitsosSPS13","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1016\/j.micpro.2012.09.007","article-title":"FPGA-based performance analysis of stream ciphers ZUC,\n  Snow3g, Grain V1, Mickey V2, Trivium and E0","volume":"37","author":"Paris Kitsos","year":"2013","journal-title":"Microprocess. Microsystems"},{"key":"ref74:DBLP:journals\/mam\/LiLL20","doi-asserted-by":"publisher","first-page":"103210","DOI":"10.1016\/j.micpro.2020.103210","article-title":"FPGA implementations of Grain v1, Mickey 2.0, Trivium,\n  Lizard and Plantlet","volume":"78","author":"Bohan Li","year":"2020","journal-title":"Microprocess. Microsystems"},{"key":"ref75:DBLP:conf\/crypto\/TodoIMAZ18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1007\/978-3-319-96881-0_5","article-title":"Fast Correlation Attack Revisited - Cryptanalysis on Full\n  Grain-128a, Grain-128, and Grain-v1","volume-title":"Advances in Cryptology - CRYPTO 2018 - 38th Annual\n  International Cryptology Conference, Santa Barbara, CA, USA, August 19-23,\n  2018, Proceedings, Part II","volume":"10992","author":"Yosuke Todo","year":"2018"},{"key":"ref76:DBLP:journals\/jce\/MedwedS11","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1007\/S13389-011-0014-Y","article-title":"Extractors against side-channel attacks: weak or strong?","volume":"1","author":"Marcel Medwed","year":"2011","journal-title":"J. Cryptogr. Eng."},{"key":"ref77:DBLP:reference\/crypt\/Canteaut11c","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1007\/978-1-4419-5906-5_339","article-title":"Correlation Attack for Stream Ciphers","volume-title":"Encyclopedia of Cryptography and Security, 2nd Ed","author":"Anne Canteaut","year":"2011"},{"key":"ref78:DBLP:conf\/ches\/BattistelloCPZ16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-662-53140-2_2","article-title":"Horizontal Side-Channel Attacks and Countermeasures on the\n  ISW Masking Scheme","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2016 -\n  18th International Conference, Santa Barbara, CA, USA, August 17-19, 2016,\n  Proceedings","volume":"9813","author":"Alberto Battistello","year":"2016"},{"key":"ref79:DBLP:conf\/ches\/FischerD02","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"415","DOI":"10.1007\/3-540-36400-5_30","article-title":"True Random Number Generator Embedded in Reconfigurable\n  Hardware","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2002,\n  4th International Workshop, Redwood Shores, CA, USA, August 13-15, 2002,\n  Revised Papers","volume":"2523","author":"Viktor Fischer","year":"2002"},{"key":"ref80:DBLP:conf\/ches\/FischerL14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"527","DOI":"10.1007\/978-3-662-44709-3_29","article-title":"Embedded Evaluation of Randomness in Oscillator Based\n  Elementary TRNG","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2014 -\n  16th International Workshop, Busan, South Korea, September 23-26, 2014.\n  Proceedings","volume":"8731","author":"Viktor Fischer","year":"2014"},{"key":"ref81:DBLP:conf\/fpl\/PeturaMBFB16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/FPL.2016.7577379","article-title":"A survey of AIS-20\/31 compliant TRNG cores suitable for\n  FPGA devices","volume-title":"26th International Conference on Field Programmable Logic\n  and Applications, FPL 2016, Lausanne, Switzerland, August 29 - September 2,\n  2016","author":"Oto Petura","year":"2016"},{"key":"ref82:DBLP:conf\/focs\/BlumM82","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1109\/SFCS.1982.72","article-title":"How to Generate Cryptographically Strong Sequences of Pseudo\n  Random Bits","volume-title":"23rd Annual Symposium on Foundations of Computer Science,\n  Chicago, Illinois, USA, 3-5 November 1982","author":"Manuel Blum","year":"1982"},{"key":"ref83:DBLP:conf\/ccs\/YuSPY10","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1145\/1866307.1866324","article-title":"Practical leakage-resilient pseudorandom generators","volume-title":"Proceedings of the 17th ACM Conference on Computer and\n  Communications Security, CCS 2010, Chicago, Illinois, USA, October 4-8,\n  2010","author":"Yu Yu","year":"2010"},{"key":"ref84:DBLP:series\/isc\/StandaertPYQYO10","series-title":"Information Security and Cryptography","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/978-3-642-14452-3_5","article-title":"Leakage Resilient Cryptography in Practice","volume-title":"Towards Hardware-Intrinsic Security - Foundations and\n  Practice","author":"Fran\u00e7ois-Xavier Standaert","year":"2010"},{"key":"ref85:DBLP:conf\/crypto\/BelliziaBCGGMPP20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"369","DOI":"10.1007\/978-3-030-56784-2_13","article-title":"Mode-Level vs. Implementation-Level Physical Security in\n  Symmetric Cryptography - A Practical Guide Through the Leakage-Resistance\n  Jungle","volume-title":"Advances in Cryptology - CRYPTO 2020 - 40th Annual\n  International Cryptology Conference, CRYPTO 2020, Santa Barbara, CA, USA,\n  August 17-21, 2020, Proceedings, Part I","volume":"12170","author":"Davide Bellizia","year":"2020"},{"key":"ref86:DBLP:conf\/sacrypt\/MaximovB07","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1007\/978-3-540-77360-3_3","article-title":"Two Trivial Attacks on Trivium","volume-title":"Selected Areas in Cryptography, 14th International Workshop,\n  SAC 2007, Ottawa, Canada, August 16-17, 2007, Revised Selected Papers","volume":"4876","author":"Alexander Maximov","year":"2007"},{"key":"ref87:DBLP:conf\/africacrypt\/HuangL11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/978-3-642-21969-6_5","article-title":"Attacking Bivium and Trivium with the Characteristic Set\n  Method","volume-title":"Progress in Cryptology - AFRICACRYPT 2011 - 4th\n  International Conference on Cryptology in Africa, Dakar, Senegal, July 5-7,\n  2011. Proceedings","volume":"6737","author":"Zhenyu Huang","year":"2011"},{"key":"ref88:DBLP:conf\/space\/ShahapureSD19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/978-3-030-35869-3_5","article-title":"Internal State Recovery Attack on Stream Ciphers: Breaking\n  BIVIUM","volume-title":"Security, Privacy, and Applied Cryptography Engineering -\n  9th International Conference, SPACE 2019, Gandhinagar, India, December 3-7,\n  2019, Proceedings","volume":"11947","author":"Shravani Shahapure","year":"2019"},{"key":"ref89:DBLP:journals\/tosc\/BanikMAIMBWR18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.13154\/TOSC.V2018.I2.1-19","article-title":"Towards Low Energy Stream Ciphers","volume":"2018","author":"Subhadeep Banik","year":"2018","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref90:DBLP:journals\/sncs\/LeviBS22","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1007\/s42979-022-01219-5","article-title":"Tight-ES-TRNG: Improved Construction and Robustness\n  Analysis","volume":"3","author":"Itamar Levi","year":"2022","journal-title":"SN Comput. Sci."},{"key":"ref91:DBLP:conf\/async\/CherkaouiFAF13","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1109\/ASYNC.2013.15","article-title":"A Self-Timed Ring Based True Random Number Generator","volume-title":"19th IEEE International Symposium on Asynchronous Circuits\n  and Systems, ASYNC 2013, Santa Monica, CA, USA, May 19-22, 2013","author":"Abdelkarim Cherkaoui","year":"2013"},{"key":"ref92:DBLP:conf\/ches\/CherkaouiFFA13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1007\/978-3-642-40349-1_11","article-title":"A Very High Speed True Random Number Generator with Entropy\n  Assessment","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2013 -\n  15th International Workshop, Santa Barbara, CA, USA, August 20-23, 2013.\n  Proceedings","volume":"8086","author":"Abdelkarim Cherkaoui","year":"2013"},{"key":"ref93:DBLP:conf\/crypto\/DziembowskiFHJM16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"272","DOI":"10.1007\/978-3-662-53008-5_10","article-title":"Towards Sound Fresh Re-keying with Hard (Physical) Learning\n  Problems","volume-title":"Advances in Cryptology - CRYPTO 2016 - 36th Annual\n  International Cryptology Conference, Santa Barbara, CA, USA, August 14-18,\n  2016, Proceedings, Part II","volume":"9815","author":"Stefan Dziembowski","year":"2016"},{"key":"ref94:A511998","article-title":"A pedagogical implementation of A5\/1","author":"Marc Briceno","year":"1998"},{"key":"ref95:DBLP:books\/daglib\/0078909","isbn-type":"print","volume-title":"Applied cryptography - protocols, algorithms, and source\n  code in C, 2nd Edition","author":"Bruce Schneier","year":"1996","ISBN":"https:\/\/id.crossref.org\/isbn\/9780471117094"},{"key":"ref96:E02001","article-title":"Specification of the Bluetooth System - Version 1.1"},{"key":"ref97:DBLP:conf\/indocrypt\/BihamD00","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1007\/3-540-44495-5_5","article-title":"Cryptanalysis of the A5\/1 GSM Stream Cipher","volume-title":"Progress in Cryptology - INDOCRYPT 2000, First\n  International Conference in Cryptology in India, Calcutta, India, December\n  10-13, 2000, Proceedings","volume":"1977","author":"Eli Biham","year":"2000"},{"key":"ref98:SNOW3G2006","article-title":"Specification of the 3GPP Confidentiality and Integrity\n  Algorithms UEA2 & UIA2. Document 2: SNOW 3G Specification"},{"key":"ref99:Phelix2005","article-title":"Phelix: Fast Encryption and Authentication in a Single\n  Cryptographic Primitive","author":"Doug Whiting","year":"2005"},{"key":"ref100:DBLP:series\/lncs\/Biryukov08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1007\/978-3-540-68351-3_5","article-title":"Design of a New Stream Cipher-LEX","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"Alex Biryukov","year":"2008"},{"key":"ref101:Achterbahn2005","article-title":"The Achterbahn Stream Cipher","author":"Berndt M. Gammel","year":"2005"},{"key":"ref102:MOSQUITO2005","article-title":"The self-synchronizing stream cipher Mosquito: eSTREAM\n  documentation, version 2","author":"Joan Daemen","year":"2005"},{"key":"ref103:SFINKS2005","article-title":"SFINKS: A Synchronous Stream Cipher for Restricted Hardware\n  Environments","author":"An Braeken","year":"2005"},{"key":"ref104:VEST2005","article-title":"VEST - Hardware-Dedicated Stream Ciphers","author":"Sean O'Neil","year":"2005"},{"key":"ref105:ZK-Crypt2005","article-title":"ZK-Crypt - a Compact Stream Cipher and more","author":"Carmi Gressel","year":"2005"},{"key":"ref106:DBLP:series\/lncs\/BerbainBCCDGGGGLMPS08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"140","DOI":"10.1007\/978-3-540-68351-3_11","article-title":"Decimv2","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"C\u00f4me Berbain","year":"2008"},{"key":"ref107:DBLP:series\/lncs\/GligoroskiMK08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1007\/978-3-540-68351-3_12","article-title":"The Stream Cipher Edon80","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"Danilo Gligoroski","year":"2008"},{"key":"ref108:DBLP:series\/lncs\/ArnaultBL08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"170","DOI":"10.1007\/978-3-540-68351-3_13","article-title":"F-FCSR Stream Ciphers","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"Fran\u00e7ois Arnault","year":"2008"},{"key":"ref109:DBLP:series\/lncs\/DaemenK08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"210","DOI":"10.1007\/978-3-540-68351-3_16","article-title":"The Self-synchronizing Stream Cipher Moustique","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"Joan Daemen","year":"2008"},{"key":"ref110:DBLP:series\/lncs\/JansenHK08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1007\/978-3-540-68351-3_17","article-title":"Cascade Jump Controlled Sequence Generator and Pomaranch\n  Stream Cipher","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"Cees J. A. Jansen","year":"2008"},{"key":"ref111:DBLP:series\/lncs\/Bernstein08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1007\/978-3-540-68351-3_8","article-title":"The Salsa20 Family of Stream Ciphers","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","volume":"4986","author":"Daniel J. Bernstein","year":"2008"},{"key":"ref112:ZUC2011","article-title":"Specification of the 3GPP Confidentiality and Integrity\n  Algorithms 128-EEA3 & 128-EIA3. Document 2: ZUC Specification"},{"key":"ref113:DBLP:journals\/tosc\/MikhalevAM16","doi-asserted-by":"publisher","first-page":"52","DOI":"10.13154\/tosc.v2016.i2.52-79","article-title":"On Ciphers that Continuously Access the Non-Volatile Key","volume":"2016","author":"Vasily Mikhalev","year":"2016","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref114:DBLP:journals\/tosc\/HamannKM17","doi-asserted-by":"publisher","first-page":"45","DOI":"10.13154\/tosc.v2017.i1.45-79","article-title":"LIZARD - A Lightweight Stream Cipher for\n  Power-constrained Devices","volume":"2017","author":"Matthias Hamann","year":"2017","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref115:DBLP:conf\/acns\/BanikCM23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"178","DOI":"10.1007\/978-3-031-33488-7_7","article-title":"Near Collision Attack Against Grain V1","volume-title":"Applied Cryptography and Network Security - 21st\n  International Conference, ACNS 2023, Kyoto, Japan, June 19-22, 2023,\n  Proceedings, Part I","volume":"13905","author":"Subhadeep Banik","year":"2023"},{"key":"ref116:Gierlichs2008SusceptibilityOE","article-title":"Susceptibility of eSTREAM Candidates towards Side Channel\n  Analysis","author":"Benedikt Gierlichs","year":"2008"},{"key":"ref117:DBLP:reference\/crypt\/Canteaut11e","doi-asserted-by":"publisher","first-page":"458","DOI":"10.1007\/978-1-4419-5906-5_349","article-title":"Filter Generator","volume-title":"Encyclopedia of Cryptography and Security, 2nd Ed","author":"Anne Canteaut","year":"2011"},{"key":"ref118:DBLP:reference\/crypt\/Canteaut11b","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1007\/978-1-4419-5906-5_338","article-title":"Combination Generator","volume-title":"Encyclopedia of Cryptography and Security, 2nd Ed","author":"Anne Canteaut","year":"2011"},{"key":"ref119:DBLP:reference\/crypt\/Fontaine11","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/978-1-4419-5906-5_337","article-title":"Clock-Controlled Generator","volume-title":"Encyclopedia of Cryptography and Security, 2nd Ed","author":"Caroline Fontaine","year":"2011"},{"key":"ref120:DBLP:reference\/crypt\/Fontaine11h","doi-asserted-by":"publisher","first-page":"1197","DOI":"10.1007\/978-1-4419-5906-5_373","article-title":"Shrinking Generator","volume-title":"Encyclopedia of Cryptography and Security, 2nd Ed","author":"Caroline Fontaine","year":"2011"},{"key":"ref121:ascon","article-title":"Status Update on Ascon v1. 2","author":"Christoph Dobraunig","year":"2020","journal-title":"Submission to the NIST LWC competition"},{"key":"ref122:lfsr","article-title":"Efficient Shift Registers, LFSR Counters, and\n  Long-Pseudo-Random Generators","author":"P Alfke","year":"1996"},{"key":"ref123:DBLP:journals\/tches\/MullerM22","doi-asserted-by":"publisher","first-page":"311","DOI":"10.46586\/tches.v2022.i4.311-348","article-title":"PROLEAD A Probing-Based Hardware Leakage Detection\n  Tool","volume":"2022","author":"Nicolai M\u00fcller","year":"2022","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref124:DBLP:conf\/ches\/SchneiderM15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"495","DOI":"10.1007\/978-3-662-48324-4_25","article-title":"Leakage Assessment Methodology - A Clear Roadmap for\n  Side-Channel Evaluations","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2015 -\n  17th International Workshop, Saint-Malo, France, September 13-16, 2015,\n  Proceedings","volume":"9293","author":"Tobias Schneider","year":"2015"},{"key":"ref125:DBLP:journals\/tches\/KumarDBSJBB22","doi-asserted-by":"publisher","first-page":"166","DOI":"10.46586\/tches.v2022.i2.166-191","article-title":"Side Channel Attack On Stream Ciphers: A Three-Step\n  Approach To State\/Key Recovery","volume":"2022","author":"Satyam Kumar","year":"2022","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref126:DBLP:conf\/ches\/RenauldSV09","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1007\/978-3-642-04138-9_8","article-title":"Algebraic Side-Channel Attacks on the AES: Why Time also\n  Matters in DPA","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2009,\n  11th International Workshop, Lausanne, Switzerland, September 6-9, 2009,\n  Proceedings","volume":"5747","author":"Mathieu Renauld","year":"2009"},{"key":"ref127:DBLP:conf\/ches\/BelaidCFGKP15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-662-48324-4_20","article-title":"Improved Side-Channel Analysis of Finite-Field\n  Multiplication","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2015 -\n  17th International Workshop, Saint-Malo, France, September 13-16, 2015,\n  Proceedings","volume":"9293","author":"Sonia Bela\u00efd","year":"2015"},{"key":"ref128:DBLP:conf\/asiacrypt\/BelaidFG14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"306","DOI":"10.1007\/978-3-662-45608-8_17","article-title":"Side-Channel Analysis of Multiplications in GF(2128) -\n  Application to AES-GCM","volume-title":"Advances in Cryptology - ASIACRYPT 2014 - 20th\n  International Conference on the Theory and Application of Cryptology and\n  Information Security, Kaoshiung, Taiwan, R.O.C., December 7-11, 2014,\n  Proceedings, Part II","volume":"8874","author":"Sonia Bela\u00efd","year":"2014"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T16:26:52Z","timestamp":1733848012000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/2\/4"}},"issued":{"date-parts":[[2024,7,8]]},"references-count":128,"URL":"https:\/\/doi.org\/10.62056\/akdkp2fgx","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2024,7,8]]},"assertion":[{"value":"2024-01-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-06-04","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-1-93"},{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T14:33:47Z","timestamp":1786113227644,"version":"build-2736575974"},"reference-count":10,"publisher":"International Association for Cryptologic Research","issue":"2","license":[{"start":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T00:00:00Z","timestamp":1777248000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>\n                    We give an explicit algorithm to evaluate an efficiently computable cubic genus invariant on ideal class groups of non-maximal imaginary quadratic orders in\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>K<\/mml:mi>\n                        <mml:mo>=<\/mml:mo>\n                        <mml:mi>\u211a<\/mml:mi>\n                        <mml:mo stretchy=\"false\">(<\/mml:mo>\n                        <mml:msqrt>\n                          <mml:mrow>\n                            <mml:mo>\u2212<\/mml:mo>\n                            <mml:mn>3<\/mml:mn>\n                          <\/mml:mrow>\n                        <\/mml:msqrt>\n                        <mml:mo stretchy=\"false\">)<\/mml:mo>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    . Concretely, we consider the order\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:msub>\n                          <mml:mi>\ud835\udcaa<\/mml:mi>\n                          <mml:mrow>\n                            <mml:mi>\u0394<\/mml:mi>\n                          <\/mml:mrow>\n                        <\/mml:msub>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    of discriminant\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>\u0394<\/mml:mi>\n                        <mml:mo>=<\/mml:mo>\n                        <mml:mo>\u2212<\/mml:mo>\n                        <mml:mn>3<\/mml:mn>\n                        <mml:msup>\n                          <mml:mi>f<\/mml:mi>\n                          <mml:mrow>\n                            <mml:mn>2<\/mml:mn>\n                          <\/mml:mrow>\n                        <\/mml:msup>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    with conductor\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>f<\/mml:mi>\n                        <mml:mo>&gt;<\/mml:mo>\n                        <mml:mn>1<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    . We assume that\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>f<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    is known as an integer, but its prime factorization is not; instead, we are given only a single nontrivial factor\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>a<\/mml:mi>\n                        <mml:mo>\u2223<\/mml:mo>\n                        <mml:mi>f<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    arising in Dedekind's parametrization of these discriminants (so that the complementary factor needed in the cubic-residuosity test can be recovered as an integer from\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mo stretchy=\"false\">(<\/mml:mo>\n                        <mml:mi>f<\/mml:mi>\n                        <mml:mo>,<\/mml:mo>\n                        <mml:mi>a<\/mml:mi>\n                        <mml:mo stretchy=\"false\">)<\/mml:mo>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    , without factoring it).\n                  <\/jats:p>\n                  <jats:p>\n                    Under these assumptions, our method computes a nontrivial two-valued genus invariant on the ideal class group of\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:msub>\n                          <mml:mi>\ud835\udcaa<\/mml:mi>\n                          <mml:mrow>\n                            <mml:mi>\u0394<\/mml:mi>\n                          <\/mml:mrow>\n                        <\/mml:msub>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    , taking values\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mo>+<\/mml:mo>\n                        <mml:mn>1<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    and\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mo>\u2212<\/mml:mo>\n                        <mml:mn>1<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    , whose\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mo>+<\/mml:mo>\n                        <mml:mn>1<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    -fiber is a distinguished index-\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>3<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    subgroup singled out by classical work of Dedekind; equivalently, the invariant takes the value\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mo>+<\/mml:mo>\n                        <mml:mn>1<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    if and only if the ideal class lies in that subgroup.\n                  <\/jats:p>\n                  <jats:p>\n                    The construction is inspired by work of Dedekind and Shanks on index-\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>3<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    subgroups of quadratic form class groups and their characterization via cubic residuosity of primes represented by form classes. We prove correctness and analyze the running time of the resulting evaluation procedure, and we validate the approach with a SageMath implementation. As an application, we obtain an explicit Decisional Diffie\u2013Hellman (DDH) distinguisher in cyclic subgroups of the class group generated by an element outside the distinguished index-\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>3<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    subgroup, under the same partial-factorization assumption.\n                  <\/jats:p>","DOI":"10.62056\/a66chevtw","type":"journal-article","created":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T19:02:55Z","timestamp":1785783775000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Efficient DDH Distinguishers in Class Groups of Orders in $\u211a(\u221a(-3))$"],"prefix":"10.62056","volume":"3","author":[{"given":"Antonio","family":"Sanso","sequence":"first","affiliation":[{"name":"Ethereum Foundation","place":["Switzerland"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2026,8,3]]},"reference":[{"key":"ref1:bsgs","doi-asserted-by":"publisher","DOI":"10.1090\/pspum\/020\/0316385","article-title":"Class Number, a Theory of Factorization, and Genera","author":"D. Shanks","year":"1971"},{"key":"ref2:jofc-1988-14152","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1007\/BF02351719","article-title":"A Key-Exchange System Based on Imaginary Quadratic Fields","volume":"1","author":"Johannes Buchmann","year":"1988","journal-title":"J. Cryptology"},{"key":"ref3:Lipmaa12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1007\/978-3-642-31284-7_14","article-title":"Secure Accumulators from Euclidean Rings without Trusted\n  Setup","volume":"7341","author":"Helger Lipmaa","year":"2012"},{"key":"ref4:Wesolowski","series-title":"Lecture Notes in Computer Science","isbn-type":"print","doi-asserted-by":"publisher","first-page":"379","DOI":"10.1007\/978-3-030-17659-4_13","article-title":"Efficient Verifiable Delay Functions","volume":"11478","author":"Benjamin Wesolowski","year":"2019","ISBN":"https:\/\/id.crossref.org\/isbn\/9783030176594"},{"key":"ref5:Pietrzak","series-title":"Leibniz International Proceedings in Informatics (LIPIcs)","isbn-type":"print","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ITCS.2019.60","article-title":"Simple Verifiable Delay Functions","volume":"124","author":"Krzysztof Pietrzak","year":"2019","ISBN":"https:\/\/id.crossref.org\/isbn\/9783959770958","ISSN":"https:\/\/id.crossref.org\/issn\/1868-8969","issn-type":"electronic"},{"key":"ref6:10.1007\/978-3-030-26948-7_20","isbn-type":"print","doi-asserted-by":"publisher","first-page":"561","DOI":"10.1007\/978-3-030-26948-7_20","article-title":"Batching Techniques for Accumulators with Applications to\n  IOPs and Stateless Blockchains","author":"Dan Boneh","year":"2019","ISBN":"https:\/\/id.crossref.org\/isbn\/9783030269487"},{"key":"ref7:Dedekind1900","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1515\/crll.1900.121.40","article-title":"Ueber die Anzahl der Idealklassen in reinen kubischen\n  Zahlk\u00f6rpern.","volume":"121","author":"R. Dedekind","year":"1900","journal-title":"Journal f\u00fcr die reine und angewandte Mathematik"},{"key":"ref8:C","series-title":"A Wiley-Interscience Publication","doi-asserted-by":"publisher","DOI":"10.1002\/9781118400722","volume-title":"Primes of the form x\u00b2 + ny\u00b2","author":"David A. Cox","year":"1989"},{"key":"ref9:10.1007\/978-3-319-16715-2_26","isbn-type":"print","doi-asserted-by":"publisher","first-page":"487","DOI":"10.1007\/978-3-319-16715-2_26","article-title":"Linearly Homomorphic Encryption from DDH","author":"Guilhem Castagnos","year":"2015","ISBN":"https:\/\/id.crossref.org\/isbn\/9783319167152"},{"key":"ref10:10.1007\/978-3-030-03329-3_25","isbn-type":"print","doi-asserted-by":"publisher","first-page":"733","DOI":"10.1007\/978-3-030-03329-3_25","article-title":"Practical Fully Secure Unrestricted Inner Product Functional\n  Encryption Modulo p","author":"Guilhem Castagnos","year":"2018","ISBN":"https:\/\/id.crossref.org\/isbn\/9783030033293"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T18:28:32Z","timestamp":1785954512000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/3\/2\/24"}},"issued":{"date-parts":[[2026,8,3]]},"references-count":10,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2026,8,3]]}},"URL":"https:\/\/doi.org\/10.62056\/a66chevtw","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2026,8,3]]},"assertion":[{"value":"2026-04-27","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-06-30","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc3-2-30"},{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T20:34:45Z","timestamp":1786826085071,"version":"build-2736575974"},"reference-count":8,"publisher":"International Association for Cryptologic Research","issue":"4","license":[{"start":{"date-parts":[[2024,9,10]],"date-time":"2024-09-10T00:00:00Z","timestamp":1725926400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,12,3]]},"abstract":"<jats:p>A linear error-correcting code exhibits proximity gaps if each affine line of words either consists entirely of words which are close to the code or else contains almost no such words. In this short note, we prove that for each linear code which exhibits proximity gaps within the unique decoding radius, that code's interleaved code also does. Combining our result with a recent argument of Angeris, Evans and Roh ('24), we extend those authors' sharpening of the tensor-based proximity gap of Diamond and Posen (Commun. Cryptol. '24) up to the unique decoding radius, at least in the Reed\u2013Solomon setting. <\/jats:p>","DOI":"10.62056\/a0ljbkrz","type":"journal-article","created":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T17:00:52Z","timestamp":1736787652000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":3,"title":["Proximity Gaps in Interleaved Codes"],"prefix":"10.62056","volume":"1","author":[{"given":"Benjamin","family":"Diamond","sequence":"first","affiliation":[{"name":"Irreducible","place":["United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Angus","family":"Gruen","sequence":"additional","affiliation":[{"name":"Polygon","place":["United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,1,13]]},"reference":[{"key":"ref1:Ben-Sasson:2023aa","doi-asserted-by":"publisher","DOI":"10.1145\/3614423","article-title":"Proximity Gaps for Reed\u2013Solomon Codes","volume":"70","author":"Eli Ben-Sasson","year":"2023","journal-title":"Journal of the ACM"},{"key":"ref2:Diamond:2024aa","doi-asserted-by":"publisher","DOI":"10.62056\/aksdkp10","article-title":"Proximity Testing with Logarithmic Randomness","volume":"1","author":"Benjamin E. Diamond","year":"2024","journal-title":"IACR Communications in Cryptology","ISSN":"https:\/\/id.crossref.org\/issn\/3006-5496","issn-type":"electronic"},{"key":"ref3:Ames:2023aa","doi-asserted-by":"publisher","DOI":"10.1007\/s10623-023-01222-8","article-title":"Ligero: lightweight sublinear arguments without a trusted\n  setup","author":"Scott Ames","year":"2023","journal-title":"Designs, Codes and Cryptography"},{"key":"ref4:Golovnev:2023aa","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/978-3-031-38545-2_7","article-title":"Brakedown: Linear-Time and Field-Agnostic SNARKs for\n  R1CS","author":"Alexander Golovnev","year":"2023"},{"key":"ref5:Angeris:2024aa","volume-title":"A Note on Ligero and Logarithmic Randomness","author":"Guillermo Angeris","year":"2024"},{"key":"ref6:Diamond:2024ab","volume-title":"Polylogarithmic Proofs for Multilinears over Binary Towers","author":"Benjamin E. Diamond","year":"2024"},{"key":"ref7:Ben-Sasson:2018aa","series-title":"Leibniz International Proceedings in Informatics","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ICALP.2018.14","article-title":"Fast Reed\u2013Solomon Interactive Oracle Proofs of\n  Proximity","volume":"107","author":"Eli Ben-Sasson","year":"2018"},{"key":"ref8:Guruswami:2006aa","series-title":"Foundations and Trends in Theoretical Computer Science","doi-asserted-by":"publisher","DOI":"10.1561\/0400000007","volume-title":"Algorithmic Results in List Decoding","volume":"2","author":"Venkatesan Guruswami","year":"2006"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T17:11:05Z","timestamp":1736788265000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/4\/8"}},"issued":{"date-parts":[[2025,1,13]]},"references-count":8,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,1,13]]}},"URL":"https:\/\/doi.org\/10.62056\/a0ljbkrz","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2025,1,13]]},"assertion":[{"value":"2024-09-10","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-03","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-4-4"},{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T05:53:53Z","timestamp":1787032433811,"version":"build-2736575974"},"reference-count":71,"publisher":"International Association for Cryptologic Research","issue":"4","license":[{"start":{"date-parts":[[2024,10,9]],"date-time":"2024-10-09T00:00:00Z","timestamp":1728432000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,12,3]]},"abstract":"<jats:p>\n                    In recent years, there has been much focus on developing core cryptographic primitives based on lattice assumptions, driven by the NIST call for post-quantum key encapsulation and digital signature algorithms. However, more work must be conducted on efficient privacy-preserving protocols based on quantum-safe assumptions.                  Electronic voting is one such privacy-preserving protocol whose adoption is increasing across the democratic world. E-voting offers both a fast and convenient alternative to postal voting whilst further ensuring cryptographic privacy of votes and offering full verifiability of the process. Owing to the sensitivity of voting and its infrastructure challenges, it is crucial to ensure security against quantum computers is baked into e-voting solutions.                  We present an e-voting scheme from quantum-safe assumptions based on the hardness of the RLWE and NTRU lattice problems, providing concrete parameters and an efficient implementation. Our design achieves a factor\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>5.3<\/mml:mn>\n                        <mml:mi>\u00d7<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    reduction in ciphertext size,\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>2.5<\/mml:mn>\n                        <mml:mi>\u00d7<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    reduction in total communication cost, and\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>2<\/mml:mn>\n                        <mml:mi>\u00d7<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    reduction in total computation time compared to the state-of-the-art lattice-based voting scheme by Aranha et al. (ACM CCS 2023). We argue that the efficiency of this scheme makes it suitable for real-world elections.                  Our scheme makes use of non-ternary NTRU secrets to achieve optimal parameters. In order to compute the security of our design, we extend the ternary-NTRU work of Ducas and van Woerden (ASIACRYPT 2021) by determining the concrete fatigue point (for general secrets) of NTRU to be\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>q<\/mml:mi>\n                        <mml:mo>=<\/mml:mo>\n                        <mml:mn>0.0058<\/mml:mn>\n                        <mml:mi>\u00b7<\/mml:mi>\n                        <mml:msup>\n                          <mml:mi>\u03c3<\/mml:mi>\n                          <mml:mn>2<\/mml:mn>\n                        <\/mml:msup>\n                        <mml:mi>\u00b7<\/mml:mi>\n                        <mml:msup>\n                          <mml:mi>d<\/mml:mi>\n                          <mml:mrow>\n                            <mml:mn>2.484<\/mml:mn>\n                          <\/mml:mrow>\n                        <\/mml:msup>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    (above which parameters become overstretched) for modulus\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>q<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    , ring dimension\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>d<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    , and secrets drawn from a Gaussian of parameter\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>\u03c3<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    . We consider this relation to be of independent interest and demonstrate its significance by improving the efficiency of the (partially) blind signature scheme by del Pino and Katsumata (CRYPTO 2022).\n                  <\/jats:p>","DOI":"10.62056\/a69qudhdj","type":"journal-article","created":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T12:00:52Z","timestamp":1736769652000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":5,"title":["More Efficient Lattice-Based Electronic Voting from NTRU"],"prefix":"10.62056","volume":"1","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4037-5512","authenticated-orcid":false,"given":"Patrick","family":"Hough","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/052gg0110","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Oxford","place":["Oxford, United Kingdom"],"department":["Mathematical Institute"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1296-2093","authenticated-orcid":false,"given":"Caroline","family":"Sandsbr\u00e5ten","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05xg72x27","id-type":"ROR","asserted-by":"publisher"}],"name":"Norwegian University of Science and Technology","place":["Trondheim, Norway"],"department":["Department of Information Security and Communication Technology"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5455-0409","authenticated-orcid":false,"given":"Tjerand","family":"Silde","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05xg72x27","id-type":"ROR","asserted-by":"publisher"}],"name":"Norwegian University of Science and Technology","place":["Trondheim, Norway"],"department":["Department of Information Security and Communication Technology"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,1,13]]},"reference":[{"key":"ref1:NISTPQC:CRYSTALS-KYBER22","volume-title":"CRYSTALS-KYBER","author":"Peter Schwabe","year":"2022"},{"key":"ref2:NISTPQC:CRYSTALS-DILITHIUM22","volume-title":"CRYSTALS-DILITHIUM","author":"Vadim Lyubashevsky","year":"2022"},{"key":"ref3:NISTPQC:FALCON22","volume-title":"FALCON","author":"Thomas Prest","year":"2022"},{"key":"ref4:STOC:Ajtai96","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1145\/237814.237838","article-title":"Generating Hard Instances of Lattice Problems (Extended\n  Abstract)","author":"Mikl\u00f3s Ajtai","year":"1996"},{"key":"ref5:TCC:PeiRos06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1007\/11681878_8","article-title":"Efficient Collision-Resistant Hashing from Worst-Case\n  Assumptions on Cyclic Lattices","volume":"3876","author":"Chris Peikert","year":"2006"},{"key":"ref6:ICALP:LyuMic06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"144","DOI":"10.1007\/11787006_13","article-title":"Generalized Compact Knapsacks Are Collision Resistant","volume":"4052","author":"Vadim Lyubashevsky","year":"2006"},{"key":"ref7:STOC:Regev05","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1145\/1060590.1060603","article-title":"On lattices, learning with errors, random linear codes, and\n  cryptography","author":"Oded Regev","year":"2005"},{"key":"ref8:EC:LyuPeiReg10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-13190-5_1","article-title":"On Ideal Lattices and Learning with Errors over Rings","volume":"6110","author":"Vadim Lyubashevsky","year":"2010"},{"key":"ref9:HofPipSil98","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1007\/BFb0054868","article-title":"NTRU: A Ring-Based Public Key Cryptosystem","volume":"1423","author":"Jeffrey Hoffstein","year":"1998"},{"key":"ref10:DCC:LanSte15","doi-asserted-by":"publisher","first-page":"565","DOI":"10.1007\/s10623-014-9938-4","article-title":"Worst-case to average-case reductions for module lattices","volume":"75","author":"Adeline Langlois","year":"2015","journal-title":"Designs, Codes and Cryptography"},{"key":"ref11:cbsnews-arizona","volume-title":"Online First in Arizona","author":"CBS News","year":"2000"},{"key":"ref12:vinkel2015remote","article-title":"Remote Electronic Voting in Estonia: Legality, Impact, and\n  Confidence","author":"Priit Vinkel","year":"2015","journal-title":"ResearchGate"},{"key":"ref13:post-medien-evoting","volume-title":"Swiss Post article on e-voting introduction","author":"Swiss Post","year":"2023"},{"key":"ref14:ontario2018","volume-title":"Online Voting in Ontario Municipal Elections: A Conflict of\n  Legal Principles and Technology?","author":"Anthony Cardillo","year":"2019"},{"key":"ref15:nsw-elections-ivote","volume-title":"iVote and 2021 NSW Local Government Elections","author":"New South Wales Electoral Commission","year":"2021"},{"key":"ref16:USENIX:Adida08","first-page":"335","article-title":"Helios: Web-based Open-Audit Voting","author":"Ben Adida","year":"2008"},{"key":"ref17:estoniacost","volume-title":"How Much Does an e-Vote Cost? Cost Comparison per Vote in\n  Multichannel Elections in Estonia","author":"Robert Krimmer","year":"2018"},{"key":"ref18:solop2001digital","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1057\/9780230523531_14","article-title":"Digital Democracy Comes of Age: Internet Voting and the 2000\n  Arizona Democratic Primary Election","volume":"34","author":"Frederic I. Solop","year":"2001","journal-title":"PS: Political Science & Politics"},{"key":"ref19:spada2016effects","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1080\/19331681.2016.1162250","article-title":"Effects of the Internet on Participation: Study of a Public\n  Policy Referendum in Brazil","volume":"13","author":"Paolo Spada","year":"2016","journal-title":"Journal of Information Technology & Politics"},{"key":"ref20:PoPETS:HMMP23","doi-asserted-by":"publisher","first-page":"279","DOI":"10.56553\/popets-2023-0017","article-title":"SoK: Secure E-Voting with Everlasting Privacy","volume":"2023","author":"Thomas Haines","year":"2023","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"ref21:Chaum81","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1145\/358549.358563","article-title":"Untraceable electronic mail, return addresses, and digital\n  pseudonyms","volume":"24","author":"David L. Chaum","year":"1981","journal-title":"Commun. ACM","ISSN":"https:\/\/id.crossref.org\/issn\/0001-0782","issn-type":"electronic"},{"key":"ref22:EC:BayGro12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"263","DOI":"10.1007\/978-3-642-29011-4_17","article-title":"Efficient Zero-Knowledge Argument for Correctness of a\n  Shuffle","volume":"7237","author":"Stephanie Bayer","year":"2012"},{"key":"ref23:CCS:PLNS17","doi-asserted-by":"publisher","first-page":"1565","DOI":"10.1145\/3133956.3134101","article-title":"Practical Quantum-Safe Voting from Lattices","author":"Rafa\u00ebl del Pino","year":"2017"},{"key":"ref24:RSA:ABGST21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/978-3-030-75539-3_10","article-title":"Lattice-Based Proof of Shuffle and Applications to\n  Electronic Voting","volume":"12704","author":"Diego F. Aranha","year":"2021"},{"key":"ref25:ICISC:FarWilKaa21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1007\/978-3-031-08896-4_6","article-title":"Improved Lattice-Based Mix-Nets for Electronic Voting","volume":"13218","author":"Valeh Farzaliyev","year":"2021"},{"key":"ref26:CCS:ABGS23","doi-asserted-by":"publisher","first-page":"1467","DOI":"10.1145\/3576915.3616683","article-title":"Verifiable Mix-Nets and Distributed Decryption for Voting\n  from Lattice-Based Assumptions","author":"Diego F. Aranha","year":"2023"},{"key":"ref27:TCC:BenDam10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1007\/978-3-642-11799-2_13","article-title":"Threshold Decryption and Zero-Knowledge Proofs for\n  Lattice-Based Cryptosystems","volume":"5978","author":"Rikke Bendlin","year":"2010"},{"key":"ref28:C:BBCPGL18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"669","DOI":"10.1007\/978-3-319-96881-0_23","article-title":"Sub-linear Lattice-Based Zero-Knowledge Arguments for\n  Arithmetic Circuits","volume":"10992","author":"Carsten Baum","year":"2018"},{"key":"ref29:NISTPQC-R3:FALCON20","volume-title":"FALCON","author":"Thomas Prest","year":"2020"},{"key":"ref30:ITCS:BraGenVai12","doi-asserted-by":"publisher","first-page":"309","DOI":"10.1145\/2090236.2090262","article-title":"(Leveled) fully homomorphic encryption without\n  bootstrapping","author":"Zvika Brakerski","year":"2012"},{"key":"ref31:C:AlbBaiDuc16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1007\/978-3-662-53018-4_6","article-title":"A Subfield Lattice Attack on Overstretched NTRU\n  Assumptions - Cryptanalysis of Some FHE and Graded Encoding Schemes","volume":"9814","author":"Martin R. Albrecht","year":"2016"},{"key":"ref32:CheonJeongLee2016","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1112\/S1461157016000371","article-title":"An algorithm for NTRU problems and cryptanalysis of the GGH\n  multilinear map without a low-level encoding of zero","volume":"19","author":"Jung Hee Cheon","year":"2016","journal-title":"LMS Journal of Computation and Mathematics"},{"key":"ref33:EC:KirFou17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-56620-7_1","article-title":"Revisiting Lattice Attacks on Overstretched NTRU\n  Parameters","volume":"10210","author":"Paul Kirchner","year":"2017"},{"key":"ref34:AC:DucvWo21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-92068-5_1","article-title":"NTRU Fatigue: How Stretched is Overstretched?","volume":"13093","author":"L\u00e9o Ducas","year":"2021"},{"key":"ref35:EC:SteSte11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/978-3-642-20465-4_4","article-title":"Making NTRU as Secure as Worst-Case Problems over Ideal\n  Lattices","volume":"6632","author":"Damien Stehl\u00e9","year":"2011"},{"key":"ref36:ESORICS:BLNS21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"608","DOI":"10.1007\/978-3-030-88428-4_30","article-title":"More Efficient Amortization of Exact Zero-Knowledge Proofs\n  for LWE","volume":"12973","author":"Jonathan Bootle","year":"2021"},{"key":"ref37:C:dPiKat22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"306","DOI":"10.1007\/978-3-031-15979-4_11","article-title":"A New Framework for More Efficient Round-Optimal\n  Lattice-Based (Partially) Blind Signature via Trapdoor Sampling","volume":"13508","author":"Rafa\u00ebl del Pino","year":"2022"},{"key":"ref38:FCW:CosMarMor19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1007\/978-3-030-43725-1_23","article-title":"Lattice-Based Proof of a Shuffle","volume":"11599","author":"N\u00faria Costa","year":"2019"},{"key":"ref39:FCW:HerMarSan21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1007\/978-3-662-63958-0_27","article-title":"Shorter Lattice-Based Zero-Knowledge Proofs for the\n  Correctness of a Shuffle","volume":"12676","author":"Javier Herranz","year":"2021"},{"key":"ref40:FCW:Strand18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/978-3-662-58820-8_12","article-title":"A Verifiable Shuffle for the GSW Cryptosystem","volume":"10958","author":"Martin Strand","year":"2019"},{"key":"ref41:PQCRYPTO:CGGI16","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1007\/978-3-319-29360-8_16","article-title":"A Homomorphic LWE Based E-voting Scheme","author":"Ilaria Chillotti","year":"2016"},{"key":"ref42:ESORICS:BoyHaiMul20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"336","DOI":"10.1007\/978-3-030-59013-0_17","article-title":"A Verifiable and Practical Lattice-Based Decryption Mix Net\n  with External Auditing","volume":"12309","author":"Xavier Boyen","year":"2020"},{"key":"ref43:JC:RSTVW22","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1007\/s00145-021-09416-w","article-title":"Actively Secure Setup for SPDZ","volume":"35","author":"Dragos Rotaru","year":"2022","journal-title":"Journal of Cryptology"},{"key":"ref44:FOCS:MicReg04","doi-asserted-by":"publisher","first-page":"372","DOI":"10.1109\/FOCS.2004.72","article-title":"Worst-Case to Average-Case Reductions Based on Gaussian\n  Measures","author":"Daniele Micciancio","year":"2004"},{"key":"ref45:EC:Lyubashevsky12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"738","DOI":"10.1007\/978-3-642-29011-4_43","article-title":"Lattice Signatures without Trapdoors","volume":"7237","author":"Vadim Lyubashevsky","year":"2012"},{"key":"ref46:C:BooLyuSei19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"176","DOI":"10.1007\/978-3-030-26948-7_7","article-title":"Algebraic Techniques for Short(er) Exact Lattice-Based\n  Zero-Knowledge Proofs","volume":"11692","author":"Jonathan Bootle","year":"2019"},{"key":"ref47:PKC:LyuNguSei21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"215","DOI":"10.1007\/978-3-030-75245-3_9","article-title":"Shorter Lattice-Based Zero-Knowledge Proofs via One-Time\n  Commitments","volume":"12710","author":"Vadim Lyubashevsky","year":"2021"},{"key":"ref48:STOC:LopTroVai12","doi-asserted-by":"publisher","first-page":"1219","DOI":"10.1145\/2213977.2214086","article-title":"On-the-fly multiparty computation on the cloud via multikey\n  fully homomorphic encryption","author":"Adriana L\u00f3pez-Alt","year":"2012"},{"key":"ref49:EC:SaiXagYam18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"520","DOI":"10.1007\/978-3-319-78372-7_17","article-title":"Tightly-Secure Key-Encapsulation Mechanism in the Quantum\n  Random Oracle Model","volume":"10822","author":"Tsunekazu Saito","year":"2018"},{"key":"ref50:EPRINT:CKKS19","volume-title":"A New Trapdoor over Module-NTRU Lattice and its\n  Application to ID-based Encryption","author":"Jung Hee Cheon","year":"2019"},{"key":"ref51:ASIACCS:CPSWX20","doi-asserted-by":"publisher","first-page":"853","DOI":"10.1145\/3320269.3384758","article-title":"ModFalcon: Compact Signatures Based On Module-NTRU\n  Lattices","author":"Chitchanok Chuengsatiansup","year":"2020"},{"key":"ref52:SCN:BDLOP18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"368","DOI":"10.1007\/978-3-319-98113-0_20","article-title":"More Efficient Commitments from Structured Lattice\n  Assumptions","volume":"11035","author":"Carsten Baum","year":"2018"},{"key":"ref53:gjosteen22","doi-asserted-by":"crossref","DOI":"10.1201\/9781003149422","volume-title":"Practical Mathematical Cryptography","author":"Kristian Gjosteen","year":"2022"},{"key":"ref54:EPRINT:ABGS22","volume-title":"Verifiable Mix-Nets and Distributed Decryption for Voting\n  from Lattice-Based Assumptions","author":"Diego F. Aranha","year":"2022"},{"key":"ref55:C:LyuNguPla22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/978-3-031-15979-4_3","article-title":"Lattice-Based Zero-Knowledge Proofs and Applications:\n  Shorter, Simpler, and More General","volume":"13508","author":"Vadim Lyubashevsky","year":"2022"},{"key":"ref56:EPRINT:LeeWal20","volume-title":"Lattice analysis on MiNTRU problem","author":"Changmin Lee","year":"2020"},{"key":"ref57:pataki2008sublatticedeterminantsreducedbases","volume-title":"On sublattice determinants in reduced bases","author":"Gabor Pataki","year":"2008"},{"key":"ref58:USENIX:ADPS16","first-page":"327","article-title":"Post-quantum Key Exchange - A New Hope","author":"Erdem Alkim","year":"2016"},{"key":"ref59:albrecht2015concrete","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1515\/jmc-2015-0016","article-title":"On the concrete hardness of learning with errors","volume":"9","author":"Martin R Albrecht","year":"2015","journal-title":"Journal of Mathematical Cryptology"},{"key":"ref60:C:Katsumata21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"580","DOI":"10.1007\/978-3-030-84245-1_20","article-title":"A New Simple Technique to Bootstrap Various Lattice\n  Zero-Knowledge Proofs to QROM Secure NIZKs","volume":"12826","author":"Shuichi Katsumata","year":"2021"},{"key":"ref61:NISTPQC-R1:DingKeyExchange17","volume-title":"Ding Key Exchange","author":"Jintai Ding","year":"2017"},{"key":"ref62:NISTPQC-R1:EMBLEMandR.EMBLEM17","volume-title":"EMBLEM and R.EMBLEM","author":"Minhye Seo","year":"2017"},{"key":"ref63:AC:BIPPS22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"188","DOI":"10.1007\/978-3-031-22966-4_7","article-title":"FINAL: Faster FHE Instantiated with NTRU and LWE","volume":"13792","author":"Charlotte Bonte","year":"2022"},{"key":"ref64:Micciancio2009","isbn-type":"print","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/978-3-540-88702-7_5","volume-title":"Post-Quantum Cryptography","author":"Daniele Micciancio","year":"2009","ISBN":"https:\/\/id.crossref.org\/isbn\/9783540887027"},{"key":"ref65:returncodes","doi-asserted-by":"publisher","DOI":"10.15157\/diss\/025","article-title":"Return Codes from Lattice Assumptions","author":"Audhild H\u00f8g\u00e5sen","year":"2022","journal-title":"E-VOTE-ID"},{"key":"ref66:CCS:AKSY22","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1145\/3548606.3560650","article-title":"Practical, Round-Optimal Lattice-Based Blind Signatures","author":"Shweta Agrawal","year":"2022"},{"key":"ref67:AC:BouSch23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1007\/978-981-99-8721-4_12","article-title":"Simple Threshold (Fully Homomorphic) Encryption from LWE\n  with Polynomial Modulus","volume":"14438","author":"Katharina Boudgoust","year":"2023"},{"key":"ref68:EPRINT:CSSMCP22","volume-title":"Efficient Threshold FHE with Application to Real-Time\n  Systems","author":"Siddhartha Chowdhury","year":"2022"},{"key":"ref69:C:KLSS23b","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"549","DOI":"10.1007\/978-3-031-38554-4_18","article-title":"Toward Practical Lattice-Based Proof of Knowledge from\n  Hint-MLWE","volume":"14085","author":"Duhyeong Kim","year":"2023"},{"key":"ref70:C:BeuSei23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"518","DOI":"10.1007\/978-3-031-38554-4_17","article-title":"LaBRADOR: Compact Proofs for R1CS from Module-SIS","volume":"14085","author":"Ward Beullens","year":"2023"},{"key":"ref71:CCS:Kluczniak22","doi-asserted-by":"publisher","first-page":"1783","DOI":"10.1145\/3548606.3560700","article-title":"NTRU-v-um: Secure Fully Homomorphic Encryption from NTRU\n  with Small Modulus","author":"Kamil Kluczniak","year":"2022"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T12:11:12Z","timestamp":1736770272000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/4\/10"}},"issued":{"date-parts":[[2025,1,13]]},"references-count":71,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,1,13]]}},"URL":"https:\/\/doi.org\/10.62056\/a69qudhdj","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2025,1,13]]},"assertion":[{"value":"2024-10-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-03","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-4-10"},{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T05:54:30Z","timestamp":1787032470384,"version":"build-2736575974"},"reference-count":73,"publisher":"International Association for Cryptologic Research","issue":"1","license":[{"start":{"date-parts":[[2024,10,8]],"date-time":"2024-10-08T00:00:00Z","timestamp":1728345600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,3,11]]},"abstract":"<jats:p>A wide range of countermeasures have been proposed to defend against side-channel attacks, with masking being one of the most effective and commonly used techniques. While theoretical models provide formal security proofs, these often rely on assumptions\u2014sometimes implicit\u2014that can be difficult to assess in practice. As a result, the design of secure masked implementations frequently combines proven theoretical arguments with heuristic and empirical validation.<\/jats:p>\n                  <jats:p>Despite the significant body of work, the literature still lacks a cohesive and well-defined framework for translating theoretical security guarantees into practical implementations on physical devices. Specifically, there remains a gap in connecting provable results from abstract models to quantitative security guarantees at the implementation level.<\/jats:p>\n                  <jats:p>In this Systematization of Knowledge (SoK), we aim to provide a comprehensive methodology to transform abstract cryptographic algorithms into physically secure implementations against side-channel attacks on microcontrollers. We introduce new tools to adapt the ideal noisy leakage model to practical, real-world scenarios, and we integrate state-of-the-art techniques to build secure implementations based on this model.<\/jats:p>\n                  <jats:p>Our work systematizes the design objectives necessary for achieving high security levels in embedded devices and identifies the remaining challenges in concretely applying security reductions. By bridging the gap between theory and practice, we seek to provide a foundation for future research that can develop implementations with proven security against side-channel attacks, based on well-understood leakage assumptions.<\/jats:p>","DOI":"10.62056\/aebngy4e-","type":"journal-article","created":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T17:23:17Z","timestamp":1744132997000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":4,"title":["SoK: A Methodology to Achieve Provable Side-Channel Security in Real-World Implementations"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9437-6425","authenticated-orcid":false,"given":"Sonia","family":"Bela\u00efd","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0030xrh72","id-type":"ROR","asserted-by":"publisher"}],"name":"CryptoExperts","place":["Paris, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5426-9345","authenticated-orcid":false,"given":"Ga\u00ebtan","family":"Cassiers","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0030xrh72","id-type":"ROR","asserted-by":"publisher"}],"name":"CryptoExperts","place":["Paris, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Camille","family":"Mutschler","sequence":"additional","affiliation":[{"name":"Idemia","place":["Courbevoie, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9855-4161","authenticated-orcid":false,"given":"Matthieu","family":"Rivain","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0030xrh72","id-type":"ROR","asserted-by":"publisher"}],"name":"CryptoExperts","place":["Paris, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas","family":"Roche","sequence":"additional","affiliation":[{"name":"NinjaLab","place":["Montpellier, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7444-0285","authenticated-orcid":false,"given":"Fran\u00e7ois-Xavier","family":"Standaert","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02495e989","id-type":"ROR","asserted-by":"publisher"}],"name":"UCLouvain","place":["Louvain-la-Neuve, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5725-8474","authenticated-orcid":false,"given":"Abdul","family":"Taleb","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0030xrh72","id-type":"ROR","asserted-by":"publisher"}],"name":"CryptoExperts","place":["Paris, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,4,8]]},"reference":[{"key":"ref1:C:Kocher96","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","article-title":"Timing Attacks on Implementations of Diffie-Hellman,\n  RSA, DSS, and Other Systems","volume":"1109","author":"Paul C. Kocher","year":"1996"},{"key":"ref2:DBLP:conf\/cardis\/HutterS13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1007\/978-3-319-08302-5_15","article-title":"The Temperature Side Channel and Heating Fault Attacks","volume":"8419","author":"Michael Hutter","year":"2013"},{"key":"ref3:C:KocJafJun99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","article-title":"Differential Power Analysis","volume":"1666","author":"Paul C. Kocher","year":"1999"},{"key":"ref4:DBLP:conf\/esmart\/QuisquaterS01","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"200","DOI":"10.1007\/3-540-45418-7_17","article-title":"ElectroMagnetic Analysis (EMA): Measures and\n  Counter-Measures for Smart Cards","volume":"2140","author":"Jean-Jacques Quisquater","year":"2001"},{"key":"ref5:C:CJRR99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"398","DOI":"10.1007\/3-540-48405-1_26","article-title":"Towards Sound Approaches to Counteract Power-Analysis\n  Attacks","volume":"1666","author":"Suresh Chari","year":"1999"},{"key":"ref6:CHES:GouPat99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/3-540-48059-5_15","article-title":"DES and Differential Power Analysis (The \u201cDuplication\u201d\n  Method)","volume":"1717","author":"Louis Goubin","year":"1999"},{"key":"ref7:COSADE:BCGLMR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1007\/978-3-031-29497-6_5","article-title":"Removing the Field Size Loss from Duc et al.'s Conjectured\n  Bound for Masked Encodings","volume":"13979","author":"Julien B\u00e9guinot","year":"2023"},{"key":"ref8:TCHES:BroSta21","doi-asserted-by":"publisher","first-page":"202","DOI":"10.46586\/tches.v2021.i3.202-234","article-title":"Breaking Masked Implementations with Many Shares on 32-bit\n  Software Platforms","volume":"2021","author":"Olivier Bronchain","year":"2021","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref9:EC:GroSta18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1007\/978-3-319-78375-8_13","article-title":"Masking Proofs Are Tight and How to Exploit it in Security\n  Evaluations","volume":"10821","author":"Vincent Grosso","year":"2018"},{"key":"ref10:EC:DucFauSta15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1007\/978-3-662-46800-5_16","article-title":"Making Masking Security Proofs Concrete - Or How to Evaluate\n  the Security of Any Leaking Device","volume":"9056","author":"Alexandre Duc","year":"2015"},{"key":"ref11:CHES:JouSta17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"623","DOI":"10.1007\/978-3-319-66787-4_30","article-title":"Very High Order Masking: Efficient Implementation and\n  Security Evaluation","volume":"10529","author":"Anthony Journault","year":"2017"},{"key":"ref12:COSADE:GPSS18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-319-89641-0_2","article-title":"Vectorizing Higher-Order Masking","volume":"10815","author":"Benjamin Gr\u00e9goire","year":"2018"},{"key":"ref13:ISO17825","volume-title":"Information technology \u2013 Security techniques \u2013 Testing\n  methods for the mitigation of non-invasive attack classes against\n  cryptographic modules","volume":"2016","author":"ISO\/IEC JTC 1\/SC 27","year":"2016"},{"key":"ref14:AC:WhiOsw19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1007\/978-3-030-34618-8_9","article-title":"A Critical Analysis of ISO 17825 ('Testing Methods for the\n  Mitigation of Non-invasive Attack Classes Against Cryptographic Modules')","volume":"11923","author":"Carolyn Whitnall","year":"2019"},{"key":"ref15:gilbert2011testing","first-page":"115","article-title":"A testing methodology for side-channel resistance\n  validation","volume":"7","author":"Benjamin Jun Gilbert Goodwill","year":"2011"},{"key":"ref16:CHES:BGNT15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"475","DOI":"10.1007\/978-3-662-48324-4_24","article-title":"Multi-variate High-Order Attacks of Shuffled Tables\n  Recomputation","volume":"9293","author":"Nicolas Bruneau","year":"2015"},{"key":"ref17:C:IshSahWag03","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-3-540-45146-4_27","article-title":"Private Circuits: Securing Hardware against Probing\n  Attacks","volume":"2729","author":"Yuval Ishai","year":"2003"},{"key":"ref18:RSA:SchPaa06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1007\/11605805_14","article-title":"Higher Order Masking of the AES","volume":"3860","author":"Kai Schramm","year":"2006"},{"key":"ref19:CHES:RivPro10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"413","DOI":"10.1007\/978-3-642-15031-9_28","article-title":"Provably Secure Higher-Order Masking of AES","volume":"6225","author":"Matthieu Rivain","year":"2010"},{"key":"ref20:FSE:CPRR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1007\/978-3-662-43933-3_21","article-title":"Higher-Order Side Channel Security and Mask Refreshing","volume":"8424","author":"Jean-S\u00e9bastien Coron","year":"2014"},{"key":"ref21:EC:BBPPTV16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"616","DOI":"10.1007\/978-3-662-49896-5_22","article-title":"Randomness Complexity of Private Circuits for\n  Multiplication","volume":"9666","author":"Sonia Bela\u00efd","year":"2016"},{"key":"ref22:TCHES:CorRonZei18","doi-asserted-by":"publisher","first-page":"40","DOI":"10.13154\/tches.v2018.i1.40-72","article-title":"High Order Masking of Look-up Tables with Common Shares","volume":"2018","author":"Jean-S\u00e9bastien Coron","year":"2018","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref23:CHES:BCPZ16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-662-53140-2_2","article-title":"Horizontal Side-Channel Attacks and Countermeasures on the\n  ISW Masking Scheme","volume":"9813","author":"Alberto Battistello","year":"2016"},{"key":"ref24:EC:ProRiv13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/978-3-642-38348-9_9","article-title":"Masking against Side-Channel Attacks: A Formal Security\n  Proof","volume":"7881","author":"Emmanuel Prouff","year":"2013"},{"key":"ref25:C:MasSta23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1007\/978-3-031-38548-3_12","article-title":"Prouff and Rivain's Formal Security Proof of Masking,\n  Revisited - Tight Bounds in the Noisy Leakage Model","volume":"14083","author":"Lo\u00efc Masure","year":"2023"},{"key":"ref26:EC:DucDziFau14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/978-3-642-55220-5_24","article-title":"Unifying Leakage Models: From Probing Attacks to Noisy\n  Leakage","volume":"8441","author":"Alexandre Duc","year":"2014"},{"key":"ref27:JC:DucDziFau19","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1007\/s00145-018-9284-1","article-title":"Unifying Leakage Models: From Probing Attacks to Noisy\n  Leakage","volume":"32","author":"Alexandre Duc","year":"2019","journal-title":"Journal of Cryptology"},{"key":"ref28:STOC:Ajtai11","doi-asserted-by":"publisher","first-page":"715","DOI":"10.1145\/1993636.1993731","article-title":"Secure computation with information leaking to an\n  adversary","author":"Mikl\u00f3s Ajtai","year":"2011"},{"key":"ref29:EC:AndDziFau16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"586","DOI":"10.1007\/978-3-662-49896-5_21","article-title":"Circuit Compilers with $O(1\/\\log(n))$ Leakage Rate","volume":"9666","author":"Marcin Andrychowicz","year":"2016"},{"key":"ref30:C:AnaIshSah18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"427","DOI":"10.1007\/978-3-319-96878-0_15","article-title":"Private Circuits: A Modular Approach","volume":"10993","author":"Prabhanjan Ananth","year":"2018"},{"key":"ref31:C:BCPRT20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"339","DOI":"10.1007\/978-3-030-56784-2_12","article-title":"Random Probing Security: Verification, Composition,\n  Expansion and New Constructions","volume":"12170","author":"Sonia Bela\u00efd","year":"2020"},{"key":"ref32:EC:BelRivTal21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1007\/978-3-030-77886-6_11","article-title":"On the Power of Expansion: More Efficient Constructions in\n  the Random Probing Model","volume":"12697","author":"Sonia Bela\u00efd","year":"2021"},{"key":"ref33:AC:BRTV21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1007\/978-3-030-92075-3_6","article-title":"Dynamic Random Probing Expansion with Quasi Linear\n  Asymptotic Complexity","volume":"13091","author":"Sonia Bela\u00efd","year":"2021"},{"key":"ref34:C:CFOS21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/978-3-030-84252-9_7","article-title":"Towards Tight Random Probing Security","volume":"12827","author":"Ga\u00ebtan Cassiers","year":"2021"},{"key":"ref35:COSADE:CGPRRV12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1007\/978-3-642-29912-4_6","article-title":"Conversion of Security Proofs from One Leakage Model to\n  Another: A New Issue","volume":"7275","author":"Jean-S\u00e9bastien Coron","year":"2012"},{"key":"ref36:DBLP:conf\/cardis\/BalaschGGRS14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-319-16763-3_5","article-title":"On the Cost of Lazy Engineering for Masked Software\n  Implementations","volume":"8968","author":"Josep Balasch","year":"2014"},{"key":"ref37:RSA:ManPopGam05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"351","DOI":"10.1007\/978-3-540-30574-3_24","article-title":"Side-Channel Leakage of Masked CMOS Gates","volume":"3376","author":"Stefan Mangard","year":"2005"},{"key":"ref38:CHES:ManPraOsw05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1007\/11545262_12","article-title":"Successfully Attacking Masked AES Hardware\n  Implementations","volume":"3659","author":"Stefan Mangard","year":"2005"},{"key":"ref39:TCHES:FGMPS18","doi-asserted-by":"publisher","first-page":"89","DOI":"10.13154\/tches.v2018.i3.89-120","article-title":"Composable Masking Schemes in the Presence of Physical\n  Defaults & the Robust Probing Model","volume":"2018","author":"Sebastian Faust","year":"2018","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref40:TCHES:CasSta21","doi-asserted-by":"publisher","first-page":"136","DOI":"10.46586\/tches.v2021.i2.136-158","article-title":"Provably Secure Hardware Masking in the Transition- and\n  Glitch-Robust Probing Model: Better Safe than Sorry","volume":"2021","author":"Ga\u00ebtan Cassiers","year":"2021","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref41:TCHES:GMPO19","doi-asserted-by":"publisher","first-page":"152","DOI":"10.13154\/tches.v2020.i1.152-174","article-title":"Share-slicing: Friend or Foe?","volume":"2020","author":"Si Gao","year":"2019","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref42:TCHES:BroCas22","doi-asserted-by":"publisher","first-page":"553","DOI":"10.46586\/tches.v2022.i4.553-588","article-title":"Bitslicing Arithmetic\/Boolean Masking Conversions for Fun\n  and Profit with Application to Lattice-Based KEMs","volume":"2022","author":"Olivier Bronchain","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref43:CCS:BGGHMP22","doi-asserted-by":"publisher","first-page":"381","DOI":"10.1145\/3548606.3560600","article-title":"Power Contracts: Provably Complete Power Leakage Models for\n  Processors","author":"Roderick Bloem","year":"2022"},{"key":"ref44:EC:BDFGSS17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"535","DOI":"10.1007\/978-3-319-56620-7_19","article-title":"Parallel Implementations of Masking Schemes and the Bounded\n  Moment Leakage Model","volume":"10210","author":"Gilles Barthe","year":"2017"},{"key":"ref45:CHES:SchMor15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"495","DOI":"10.1007\/978-3-662-48324-4_25","article-title":"Leakage Assessment Methodology - A Clear Roadmap for\n  Side-Channel Evaluations","volume":"9293","author":"Tobias Schneider","year":"2015"},{"key":"ref46:choudary2015efficient","volume-title":"Efficient multivariate statistical techniques for extracting\n  secrets from electronic devices","author":"Marios O Choudary","year":"2015"},{"key":"ref47:C:PGMP19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"683","DOI":"10.1007\/978-3-030-26948-7_24","article-title":"Unifying Leakage Models on a R\u00e9nyi Day","volume":"11692","author":"Thomas Prest","year":"2019"},{"key":"ref48:ICITS:Dodis12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"100","DOI":"10.1007\/978-3-642-32284-6_6","article-title":"Shannon Impossibility, Revisited","volume":"7412","author":"Yevgeniy Dodis","year":"2012"},{"key":"ref49:RSA:Mangard04","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1007\/978-3-540-24660-2_18","article-title":"Hardware Countermeasures against DPA \u2013 A Statistical\n  Analysis of Their Effectiveness","volume":"2964","author":"Stefan Mangard","year":"2004"},{"key":"ref50:CHES:BriClaOli04","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/978-3-540-28632-5_2","article-title":"Correlation Power Analysis with a Leakage Model","volume":"3156","author":"Eric Brier","year":"2004"},{"key":"ref51:DBLP:journals\/iet-ifs\/MangardOS11","doi-asserted-by":"publisher","first-page":"100","DOI":"10.1049\/iet-ifs.2010.0096","article-title":"One for all - all for one: unifying standard differential\n  power analysis attacks","volume":"5","author":"Stefan Mangard","year":"2011","journal-title":"IET Inf. Secur."},{"key":"ref52:CHES:ChaRaoRoh02","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1007\/3-540-36400-5_3","article-title":"Template Attacks","volume":"2523","author":"Suresh Chari","year":"2003"},{"key":"ref53:CHES:SchLemPaa05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1007\/11545262_3","article-title":"A Stochastic Model for Differential Side Channel\n  Cryptanalysis","volume":"3659","author":"Werner Schindler","year":"2005"},{"key":"ref54:XUSENIX:McCOswWhi17","first-page":"199","article-title":"Towards Practical Tools for Side Channel Aware Software\n  Engineering: 'Grey Box' Modelling for Instruction Leakages","author":"David McCann","year":"2017"},{"key":"ref55:TCHES:MarPagWeb22","doi-asserted-by":"publisher","first-page":"175","DOI":"10.46586\/tches.v2022.i1.175-220","article-title":"MIRACLE: MIcRo-ArChitectural Leakage Evaluation A\n  study of micro-architectural power leakage across many devices","volume":"2022","author":"Ben Marshall","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref56:TCHES:MKSM22","doi-asserted-by":"publisher","first-page":"266","DOI":"10.46586\/tches.v2022.i2.266-288","article-title":"Transitional Leakage in Theory and Practice Unveiling\n  Security Flaws in Masked Circuits","volume":"2022","author":"Nicolai M\u00fcller","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref57:DBLP:conf\/cardis\/ChoudaryK13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"253","DOI":"10.1007\/978-3-319-08302-5_17","article-title":"Efficient Template Attacks","volume":"8419","author":"Omar Choudary","year":"2013"},{"key":"ref58:CHES:StaArc08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"411","DOI":"10.1007\/978-3-540-85053-3_26","article-title":"Using Subspace-Based Template Attacks to Compare and Combine\n  Power and Electromagnetic Information Leakages","volume":"5154","author":"Fran\u00e7ois-Xavier Standaert","year":"2008"},{"key":"ref59:TCHES:CDSU23","doi-asserted-by":"publisher","first-page":"270","DOI":"10.46586\/tches.v2023.i3.270-293","article-title":"Efficient Regression-Based Linear Discriminant Analysis for\n  Side-Channel Security Evaluations Towards Analytical Attacks against 32-bit\n  Implementations","volume":"2023","author":"Ga\u00ebtan Cassiers","year":"2023","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref60:TCHES:MasDumPro19","doi-asserted-by":"publisher","first-page":"348","DOI":"10.13154\/tches.v2020.i1.348-375","article-title":"A Comprehensive Study of Deep Learning for Side-Channel\n  Analysis","volume":"2020","author":"Lo\u00efc Masure","year":"2019","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref61:DBLP:journals\/csur\/PicekPMWB23","doi-asserted-by":"publisher","DOI":"10.1145\/3569577","article-title":"SoK: Deep Learning-based Physical Side-channel Analysis","volume":"55","author":"Stjepan Picek","year":"2023","journal-title":"ACM Comput. Surv."},{"key":"ref62:DBLP:conf\/cardis\/BelliziaUS21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-030-97348-3_4","article-title":"Towards a Better Understanding of Side-Channel Analysis\n  Measurements Setups","volume":"13173","author":"Davide Bellizia","year":"2021"},{"key":"ref63:smaeshdataset","volume-title":"The SMAesH dataset","author":"Ga\u00ebtan Cassiers","year":"2024"},{"key":"ref64:JCEng:SchMor16","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1007\/s13389-016-0120-y","article-title":"Leakage assessment methodology - Extended version","volume":"6","author":"Tobias Schneider","year":"2016","journal-title":"Journal of Cryptographic Engineering"},{"key":"ref65:JC:DucFauSta19","doi-asserted-by":"publisher","first-page":"1263","DOI":"10.1007\/s00145-018-9277-0","article-title":"Making Masking Security Proofs Concrete (Or How to Evaluate\n  the Security of Any Leaking Device), Extended Version","volume":"32","author":"Alexandre Duc","year":"2019","journal-title":"Journal of Cryptology"},{"key":"ref66:DBLP:conf\/cardis\/DingZDSF17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1007\/978-3-319-75208-2_7","article-title":"Towards Sound and Optimal Leakage Detection Procedure","volume":"10728","author":"A. Adam Ding","year":"2017"},{"key":"ref67:TCHES:GMPP20","doi-asserted-by":"publisher","first-page":"73","DOI":"10.13154\/tches.v2020.i2.73-98","article-title":"FENL: an ISE to mitigate analogue micro-architectural\n  leakage","volume":"2020","author":"Si Gao","year":"2020","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref68:TCHES:ChePagWan24","doi-asserted-by":"publisher","first-page":"329","DOI":"10.46586\/tches.v2024.i2.329-358","article-title":"eLIMInate: a Leakage-focused ISE for Masked\n  Implementation","volume":"2024","author":"Hao Cheng","year":"2024","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref69:JC:BoyMatPer13","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/s00145-012-9124-7","article-title":"Logic Minimization Techniques with Applications to\n  Cryptology","volume":"26","author":"Joan Boyar","year":"2013","journal-title":"Journal of Cryptology"},{"key":"ref70:TCHES:AdoPey21","doi-asserted-by":"publisher","first-page":"402","DOI":"10.46586\/tches.v2021.i1.402-425","article-title":"Fixslicing AES-like Ciphers","volume":"2021","author":"Alexandre Adomnicai","year":"2021","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref71:SP:BMRT22","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1109\/SP46214.2022.9833600","article-title":"IronMask: Versatile Verification of Masking Security","author":"Sonia Bela\u00efd","year":"2022"},{"key":"ref72:EPRINT:BroCasSta21","volume-title":"Give Me 5 Minutes: Attacking ASCAD with a Single\n  Side-Channel Trace","author":"Olivier Bronchain","year":"2021"},{"key":"ref73:EC:DziFauSko15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/978-3-662-46803-6_6","article-title":"Noisy Leakage Revisited","volume":"9057","author":"Stefan Dziembowski","year":"2015"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T17:23:28Z","timestamp":1744133008000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/1\/4"}},"issued":{"date-parts":[[2025,4,8]]},"references-count":73,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,4,8]]}},"URL":"https:\/\/doi.org\/10.62056\/aebngy4e-","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2025,4,8]]},"assertion":[{"value":"2024-10-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-03-11","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-4-47"},{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T12:11:18Z","timestamp":1785413478502,"version":"3.56.0"},"reference-count":26,"publisher":"International Association for Cryptologic Research","issue":"3","license":[{"start":{"date-parts":[[2025,7,6]],"date-time":"2025-07-06T00:00:00Z","timestamp":1751760000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,9,2]]},"abstract":"<jats:p>We introduce zkMaP (Zero-Knowledge Succinct Non-Interactive Matrix Multiplication Proofs), a novel non-interactive zero-knowledge proof system for verifying matrix multiplication with significant improvements in efficiency and scalability. Our protocol leverages KZG polynomial commitments and an innovative inner-product reduction technique to reduce the verification of n x n matrix multiplication to a single pairing equation, thereby enabling constant-time verification independent of the matrix size. In particular, zkMaP requires only two pairing operations and produces proofs as small as 320 bytes, yielding a 96 percent reduction in proof size compared to prior schemes. Furthermore, the prover's computational complexity follows the state-of-the-art at O(n^2), with experimental results demonstrating that proofs for 1024 x 1024 matrices can be generated in approximately 12.21 seconds, offering a 16.14x speedup over previous methods. Our implementation also exhibits better memory efficiency, using only 24.58 MB of prover-side RAM for 1024 x 1024 matrices, and supports scalable batch processing, achieving per-proof generation times of 46.79 milliseconds for 1024 instances while maintaining a constant verification time of 3.6 ms.<\/jats:p>","DOI":"10.62056\/angy11fgx","type":"journal-article","created":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T18:49:52Z","timestamp":1759776592000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":1,"title":["zkMaP: Zero-Knowledge Succinct Non-Interactive Matrix Multiplication Proofs"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9612-8695","authenticated-orcid":false,"given":"Biniyam","family":"Deressa","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01aff2v68","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Waterloo","place":["200 University Ave. W., Waterloo, N2L 3G1, Canada"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4103-7945","authenticated-orcid":false,"given":"M.","family":"Hasan","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01aff2v68","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Waterloo","place":["200 University Ave. W., Waterloo, N2L 3G1, Canada"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,10,6]]},"reference":[{"key":"ref1:bitansky2012extractable","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1145\/2090236.2090263","article-title":"From Extractable Collision Resistance to Succinct\n  Non-Interactive Arguments of Knowledge, and Back Again","author":"Nir Bitansky","year":"2012"},{"key":"ref2:ben2018scalable","volume-title":"Scalable, Transparent, and Post-Quantum Secure Computational\n  Integrity","author":"Eli Ben-Sasson","year":"2018"},{"key":"ref3:xie2019libra","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"733","DOI":"10.1007\/978-3-030-26954-8_24","article-title":"Libra: Succinct Zero-Knowledge Proofs with Optimal Prover\n  Computation","volume":"11693","author":"Tiacheng Xie","year":"2019"},{"key":"ref4:parno2016pinocchio","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1145\/2856449","article-title":"Pinocchio: Nearly Practical Verifiable Computation","volume":"59","author":"Bryan Parno","year":"2016","journal-title":"Communications of the ACM"},{"key":"ref5:kate2010constant","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1007\/978-3-642-17373-8_11","article-title":"Constant-Size Commitments to Polynomials and Their\n  Applications","volume":"6476","author":"Aniket Kate","year":"2010"},{"key":"ref6:maller2019sonic","doi-asserted-by":"publisher","first-page":"2111","DOI":"10.1145\/3319535.3339817","article-title":"Sonic: Zero-Knowledge SNARKs from Linear-Size Universal\n  and Updatable Structured Reference Strings","author":"Mary Maller","year":"2019"},{"key":"ref7:chen2023hyperplonk","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"499","DOI":"10.1007\/978-3-031-30617-4_17","article-title":"HyperPlonk: Plonk with Linear-Time Prover and High-Degree\n  Custom Gates","volume":"14077","author":"Binyi Chen","year":"2023"},{"key":"ref8:groth2016size","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"305","DOI":"10.1007\/978-3-662-49896-5_11","article-title":"On the Size of Pairing-Based Non-Interactive Arguments","volume":"9666","author":"Jens Groth","year":"2016"},{"key":"ref9:thaler2013time","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/978-3-642-40084-1_5","article-title":"Time-Optimal Interactive Proofs for Circuit Evaluation","author":"Justin Thaler","year":"2013"},{"key":"ref10:campanelli2019legosnark","doi-asserted-by":"publisher","first-page":"2075","DOI":"10.1145\/3319535.3339820","article-title":"LegoSNARK: Modular Design and Composition of Succinct\n  Zero-Knowledge Proofs","author":"Matteo Campanelli","year":"2019"},{"key":"ref11:yang2021quicksilver","doi-asserted-by":"publisher","first-page":"2986","DOI":"10.1145\/3460120.3484556","article-title":"Quicksilver: Efficient and Affordable Zero-Knowledge\n  Proofs for Circuits and Polynomials Over Any Field","author":"Kang Yang","year":"2021"},{"key":"ref12:bunz2018bulletproofs","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1109\/SP.2018.00020","article-title":"Bulletproofs: Short Proofs for Confidential Transactions\n  and More","author":"Benedikt B\u00fcnz","year":"2018"},{"key":"ref13:chiesa2020marlin","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"738","DOI":"10.1007\/978-3-030-45721-1_26","article-title":"Marlin: Preprocessing zkSNARKs with Universal and\n  Updatable SRS","volume":"12105","author":"Alessandro Chiesa","year":"2020"},{"key":"ref14:gabizon2019plonk","volume-title":"Plonk: Permutations Over Lagrange-Bases for Oecumenical\n  Noninteractive Arguments of Knowledge","author":"Ariel Gabizon","year":"2019"},{"key":"ref15:cong2024zkmatrix","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1145\/3634737.3645003","article-title":"zkMatrix: Batched Short Proof for Committed Matrix\n  Multiplication","author":"Mingshu Cong","year":"2024"},{"key":"ref16:fiat1986prove","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1007\/3-540-47721-7_12","article-title":"How to Prove Yourself: Practical Solutions to Identification\n  and Signature Problems","volume":"263","author":"Amos Fiat","year":"1986"},{"key":"ref17:wahby2018doubly","doi-asserted-by":"publisher","first-page":"926","DOI":"10.1109\/SP.2018.00060","article-title":"Doubly-Efficient zkSNARKs Without Trusted Setup","author":"Riad S Wahby","year":"2018"},{"key":"ref18:schwartz1980fast","doi-asserted-by":"publisher","first-page":"701","DOI":"10.1145\/322217.322225","article-title":"Fast Probabilistic Algorithms for Verification of Polynomial\n  Identities","volume":"27","author":"Jacob T Schwartz","year":"1980","journal-title":"Journal of the ACM (JACM)"},{"key":"ref19:groth2009linear","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"192","DOI":"10.1007\/978-3-642-03356-8_12","article-title":"Linear Algebra with Sub-Linear Zero-Knowledge Arguments","volume":"5677","author":"Jens Groth","year":"2009"},{"key":"ref20:goldreich1994definitions","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/BF00195207","article-title":"Definitions and Properties of Zero-Knowledge Proof Systems","volume":"7","author":"Oded Goldreich","year":"1994","journal-title":"Journal of Cryptology"},{"key":"ref21:fuchsbauer2018algebraic","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-319-96881-0_2","article-title":"The Algebraic Group Model and Its Applications","volume":"10991","author":"Georg Fuchsbauer","year":"2018"},{"key":"ref22:boneh2004short","doi-asserted-by":"publisher","first-page":"297","DOI":"10.1007\/s00145-004-0314-9","article-title":"Short Signatures from the Weil Pairing","volume":"17","author":"Dan Boneh","year":"2004","journal-title":"Journal of Cryptology"},{"key":"ref23:bowe2017scalable","article-title":"Scalable Multi-Party Computation for zk-SNARK Parameters in\n  the Random Beacon Model","author":"Sean Bowe","year":"2017","journal-title":"Cryptology ePrint Archive"},{"key":"ref24:bellare2006multi","doi-asserted-by":"publisher","first-page":"390","DOI":"10.1145\/1180405.1180453","article-title":"Multi-Signatures in the Plain Public-Key Model and a General\n  Forking Lemma","author":"Mihir Bellare","year":"2006"},{"key":"ref25:bellare1993random","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1145\/168588.168596","article-title":"Random Oracles Are Practical: A Paradigm for Designing\n  Efficient Protocols","author":"Mihir Bellare","year":"1993"},{"key":"ref26:albrecht2024slap","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1007\/978-3-031-58754-2_4","article-title":"SLAP: Succinct Lattice-Based Polynomial Commitments from\n  Standard Assumptions","volume":"14657","author":"Martin R. Albrecht","year":"2024"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T20:23:03Z","timestamp":1759782183000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/3\/23"}},"issued":{"date-parts":[[2025,10,6]]},"references-count":26,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,10,6]]}},"URL":"https:\/\/doi.org\/10.62056\/angy11fgx","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2025,10,6]]},"assertion":[{"value":"2025-07-06","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-3-41"},{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T11:06:02Z","timestamp":1785409562420,"version":"3.56.0"},"reference-count":20,"publisher":"International Association for Cryptologic Research","issue":"3","license":[{"start":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T00:00:00Z","timestamp":1751846400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,9,2]]},"abstract":"<jats:p>Updatable encryption (UE), introduced by Boneh et al. (Crypto 2013), enables a secure rotation of symmetric encryption keys for outsourced encrypted data, without needing to download, decrypt, and re-encrypt the data. Many existing UE schemes, however, use public-key operations for the update step. This work investigates whether truly symmetric UE schemes can achieve modern UE security notions such as IND-ENC (indistinguishability of encryption) or IND-UPD (indistinguishability of updates) without relying on public-key primitives.<\/jats:p>\n                  <jats:p>Alamati et al. (Crypto 2019) showed that randomized update steps in IND-UPD-secure UE schemes already necessitate public-key cryptography if the update step is independent of the ciphertext. However, the IND-UPD security notion is usually not required for scenarios in which the history of updates is known, such that one may still hope to derive an IND-ENC secure solution based on symmetric encryption. We argue here that this is illusory for IND-ENC solutions with optimal leakage. Optimal leakage refers to the ideal situation where update steps only allow the computation of ciphertexts in the forward direction and do not leak anything about the updated keys. We show that such schemes inherently rely on public-key cryptography.<\/jats:p>","DOI":"10.62056\/a63ziv7sf","type":"journal-article","created":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T18:49:52Z","timestamp":1759776592000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Strongly Secure Updatable Encryption Requires Public-Key Cryptography"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0597-8297","authenticated-orcid":false,"given":"Marc","family":"Fischlin","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05n911h24","id-type":"ROR","asserted-by":"publisher"}],"name":"Technische Universit\u00e4t Darmstadt","place":["Germany"],"department":["Cryptoplexity"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-7980-9939","authenticated-orcid":false,"given":"G\u00f6zde","family":"Sa\u00e7\u0131ak","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05n911h24","id-type":"ROR","asserted-by":"publisher"}],"name":"Technische Universit\u00e4t Darmstadt","place":["Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,10,6]]},"reference":[{"key":"ref1:pcidss","volume-title":"Payment Card Industry Data Security Standard: Requirements\n  and Testing Procedures, v4.0.1","author":"PCI Security Standards Council","year":"2024"},{"key":"ref2:NIST800-57","volume-title":"Recommendation for Key Management: Part 1 \u2013 General","author":"National Institute of Standards","year":"2020"},{"key":"ref3:Boneh2013","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1007\/978-3-642-40041-4_23","article-title":"Key Homomorphic PRFs and Their Applications","volume":"8042","author":"Dan Boneh","year":"2013"},{"key":"ref4:JMM19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/978-3-030-17653-2_6","article-title":"Efficient Ratcheting: Almost-Optimal Guarantees for Secure\n  Messaging","volume":"11476","author":"Daniel Jost","year":"2019"},{"key":"ref5:Everspaugh2017","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1007\/978-3-319-63697-9_4","article-title":"Key Rotation for Authenticated Encryption","volume":"10403","author":"Adam Everspaugh","year":"2017"},{"key":"ref6:Lehmann2018","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"685","DOI":"10.1007\/978-3-319-78372-7_22","article-title":"Updatable Encryption with Post-Compromise Security","volume":"10822","author":"Anja Lehmann","year":"2018"},{"key":"ref7:Klooss2019","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1007\/978-3-030-17653-2_3","article-title":"(R)CCA Secure Updatable Encryption with Integrity\n  Protection","volume":"11476","author":"Michael Kloo\u00df","year":"2019"},{"key":"ref8:BoydDGJ20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"464","DOI":"10.1007\/978-3-030-56784-2_16","article-title":"Fast and Secure Updatable Encryption","volume":"12170","author":"Colin Boyd","year":"2020"},{"key":"ref9:CGL23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"374","DOI":"10.1007\/978-981-99-8733-7_12","article-title":"CCA-1 Secure Updatable Encryption with Adaptive Security","volume":"14442","author":"Huanhuan Chen","year":"2023"},{"key":"ref10:Jiang2020","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"529","DOI":"10.1007\/978-3-030-64840-4_18","article-title":"The Direction of Updatable Encryption Does Not Matter Much","volume":"12493","author":"Yao Jiang","year":"2020"},{"key":"ref11:Nishimaki2022","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"194","DOI":"10.1007\/978-3-030-97131-1_7","article-title":"The Direction of Updatable Encryption Does Matter","volume":"13178","author":"Ryo Nishimaki","year":"2022"},{"key":"ref12:JiangGalteland2023","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"399","DOI":"10.1007\/978-3-031-31371-4_14","article-title":"Backward-Leak Uni-Directional Updatable Encryption from\n  (Homomorphic) Public Key Encryption","volume":"13941","author":"Yao Jiang Galteland","year":"2023"},{"key":"ref13:Slamanig2023","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"220","DOI":"10.1007\/978-3-031-48618-0_8","article-title":"Revisiting Updatable Encryption: Controlled Forward\n  Security, Constructions and a Puncturable Perspective","volume":"14370","author":"Daniel Slamanig","year":"2023"},{"key":"ref14:Miao2023","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"368","DOI":"10.1007\/978-3-031-31371-4_13","article-title":"Unidirectional Updatable Encryption and Proxy Re-encryption\n  from DDH","volume":"13941","author":"Peihan Miao","year":"2023"},{"key":"ref15:LR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1007\/978-3-031-62746-0_2","article-title":"Updatable Encryption from Group Actions","volume":"14772","author":"Antonin Leroux","year":"2024"},{"key":"ref16:MR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/978-3-031-62743-9_5","article-title":"CCA Secure Updatable Encryption from Non-mappable Group\n  Actions","volume":"14771","author":"Jonas Meers","year":"2024"},{"key":"ref17:Boneh2020","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1007\/978-3-030-64840-4_19","article-title":"Improving Speed and Security in Updatable Encryption\n  Schemes","volume":"12493","author":"Dan Boneh","year":"2020"},{"key":"ref18:Alamati2019","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"650","DOI":"10.1007\/978-3-030-26948-7_23","article-title":"Symmetric Primitives with Structured Secrets","volume":"11692","author":"Navid Alamati","year":"2019"},{"key":"ref19:LT18eprint","first-page":"118","article-title":"Updatable Encryption with Post-Compromise Security","author":"Anja Lehmann","year":"2018","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref20:IR89","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1145\/73007.73012","article-title":"Limits on the Provable Consequences of One-Way\n  Permutations","author":"Russell Impagliazzo","year":"1989"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T20:23:16Z","timestamp":1759782196000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/3\/27"}},"issued":{"date-parts":[[2025,10,6]]},"references-count":20,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,10,6]]}},"URL":"https:\/\/doi.org\/10.62056\/a63ziv7sf","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2025,10,6]]},"assertion":[{"value":"2025-07-07","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-3-50"},{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T11:21:08Z","timestamp":1785410468164,"version":"3.56.0"},"reference-count":36,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,7,9]],"date-time":"2024-07-09T00:00:00Z","timestamp":1720483200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/S022503\/1"],"award-info":[{"award-number":["EP\/S022503\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002347","name":"Federal Ministry of Education and Research","doi-asserted-by":"publisher","award":["16KISK033"],"award-info":[{"award-number":["16KISK033"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,9,2]]},"abstract":"<jats:p>\n                    Isogeny-based schemes often come with special requirements on         the field of definition of the involved elliptic curves.         For instance, the efficiency of SQIsign, a promising candidate in the NIST         signature standardisation process,         requires a large power of two and a large smooth integer\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>T<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    to         divide\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:msup>\n                          <mml:mi>p<\/mml:mi>\n                          <mml:mn>2<\/mml:mn>\n                        <\/mml:msup>\n                        <mml:mo>\u2212<\/mml:mo>\n                        <mml:mn>1<\/mml:mn>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    for its prime parameter\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>p<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    .                  We present two new methods that combine previous techniques for finding         suitable primes: sieve-and-boost and XGCD-and-boost.         We use these methods to find primes for the NIST submission of SQIsign.         Furthermore, we show that our methods are flexible and can be adapted         to find suitable parameters for other isogeny-based schemes such as         Apr\u00e8sSQI or POKE.         For all three schemes, the parameters we present offer the best performance         among all parameters proposed in the literature.\n                  <\/jats:p>","DOI":"10.62056\/ayojbhey6b","type":"journal-article","created":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T11:13:33Z","timestamp":1728299613000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":5,"title":["Finding Practical Parameters for   Isogeny-based Cryptography"],"prefix":"10.62056","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2651-8951","authenticated-orcid":false,"given":"Maria","family":"Santos","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02jx3x895","id-type":"ROR","asserted-by":"publisher"}],"name":"University College London","place":["London, UK"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3040-2965","authenticated-orcid":false,"given":"Jonathan","family":"Eriksen","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05xg72x27","id-type":"ROR","asserted-by":"publisher"}],"name":"Norwegian University of Science and Technology","place":["Trondheim, Norway"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-2972-7324","authenticated-orcid":false,"given":"Michael","family":"Meyer","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01eezs655","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Regensburg","place":["Regensburg, Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5916-6625","authenticated-orcid":false,"given":"Francisco","family":"Rodr\u00edguez-Henr\u00edquez","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/001kv2y39","id-type":"ROR","asserted-by":"publisher"}],"name":"Cryptography Research Center, Technology Innovation Institute","place":["Abu Dhabi, United Arab Emirates"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2024,10,7]]},"reference":[{"key":"ref1:NIS23a","volume-title":"Post-quantum cryptography: Digital signature schemes, 2023","author":"NIST","year":"2023"},{"key":"ref2:AC:Costello20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"440","DOI":"10.1007\/978-3-030-64834-3_15","article-title":"B-SIDH: Supersingular Isogeny Diffie-Hellman Using\n  Twisted Torsion","volume":"12492","author":"Craig Costello","year":"2020"},{"key":"ref3:AC:DKLPW20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-030-64837-4_3","article-title":"SQISign: Compact Post-quantum Signatures from Quaternions\n  and Isogenies","volume":"12491","author":"Luca De Feo","year":"2020"},{"key":"ref4:EC:DLLW23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"659","DOI":"10.1007\/978-3-031-30589-4_23","article-title":"New Algorithms for the Deuring Correspondence - Towards\n  Practical and Secure SQISign Signatures","volume":"14008","author":"Luca De Feo","year":"2023"},{"key":"ref5:poke","volume-title":"POKE: A Framework for Efficient PKEs, Split KEMs, and OPRFs\n  from Higher-dimensional Isogenies","author":"Andrea Basso","year":"2024"},{"key":"ref6:velu","first-page":"238","article-title":"Isog\u00e9nies entre courbes elliptiques","volume":"273","author":"Jacques V\u00e9lu","year":"1971","journal-title":"Comptes Rendus de l'Acad\u00e9mie des Sciences de Paris,\n  S\u00e9ries A"},{"key":"ref7:velusqrt","doi-asserted-by":"publisher","first-page":"39","DOI":"10.2140\/obs.2020.4.39","article-title":"Faster computation of isogenies of large prime degree","volume":"4","author":"Daniel J Bernstein","year":"2020","journal-title":"Open Book Series"},{"key":"ref8:EC:CosMeyNae21","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"272","DOI":"10.1007\/978-3-030-77870-5_10","article-title":"Sieving for Twin Smooth Integers with Solutions to the\n  Prouhet-Tarry-Escott Problem","volume":"12696","author":"Craig Costello","year":"2021"},{"key":"ref9:AC:BSCEMNS23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1007\/978-981-99-8739-9_7","article-title":"Cryptographic Smooth Neighbors","volume":"14444","author":"Giacomo Bruno","year":"2023"},{"key":"ref10:EC:CasDec23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/978-3-031-30589-4_15","article-title":"An Efficient Key Recovery Attack on SIDH","volume":"14008","author":"Wouter Castryck","year":"2023"},{"key":"ref11:EC:MMPPW23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"448","DOI":"10.1007\/978-3-031-30589-4_16","article-title":"A Direct Key Recovery Attack on SIDH","volume":"14008","author":"Luciano Maino","year":"2023"},{"key":"ref12:EC:Robert23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"472","DOI":"10.1007\/978-3-031-30589-4_17","article-title":"Breaking SIDH in Polynomial Time","volume":"14008","author":"Damien Robert","year":"2023"},{"key":"ref13:apressqi","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-031-58716-0_3","article-title":"Apr\u00e8sSQI: Extra Fast Verification for SQIsign Using\n  Extension-Field Signing","volume":"14651","author":"Maria Corte-Real Santos","year":"2024"},{"key":"ref14:sqisign-specs","volume-title":"SQIsign: Algorithm specifications and supporting\n  documentation","author":"Jorge Chavez-Saab","year":"2023"},{"key":"ref15:SQIsign2D-West","volume-title":"SQIsign2D-West: The Fast, the Small, and the Safer","author":"Andrea Basso","year":"2024"},{"key":"ref16:SQIPrime","volume-title":"SQIPrime: A dimension 2 variant of SQISignHD with non-smooth\n  challenge isogenies","author":"Max Duparc","year":"2024"},{"key":"ref17:SQIsign2D-East","volume-title":"SQIsign2D-East: A New Signature Scheme Using 2-dimensional\n  Isogenies","author":"Kohei Nakagawa","year":"2024"},{"key":"ref18:SQIsignHD","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-58716-0_1","article-title":"SQIsignHD: New Dimensions in Cryptography","volume":"14651","author":"Pierrick Dartois","year":"2024"},{"key":"ref19:AAA+24","volume-title":"Optimized SQIsign 1D verification on Intel and Cortex-M4","author":"Marius A. Aardal","year":"2024"},{"key":"ref20:Stormer","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1215\/ijm\/1256067456","article-title":"Quelques th\u00e9or\u00e8mes sur l'\u00e9quation de Pell\n  $x^2-Dy^2=\\pm1$ et leurs applications","author":"Carl St\u00f8rmer","year":"1897","journal-title":"Christiania Videnskabens Selskabs Skrifter, Math. Nat. Kl"},{"key":"ref21:Lehmer","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1215\/ijm\/1256067456","article-title":"On a problem of St\u00f6rmer","volume":"8","author":"Derrick H. Lehmer","year":"1964","journal-title":"Illinois Journal of Mathematics"},{"key":"ref22:BHLNV","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2211.04315","article-title":"Finding twin smooth integers by solving Pell equations","volume":"abs\/2211.04315","author":"Jan Buzek","year":"2022","journal-title":"CoRR"},{"key":"ref23:chm","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1080\/10586458.2013.768483","article-title":"Smooth neighbors","volume":"22","author":"Brian Conrey","year":"2013","journal-title":"Experimental Mathematics"},{"key":"ref24:cryptoeprint:2023\/1576","volume-title":"Towards Optimally Small Smoothness Bounds for\n  Cryptographic-Sized Twin Smooth Integers and their Isogeny-based\n  Applications","author":"Bruno Sterner","year":"2023"},{"key":"ref25:AAA+24b","volume-title":"Scoring primes for computing isogenies in extension\n  fields","author":"Marius A. Aardal","year":"2024"},{"key":"ref26:TCHES:BBCCLMSS21","doi-asserted-by":"publisher","first-page":"351","DOI":"10.46586\/tches.v2021.i4.351-387","article-title":"CTIDH: faster constant-time CSIDH","volume":"2021","author":"Gustavo Banegas","year":"2021","journal-title":"IACR TCHES","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref27:LC:CCCDRS19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/978-3-030-30530-7_9","article-title":"Stronger and Faster Side-Channel Protections for CSIDH","volume":"11774","author":"Daniel Cervantes-V\u00e1zquez","year":"2019"},{"key":"ref28:CCC+24","doi-asserted-by":"publisher","DOI":"10.62056\/ANJBKSDJA","article-title":"Optimizations and Practicality of High-Security CSIDH","volume":"1","author":"Fabio Campos","year":"2024","journal-title":"IACR Communications in Cryptology"},{"key":"ref29:DftP","series-title":"Contemporary Mathematics","isbn-type":"print","doi-asserted-by":"publisher","first-page":"339","DOI":"10.1090\/conm\/796\/16008","article-title":"Deuring for the People: Supersingular elliptic curves with\n  prescribed endomorphism ring in general characteristic","volume":"796","author":"Jonathan Komada Eriksen","year":"2024","ISBN":"https:\/\/id.crossref.org\/isbn\/9781470472603"},{"key":"ref30:JCEng:BajDuq21","doi-asserted-by":"publisher","first-page":"399","DOI":"10.1007\/s13389-021-00260-z","article-title":"Montgomery-friendly primes and applications to\n  cryptography","volume":"11","author":"Jean-Claude Bajard","year":"2021","journal-title":"Journal of Cryptographic Engineering"},{"key":"ref31:Montgomery05","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1109\/TC.2005.49","article-title":"Five, Six, and Seven-Term Karatsuba-Like Formulae","volume":"54","author":"Peter L. Montgomery","year":"2005","journal-title":"IEEE Trans. Computers"},{"key":"ref32:JCEng:Cenk18","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/s13389-017-0155-8","article-title":"Karatsuba-like formulae and their associated techniques","volume":"8","author":"Murat Cenk","year":"2018","journal-title":"Journal of Cryptographic Engineering"},{"key":"ref33:bernstein2004find","volume-title":"How to find smooth parts of integers","author":"Daniel J. Bernstein","year":"2004"},{"key":"ref34:BanksShparlinski","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.8281131","article-title":"Integers with a large smooth divisor","volume":"7","author":"William D. Banks","year":"2007","journal-title":"Integers. Electronic Journal of Combinatorial Number\n  Theory","ISSN":"https:\/\/id.crossref.org\/issn\/1553-1732","issn-type":"electronic"},{"key":"ref35:dickman","article-title":"On the frequency of numbers containing prime factors of a\n  certain relative magnitude","volume":"22","author":"Karl Dickman","year":"1930","journal-title":"Arkiv for matematik, astronomi och fysik"},{"key":"ref36:deBruijn","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1016\/S1385-7258(66)50029-4","article-title":"On the number of positive integers $\\leq$ x and free of\n  prime factors $> y$, II","volume":"38","author":"Nicolaas G. de Bruijn","year":"1966","journal-title":"Indag. Math"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T16:28:40Z","timestamp":1733848120000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/3\/39"}},"issued":{"date-parts":[[2024,10,7]]},"references-count":36,"URL":"https:\/\/doi.org\/10.62056\/ayojbhey6b","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2024,10,7]]},"assertion":[{"value":"2024-07-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-3-106"},{"indexed":{"date-parts":[[2026,8,27]],"date-time":"2026-08-27T15:25:35Z","timestamp":1787844335559,"version":"build-2784847793"},"reference-count":137,"publisher":"International Association for Cryptologic Research","issue":"3","license":[{"start":{"date-parts":[[2025,7,8]],"date-time":"2025-07-08T00:00:00Z","timestamp":1751932800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"publisher","award":["RGPIN-2022-03187"],"award-info":[{"award-number":["RGPIN-2022-03187"]}],"id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"publisher","award":["ALLRP 578463-22"],"award-info":[{"award-number":["ALLRP 578463-22"]}],"id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,9,2]]},"abstract":"<jats:p>Large-scale quantum computers capable of implementing Shor's algorithm pose a significant threat to the security of the most widely used public-key cryptographic schemes.   This risk has motivated substantial efforts by standards bodies and government agencies to identify and standardize quantum-safe cryptographic systems.   Among the proposed solutions, lattice-based cryptography has emerged as the foundation for some of the most promising protocols.<\/jats:p>\n                  <jats:p>This paper describes FrodoKEM, a family of conservative key-encapsulation mechanisms (KEMs) whose security is based on generic, \u201cunstructured\u201d lattices.   FrodoKEM is proposed as an alternative to the more efficient lattice schemes that utilize algebraically structured lattices, such as the recently standardized ML-KEM scheme.   By relying on generic lattices, FrodoKEM minimizes the potential for future attacks that exploit algebraic structures while enabling simple and compact implementations.   Our plain C implementations demonstrate that, despite its conservative design and parameterization, FrodoKEM remains practical.   For instance, the full protocol at NIST security level 1 runs in approximately 0.97 ms on a server-class processor, and 4.98 ms on a smartphone-class processor.<\/jats:p>\n                  <jats:p>FrodoKEM obtains (single-target) IND-CCA security using a variant of the Fujisaki-Okamoto transform, applied to an underlying public-key encryption scheme called FrodoPKE.   In addition, using a new tool called the Salted Fujisaki-Okamoto (SFO) transform, FrodoKEM is also shown to tightly achieve multi-target security, without increasing the FrodoPKE message length and with a negligible performance impact, based on the multi-target IND-CPA security of FrodoPKE.<\/jats:p>","DOI":"10.62056\/ayivom2hd","type":"journal-article","created":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T18:49:52Z","timestamp":1759776592000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":6,"title":["FrodoKEM: A CCA-Secure Learning With Errors Key Encapsulation Mechanism"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-7165-6150","authenticated-orcid":false,"given":"Lewis","family":"Glabush","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02s376052","id-type":"ROR","asserted-by":"publisher"}],"name":"EPFL","place":["Lausanne, Switzerland"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5791-6341","authenticated-orcid":false,"given":"Patrick","family":"Longa","sequence":"additional","affiliation":[{"name":"Microsoft Research","place":["Redmond, United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-7119-5242","authenticated-orcid":false,"given":"Michael","family":"Naehrig","sequence":"additional","affiliation":[{"name":"Microsoft Research","place":["Redmond, United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0419-7501","authenticated-orcid":false,"given":"Chris","family":"Peikert","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/00jmfr291","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Michigan","place":["Ann Arbor, United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9443-3170","authenticated-orcid":false,"given":"Douglas","family":"Stebila","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01aff2v68","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Waterloo","place":["Waterloo, Canada"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0001-2955","authenticated-orcid":false,"given":"Fernando","family":"Virdia","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0220mzb33","id-type":"ROR","asserted-by":"publisher"}],"name":"King's College London","place":["London, United Kingdom"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,10,6]]},"reference":[{"key":"ref1:You_2005","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1063\/1.2155757","article-title":"Superconducting Circuits and Quantum Information","volume":"58","author":"J. Q. You","year":"2005","journal-title":"Physics Today","ISSN":"https:\/\/id.crossref.org\/issn\/1945-0699","issn-type":"electronic"},{"key":"ref2:Kelly_2015","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1038\/nature14270","article-title":"State preservation by repetitive error detection in a\n  superconducting quantum circuit","volume":"519","author":"J. Kelly","year":"2015","journal-title":"Nature","ISSN":"https:\/\/id.crossref.org\/issn\/1476-4687","issn-type":"electronic"},{"key":"ref3:NIST17","volume-title":"Post-Quantum Cryptography Standardization Project","author":"National Institute of Standards","year":"2017"},{"key":"ref4:Reg09","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1145\/1568318.1568324","article-title":"On lattices, learning with errors, random linear codes, and\n  cryptography","volume":"56","author":"Oded Regev","year":"2009","journal-title":"Journal of the ACM"},{"key":"ref5:STOC:Ajtai96","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1145\/237814.237838","article-title":"Generating Hard Instances of Lattice Problems (Extended\n  Abstract)","author":"Mikl\u00f3s Ajtai","year":"1996"},{"key":"ref6:MLKEM","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.FIPS.203","volume-title":"Module-Lattice-Based Key-Encapsulation Mechanism Standard\n  (FIPS 203)","author":"National Institute of Standards","year":"2024"},{"key":"ref7:MLDSA","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.FIPS.204","volume-title":"Module-Lattice-Based Digital Signature Standard (FIPS\n  204)","author":"National Institute of Standards","year":"2024"},{"key":"ref8:CME","volume-title":"Classic McEliece: conservative code-based cryptography","author":"Martin R. Albrecht"},{"key":"ref9:BSI","volume-title":"Cryptographic Mechanisms: Recommendations and Key Lengths,\n  BSI TR-02102-1, Version: 2024-1","author":"Federal Office for Information Security (BSI)","year":"2024"},{"key":"ref10:ANSSI","volume-title":"ANSSI views on the Post-Quantum Cryptography transition\n  (2023 follow up)","author":"National Cybersecurity Agency of France (ANSSI)","year":"2023"},{"key":"ref11:AIVD","volume-title":"Prepare for the threat of quantum computers","author":"General Intelligence","year":"2022"},{"key":"ref12:Dutch_HB","volume-title":"The PQC Migration Handbook: Guidelines for Migrating to\n  Post-Quantum Cryptography (second edition)","author":"General Intelligence","year":"2024"},{"key":"ref13:ISO","volume-title":"ISO\/IEC 18033-2:2006\/DAmd 2, Information technology \u2013\n  Security techniques \u2013 Encryption algorithms \u2013 Part 2: Asymmetric ciphers","author":"International Organization for Standardization (ISO)","year":"2024"},{"key":"ref14:Micciancio10","series-title":"Information Security and Cryptography","doi-asserted-by":"publisher","first-page":"427","DOI":"10.1007\/978-3-642-02295-1_13","article-title":"Cryptographic Functions from Worst-Case Complexity\n  Assumptions","author":"Daniele Micciancio","year":"2010"},{"key":"ref15:RegevLWESurvey","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1109\/CCC.2010.26","article-title":"The Learning with Errors Problem (Invited Survey)","author":"Oded Regev","year":"2010"},{"key":"ref16:DBLP:journals\/fttcs\/Peikert16","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1561\/0400000074","article-title":"A Decade of Lattice Cryptography","volume":"10","author":"Chris Peikert","year":"2016","journal-title":"Foundations and Trends in Theoretical Computer Science"},{"key":"ref17:STOC:AjtDwo97","doi-asserted-by":"publisher","first-page":"284","DOI":"10.1145\/258533.258604","article-title":"A Public-Key Cryptosystem with Worst-Case\/Average-Case\n  Equivalence","author":"Mikl\u00f3s Ajtai","year":"1997"},{"key":"ref18:EPRINT:GolGolHal96a","volume-title":"Collision-Free Hashing from Lattice Problems","author":"Oded Goldreich","year":"1996"},{"key":"ref19:FOCS:CaiNer97","doi-asserted-by":"publisher","first-page":"468","DOI":"10.1109\/SFCS.1997.646135","article-title":"An Improved Worst-Case to Average-Case Connection for\n  Lattice Problems","author":"Jin-yi Cai","year":"1997"},{"key":"ref20:STOC:Micciancio02","doi-asserted-by":"publisher","first-page":"609","DOI":"10.1145\/509907.509995","article-title":"Improved cryptographic hash functions with\n  worst-case\/average-case connection","author":"Daniele Micciancio","year":"2002"},{"key":"ref21:DBLP:journals\/jacm\/Regev04","doi-asserted-by":"publisher","first-page":"899","DOI":"10.1145\/1039488.1039490","article-title":"New lattice-based cryptographic constructions","volume":"51","author":"Oded Regev","year":"2004","journal-title":"J.\u00a0ACM"},{"key":"ref22:DBLP:journals\/siamcomp\/MicciancioR07","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1137\/S0097539705447360","article-title":"Worst-Case to Average-Case Reductions Based on Gaussian\n  Measures.","volume":"37","author":"Daniele Micciancio","year":"2007","journal-title":"SIAM J.\u00a0Comput."},{"key":"ref23:TCC:Peikert09_slides","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"72","DOI":"10.1007\/978-3-642-00457-5_5","article-title":"Some Recent Progress in Lattice-Based Cryptography","volume":"5444","author":"Chris Peikert","year":"2009"},{"key":"ref24:DifHel76","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","article-title":"New Directions in Cryptography","volume":"22","author":"Whitfield Diffie","year":"1976","journal-title":"IEEE Transactions on Information Theory"},{"key":"ref25:STOC:Peikert09","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1145\/1536414.1536461","article-title":"Public-key cryptosystems from the worst-case shortest vector\n  problem: extended abstract","author":"Chris Peikert","year":"2009"},{"key":"ref26:C:ACPS09","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"595","DOI":"10.1007\/978-3-642-03356-8_35","article-title":"Fast Cryptographic Primitives and Circular-Secure Encryption\n  Based on Hard Learning Problems","volume":"5677","author":"Benny Applebaum","year":"2009"},{"key":"ref27:STOC:BLPRS13","doi-asserted-by":"publisher","first-page":"575","DOI":"10.1145\/2488608.2488680","article-title":"Classical hardness of learning with errors","author":"Zvika Brakerski","year":"2013"},{"key":"ref28:EC:DotMul13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1007\/978-3-642-38348-9_2","article-title":"Lossy Codes and a New Variant of the Learning-With-Errors\n  Problem","volume":"7881","author":"Nico D\u00f6ttling","year":"2013"},{"key":"ref29:C:MicPei13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/978-3-642-40041-4_2","article-title":"Hardness of SIS and LWE with Small Parameters","volume":"8042","author":"Daniele Micciancio","year":"2013"},{"key":"ref30:STOC:PeiRegSte17","doi-asserted-by":"publisher","first-page":"461","DOI":"10.1145\/3055399.3055489","article-title":"Pseudorandomness of ring-LWE for any ring and modulus","author":"Chris Peikert","year":"2017"},{"key":"ref31:MR09:_post_quant_crypt","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/978-3-540-88702-7_5","article-title":"Lattice-based Cryptography","author":"Daniele Micciancio","year":"2009"},{"key":"ref32:AC:CheNgu11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-25385-0_1","article-title":"BKZ 2.0: Better Lattice Security Estimates","volume":"7073","author":"Yuanmi Chen","year":"2011"},{"key":"ref33:RSA:LiuNgu13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1007\/978-3-642-36095-4_19","article-title":"Solving BDD by Enumeration: An Update","volume":"7779","author":"Mingjie Liu","year":"2013"},{"key":"ref34:ICISC:AlbFitGop13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1007\/978-3-319-12160-4_18","article-title":"On the Efficacy of Solving LWE by Reduction to\n  Unique-SVP","volume":"8565","author":"Martin R. Albrecht","year":"2014"},{"key":"ref35:ChenThesis","volume-title":"Lattice reduction and concrete security of fully homomorphic\n  encryption","author":"Yuanmi Chen","year":"2013"},{"key":"ref36:EPRINT:ACFP14","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1145\/2815111.2815158","article-title":"Algebraic Algorithms for LWE","volume":"49","author":"Martin R. Albrecht","year":"2015","journal-title":"ACM Commun. Comput. Algebra"},{"key":"ref37:PKC:AFFP14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"429","DOI":"10.1007\/978-3-642-54631-0_25","article-title":"Lazy Modulus Switching for the BKW Algorithm on LWE","volume":"8383","author":"Martin R. Albrecht","year":"2014"},{"key":"ref38:LaarhovenThesis","volume-title":"Search problems in cryptography","author":"Thijs Laarhoven","year":"2015"},{"key":"ref39:C:KirFou15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1007\/978-3-662-47989-6_3","article-title":"An Improved BKW Algorithm for LWE with Applications to\n  Cryptography and Lattices","volume":"9215","author":"Paul Kirchner","year":"2015"},{"key":"ref40:albrecht15:_concrete_lwe","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1515\/jmc-2015-0016","article-title":"On the concrete hardness of Learning with Errors","volume":"9","author":"Martin R. Albrecht","year":"2015","journal-title":"Journal of Mathematical Cryptology"},{"key":"ref41:USENIX:ADPS16","first-page":"327","article-title":"Post-quantum Key Exchange - A New Hope","author":"Erdem Alkim","year":"2016"},{"key":"ref42:CCS:BCDMNN16","doi-asserted-by":"publisher","first-page":"1006","DOI":"10.1145\/2976749.2978425","article-title":"Frodo: Take off the Ring! Practical, Quantum-Secure Key\n  Exchange from LWE","author":"Joppe W. Bos","year":"2016"},{"key":"ref43:EC:Albrecht17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1007\/978-3-319-56614-6_4","article-title":"On Dual Lattice Attacks Against Small-Secret LWE and\n  Parameter Choices in HElib and SEAL","volume":"10211","author":"Martin R. Albrecht","year":"2017"},{"key":"ref44:EPRINT:AGVW17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"297","DOI":"10.1007\/978-3-319-70694-8_11","article-title":"Revisiting the Expected Cost of Solving uSVP and\n  Applications to LWE","volume":"10624","author":"Martin R. Albrecht","year":"2017"},{"key":"ref45:STOC:PeiWat08","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1145\/1374376.1374406","article-title":"Lossy trapdoor functions and their applications","author":"Chris Peikert","year":"2008"},{"key":"ref46:C:PeiVaiWat08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"554","DOI":"10.1007\/978-3-540-85174-5_31","article-title":"A Framework for Efficient and Composable Oblivious\n  Transfer","volume":"5157","author":"Chris Peikert","year":"2008"},{"key":"ref47:STOC:GenPeiVai08","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1145\/1374376.1374407","article-title":"Trapdoors for hard lattices and new cryptographic\n  constructions","author":"Craig Gentry","year":"2008"},{"key":"ref48:JC:CHKP12","doi-asserted-by":"publisher","first-page":"601","DOI":"10.1007\/s00145-011-9105-2","article-title":"Bonsai Trees, or How to Delegate a Lattice Basis","volume":"25","author":"David Cash","year":"2012","journal-title":"Journal of Cryptology"},{"key":"ref49:FOCS:BraVai11","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1109\/FOCS.2011.12","article-title":"Efficient Fully Homomorphic Encryption from (Standard)\n  LWE","author":"Zvika Brakerski","year":"2011"},{"key":"ref50:C:GenSahWat13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1007\/978-3-642-40041-4_5","article-title":"Homomorphic Encryption from Learning with Errors:\n  Conceptually-Simpler, Asymptotically-Faster, Attribute-Based","volume":"8042","author":"Craig Gentry","year":"2013"},{"key":"ref51:EC:BGGHNS14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1007\/978-3-642-55220-5_30","article-title":"Fully Key-Homomorphic Encryption, Arithmetic Circuit ABE\n  and Compact Garbled Circuits","volume":"8441","author":"Dan Boneh","year":"2014"},{"key":"ref52:C:GorVaiWee15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"503","DOI":"10.1007\/978-3-662-48000-7_25","article-title":"Predicate Encryption for Circuits from LWE","volume":"9216","author":"Sergey Gorbunov","year":"2015"},{"key":"ref53:RSA:LinPei11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/978-3-642-19074-2_21","article-title":"Better Key Sizes (and Attacks) for LWE-Based Encryption","volume":"6558","author":"Richard Lindner","year":"2011"},{"key":"ref54:NISTPQC-R1:FrodoKEM17","volume-title":"FrodoKEM","author":"Michael Naehrig","year":"2017"},{"key":"ref55:NISTPQC-R2:FrodoKEM19","volume-title":"FrodoKEM","author":"Michael Naehrig","year":"2019"},{"key":"ref56:NISTPQC-R3:FrodoKEM20","volume-title":"FrodoKEM","author":"Michael Naehrig","year":"2020"},{"key":"ref57:PKC:FujOka99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/3-540-49162-7_5","article-title":"How to Enhance the Security of Public-Key Encryption at\n  Minimum Cost","volume":"1560","author":"Eiichiro Fujisaki","year":"1999"},{"key":"ref58:EPRINT:DinXieLin12","volume-title":"A Simple Provably Secure Key Exchange Scheme Based on the\n  Learning with Errors Problem","author":"Jintai Ding","year":"2012"},{"key":"ref59:PQCRYPTO:Peikert14","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1007\/978-3-319-11659-4_12","article-title":"Lattice Cryptography for the Internet","author":"Chris Peikert","year":"2014"},{"key":"ref60:SP:BCNS15","doi-asserted-by":"publisher","first-page":"553","DOI":"10.1109\/SP.2015.40","article-title":"Post-Quantum Key Exchange for the TLS Protocol from the\n  Ring Learning with Errors Problem","author":"Joppe W. Bos","year":"2015"},{"key":"ref61:ISOdraft","volume-title":"FrodoKEM Preliminary Standardization Proposal (submitted to\n  ISO)","author":"Erdem Alkim"},{"key":"ref62:DBLP:journals\/jacm\/LyubashevskyPR13","doi-asserted-by":"publisher","DOI":"10.1145\/2535925","article-title":"On Ideal Lattices and Learning with Errors Over Rings","volume":"60","author":"Vadim Lyubashevsky","year":"2013","journal-title":"Journal of the ACM"},{"key":"ref63:ITCS:BraGenVai12","doi-asserted-by":"publisher","first-page":"309","DOI":"10.1145\/2090236.2090262","article-title":"(Leveled) fully homomorphic encryption without\n  bootstrapping","author":"Zvika Brakerski","year":"2012"},{"key":"ref64:DBLP:journals\/dcc\/LangloisS15","doi-asserted-by":"publisher","first-page":"565","DOI":"10.1007\/S10623-014-9938-4","article-title":"Worst-case to average-case reductions for module lattices","volume":"75","author":"Adeline Langlois","year":"2015","journal-title":"Designs, Codes and Cryptography"},{"key":"ref65:HofPipSil98","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/BFB0054868","article-title":"NTRU: A Ring-Based Public Key Cryptosystem","volume":"1423","author":"Jeffrey Hoffstein","year":"1998"},{"key":"ref66:AFRICACRYPT:Schneider13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"375","DOI":"10.1007\/978-3-642-38553-7_22","article-title":"Sieving for Shortest Vectors in Ideal Lattices","volume":"7918","author":"Michael Schneider","year":"2013"},{"key":"ref67:PKC:IKMT14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"411","DOI":"10.1007\/978-3-642-54631-0_24","article-title":"Parallel Gauss Sieve Algorithm: Solving the SVP Challenge\n  over a 128-Dimensional Ideal Lattice","volume":"8383","author":"Tsukasa Ishiguro","year":"2014"},{"key":"ref68:BNP_IJAC16","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1504\/IJACT.2017.10010312","article-title":"Sieving for Shortest Vectors in Ideal Lattices: a Practical\n  Perspective","volume":"3","author":"Joppe W. Bos","year":"2017","journal-title":"Int.\u00a0J.\u00a0 of Applied Cryptography"},{"key":"ref69:C:Laarhoven15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-662-47989-6_1","article-title":"Sieving for Shortest Vectors in Lattices Using Angular\n  Locality-Sensitive Hashing","volume":"9215","author":"Thijs Laarhoven","year":"2015"},{"key":"ref70:C:ELOS15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-662-47989-6_4","article-title":"Provably Weak Instances of Ring-LWE","volume":"9215","author":"Yara Elias","year":"2015"},{"key":"ref71:EPRINT:CheLauSta15","doi-asserted-by":"publisher","first-page":"665","DOI":"10.1137\/16M1096566","article-title":"Attacks on the Search RLWE Problem with Small Errors","volume":"1","author":"Hao Chen","year":"2017","journal-title":"SIAM J. Appl. Algebra Geom."},{"key":"ref72:EC:CasIliVer16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/978-3-662-49890-3_6","article-title":"Provably Weak Instances of Ring-LWE Revisited","volume":"9665","author":"Wouter Castryck","year":"2016"},{"key":"ref73:EPRINT:CheLauSta16","volume-title":"Vulnerable Galois RLWE Families and Improved Attacks","author":"Hao Chen","year":"2016"},{"key":"ref74:SCN:Peikert16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"411","DOI":"10.1007\/978-3-319-44618-9_22","article-title":"How (Not) to Instantiate Ring-LWE","volume":"9841","author":"Chris Peikert","year":"2016"},{"key":"ref75:EC:KirFou17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-56620-7_1","article-title":"Revisiting Lattice Attacks on Overstretched NTRU\n  Parameters","volume":"10210","author":"Paul Kirchner","year":"2017"},{"key":"ref76:soliloquyattack","volume-title":"Soliloquy: a Cautionary Tale","author":"Peter Campbell","year":"2014"},{"key":"ref77:EC:CDPR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1007\/978-3-662-49896-5_20","article-title":"Recovering Short Generators of Principal Ideals in\n  Cyclotomic Rings","volume":"9666","author":"Ronald Cramer","year":"2016"},{"key":"ref78:EC:CraDucWes17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"324","DOI":"10.1007\/978-3-319-56620-7_12","article-title":"Short Stickelberger Class Relations and Application to\n  Ideal-SVP","volume":"10210","author":"Ronald Cramer","year":"2017"},{"key":"ref79:lenstra82:_factor","doi-asserted-by":"crossref","first-page":"515","DOI":"10.1007\/BF01457454","article-title":"Factoring polynomials with rational coefficients","volume":"261","author":"Arjen K. Lenstra","year":"1982","journal-title":"Mathematische Annalen"},{"key":"ref80:DBLP:journals\/tcs\/Schnorr87","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1016\/0304-3975(87)90064-8","article-title":"A Hierarchy of Polynomial Time Lattice Basis Reduction\n  Algorithms","volume":"53","author":"Claus-Peter Schnorr","year":"1987","journal-title":"Theoretical Computer Science"},{"key":"ref81:EC:PelHanSte19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"685","DOI":"10.1007\/978-3-030-17656-3_24","article-title":"Approx-SVP in Ideal Lattices with Pre-processing","volume":"11477","author":"Alice Pellet-Mary","year":"2019"},{"key":"ref82:perlner21","volume-title":"Multi-ciphertext attacks","author":"Ray Perlner","year":"2021"},{"key":"ref83:EPRINT:Bernstein22d","volume-title":"Multi-ciphertext security degradation for lattices","author":"Daniel J. Bernstein","year":"2022"},{"key":"ref84:EPRINT:GlaHovSte25","volume-title":"Tight Multi-challenge Security Reductions for Key\n  Encapsulation Mechanisms","author":"Lewis Glabush","year":"2025"},{"key":"ref85:GlabushThesis","volume-title":"Tight Multi-Target Security for Key Encapsulation\n  Mechanisms","author":"Lewis Glabush","year":"2024"},{"key":"ref86:TCC:HofHovKil17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/978-3-319-70500-2_12","article-title":"A Modular Analysis of the Fujisaki-Okamoto\n  Transformation","volume":"10677","author":"Dennis Hofheinz","year":"2017"},{"key":"ref87:CCS:DHKLS21","doi-asserted-by":"publisher","first-page":"2722","DOI":"10.1145\/3460120.3484819","article-title":"Faster Lattice-Based KEMs via a Generic Fujisaki-Okamoto\n  Transform Using Prefix Hashing","author":"Julien Duman","year":"2021"},{"key":"ref88:EC:BelBolMic00","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/3-540-45539-6_18","article-title":"Public-Key Encryption in a Multi-user Setting: Security\n  Proofs and Improvements","volume":"1807","author":"Mihir Bellare","year":"2000"},{"key":"ref89:dworkin2015sha","volume-title":"SHA-3 standard: Permutation-based hash and\n  extendable-output functions","author":"Morris J. Dworkin","year":"2015"},{"key":"ref90:C:FujOka99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/3-540-48405-1_34","article-title":"Secure Integration of Asymmetric and Symmetric Encryption\n  Schemes","volume":"1666","author":"Eiichiro Fujisaki","year":"1999"},{"key":"ref91:TCC:TarUnr16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"192","DOI":"10.1007\/978-3-662-53644-5_8","article-title":"Post-Quantum Security of the Fujisaki-Okamoto and OAEP\n  Transforms","volume":"9986","author":"Ehsan Ebrahimi Targhi","year":"2016"},{"key":"ref92:FrodoUpdates","volume-title":"Annex on FrodoKEM Updates","author":"Erdem Alkim","year":"2023"},{"key":"ref93:EuroSP:Kyber","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1109\/EuroSP.2018.00032","article-title":"CRYSTALS \u2014 Kyber: A CCA-Secure Module-Lattice-Based\n  KEM","author":"Joppe Bos","year":"2018"},{"key":"ref94:C:GuoJohNil20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-030-56880-1_13","article-title":"A Key-Recovery Timing Attack on Post-quantum Primitives\n  Using the Fujisaki-Okamoto Transformation and Its Application on\n  FrodoKEM","volume":"12171","author":"Qian Guo","year":"2020"},{"key":"ref95:NISTPQC-R3:CRYSTALS-Kyber20","volume-title":"CRYSTALS-KYBER","author":"Peter Schwabe","year":"2020"},{"key":"ref96:EC:LanSteSte14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/978-3-642-55220-5_14","article-title":"GGHLite: More Efficient Multilinear Maps from Ideal\n  Lattices","volume":"8441","author":"Adeline Langlois","year":"2014"},{"key":"ref97:C:JZCWM18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1007\/978-3-319-96878-0_4","article-title":"IND-CCA-Secure Key Encapsulation Mechanism in the\n  Quantum Random Oracle Model, Revisited","volume":"10993","author":"Haodong Jiang","year":"2018"},{"key":"ref98:AC:HovHulMaj22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1007\/978-3-031-22972-5_15","article-title":"Failing Gracefully: Decryption Failures and the\n  Fujisaki-Okamoto Transform","volume":"13794","author":"Kathrin H\u00f6velmanns","year":"2022"},{"key":"ref99:dachman2020lwe","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-030-56880-1_12","article-title":"LWE with Side Information: Attacks and Concrete Security\n  Estimation","volume":"12171","author":"Dana Dachman-Soled","year":"2020"},{"key":"ref100:_JoC:LiNgu24","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-024-09527-0","article-title":"A Complete Analysis of the BKZ Lattice Reduction Algorithm","volume":"38","author":"Jianwei Li","year":"2024","journal-title":"J. Cryptol.","ISSN":"https:\/\/id.crossref.org\/issn\/0933-2790","issn-type":"electronic"},{"key":"ref101:FCT:SE91","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1007\/3-540-54458-5_51","article-title":"Lattice basis reduction: Improved practical algorithms and\n  solving subset sum problems","volume":"529","author":"Claus-Peter Schnorr","year":"1991"},{"key":"ref102:schnorr1994lattice","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/BF01581144","article-title":"Lattice basis reduction: Improved practical algorithms and\n  solving subset sum problems","volume":"66","author":"Claus-Peter Schnorr","year":"1994","journal-title":"Mathematical Programming"},{"key":"ref103:EC:AWHT16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"789","DOI":"10.1007\/978-3-662-49890-3_30","article-title":"Improved Progressive BKZ Algorithms and Their Precise Cost\n  Estimation by Sharp Simulator","volume":"9665","author":"Yoshinori Aono","year":"2016"},{"key":"ref104:EC:MicWal16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"820","DOI":"10.1007\/978-3-662-49890-3_31","article-title":"Practical, Predictable Lattice Basis Reduction","volume":"9665","author":"Daniele Micciancio","year":"2016"},{"key":"ref105:EC:ADHKPS19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"717","DOI":"10.1007\/978-3-030-17656-3_25","article-title":"The General Sieve Kernel and New Records in Lattice\n  Reduction","volume":"11477","author":"Martin R. Albrecht","year":"2019"},{"key":"ref106:SODA:BDGL16","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1137\/1.9781611974331.ch2","article-title":"New directions in nearest neighbor searching with\n  applications to lattice sieving","author":"Anja Becker","year":"2016"},{"key":"ref107:AC:ChaLoy21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-030-92068-5_3","article-title":"Lattice Sieving via Quantum Random Walks","volume":"13093","author":"Andr\u00e9 Chailloux","year":"2021"},{"key":"ref108:EC:Ducas18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1007\/978-3-319-78381-9_5","article-title":"Shortest Vector from Lattice Sieving: A Few Dimensions for\n  Free","volume":"10820","author":"L\u00e9o Ducas","year":"2018"},{"key":"ref109:STOC:MNRS07","doi-asserted-by":"publisher","first-page":"575","DOI":"10.1145\/1250790.1250874","article-title":"Search via quantum walk","author":"Fr\u00e9d\u00e9ric Magniez","year":"2007"},{"key":"ref110:AC:GuoJoh21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-030-92068-5_2","article-title":"Faster Dual Lattice Attacks for Solving LWE with\n  Applications to CRYSTALS","volume":"13093","author":"Qian Guo","year":"2021"},{"key":"ref111:MATZOV22","volume-title":"Report on the Security of LWE: Improved Dual Lattice\n  Attack","author":"MATZOV","year":"2022"},{"key":"ref112:_C:CMHST25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"444","DOI":"10.1007\/978-3-032-01855-7_15","article-title":"Assessing the Impact of a Variant of MATZOV's Dual Attack\n  on Kyber","volume":"16000","author":"Kevin Carrier","year":"2025"},{"key":"ref113:CiC:Jaques24","doi-asserted-by":"publisher","first-page":"6","DOI":"10.62056\/ay4fbn2hd","article-title":"Memory adds no cost to lattice sieving for computers in 3 or\n  more spatial dimensions","volume":"1","author":"Samuel Jaques","year":"2024","journal-title":"IACR Communications in Cryptology (CiC)"},{"key":"ref114:C:ABLR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"732","DOI":"10.1007\/978-3-030-84245-1_25","article-title":"Lattice Reduction with Approximate Enumeration Oracles -\n  Practical Algorithms and Concrete Performance","volume":"12826","author":"Martin R. Albrecht","year":"2021"},{"key":"ref115:C:DucPul23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/978-3-031-38548-3_2","article-title":"Does the Dual-Sieve Attack on Learning with Errors Even\n  Work?","volume":"14083","author":"L\u00e9o Ducas","year":"2023"},{"key":"ref116:EC:PouShe24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1007\/978-3-031-58754-2_10","article-title":"Provable Dual Attacks on Learning with Errors","volume":"14657","author":"Amaury Pouly","year":"2024"},{"key":"ref117:cryptoeprint:2023\/1850","volume-title":"Accurate Score Prediction for Dual-Sieve Attacks","author":"L\u00e9o Ducas","year":"2023"},{"key":"ref118:EC:JNRV20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/978-3-030-45724-2_10","article-title":"Implementing Grover Oracles for Quantum Key Search on AES\n  and LowMC","volume":"12106","author":"Samuel Jaques","year":"2020"},{"key":"ref119:NISTPQC-R1:NTRU-HRSS-KEM17","volume-title":"NTRU-HRSS-KEM","author":"John M. Schanck","year":"2017"},{"key":"ref120:AC:AonNguShe18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"405","DOI":"10.1007\/978-3-030-03326-2_14","article-title":"Quantum Lattice Enumeration and Tweaking Discrete Pruning","volume":"11272","author":"Yoshinori Aono","year":"2018"},{"key":"ref121:C:BBTV24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1007\/978-3-031-68391-6_3","article-title":"Quantum Lattice Enumeration in Limited Depth","volume":"14925","author":"Nina Bindel","year":"2024"},{"key":"ref122:AC:AGPS20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"583","DOI":"10.1007\/978-3-030-64834-3_20","article-title":"Estimating Quantum Speedups for Lattice Sieves","volume":"12492","author":"Martin R. Albrecht","year":"2020"},{"key":"ref123:cryptoeprint:2024\/1692","volume-title":"On the practicality of quantum sieving algorithms for the\n  shortest vector problem","author":"Joao F. Doriguello","year":"2024"},{"key":"ref124:EC:GruMarPat22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"402","DOI":"10.1007\/978-3-031-07082-2_15","article-title":"Anonymous, Robust Post-quantum Public Key Encryption","volume":"13277","author":"Paul Grubbs","year":"2022"},{"key":"ref125:CCS:CreDaxMed24","doi-asserted-by":"publisher","first-page":"1046","DOI":"10.1145\/3658644.3670283","article-title":"Keeping Up with the KEMs: Stronger Security Notions for\n  KEMs and Automated Analysis of KEM-based Protocols","author":"Cas Cremers","year":"2024"},{"key":"ref126:SUPERCOP","volume-title":"SUPERCOP benchmarking results","author":"Daniel J. Bernstein"},{"key":"ref127:C:BFKL93","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1007\/3-540-48329-2_24","article-title":"Cryptographic Primitives Based on Hard Learning Problems","volume":"773","author":"Avrim Blum","year":"1994"},{"key":"ref128:PKC:KawTanXag07","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1007\/978-3-540-71677-8_21","article-title":"Multi-bit Cryptosystems Based on Lattice Problems","volume":"4450","author":"Akinori Kawachi","year":"2007"},{"key":"ref129:Hoevelmanns2021","doi-asserted-by":"publisher","DOI":"10.13154\/294-7758","volume-title":"Generic constructions of quantum-resistant cryptosystems","author":"Kathrin H\u00f6velmanns","year":"2021"},{"key":"ref130:RSA:OkaPoi01","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/3-540-45353-9_13","article-title":"REACT: Rapid Enhanced-Security Asymmetric\n  Cryptosystem Transform","volume":"2020","author":"Tatsuaki Okamoto","year":"2001"},{"key":"ref131:_SFCS:BCK96","doi-asserted-by":"publisher","first-page":"514","DOI":"10.1109\/SFCS.1996.548510","article-title":"Pseudorandom functions revisited: the cascade construction\n  and its concrete security","author":"M. Bellare","year":"1996"},{"key":"ref132:TCC:MauRenHol04","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/978-3-540-24638-1_2","article-title":"Indifferentiability, Impossibility Results on Reductions,\n  and Applications to the Random Oracle Methodology","volume":"2951","author":"Ueli M. Maurer","year":"2004"},{"key":"ref133:C:CDMP05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"430","DOI":"10.1007\/11535218_26","article-title":"Merkle-Damg\u00e5rd Revisited: How to Construct a Hash\n  Function","volume":"3621","author":"Jean-S\u00e9bastien Coron","year":"2005"},{"key":"ref134:DBLP:conf\/approx\/LiuLM06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"450","DOI":"10.1007\/11830924_41","article-title":"On Bounded Distance Decoding for General Lattices","volume":"4110","author":"Yi-Kai Liu","year":"2006"},{"key":"ref135:DBLP:conf\/coco\/DadushRS14","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1109\/CCC.2014.18","article-title":"On the Closest Vector Problem with a Distance Guarantee","author":"Daniel Dadush","year":"2014"},{"key":"ref136:DBLP:journals\/jacm\/AharonovR05","doi-asserted-by":"publisher","first-page":"749","DOI":"10.1145\/1089023.1089025","article-title":"Lattice problems in NP $\\cap$ coNP","volume":"52","author":"Dorit Aharonov","year":"2005","journal-title":"Journal of the ACM"},{"key":"ref137:C:Peikert10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/978-3-642-14623-7_5","article-title":"An Efficient and Parallel Gaussian Sampler for Lattices","volume":"6223","author":"Chris Peikert","year":"2010"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T20:23:11Z","timestamp":1759782191000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/3\/25"}},"issued":{"date-parts":[[2025,10,6]]},"references-count":137,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,10,6]]}},"URL":"https:\/\/doi.org\/10.62056\/ayivom2hd","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2025,10,6]]},"assertion":[{"value":"2025-07-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-3-46"},{"indexed":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T07:26:03Z","timestamp":1763018763241,"version":"3.41.2"},"reference-count":224,"publisher":"International Association for Cryptologic Research","issue":"1","license":[{"start":{"date-parts":[[2025,1,14]],"date-time":"2025-01-14T00:00:00Z","timestamp":1736812800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,3,11]]},"abstract":"<jats:p>Modern security systems depend fundamentally on the ability of users to authenticate their communications to other parties in a network. Unfortunately, cryptographic authentication can substantially undermine the privacy of users. One possible solution to this problem is to use privacy-preserving cryptographic authentication. These protocols allow users to authenticate their communications without revealing their identity to the verifier. In the non-interactive setting, the most common protocols include blind, ring, and group signatures, each of which has been the subject of enormous research in the security and cryptography literature. These primitives are now being deployed at scale in major applications, including Intel's SGX software attestation framework. The depth of the research literature and the prospect of large-scale deployment motivate us to systematize our understanding of the research in this area. This work provides an overview of these techniques, focusing on applications and efficiency. <\/jats:p>","DOI":"10.62056\/a3wa3z10k","type":"journal-article","created":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T21:23:17Z","timestamp":1744147397000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":1,"title":["SoK: Privacy-Preserving Signatures"],"prefix":"10.62056","volume":"2","author":[{"given":"Alishah","family":"Chator","sequence":"first","affiliation":[{"name":"Boston University","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthew","family":"Green","sequence":"additional","affiliation":[{"name":"Johns Hopkins University","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pratyush","family":"Tiwari","sequence":"additional","affiliation":[{"name":"Eternis Labs","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"48349","published-online":{"date-parts":[[2025,4,8]]},"reference":[{"key":"ref1:diffieHellman","doi-asserted-by":"publisher","DOI":"10.1109\/tit.1976.1055638","article-title":"New Directions in Cryptography","author":"Whitfield Diffie","year":"1976","journal-title":"IEEE Transactions on Information Theory"},{"key":"ref2:chaum85","doi-asserted-by":"publisher","DOI":"10.1145\/4372.4373","article-title":"Security Without Identification: Transaction Systems to Make\n  Big Brother Obsolete","author":"David Chaum","year":"1985","journal-title":"Commun. ACM"},{"volume-title":"TPM Library Specification","year":"2014","author":"TPM","key":"ref3:tpm20"},{"key":"ref4:nytZcash","article-title":"Zcash, a Harder-to-Trace Virtual Currency, Generates Price\n  Frenzy","author":"Nathaniel Popper","year":"2016","journal-title":"The New York Times"},{"key":"ref5:noether15","article-title":"Ring Signature Confidential Transactions for Monero","author":"Shen Noether","year":"2015","journal-title":"IACR Cryptology ePrint Archive"},{"volume-title":"Vehicle Safety Communications Security Studies: Technical\n  Design of the Security Credential Management System","year":"2014","author":"Thorsten Hehn","key":"ref6:camp"},{"key":"ref7:irtfRSABlind","doi-asserted-by":"publisher","DOI":"10.17487\/rfc9474","volume-title":"RSA Blind Signatures","author":"Frank Denis","year":"2023"},{"key":"ref8:chaum82","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/978-1-4757-0602-4_18","article-title":"Blind signatures for untraceable payments","author":"David Chaum","year":"1982"},{"key":"ref9:chaum04","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/msecp.2004.1264852","article-title":"Secret-Ballot Receipts: True Voter-Verifiable Elections","volume":"2","author":"David Chaum","year":"2004","journal-title":"IEEE Security & Privacy"},{"key":"ref10:chaum84","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4684-4730-9_14","article-title":"Blind Signature System","author":"David Chaum","year":"1983"},{"key":"ref11:ps96","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1007\/bfb0034852","article-title":"Provably Secure Blind Signature Schemes","volume":"1163 of LNCS","author":"David Pointcheval","year":"1996"},{"key":"ref12:okamoto93","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48071-4_3","article-title":"Provably Secure and Practical Identification Schemes and\n  Corresponding Signature Schemes","author":"Tatsuaki Okamoto","year":"1993"},{"key":"ref13:pointcheval98","doi-asserted-by":"publisher","DOI":"10.1007\/bfb0054141","article-title":"Strengthened security for blind signatures","author":"David Pointcheval","year":"1998"},{"key":"ref14:mss98","doi-asserted-by":"publisher","DOI":"10.1007\/bfb0055857","article-title":"On the Security of Some Variants of the RSA Signature\n  Scheme","author":"Markus Michels","year":"1998"},{"key":"ref15:bnps03","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-002-0120-1","article-title":"The One-More-RSA-Inversion Problems and the Security of\n  Chaum's Blind Signature Scheme","volume":"16","author":"Mihir Bellare","year":"2003"},{"key":"ref16:jlo97","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1007\/bfb0052233","article-title":"Security of Blind Digital Signatures (Extended Abstract)","volume":"1294 of LNCS","author":"Ari Juels","year":"1997"},{"key":"ref17:lindell03","doi-asserted-by":"publisher","DOI":"10.1145\/780542.780641","article-title":"Bounded-concurrent secure two-party computation without\n  setup assumptions","author":"Yehuda Lindell","year":"2003"},{"key":"ref18:fs10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13190-5_10","article-title":"On the Impossibility of Three-Move Blind Signature Schemes","author":"Marc Fischlin","year":"2010"},{"key":"ref19:ksy11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-19571-6_37","article-title":"Impossibility of Blind Signatures from One-Way\n  Permutations","author":"Jonathan Katz","year":"2011"},{"key":"ref20:su12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-30057-8_39","article-title":"Security of Blind Signatures Revisited","author":"Dominique Schr\u00f6der","year":"2012"},{"key":"ref21:gmw87","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1145\/3335741.3335755","article-title":"How to Play any Mental Game or A Completeness Theorem for\n  Protocols with Honest Majority","author":"Oded Goldreich","year":"1987"},{"key":"ref22:yao86","doi-asserted-by":"publisher","first-page":"162","DOI":"10.1109\/sfcs.1986.25","article-title":"How to Generate and Exchange Secrets","author":"Andrew Yao","year":"1986"},{"key":"ref23:chaum87a","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-39118-5_21","article-title":"Blinding for Unanticipated Signatures","author":"David Chaum","year":"1988"},{"key":"ref24:cp92","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1007\/3-540-48071-4_7","article-title":"Wallet databases with observers","volume":"740 of LNCS","author":"David Chaum","year":"1992"},{"key":"ref25:cps94","doi-asserted-by":"publisher","DOI":"10.1007\/bfb0053458","article-title":"Blind signatures based on the discrete logarithm problem","author":"Jan L. Camenisch","year":"1995"},{"key":"ref26:fty96","doi-asserted-by":"publisher","DOI":"10.1007\/bfb0034855","article-title":"\"Indirect Discourse Proof\": Achieving Efficient Fair\n  Off-Line E-cash","author":"Yair Frankel","year":"1996"},{"key":"ref27:sn92","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(92)90193-U","article-title":"On blind signatures and perfect crimes","author":"Sebastiaan H. von Solms","year":"1992","journal-title":"Comput. Secur."},{"key":"ref28:spc95","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-49264-x_17","article-title":"Fair Blind Signatures","author":"Markus Stadler","year":"1995"},{"key":"ref29:ao01","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45682-1_34","article-title":"Provably Secure Fair Blind Signatures with Tight\n  Revocation","author":"Masayuki Abe","year":"2001"},{"key":"ref30:ht07","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-73489-5_14","article-title":"Fair Blind Signatures Revisited","author":"Emeline Hufschmitt","year":"2007"},{"key":"ref31:fv10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12678-9_2","article-title":"Fair Blind Signatures without Random Oracles","author":"Georg Fuchsbauer","year":"2010"},{"key":"ref32:rs10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12678-9_3","article-title":"Fair Partially Blind Signatures","author":"Markus R\u00fcckert","year":"2010"},{"key":"ref33:brands93a","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48329-2_26","article-title":"Untraceable Off-line Cash in Wallets with Observers\n  (Extended Abstract)","author":"Stefan Brands","year":"1993"},{"key":"ref34:af96","doi-asserted-by":"publisher","DOI":"10.1007\/bfb0034851","article-title":"How to Date Blind Signatures","author":"Masayuki Abe","year":"1996"},{"key":"ref35:ao00","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44598-6_17","article-title":"Provably Secure Partially Blind Signatures","author":"Masayuki Abe","year":"2000"},{"key":"ref36:kastner2023abe","doi-asserted-by":"publisher","first-page":"279","DOI":"10.1007\/978-3-031-22972-5_10","article-title":"The Abe-Okamoto partially blind signature scheme\n  revisited","author":"Julia Kastner","year":"2023"},{"key":"ref37:boldyreva03","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36288-6_3","article-title":"Threshold Signatures, Multisignatures and Blind Signatures\n  Based on the Gap-Diffie-Hellman-Group Signature Scheme","author":"Alexandra Boldyreva","year":"2003"},{"key":"ref38:zk02","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36178-2_33","article-title":"ID-Based Blind Signature and Ring Signature from Pairings","author":"Fangguo Zhang","year":"2002"},{"key":"ref39:ghk06","doi-asserted-by":"publisher","DOI":"10.1007\/11935230_12","article-title":"On the Generic Construction of Identity-Based Signatures\n  with Additional Properties","author":"David Galindo","year":"2006"},{"key":"ref40:ckw04","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1007\/978-3-540-30598-9_10","article-title":"Efficient Blind Signatures without Random Oracles","volume":"3352 of LNCS","author":"Jan Camenisch","year":"2004"},{"key":"ref41:Fischlin06","doi-asserted-by":"publisher","DOI":"10.1007\/11818175_4","article-title":"Round-Optimal Composable Blind Signatures in the Common\n  Reference String Model","author":"Marc Fischlin","year":"2006"},{"key":"ref42:grssu11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22792-9_36","article-title":"Round Optimal Blind Signatures.","author":"Sanjam Garg","year":"2011"},{"key":"ref43:bfpv13","doi-asserted-by":"publisher","DOI":"10.3233\/jcs-130477","article-title":"Short blind signatures","author":"Olivier Blazy","year":"2013"},{"key":"ref44:fhks16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-44618-9_21","article-title":"Practical Round-Optimal Blind Signatures in the Standard\n  Model from Weaker Assumptions","author":"Georg Fuchsbauer","year":"2016"},{"key":"ref45:ghadafi2017efficient","doi-asserted-by":"publisher","first-page":"455","DOI":"10.1007\/978-3-319-70972-7_26","article-title":"Efficient round-optimal blind signatures in the standard\n  model","author":"Essam Ghadafi","year":"2017"},{"key":"ref46:blazy2020round","doi-asserted-by":"publisher","first-page":"213","DOI":"10.5220\/0009888702130224","article-title":"Round-optimal Constant-size Blind Signatures.","author":"Olivier Blazy","year":"2020"},{"key":"ref47:katsumata2021round","doi-asserted-by":"publisher","first-page":"404","DOI":"10.1007\/978-3-030-77870-5_15","article-title":"Round-optimal blind signatures in the plain model from\n  classical and quantum standard assumptions","author":"Shuichi Katsumata","year":"2021"},{"key":"ref48:hanzlik2023non","doi-asserted-by":"publisher","first-page":"722","DOI":"10.1007\/978-3-031-30589-4_25","article-title":"Non-interactive blind signatures for random messages","author":"Lucjan Hanzlik","year":"2023"},{"key":"ref49:benhamouda2022security","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1007\/s00145-022-09436-0","article-title":"On the (in) security of ROS","volume":"35","author":"Fabrice Benhamouda","year":"2022","journal-title":"Journal of Cryptology"},{"key":"ref50:schnorr2001security","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-45600-7_1","article-title":"Security of blind discrete log signatures against\n  interactive attacks","author":"Claus Peter Schnorr","year":"2001"},{"key":"ref51:ps00","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1007\/s001450010003","article-title":"Security Arguments for Digital Signatures and Blind\n  Signatures","volume":"13","author":"David Pointcheval","year":"2000","journal-title":"Journal of Cryptology"},{"key":"ref52:kastner2022pairing","doi-asserted-by":"publisher","first-page":"468","DOI":"10.1007\/978-3-030-97131-1_16","article-title":"On pairing-free blind signature schemes in the algebraic\n  group model","author":"Julia Kastner","year":"2022"},{"key":"ref53:katz2021boosting","doi-asserted-by":"publisher","first-page":"468","DOI":"10.1007\/978-3-030-92068-5_16","article-title":"Boosting the security of blind signature schemes","author":"Jonathan Katz","year":"2021"},{"key":"ref54:chairattana2022pi","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-15982-4_1","article-title":"PI-Cut-Choo and Friends: Compact Blind Signatures via\n  Parallel Instance Cut-and-Choose and More","author":"Rutchathon Chairattana-Apirom","year":"2022"},{"key":"ref55:hanzlik2023rai","doi-asserted-by":"publisher","first-page":"753","DOI":"10.1007\/978-3-031-30589-4_26","article-title":"Rai-choo! Evolving blind signatures to the next level","author":"Lucjan Hanzlik","year":"2023"},{"key":"ref56:hauck2020lattice","doi-asserted-by":"publisher","first-page":"500","DOI":"10.1007\/978-3-030-56880-1_18","article-title":"Lattice-based blind signatures, revisited","author":"Eduard Hauck","year":"2020"},{"key":"ref57:bgss17","doi-asserted-by":"publisher","DOI":"10.1109\/isit.2017.8007023","article-title":"A code-based blind signature","author":"O. Blazy","year":"2017"},{"key":"ref58:agrawal2022practical","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1145\/3548606.3560650","article-title":"Practical, round-optimal lattice-based blind signatures","author":"Shweta Agrawal","year":"2022"},{"key":"ref59:alkeilani2021blindor","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1007\/978-3-030-92548-2_6","article-title":"BlindOR: an efficient lattice-based blind signature scheme\n  from or-proofs","author":"Nabil Alkeilani Alkadri","year":"2021"},{"key":"ref60:lyubashevsky2022efficient","doi-asserted-by":"publisher","first-page":"498","DOI":"10.1007\/978-3-030-97131-1_17","article-title":"Efficient lattice-based blind signatures via Gaussian\n  one-time signatures","author":"Vadim Lyubashevsky","year":"2022"},{"key":"ref61:del2022new","doi-asserted-by":"publisher","first-page":"306","DOI":"10.1007\/978-3-031-15979-4_11","article-title":"A new framework for more efficient round-optimal\n  lattice-based (partially) blind signature via trapdoor sampling","author":"Rafael del Pino","year":"2022"},{"key":"ref62:tessaro2022short","doi-asserted-by":"publisher","first-page":"782","DOI":"10.1007\/978-3-031-07085-3_27","article-title":"Short pairing-free blind signatures with exponential\n  security","author":"Stefano Tessaro","year":"2022"},{"key":"ref63:crites2023snowblind","doi-asserted-by":"publisher","first-page":"710","DOI":"10.1007\/978-3-031-38557-5_23","article-title":"Snowblind: A Threshold Blind Signature in Pairing-Free\n  Groups","author":"Elizabeth Crites","year":"2023"},{"key":"ref64:abe2000provably","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1007\/3-540-44598-6_17","article-title":"Provably secure partially blind signatures","author":"Masayuki Abe","year":"2000"},{"key":"ref65:okamoto06","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/11681878_5","article-title":"Efficient Blind and Partially Blind Signatures Without\n  Random Oracles","volume":"3876 of LNCS","author":"Tatsuaki Okamoto","year":"2006"},{"key":"ref66:gs08","doi-asserted-by":"publisher","first-page":"415","DOI":"10.1007\/978-3-540-78967-3_24","article-title":"Efficient Non-interactive Proof Systems for Bilinear\n  Groups","volume":"4965 of LNCS","author":"Jens Groth","year":"2008"},{"key":"ref67:chaum91","series-title":"EUROCRYPT'91","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-46416-6_22","article-title":"Group Signatures","author":"David Chaum","year":"1991"},{"key":"ref68:bbl07","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2011.63","article-title":"Enhanced Privacy ID: A Direct Anonymous Attestation\n  Scheme with Enhanced Revocation Capabilities","author":"Ernie Brickell","year":"2007"},{"key":"ref69:bmw03","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-39200-9_38","article-title":"Foundations of Group Signatures: Formal Definitions,\n  Simplified Requirements, and a Construction Based on General Assumptions","author":"Mihir Bellare","year":"2003"},{"key":"ref70:ky06","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1504\/ijsn.2006.010821","article-title":"Secure scalable group signature with dynamic joins and\n  separable authorities","volume":"1","author":"Aggelos Kiayias","year":"2006","journal-title":"Int. J. Secur. Networks"},{"key":"ref71:bootle2016foundations","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1007\/978-3-319-39555-5_7","article-title":"Foundations of fully dynamic group signatures","author":"Jonathan Bootle","year":"2016"},{"key":"ref72:backes2019membership","doi-asserted-by":"publisher","first-page":"2181","DOI":"10.1145\/3319535.3354257","article-title":"Membership privacy for fully dynamic group signatures","author":"Michael Backes","year":"2019"},{"key":"ref73:camsta97","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1007\/bfb0052252","article-title":"Efficient Group Signature Schemes for Large Groups","volume":"1296 of LNCS","author":"Jan Camenisch","year":"1997"},{"key":"ref74:chase2006signatures","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1007\/11818175_5","article-title":"On signatures of knowledge","author":"Melissa Chase","year":"2006"},{"key":"ref75:cp94","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0053433","article-title":"New Group Signature Schemes (Extended Abstract)","author":"Lidong Chen","year":"1994"},{"key":"ref76:cm98","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-49649-1_14","article-title":"A Group Signature Scheme with Improved Efficiency","author":"Jan Camenisch","year":"1998"},{"key":"ref77:actj00","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44598-6_16","article-title":"A Practical and Provably Secure Coalition-Resistant Group\n  Signature Scheme","author":"Giuseppe Ateniese","year":"2000"},{"key":"ref78:BBS04","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1007\/978-3-540-28628-8_3","article-title":"Short Group Signatures","volume":"3152 of LNCS","author":"Dan Boneh","year":"2004"},{"key":"ref79:tessaro2023revisiting","doi-asserted-by":"publisher","first-page":"691","DOI":"10.1007\/978-3-031-30589-4_24","article-title":"Revisiting BBS Signatures","author":"Stefano Tessaro","year":"2023"},{"key":"ref80:bw06a","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_26","article-title":"Compact Group Signatures Without Random Oracles","author":"Xavier Boyen","year":"2006"},{"key":"ref81:ateniese2005practical","article-title":"Practical group signatures without random oracles","author":"Giuseppe Ateniese","year":"2005","journal-title":"Cryptology ePrint Archive"},{"key":"ref82:bichsel2010get","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15317-4_24","article-title":"Get shorty via group signatures without encryption","author":"Patrik Bichsel","year":"2010"},{"key":"ref83:derler2018highly","doi-asserted-by":"publisher","first-page":"551","DOI":"10.1145\/3196494.3196507","article-title":"Highly-efficient fully-anonymous dynamic group signatures","author":"David Derler","year":"2018"},{"key":"ref84:adM03","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-40061-5_15","article-title":"Efficient Group Signatures without Trapdoors","author":"Giuseppe Ateniese","year":"2003"},{"key":"ref85:libert2012scalable","doi-asserted-by":"publisher","first-page":"609","DOI":"10.1007\/978-3-642-29011-4_36","article-title":"Scalable group signatures with revocation","author":"Beno\u00eet Libert","year":"2012"},{"key":"ref86:libert2012group","doi-asserted-by":"publisher","first-page":"571","DOI":"10.1007\/978-3-642-32009-5_34","article-title":"Group signatures with almost-for-free revocation","author":"Beno\u00eet Libert","year":"2012"},{"key":"ref87:bcc04","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030103","article-title":"Direct Anonymous Attestation","author":"Ernie Brickell","year":"2004"},{"volume-title":"Intel\u00ae Software Guard Extensions Remote\n  Attestation End-to-End Example","year":"2016","key":"ref88:sgxEPID"},{"key":"ref89:libert2021bifurcated","doi-asserted-by":"publisher","first-page":"521","DOI":"10.1007\/978-3-030-77883-5_18","article-title":"Bifurcated signatures: folding the accountability vs.\n  anonymity dilemma into a single private signing scheme","author":"Beno\u00eet Libert","year":"2021"},{"key":"ref90:nguyen2022multimodal","doi-asserted-by":"publisher","first-page":"792","DOI":"10.1007\/978-3-031-15979-4_27","article-title":"Multimodal Private Signatures","author":"Khoa Nguyen","year":"2022"},{"key":"ref91:garms2019group","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1007\/978-3-030-17253-4_7","article-title":"Group signatures with selective linkability","author":"Lydia Garms","year":"2019"},{"key":"ref92:fraser2021selectively","doi-asserted-by":"publisher","first-page":"200","DOI":"10.1007\/978-3-030-92548-2_11","article-title":"Selectively linkable group signatures\u2014stronger security\n  and preserved verifiability","author":"Ashley Fraser","year":"2021"},{"key":"ref93:diaz2021group","doi-asserted-by":"publisher","first-page":"360","DOI":"10.1007\/978-3-030-75245-3_14","article-title":"Group signatures with user-controlled and sequential\n  linkability","author":"Jesus Diaz","year":"2021"},{"key":"ref94:camenisch2020short","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1007\/978-3-030-57990-6_20","article-title":"Short threshold dynamic group signatures","author":"Jan Camenisch","year":"2020"},{"key":"ref95:llls13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-42045-0_3","article-title":"Lattice-Based Group Signatures with Logarithmic Signature\n  Size","author":"Fabien Laguillaumie","year":"2013"},{"key":"ref96:del2018lattice","doi-asserted-by":"publisher","first-page":"574","DOI":"10.1145\/3243734.3243852","article-title":"Lattice-based group signatures and zero-knowledge proofs of\n  automorphism stability","author":"Rafa\u00ebl Del Pino","year":"2018"},{"key":"ref97:lyubashevsky2021shorter","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1007\/978-3-030-92068-5_8","article-title":"Shorter lattice-based group signatures via \u201calmost free\u201d\n  encryption and other optimizations","author":"Vadim Lyubashevsky","year":"2021"},{"key":"ref98:katsumata2019group","doi-asserted-by":"publisher","first-page":"312","DOI":"10.1007\/978-3-030-17659-4_11","article-title":"Group signatures without NIZK: from lattices in the standard\n  model","author":"Shuichi Katsumata","year":"2019"},{"key":"ref99:ling2018constant","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1007\/978-3-319-76581-5_3","article-title":"Constant-size group signatures from lattices","author":"San Ling","year":"2018"},{"key":"ref100:beullens2023group","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10623-023-01192-x","article-title":"Group signatures and more from isogenies and lattices:\n  generic, simple, and efficient","author":"Ward Beullens","year":"2023","journal-title":"Designs, Codes and Cryptography"},{"key":"ref101:ellnw15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-48797-6_12","article-title":"A Provably Secure Group Signature Scheme from Code-Based\n  Assumptions","author":"Martianus Frederic Ezerman","year":"2015"},{"key":"ref102:ezerman2020provably","doi-asserted-by":"publisher","first-page":"5754","DOI":"10.1109\/tit.2020.2976073","article-title":"Provably secure group signature schemes from code-based\n  assumptions","volume":"66","author":"Martianus Frederic Ezerman","year":"2020","journal-title":"IEEE Transactions on Information Theory"},{"key":"ref103:pointcheval2016short","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-319-29485-8_7","article-title":"Short randomizable signatures","author":"David Pointcheval","year":"2016"},{"key":"ref104:bs04","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1145\/1030083.1030106","article-title":"Group signatures with Verifier-Local revocation","author":"Dan Boneh","year":"2004"},{"key":"ref105:rst01","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45682-1_32","article-title":"How to Leak a Secret","author":"Ronald L. Rivest","year":"2001"},{"key":"ref106:crdasc94","doi-asserted-by":"publisher","first-page":"174","DOI":"10.1007\/3-540-48658-5_19","article-title":"Proofs of Partial Knowledge and Simplified Design of Witness\n  Hiding Protocols","volume":"839 of LNCS","author":"Ronald Cramer","year":"1994"},{"volume-title":"CryptoNote v 2.0","year":"2013","author":"Nicolas van Saberhagen","key":"ref107:saberhagen13"},{"key":"ref108:bkm06","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_4","article-title":"Ring Signatures: Stronger Definitions, and Constructions\n  Without Random Oracles","author":"Adam Bender","year":"2006","journal-title":"Theory of Cryptography, Third Theory of Cryptography\n  Conference, TCC"},{"key":"ref109:park2019wasn","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/978-3-030-26954-8_6","article-title":"It wasn\u2019t me! Repudiability and claimability of ring\n  signatures","author":"Sunoo Park","year":"2019"},{"key":"ref110:gonzalez2019shorter","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/978-3-030-17253-4_4","article-title":"Shorter ring signatures from standard assumptions","author":"Alonso Gonz\u00e1lez","year":"2019"},{"key":"ref111:aos02","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36178-2_26","article-title":"1-out-of-n Signatures from a Variety of Keys","author":"Masayuki Abe","year":"2002"},{"key":"ref112:branco2023universal","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/978-3-031-22972-5_9","article-title":"Universal Ring Signatures in the Standard Model","author":"Pedro Branco","year":"2023"},{"key":"ref113:bgls03","doi-asserted-by":"publisher","first-page":"416","DOI":"10.1007\/3-540-39200-9_26","article-title":"Aggregate and Verifiably Encrypted Signatures from Bilinear\n  Maps","volume":"2656 of LNCS","author":"Dan Boneh","year":"2003"},{"key":"ref114:cwly06","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128861","article-title":"Ring Signatures without Random Oracles","author":"Sherman S. M. Chow","year":"2006","journal-title":"ASIACCS"},{"key":"ref115:Boyen07","doi-asserted-by":"publisher","first-page":"210","DOI":"10.1007\/978-3-540-72540-4_12","article-title":"Mesh signatures: How to leak a secret with unwitting and\n  unwilling participants","author":"Xavier Boyen","year":"2007"},{"key":"ref116:ss10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14577-3_12","article-title":"A CDH-Based Ring Signature Scheme with Short Signatures and\n  Public Keys","author":"Sven Sch\u00e4ge","year":"2010"},{"key":"ref117:sw07","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-71677-8_12","article-title":"Efficient Ring Signatures Without Random Oracles","author":"Hovav Shacham","year":"2007"},{"key":"ref118:dkns04","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24676-3_36","article-title":"Anonymous Identification in Ad Hoc Groups","author":"Yevgeniy Dodis","year":"2004"},{"key":"ref119:cl02full","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45708-9_5","article-title":"Dynamic Accumulators and Application to Efficient Revocation\n  of Anonymous Credentials","author":"Jan Camenisch","year":"2002"},{"key":"ref120:gk15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46803-6_9","article-title":"One-Out-of-Many Proofs: Or How to Leak a Secret and Spend a\n  Coin","author":"Jens Groth","year":"2015"},{"key":"ref121:libert2018logarithmic","doi-asserted-by":"publisher","first-page":"288","DOI":"10.1007\/978-3-319-98989-1_15","article-title":"Logarithmic-size ring signatures with tight security from\n  the DDH assumption","author":"Beno\u00eet Libert","year":"2018"},{"key":"ref122:cgs07","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-73420-8_38","article-title":"Ring Signatures of Sub-linear Size Without Random Oracles","author":"Nishanth Chandran","year":"2007"},{"key":"ref123:ms17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70697-9_5","volume-title":"Efficient Ring Signatures in the Standard Model","author":"Giulio Malavolta","year":"2017"},{"key":"ref124:backes2018signatures","doi-asserted-by":"publisher","first-page":"405","DOI":"10.1007\/978-3-030-03329-3_14","article-title":"Signatures with flexible public key: Introducing equivalence\n  classes for public keys","author":"Michael Backes","year":"2018"},{"key":"ref125:backes2019ring","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1007\/978-3-030-17659-4_10","article-title":"Ring signatures: logarithmic-size, no setup\u2014from standard\n  assumptions","author":"Michael Backes","year":"2019"},{"key":"ref126:haque2022logarithmic","doi-asserted-by":"publisher","first-page":"437","DOI":"10.1007\/978-3-030-97131-1_15","article-title":"Logarithmic-size (linkable) threshold ring signatures in the\n  plain model","author":"Abida Haque","year":"2022"},{"volume-title":"Borromean ring signatures","year":"2015","author":"Greg Maxwell","key":"ref127:mp15"},{"key":"ref128:noether2020triptych","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1007\/978-3-030-66172-4_22","article-title":"Triptych: logarithmic-sized linkable ring signatures with\n  applications","author":"Sarang Noether","year":"2020"},{"key":"ref129:liu2019lattice","doi-asserted-by":"publisher","first-page":"726","DOI":"10.1007\/978-3-030-29959-0_35","article-title":"A lattice-based linkable ring signature supporting stealth\n  addresses","author":"Zhen Liu","year":"2019"},{"key":"ref130:bk10","first-page":"86","article-title":"A Framework for Efficient Signatures, Ring Signatures and\n  Identity Based Encryption in the Standard Model","author":"Zvika Brakerski","year":"2010","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref131:llnw16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-49896-5_1","article-title":"Zero-Knowledge Arguments for Lattice-Based Accumulators:\n  Logarithmic-Size Ring Signatures and Group Signatures Without Trapdoors","author":"Beno\u00eet Libert","year":"2016"},{"key":"ref132:esgin2019matrict","doi-asserted-by":"publisher","first-page":"567","DOI":"10.1145\/3319535.3354200","article-title":"MatRiCT: efficient, scalable and post-quantum blockchain\n  confidential transactions protocol","author":"Muhammed F Esgin","year":"2019"},{"key":"ref133:esgin2022matrict+","doi-asserted-by":"publisher","first-page":"1281","DOI":"10.1109\/sp46214.2022.9833655","article-title":"MatRiCT+: More efficient post-quantum private blockchain\n  payments","author":"Muhammed F Esgin","year":"2022"},{"key":"ref134:esgin2019lattice","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/978-3-030-26948-7_5","article-title":"Lattice-based zero-knowledge proofs: new techniques for\n  shorter and faster constructions and applications","author":"Muhammed F Esgin","year":"2019"},{"key":"ref135:chatterjee2022note","doi-asserted-by":"publisher","first-page":"407","DOI":"10.1007\/978-3-030-97131-1_14","article-title":"A note on the post-quantum security of (ring) signatures","author":"Rohit Chatterjee","year":"2022"},{"key":"ref136:chatterjee2021compact","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1007\/978-3-030-84242-0_11","article-title":"Compact ring signatures from learning with errors","author":"Rohit Chatterjee","year":"2021"},{"key":"ref137:yuen2021dualring","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1007\/978-3-030-84242-0_10","article-title":"DualRing: generic construction of ring signatures with\n  efficient instantiations","author":"Tsz Hon Yuen","year":"2021"},{"key":"ref138:lyubashevsky2021smile","doi-asserted-by":"publisher","first-page":"611","DOI":"10.1007\/978-3-030-84245-1_21","article-title":"SMILE: set membership from ideal lattices with applications\n  to ring signatures and confidential transactions","author":"Vadim Lyubashevsky","year":"2021"},{"key":"ref139:zheng2007code","first-page":"154","article-title":"Code-based Ring Signature Scheme.","volume":"5","author":"Dong Zheng","year":"2007","journal-title":"Int. J. Netw. Secur."},{"key":"ref140:branco2019traceable","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1007\/978-3-030-25510-7_21","article-title":"A traceable ring signature scheme based on coding theory","author":"Pedro Branco","year":"2019"},{"key":"ref141:branco2018code","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-3-030-01446-9_12","article-title":"A code-based linkable ring signature scheme","author":"Pedro Branco","year":"2018"},{"key":"ref142:beullens2020calamari","doi-asserted-by":"publisher","first-page":"464","DOI":"10.1007\/978-3-030-64834-3_16","article-title":"Calamari and Falafl: logarithmic (linkable) ring signatures\n  from isogenies and lattices","author":"Ward Beullens","year":"2020"},{"key":"ref143:katz2018improved","doi-asserted-by":"publisher","first-page":"525","DOI":"10.1145\/3243734.3243805","article-title":"Improved non-interactive zero knowledge with applications to\n  post-quantum signatures","author":"Jonathan Katz","year":"2018"},{"key":"ref144:derler2018post","doi-asserted-by":"publisher","first-page":"419","DOI":"10.1007\/978-3-319-79063-3_20","article-title":"Post-quantum zero-knowledge proofs for accumulators with\n  applications to ring signatures from symmetric-key primitives","author":"David Derler","year":"2018"},{"key":"ref145:goel2022efficient","doi-asserted-by":"publisher","first-page":"304","DOI":"10.2478\/popets-2022-0047","article-title":"Efficient set membership proofs using MPC-in-the-head","volume":"2022","author":"Aarushi Goel","year":"2022","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"ref146:liu2004linkable","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1007\/978-3-540-27800-9_28","article-title":"Linkable spontaneous anonymous group signature for ad hoc\n  groups","volume":"4","author":"Joseph K Liu","year":"2004"},{"volume-title":"Concise Linkable Ring Signatures and Forgery Against\n  Adversarial Keys","year":"2019","author":"Brandon Goodell","key":"ref147:cryptoeprint:2019\/654"},{"volume-title":"Thring Signatures and their Applications to\n  Spender-Ambiguous Digital Currencies","year":"2018","author":"Brandon Goodell","key":"ref148:cryptoeprint:2018\/774"},{"key":"ref149:bresson2002threshold","doi-asserted-by":"publisher","first-page":"465","DOI":"10.1007\/3-540-45708-9_30","article-title":"Threshold ring signatures and applications to ad-hoc\n  groups","author":"Emmanuel Bresson","year":"2002"},{"key":"ref150:haque2020threshold","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/978-3-030-45388-6_15","article-title":"Threshold ring signatures: new definitions and post-quantum\n  security","author":"Abida Haque","year":"2020"},{"key":"ref151:aranha2022count","doi-asserted-by":"publisher","first-page":"379","DOI":"10.1007\/978-3-030-97131-1_13","article-title":"Count me in! extendability for threshold ring signatures","author":"Diego F Aranha","year":"2022"},{"key":"ref152:avitabile2023extendable","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1007\/978-3-031-31368-4_11","article-title":"Extendable Threshold Ring Signatures with Enhanced\n  Anonymity","author":"Gennaro Avitabile","year":"2023"},{"key":"ref153:xu2004accountable","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1007\/1-4020-8147-2_18","article-title":"Accountable ring signatures: A smart card approach","author":"Shouhuai Xu","year":"2004"},{"key":"ref154:bootle2016short","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1007\/978-3-319-24174-6_13","article-title":"Short accountable ring signatures based on DDH","author":"Jonathan Bootle","year":"2016"},{"key":"ref155:feng2021traceable","doi-asserted-by":"publisher","first-page":"1111","DOI":"10.1007\/s10623-021-00863-x","article-title":"Traceable ring signatures: general framework and\n  post-quantum security","volume":"89","author":"Hanwen Feng","year":"2021","journal-title":"Designs, Codes and Cryptography"},{"key":"ref156:naor2002deniable","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1007\/3-540-45708-9_31","article-title":"Deniable ring authentication","author":"Moni Naor","year":"2002"},{"key":"ref157:komano2006toward","doi-asserted-by":"publisher","first-page":"174","DOI":"10.1007\/11605805_12","article-title":"Toward the fair anonymous signatures: Deniable ring\n  signatures","author":"Yuichi Komano","year":"2006"},{"key":"ref158:lin2022repudiable","doi-asserted-by":"publisher","first-page":"103562","DOI":"10.1016\/j.csi.2021.103562","article-title":"Repudiable ring signature: Stronger security and\n  logarithmic-size","volume":"80","author":"Hao Lin","year":"2022","journal-title":"Computer Standards & Interfaces"},{"key":"ref159:cg18","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1109\/eurospw.2018.00012","article-title":"How to squeeze a crowd: reducing bandwidth in mixing\n  cryptocurrencies","author":"Alishah Chator","year":"2018"},{"volume-title":"Bitcoin: A peer-to-peer electronic cash system, 2009","year":"2012","author":"S. Nakamoto","key":"ref160:nakamoto"},{"volume-title":"Elliptic Enterprises Limited","year":"2013","author":"Elliptic","key":"ref161:Elliptic13"},{"volume-title":"Chainalysis","year":"2014","author":"Blockchain Analysis","key":"ref162:BlockChainAnalaysis14"},{"volume-title":"Chainalysis Inc","year":"2015","author":"Chainalysis","key":"ref163:Chainalysis15"},{"key":"ref164:zerocoin","series-title":"SP '13","doi-asserted-by":"publisher","first-page":"397","DOI":"10.1109\/sp.2013.34","article-title":"Zerocoin: Anonymous Distributed E-Cash from Bitcoin","author":"Ian Miers","year":"2013"},{"key":"ref165:sasson2014zerocash","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2014.36","article-title":"Zerocash: Decentralized anonymous payments from Bitcoin","author":"Eli Ben Sasson","year":"2014"},{"key":"ref166:stark","article-title":"Scalable, transparent, and post-quantum secure computational\n  integrity","author":"Eli Ben-Sasson","year":"2018","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref167:brakedown","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-38545-2_7","article-title":"Brakedown: Linear-time and post-quantum SNARKs for R1CS","author":"Alexander Golovnev","year":"2020"},{"key":"ref168:fractal","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-45721-1_27","article-title":"Fractal: Post-quantum and Transparent Recursive Proofs from\n  Holography","author":"Alessandro Chiesa","year":"2020"},{"key":"ref169:paquin11","volume-title":"U-prove cryptographic specification v1. 1","author":"Christian Paquin","year":"2011","journal-title":"Technical Report, Microsoft Corporation"},{"volume-title":"Microsoft open-sources clever U-Prove identity framework","year":"2010","author":"Peter Bright","key":"ref170:uproveArticle"},{"key":"ref171:bl13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-42045-0_5","article-title":"On the Security of One-Witness Blind Signature Schemes","author":"Foteini Baldimtsi","year":"2013"},{"volume-title":"An Efficient On-line Electronic Cash System Based on the\n  Representation Problem","year":"1993","author":"Stefan Brands","key":"ref172:brands93b"},{"key":"ref173:baldimtsi2013anonymous","doi-asserted-by":"publisher","first-page":"1087","DOI":"10.1145\/2508859.2516687","article-title":"Anonymous credentials light","author":"Foteini Baldimtsi","year":"2013"},{"volume-title":"Private ECDSA Verification using ZK: Motivation,\n  Optimizations & Security","year":"2023","author":"Pratyush Ranjan Tiwari","key":"ref174:blogECDSA"},{"key":"ref175:arom","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-30617-4_13","article-title":"Proof-Carrying Data from Arithmetized Random Oracles","author":"Megan Chen","year":"2023"},{"key":"ref176:prom","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-38551-3_8","article-title":"The Pseudorandom Oracle Model and Ideal Obfuscation","author":"Aayush Jain","year":"2023"},{"volume-title":"2017 Cadillac CTS Now Standard With V2V Technology","year":"2017","author":"Kelly Pleskot","key":"ref177:gmcRollout"},{"key":"ref178:sokAnonCred","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-30731-7_6","article-title":"SoK: Anonymous Credentials","author":"Saqib A. Kakvi","year":"2023"},{"key":"ref179:nakanishi2010revocable","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1587\/transfun.e93.a.50","article-title":"Revocable group signature schemes with constant costs for\n  signing and verifying","volume":"93","author":"Toru Nakanishi","year":"2010","journal-title":"IEICE transactions on fundamentals of electronics,\n  communications and computer sciences"},{"key":"ref180:libert2009group","doi-asserted-by":"publisher","first-page":"498","DOI":"10.1007\/978-3-642-10433-6_34","article-title":"Group signatures with verifier-local revocation and backward\n  unlinkability in the standard model","author":"Beno\u00eet Libert","year":"2009"},{"key":"ref181:attrapadung2014revocable","doi-asserted-by":"publisher","first-page":"419","DOI":"10.1007\/978-3-319-07536-5_25","article-title":"A revocable group signature scheme from identity-based\n  revocation techniques: Achieving constant-size revocation list","author":"Nuttapong Attrapadung","year":"2014"},{"key":"ref182:cl02","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/3-540-45708-9_5","article-title":"Dynamic Accumulators and Application to Efficient Revocation\n  of Anonymous Credentials","author":"Jan Camenisch","year":"2002"},{"key":"ref183:baldimtsi2017accumulators","doi-asserted-by":"publisher","first-page":"301","DOI":"10.1109\/eurosp.2017.13","article-title":"Accumulators with applications to anonymity-preserving\n  revocation","author":"Foteini Baldimtsi","year":"2017"},{"key":"ref184:barpfi97","doi-asserted-by":"publisher","first-page":"480","DOI":"10.1007\/3-540-69053-0_33","article-title":"Collision-free accumulators and fail-stop signature schemes\n  without trees","volume":"1233 of LNCS","author":"Niko Bari\u0107","year":"1997"},{"key":"ref185:fujoka97b","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/bfb0052225","article-title":"Statistical Zero Knowledge Protocols to Prove Modular\n  Polynomial Relations","volume":"1294 of LNCS","author":"Eiichiro Fujisaki","year":"1997"},{"key":"ref186:galbraith2008pairings","doi-asserted-by":"publisher","first-page":"3113","DOI":"10.1016\/j.dam.2007.12.010","article-title":"Pairings for cryptographers","volume":"156","author":"Steven D Galbraith","year":"2008","journal-title":"Discrete Applied Mathematics"},{"key":"ref187:Joux04","doi-asserted-by":"publisher","first-page":"263","DOI":"10.1007\/s00145-004-0312-y","article-title":"A One Round Protocol for Tripartite Diffie-Hellman","volume":"17","author":"Antoine Joux","year":"2004","journal-title":"J. Cryptol."},{"key":"ref188:barreto2005pairing","doi-asserted-by":"publisher","DOI":"10.1007\/11693383_22","article-title":"Pairing-friendly elliptic curves of prime order","author":"Paulo SLM Barreto","year":"2005"},{"key":"ref189:nfs","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53018-4_20","article-title":"Extended Tower Number Field Sieve: A New Complexity for\n  the Medium Prime Case","author":"Taechan Kim","year":"2016"},{"volume-title":"Switch from BN254 to BLS12-381","year":"2017","author":"Sean Bowe","key":"ref190:zcashswitch"},{"key":"ref191:brassard1983relativized","doi-asserted-by":"publisher","first-page":"877","DOI":"10.1109\/tit.1983.1056754","article-title":"Relativized cryptography","volume":"29","author":"Gilles Brassard","year":"1983","journal-title":"IEEE Transactions on Information Theory"},{"key":"ref192:br93","series-title":"CCS '93","article-title":"Random Oracles Are Practical: A Paradigm for Designing\n  Efficient Protocols","author":"Mihir Bellare","year":"1993"},{"key":"ref193:cgh04","doi-asserted-by":"publisher","DOI":"10.1145\/1008731.1008734","article-title":"The Random Oracle Methodology, Revisited","author":"Ran Canetti","year":"2004","journal-title":"J. ACM"},{"key":"ref194:boneh2011random","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/978-3-642-25385-0_3","article-title":"Random oracles in a quantum world","author":"Dan Boneh","year":"2011"},{"key":"ref195:shoup1997lower","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1007\/3-540-69053-0_18","article-title":"Lower bounds for discrete logarithms and related problems","author":"Victor Shoup","year":"1997"},{"key":"ref196:maurer2005abstract","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11586821_1","article-title":"Abstract models of computation in cryptography","author":"Ueli Maurer","year":"2005"},{"key":"ref197:dent2002adapting","doi-asserted-by":"publisher","first-page":"100","DOI":"10.1007\/3-540-36178-2_6","article-title":"Adapting the weaknesses of the random oracle model to the\n  generic group model","author":"Alexander W Dent","year":"2002"},{"key":"ref198:fuchsbauer2018algebraic","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-319-96881-0_2","article-title":"The algebraic group model and its applications","author":"Georg Fuchsbauer","year":"2018"},{"key":"ref199:10.1145\/3335741.3335757","isbn-type":"print","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1145\/3335741.3335757","volume-title":"Providing Sound Foundations for Cryptography: On the Work of\n  Shafi Goldwasser and Silvio Micali","author":"Manuel Blum","year":"2019","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450372664"},{"key":"ref200:canetti2007cryptography","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1109\/focs.2007.70","article-title":"Cryptography from sunspots: How to use an imperfect\n  reference string","author":"Ran Canetti","year":"2007"},{"key":"ref201:fiat1986prove","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1007\/3-540-47721-7_12","article-title":"How to prove yourself: Practical solutions to identification\n  and signature problems","author":"Amos Fiat","year":"1986"},{"key":"ref202:canetti2018fiat","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1007\/978-3-319-78381-9_4","article-title":"Fiat-Shamir and correlation intractability from strong\n  KDM-secure encryption","author":"Ran Canetti","year":"2018"},{"key":"ref203:impagliazzo1995personal","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1109\/sct.1995.514853","article-title":"A personal view of average-case complexity","author":"Russell Impagliazzo","year":"1995"},{"volume-title":"Secrecy, authentication, and public key systems.","year":"1979","author":"Ralph Charles Merkle","key":"ref204:merkle1979secrecy"},{"key":"ref205:bitansky2019complexity","doi-asserted-by":"publisher","first-page":"422","DOI":"10.1007\/978-3-030-36030-6_17","article-title":"On the complexity of collision resistant hash functions: New\n  and old black-box separations","author":"Nir Bitansky","year":"2019"},{"key":"ref206:abdalla2004minimal","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-30191-2_1","article-title":"On the minimal assumptions of group signature schemes","author":"Michel Abdalla","year":"2004"},{"key":"ref207:goldwasser1988digital","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1137\/0217017","article-title":"A digital signature scheme secure against adaptive\n  chosen-message attacks","volume":"17","author":"Shafi Goldwasser","year":"1988","journal-title":"SIAM Journal on computing"},{"key":"ref208:an2002security","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1007\/3-540-46035-7_6","article-title":"On the security of joint signature and encryption","author":"Jee Hea An","year":"2002"},{"key":"ref209:bsz05","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30574-3_11","article-title":"Foundations of Group Signatures: The Case of Dynamic\n  Groups","author":"Mihir Bellare","year":"2005"},{"key":"ref210:chaum87b","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-47721-7_10","article-title":"A Secure and Privacy-Protecting Protocol for Transmitting\n  Personal Information Between Organizations","author":"David Chaum","year":"1987"},{"key":"ref211:lrsw99","series-title":"SAC '99","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-46513-8_14","article-title":"Pseudonym Systems","author":"Anna Lysyanskaya","year":"2000"},{"key":"ref212:brands00","isbn-type":"print","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/5931.001.0001","volume-title":"Rethinking Public Key Infrastructures and Digital\n  Certificates: Building in Privacy","author":"Stefan A. Brands","year":"2000","ISBN":"https:\/\/id.crossref.org\/isbn\/0262024918"},{"key":"ref213:cl01","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1007\/3-540-44987-6_7","article-title":"An Efficient System for Non-transferable Anonymous\n  Credentials with Optional Anonymity Revocation","volume":"2045 of LCNS","author":"Jan Camenisch","year":"2001"},{"key":"ref214:cl04","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-28628-8_4","article-title":"Signature Schemes and Anonymous Credentials from Bilinear\n  Maps","author":"Jan Camenisch","year":"2004"},{"key":"ref215:bcckls09","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03356-8_7","article-title":"Randomizable Proofs and Delegatable Anonymous Credentials","author":"Mira Belenkiy","year":"2009"},{"key":"ref216:ggm14","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23253","article-title":"Decentralized Anonymous Credentials","author":"Christina Garman","year":"2014"},{"volume-title":"Specification of the Identity Mixer Cryptographic Library","year":"2010","author":"Jan Camenisch","key":"ref217:camenisch10"},{"key":"ref218:cdh16","doi-asserted-by":"publisher","DOI":"10.1145\/2994620.2994625","article-title":"Scalable Revocation Scheme for Anonymous Credentials Based\n  on N-times Unlinkable Proofs","author":"Jan Camenisch","year":"2016"},{"key":"ref219:satter_2018","volume-title":"Emails: Lawyer who met Trump Jr. tied to Russian officials","author":"Raphael Satter","year":"2018","journal-title":"AP NEWS"},{"volume-title":"Authenticating Email Using DKIM and ARC, or How We Analyzed\n  the Kasowitz Emails","year":"2017","author":"Jeremy B. Merrill","key":"ref220:merrill_2017"},{"volume-title":"Here\u2019s how The Post analyzed Hunter Biden\u2019s laptop","year":"2022","author":"Craig Timberg","key":"ref221:timberg_2022"},{"key":"ref222:EpochalSigs","doi-asserted-by":"publisher","first-page":"1677","DOI":"10.1109\/sp40001.2021.00058","article-title":"Epochal Signatures for Deniable Group Chats","author":"Andreas H\u00fclsing","year":"2021"},{"key":"ref223:tds","doi-asserted-by":"publisher","first-page":"79","DOI":"10.56553\/popets-2023-0071","article-title":"Time-Deniable Signatures","volume":"2023","author":"Gabrielle Beck","year":"2023","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"ref224:shortlived","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-22969-5_17","article-title":"Short-lived zero-knowledge proofs and signatures","author":"Arasu Arun","year":"2022"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T21:23:50Z","timestamp":1744147430000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/1\/10"}},"issued":{"date-parts":[[2025,4,8]]},"references-count":224,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,4,8]]}},"URL":"https:\/\/doi.org\/10.62056\/a3wa3z10k","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"type":"electronic","value":"3006-5496"}],"published":{"date-parts":[[2025,4,8]]},"assertion":[{"value":"2025-01-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-03-11","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-1-12"},{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T05:54:30Z","timestamp":1787032470331,"version":"build-2736575974"},"reference-count":63,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T00:00:00Z","timestamp":1704758400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,3,5]]},"abstract":"<jats:p>In this work we study algebraic and generic models for group actions, and extend them to the universal composability (UC) framework of Canetti (FOCS 2001).   We revisit the constructions of Duman et al. (PKC 2023) integrating the type-safe model by Zhandry (Crypto 2022), adapted to the group action setting, and formally define an algebraic action model (AAM). This model restricts the power of the adversary in a similar fashion to the algebraic group model (AGM).   By imposing algebraic behaviour to the adversary and environment of the UC framework, we construct the UC-AAM. Finally, we instantiate UC-AAM with isogeny-based assumptions, in particular the CSIDH action with twists, obtaining the explicit isogeny model, UC-EI; we observe that, under certain assumptions, this model is \"closer\" to standard UC than the UC-AGM, even though there still exists an important separation.   We demonstrate the utility of our definitions by proving UC-EI security for the passive-secure oblivious transfer protocol described by Lai et al. (Eurocrypt 2021), hence providing the first concretely efficient two-message isogeny-based OT protocol in the random oracle model against malicious adversaries.<\/jats:p>","DOI":"10.62056\/a39qgy4e-","type":"journal-article","created":{"date-parts":[[2024,4,9]],"date-time":"2024-04-09T15:27:10Z","timestamp":1712676430000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":7,"title":["Simple Two-Message OT in the Explicit Isogeny Model"],"prefix":"10.62056","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1917-1833","authenticated-orcid":false,"given":"Emmanuela","family":"Orsini","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05crjpb27","id-type":"ROR","asserted-by":"publisher"}],"name":"Bocconi University","place":["Milan, Lombardia, 20136, Italy"],"department":["Department of Computing Sciences"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-2086-8398","authenticated-orcid":false,"given":"Riccardo","family":"Zanotto","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02njgxr09","id-type":"ROR","asserted-by":"publisher"}],"name":"CISPA Helmholtz Center for Information Security","place":["Saarbr\u00fccken, Saarland, 66123, Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2024,4,9]]},"reference":[{"key":"ref1:EPRINT:Rabin05","article-title":"How To Exchange Secrets with Oblivious Transfer","author":"Michael O. Rabin","year":"2005"},{"key":"ref2:JC:BLNNOOSS21","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/s00145-021-09403-1","article-title":"High-Performance Multi-party Computation for Binary Circuits\n  Based on Oblivious Transfer","volume":"34","author":"Sai Sheshank Burra","year":"2021","journal-title":"Journal of Cryptology"},{"key":"ref3:CCS:KelOrsSch16","doi-asserted-by":"publisher","first-page":"830","DOI":"10.1145\/2976749.2978357","article-title":"MASCOT: Faster Malicious Arithmetic Secure Computation\n  with Oblivious Transfer","volume-title":"ACM CCS 2016","author":"Marcel Keller","year":"2016"},{"key":"ref4:CCS:DonCheWen13","doi-asserted-by":"publisher","first-page":"789","DOI":"10.1145\/2508859.2516701","article-title":"When private set intersection meets big data: an efficient\n  and scalable protocol","volume-title":"ACM CCS 2013","author":"Changyu Dong","year":"2013"},{"key":"ref5:USENIX:PinSchZoh14","first-page":"797","article-title":"Faster Private Set Intersection Based on OT Extension","volume-title":"USENIX Security 2014","author":"Benny Pinkas","year":"2014"},{"key":"ref6:C:EveGolLem82","first-page":"205","article-title":"A Randomized Protocol for Signing Contracts","volume-title":"CRYPTO'82","author":"Shimon Even","year":"1982"},{"key":"ref7:C:BelMic89","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"547","DOI":"10.1007\/0-387-34805-0_48","article-title":"Non-Interactive Oblivious Transfer and Applications","volume-title":"CRYPTO'89","volume":"435","author":"Mihir Bellare","year":"1990"},{"key":"ref8:SODA:NaoPin01","first-page":"448","article-title":"Efficient Oblivious Transfer Protocols","volume-title":"12th SODA","author":"Moni Naor","year":"2001"},{"key":"ref9:EC:AieIshRei01","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1007\/3-540-44987-6_8","article-title":"Priced Oblivious Transfer: How to Sell Digital Goods","volume-title":"EUROCRYPT\u00a02001","volume":"2045","author":"William Aiello","year":"2001"},{"key":"ref10:C:PeiVaiWat08","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"554","DOI":"10.1007\/978-3-540-85174-5_31","article-title":"A Framework for Efficient and Composable Oblivious\n  Transfer","volume-title":"CRYPTO\u00a02008","volume":"5157","author":"Chris Peikert","year":"2008"},{"key":"ref11:FC:ZLWR13","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1007\/978-3-642-39884-1_8","article-title":"Practical Fully Simulatable Oblivious Transfer with\n  Sublinear Communication","volume-title":"FC 2013","volume":"7859","author":"Bingsheng Zhang","year":"2013"},{"key":"ref12:LC:ChoOrl15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1007\/978-3-319-22174-8_3","article-title":"The Simplest Protocol for Oblivious Transfer","volume-title":"LATINCRYPT\u00a02015","volume":"9230","author":"Tung Chou","year":"2015"},{"key":"ref13:JC:HalKal12","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/s00145-010-9092-8","article-title":"Smooth Projective Hashing and Two-Message Oblivious\n  Transfer","volume":"25","author":"Shai Halevi","year":"2012","journal-title":"Journal of Cryptology"},{"key":"ref14:ICITS:DvMN08","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1007\/978-3-540-85093-9_11","article-title":"Oblivious Transfer Based on the McEliece Assumptions","volume-title":"ICITS 08","volume":"5155","author":"Rafael Dowsley","year":"2008"},{"key":"ref15:CANS:DavDowNas14","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1007\/978-3-319-12280-9_10","article-title":"Universally Composable Oblivious Transfer Based on a Variant\n  of LPN","volume-title":"CANS 14","volume":"8813","author":"Bernardo David","year":"2014"},{"key":"ref16:EC:DGHMW20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"768","DOI":"10.1007\/978-3-030-45724-2_26","article-title":"Two-Round Oblivious Transfer from CDH or LPN","volume-title":"EUROCRYPT\u00a02020, Part\u00a0II","volume":"12106","author":"Nico D\u00f6ttling","year":"2020"},{"key":"ref17:TCC:BraDot18","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"370","DOI":"10.1007\/978-3-030-03810-6_14","article-title":"Two-Message Statistically Sender-Private OT from LWE","volume-title":"TCC\u00a02018, Part\u00a0II","volume":"11240","author":"Zvika Brakerski","year":"2018"},{"key":"ref18:AC:MicSor20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"381","DOI":"10.1007\/978-3-030-64834-3_13","article-title":"Simpler Statistically Sender Private Oblivious Transfer from\n  Ideals of Cyclotomic Integers","volume-title":"ASIACRYPT\u00a02020, Part\u00a0II","volume":"12492","author":"Daniele Micciancio","year":"2020"},{"key":"ref19:AFRICACRYPT:Vitse19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1007\/978-3-030-23696-0_4","article-title":"Simple Oblivious Transfer Protocols Compatible with\n  Supersingular Isogenies","volume-title":"AFRICACRYPT 19","volume":"11627","author":"Vanessa Vitse","year":"2019"},{"key":"ref20:IMA:BDGM19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1007\/978-3-030-35199-1_5","article-title":"A Framework for Universally Composable Oblivious Transfer\n  from One-Round Key-Exchange","volume-title":"17th IMA International Conference on Cryptography and\n  Coding","volume":"11929","author":"Pedro Branco","year":"2019"},{"key":"ref21:CANS:dOPS20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1007\/978-3-030-65411-5_12","article-title":"Semi-commutative Masking: A Framework for Isogeny-Based\n  Protocols, with an Application to Fully Secure Two-Round Isogeny-Based OT","volume-title":"CANS 20","volume":"12579","author":"Cyprien Delpech de Saint Guilhem","year":"2020"},{"key":"ref22:EC:LaiGalDel21","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1007\/978-3-030-77870-5_8","article-title":"Compact, Efficient and UC-Secure Isogeny-Based Oblivious\n  Transfer","volume-title":"EUROCRYPT\u00a02021, Part\u00a0I","volume":"12696","author":"Yi-Fu Lai","year":"2021"},{"key":"ref23:FOCS:Canetti01","doi-asserted-by":"publisher","first-page":"136","DOI":"10.1109\/SFCS.2001.959888","article-title":"Universally Composable Security: A New Paradigm for\n  Cryptographic Protocols","volume-title":"42nd FOCS","author":"Ran Canetti","year":"2001"},{"key":"ref24:JC:GolOre94","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/BF00195207","article-title":"Definitions and Properties of Zero-Knowledge Proof Systems","volume":"7","author":"Oded Goldreich","year":"1994","journal-title":"Journal of Cryptology"},{"key":"ref25:EPRINT:Couveignes06","article-title":"Hard Homogeneous Spaces","author":"Jean-Marc Couveignes","year":"2006"},{"key":"ref26:EPRINT:RosSto06","article-title":"Public-Key Cryptosystem Based On Isogenies","author":"Alexander Rostovtsev","year":"2006"},{"key":"ref27:PQCRYPTO:JaoDeFo11","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","article-title":"Towards Quantum-Resistant Cryptosystems from Supersingular\n  Elliptic Curve Isogenies","volume-title":"Post-Quantum Cryptography - 4th International Workshop,\n  PQCrypto 2011","author":"David Jao","year":"2011"},{"key":"ref28:NISTPQC-R3:SIKE20","article-title":"SIKE","author":"David Jao","year":"2020"},{"key":"ref29:EC:CasDec23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/978-3-031-30589-4_15","article-title":"An Efficient Key Recovery Attack on SIDH","volume-title":"EUROCRYPT\u00a02023, Part\u00a0V","volume":"14008","author":"Wouter Castryck","year":"2023"},{"key":"ref30:EC:MMPPW23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"448","DOI":"10.1007\/978-3-031-30589-4_16","article-title":"A Direct Key Recovery Attack on SIDH","volume-title":"EUROCRYPT\u00a02023, Part\u00a0V","volume":"14008","author":"Luciano Maino","year":"2023"},{"key":"ref31:EC:Robert23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"472","DOI":"10.1007\/978-3-031-30589-4_17","article-title":"Breaking SIDH in Polynomial Time","volume-title":"EUROCRYPT\u00a02023, Part\u00a0V","volume":"14008","author":"Damien Robert","year":"2023"},{"key":"ref32:Kani97","first-page":"122","article-title":"The number of curves of genus two with elliptic\n  differentials.","volume":"1997","author":"Ernst Kani","year":"1997","journal-title":"Journal f\u00fcr die reine und angewandte Mathematik (Crelles\n  Journal)"},{"key":"ref33:AC:CLMPR18","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","article-title":"CSIDH: An Efficient Post-Quantum Commutative Group\n  Action","volume-title":"ASIACRYPT\u00a02018, Part\u00a0III","volume":"11274","author":"Wouter Castryck","year":"2018"},{"key":"ref34:C:Zhandry22b","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1007\/978-3-031-15982-4_3","article-title":"To Label, or Not To Label (in Generic Groups)","volume-title":"CRYPTO\u00a02022, Part\u00a0III","volume":"13509","author":"Mark Zhandry","year":"2022"},{"key":"ref35:PKC:DHKKLR23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"406","DOI":"10.1007\/978-3-031-31368-4_15","article-title":"Generic Models for Group Actions","volume-title":"PKC\u00a02023, Part\u00a0I","volume":"13940","author":"Julien Duman","year":"2023"},{"key":"ref36:AC:ABKLX21","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1007\/978-3-030-92078-4_11","article-title":"Algebraic Adversaries in the Universal Composability\n  Framework","volume-title":"ASIACRYPT\u00a02021, Part\u00a0III","volume":"13092","author":"Michel Abdalla","year":"2021"},{"key":"ref37:EPRINT:BDDMN17b","article-title":"A Framework for Efficient Adaptively Secure Composable\n  Oblivious Transfer in the ROM","author":"Paulo S. L. M. Barreto","year":"2017"},{"key":"ref38:C:FucKilLos18","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-319-96881-0_2","article-title":"The Algebraic Group Model and its Applications","volume-title":"CRYPTO\u00a02018, Part\u00a0II","volume":"10992","author":"Georg Fuchsbauer","year":"2018"},{"key":"ref39:EC:Shoup97","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1007\/3-540-69053-0_18","article-title":"Lower Bounds for Discrete Logarithms and Related Problems","volume-title":"EUROCRYPT'97","volume":"1233","author":"Victor Shoup","year":"1997"},{"key":"ref40:IMA:Maurer05","series-title":"LNCS","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/11586821_1","article-title":"Abstract Models of Computation in Cryptography (Invited\n  Paper)","volume-title":"10th IMA International Conference on Cryptography and\n  Coding","volume":"3796","author":"Ueli M. Maurer","year":"2005"},{"key":"ref41:AC:ZhaZhoKat22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"310","DOI":"10.1007\/978-3-031-22972-5_11","article-title":"An Analysis of the Algebraic Group Model","volume-title":"ASIACRYPT\u00a02022, Part\u00a0IV","volume":"13794","author":"Cong Zhang","year":"2022"},{"key":"ref42:C:BraYun90","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1007\/3-540-38424-3_7","article-title":"One-Way Group Actions","volume-title":"CRYPTO'90","volume":"537","author":"Gilles Brassard","year":"1991"},{"key":"ref43:Grigoriev2010","doi-asserted-by":"crossref","first-page":"194","DOI":"10.1016\/j.apal.2010.09.004","article-title":"Authentication schemes from actions on graphs, groups, or\n  rings","volume":"162","author":"Dima Grigoriev","year":"2010","journal-title":"Annals of Pure and Applied Logic","ISSN":"https:\/\/id.crossref.org\/issn\/0168-0072","issn-type":"electronic"},{"key":"ref44:EC:Ducvan22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"643","DOI":"10.1007\/978-3-031-07082-2_23","article-title":"On the Lattice Isomorphism Problem, Quadratic Forms,\n  Remarkable Lattices, and Cryptography","volume-title":"EUROCRYPT\u00a02022, Part\u00a0III","volume":"13277","author":"L\u00e9o Ducas","year":"2022"},{"key":"ref45:TCC:JQSY19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1007\/978-3-030-36030-6_11","article-title":"General Linear Group Action on Tensors: A Candidate for\n  Post-quantum Cryptography","volume-title":"TCC\u00a02019, Part\u00a0I","volume":"11891","author":"Zhengfeng Ji","year":"2019"},{"key":"ref46:AC:ADMP20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"411","DOI":"10.1007\/978-3-030-64834-3_14","article-title":"Cryptographic Group Actions and Applications","volume-title":"ASIACRYPT\u00a02020, Part\u00a0II","volume":"12492","author":"Navid Alamati","year":"2020"},{"key":"ref47:AC:MonZha22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-22963-3_1","article-title":"Full Quantum Equivalence of Group Action DLog and CDH,\n  and More","volume-title":"ASIACRYPT\u00a02022, Part\u00a0I","volume":"13791","author":"Hart Montgomery","year":"2022"},{"key":"ref48:TCC:CDPW07","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/978-3-540-70936-7_4","article-title":"Universally Composable Security with Global Setup","volume-title":"TCC\u00a02007","volume":"4392","author":"Ran Canetti","year":"2007"},{"key":"ref49:EPRINT:MulMurPin22","article-title":"Random sampling of supersingular elliptic curves","author":"Marzio Mula","year":"2022"},{"key":"ref50:EPRINT:BBDFGKMPSSTVVWZ22","article-title":"Failing to hash into supersingular isogeny graphs","author":"Jeremy Booher","year":"2022"},{"key":"ref51:C:DGIMMO19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-26954-8_1","article-title":"Trapdoor Hash Functions and Their Applications","volume-title":"CRYPTO\u00a02019, Part\u00a0III","volume":"11694","author":"Nico D\u00f6ttling","year":"2019"},{"key":"ref52:PKC:BMMPRS23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"376","DOI":"10.1007\/978-3-031-31368-4_14","article-title":"Round-Optimal Oblivious Transfer and MPC from\n  Computational CSIDH","volume-title":"PKC\u00a02023, Part\u00a0I","volume":"13940","author":"Saikrishna Badrinarayanan","year":"2023"},{"key":"ref53:AC:BeuKleVer19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/978-3-030-34578-5_9","article-title":"CSI-FiSh: Efficient Isogeny Based Signatures Through\n  Class Group Computations","volume-title":"ASIACRYPT\u00a02019, Part\u00a0I","volume":"11921","author":"Ward Beullens","year":"2019"},{"key":"ref54:CSIfish_poly","article-title":"CSI\u2011FiSh really isn't polynomial\u2011time","author":"Lorenz Panny","year":"2023"},{"key":"ref55:C:AEKKR22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"699","DOI":"10.1007\/978-3-031-15979-4_24","article-title":"Password-Authenticated Key Exchange from Group Actions","volume-title":"CRYPTO\u00a02022, Part\u00a0II","volume":"13508","author":"Michel Abdalla","year":"2022"},{"key":"ref56:velu71","series-title":"A et B, Sciences math\u00e9matiques et Sciences physiques","first-page":"238","article-title":"Isog\u00e9nies entre courbes elliptiques","volume":"273","author":"Jacques V\u00e9lu","year":"1971","journal-title":"Comptes Rendus de l'Acad\u00e9mie des Sciences de Paris"},{"key":"ref57:Silverman","series-title":"Graduate Texts in Mathematics","isbn-type":"print","article-title":"The Arithmetic of Elliptic Curves","author":"J.H. Silverman","year":"2009","ISBN":"https:\/\/id.crossref.org\/isbn\/9780387094946"},{"key":"ref58:DeFeo_intro","article-title":"Mathematics of Isogeny Based Cryptography","volume":"abs\/1711.04062","author":"Luca De Feo","year":"2017","journal-title":"CoRR"},{"key":"ref59:FOCS:Wesolowski21","doi-asserted-by":"publisher","first-page":"1100","DOI":"10.1109\/FOCS52979.2021.00109","article-title":"The supersingular isogeny path and endomorphism ring\n  problems are equivalent","volume-title":"62nd FOCS","author":"Benjamin Wesolowski","year":"2022"},{"key":"ref60:EC:CasPanVer20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"523","DOI":"10.1007\/978-3-030-45724-2_18","article-title":"Rational Isogenies from Irrational Endomorphisms","volume-title":"EUROCRYPT\u00a02020, Part\u00a0II","volume":"12106","author":"Wouter Castryck","year":"2020"},{"key":"ref61:EC:Wesolowski22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1007\/978-3-031-07082-2_13","article-title":"Orientations and the Supersingular Endomorphism Ring\n  Problem","volume-title":"EUROCRYPT\u00a02022, Part\u00a0III","volume":"13277","author":"Benjamin Wesolowski","year":"2022"},{"key":"ref62:Felderhoff","article-title":"Hard Homogenous Spaces and Commutative Supersingular\n  Isogeny based Diffie-Hellman","author":"Jo\u00ebl Felderhoff","year":"2019"},{"key":"ref63:GPSV21","first-page":"40","article-title":"Quantum Equivalence of the DLP and CDHP for Group\n  Actions","volume":"1","author":"Steven Galbraith","year":"2021","journal-title":"Mathematical Cryptology"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T16:25:26Z","timestamp":1733847926000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/1\/15"}},"issued":{"date-parts":[[2024,4,9]]},"references-count":63,"URL":"https:\/\/doi.org\/10.62056\/a39qgy4e-","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2024,4,9]]},"assertion":[{"value":"2024-01-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-03-05","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-1-42"},{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T15:06:29Z","timestamp":1785423989530,"version":"3.56.0"},"reference-count":51,"publisher":"International Association for Cryptologic Research","issue":"1","license":[{"start":{"date-parts":[[2026,2,3]],"date-time":"2026-02-03T00:00:00Z","timestamp":1770076800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2026,4,28]]},"abstract":"<jats:p>Efficient and practically secure masked software implementations are faced with significant challenges. A fundamental reason is the unknown nature of micro-architectures of commercial processors and their leakage-inducing effects. Thus, even though provably secure software algorithms have been presented in the literature, it requires additional consideration when implementing them in practice.<\/jats:p>\n                  <jats:p>In this work, we tackle horizontal leakage effects originating in the ALU micro-architecture of CPUs. Horizontal leakage is emitted when ALU operations require the combination of values at different bit indices to yield the correct result and gives adversaries the joint information of multiple bits within a register. This led to the belief that no more than one share of a secret value must be present in the same register at any point. We show that this restriction is not universally true. We introduce barriers within register that stop horizontal leakage within, and thus allows multiple shares of the same secret to be placed within a single register. This enables us to operate on multiple shares within a single software instruction and therefore increase efficiency. With our proposed share and barrier layout, we present practical case studies on a full AES round and the AES-prime Sbox and show their SCA security with up to one million traces.<\/jats:p>","DOI":"10.62056\/ana69qdja","type":"journal-article","created":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T18:09:08Z","timestamp":1777918148000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Horizontal Leakage in Micro-Architectures"],"prefix":"10.62056","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3682-1567","authenticated-orcid":false,"given":"Jannik","family":"Zeitschner","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/04tsk2644","id-type":"ROR","asserted-by":"publisher"}],"name":"Ruhr-University Bochum","place":["Universit\u00e4tsstra\u00dfe 150, Bochum, 44801, Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1626-6175","authenticated-orcid":false,"given":"John","family":"Gaspoz","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05f950310","id-type":"ROR","asserted-by":"publisher"}],"name":"Catholic University Leuven","place":["Oude Markt 13, Leuven, 3000, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3133-9261","authenticated-orcid":false,"given":"Svetla","family":"Nikova","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05f950310","id-type":"ROR","asserted-by":"publisher"}],"name":"Catholic University Leuven","place":["Oude Markt 13, Leuven, 3000, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4032-7433","authenticated-orcid":false,"given":"Amir","family":"Moradi","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05n911h24","id-type":"ROR","asserted-by":"publisher"}],"name":"Technical University Darmstadt","place":["Karolinenplatz 5, Darmstadt, 64289, Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2026,5,4]]},"reference":[{"key":"ref1:C:Kocher96","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","article-title":"Timing Attacks on Implementations of Diffie-Hellman,\n  RSA, DSS, and Other Systems","volume":"1109","author":"Paul C. Kocher","year":"1996"},{"key":"ref2:C:KocJafJun99","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","article-title":"Differential Power Analysis","volume":"1666","author":"Paul C. Kocher","year":"1999"},{"key":"ref3:EC:BDMRW20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1007\/978-3-030-45727-3_11","article-title":"Tornado: Automatic Generation of Probing-Secure Masked\n  Bitsliced Implementations","volume":"12107","author":"Sonia Bela\u00efd","year":"2020"},{"key":"ref4:DBLP:journals\/tches\/ZeitschnerMM23","doi-asserted-by":"publisher","first-page":"391","DOI":"10.46586\/TCHES.V2023.I3.391-421","article-title":"PROLEAD_SW Probing-Based Software Leakage Detection for\n  ARM Binaries","volume":"2023","author":"Jannik Zeitschner","year":"2023","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref5:DBLP:conf\/asiacrypt\/GigerlPM21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-92075-3_1","article-title":"Secure and Efficient Software Masking on Superscalar\n  Pipelined Processors","author":"Barbara Gigerl","year":"2021"},{"key":"ref6:DBLP:journals\/tches\/GaspozD23","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2023.i2.155-179","article-title":"Threshold Implementations in Software: Micro-architectural\n  Leakages in Algorithms","author":"John Gaspoz","year":"2023","journal-title":"CHES"},{"key":"ref7:DBLP:journals\/tches\/CassiersMMMS23","doi-asserted-by":"publisher","first-page":"482","DOI":"10.46586\/TCHES.V2023.I2.482-518","article-title":"Prime-Field Masking in Hardware and its Soundness against\n  Low-Noise SCA Attacks","volume":"2023","author":"Ga\u00ebtan Cassiers","year":"2023","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref8:DBLP:conf\/acns\/GigerlPM23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-33488-7_1","article-title":"Formal Verification of Arithmetic Masking in Hardware and\n  Software","author":"Barbara Gigerl","year":"2023"},{"key":"ref9:DBLP:journals\/tches\/BronchainC22","doi-asserted-by":"publisher","first-page":"553","DOI":"10.46586\/tches.v2022.i4.553-588","article-title":"Bitslicing Arithmetic\/Boolean Masking Conversions for Fun\n  and Profit with Application to Lattice-Based KEMs","volume":"2022","author":"Olivier Bronchain","year":"2022","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref10:DBLP:conf\/eurocrypt\/MasureMMS23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"596","DOI":"10.1007\/978-3-031-30634-1_20","article-title":"Effective and Efficient Masking with Low Noise Using\n  Small-Mersenne-Prime Ciphers","author":"Lo\u00efc Masure","year":"2023"},{"key":"ref11:C:IshSahWag03","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-3-540-45146-4_27","article-title":"Private Circuits: Securing Hardware against Probing\n  Attacks","volume":"2729","author":"Yuval Ishai","year":"2003"},{"key":"ref12:DBLP:journals\/tches\/FaustGPPS18","doi-asserted-by":"publisher","DOI":"10.13154\/tches.v2018.i3.89-120","article-title":"Composable Masking Schemes in the Presence of Physical\n  Defaults & the Robust Probing Model","author":"Sebastian Faust","year":"2018","journal-title":"CHES"},{"key":"ref13:DBLP:journals\/tc\/CassiersGLS21","doi-asserted-by":"publisher","first-page":"1677","DOI":"10.1109\/TC.2020.3022979","article-title":"Hardware Private Circuits: From Trivial Composition to Full\n  Verification","volume":"70","author":"Ga\u00ebtan Cassiers","year":"2021","journal-title":"IEEE Trans. Computers"},{"key":"ref14:DBLP:conf\/cosade\/MominCS22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/978-3-030-99766-3_12","article-title":"Handcrafting: Improving Automated Masking in Hardware with\n  Manual Optimizations","author":"Charles Momin","year":"2022"},{"key":"ref15:DBLP:journals\/tches\/KnichelSM22","doi-asserted-by":"publisher","first-page":"323","DOI":"10.46586\/tches.v2022.i1.323-344","article-title":"Generic Hardware Private Circuits: Towards Automated\n  Generation of Composable Secure Gadgets","volume":"2022","author":"David Knichel","year":"2022","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref16:DBLP:journals\/tches\/KnichelMMS22","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2022.i1.589-629","article-title":"Automated Generation of Masked Hardware","author":"David Knichel","year":"2022","journal-title":"CHES"},{"key":"ref17:DBLP:journals\/tches\/CassiersSV24","doi-asserted-by":"publisher","DOI":"10.46586\/TCHES.V2024.I3.603-633","article-title":"Low-Latency Masked Gadgets Robust against Physical Defaults\n  with Application to Ascon","author":"Ga\u00ebtan Cassiers","year":"2024","journal-title":"CHES"},{"key":"ref18:DBLP:journals\/tches\/MullerM24a","doi-asserted-by":"publisher","DOI":"10.46586\/TCHES.V2024.I4.451-482","article-title":"Robust but Relaxed Probing Model","author":"Nicolai M\u00fcller","year":"2024","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref19:DBLP:conf\/cosade\/Papagiannopoulos17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1007\/978-3-319-64647-3_17","article-title":"Mind the Gap: Towards Secure 1st-Order Masking in Software","author":"Kostas Papagiannopoulos","year":"2017"},{"key":"ref20:DBLP:conf\/cosade\/CorreGD18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1007\/978-3-319-89641-0_5","article-title":"Micro-architectural Power Simulator for Leakage Assessment\n  of Cryptographic Software on ARM Cortex-M3 Processors","author":"Yann Le Corre","year":"2018"},{"key":"ref21:DBLP:conf\/eurocrypt\/GaoOP22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"284","DOI":"10.1007\/978-3-031-07082-2_11","article-title":"Towards Micro-architectural Leakage Simulators: Reverse\n  Engineering Micro-architectural Leakage Features Is Practical","author":"Si Gao","year":"2022"},{"key":"ref22:DBLP:journals\/tches\/MarshallPW22","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2022.i1.175-220","article-title":"MIRACLE: MIcRo-ArChitectural Leakage Evaluation A study\n  of micro-architectural power leakage across many devices","author":"Ben Marshall","year":"2022","journal-title":"CHES"},{"key":"ref23:DBLP:conf\/ches\/BattistelloCPZ16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-662-53140-2_2","article-title":"Horizontal Side-Channel Attacks and Countermeasures on the\n  ISW Masking Scheme","author":"Alberto Battistello","year":"2016"},{"key":"ref24:DBLP:conf\/uss\/GigerlHPMB21","first-page":"1469","article-title":"Coco: Co-Design and Co-Verification of Masked Software\n  Implementations on CPUs","author":"Barbara Gigerl","year":"2021"},{"key":"ref25:DBLP:journals\/tches\/GaoMPO20","doi-asserted-by":"publisher","DOI":"10.13154\/TCHES.V2020.I1.152-174","article-title":"Share-slicing: Friend or Foe?","author":"Si Gao","year":"2020","journal-title":"CHES"},{"key":"ref26:ICICS:NikRecRij06","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"529","DOI":"10.1007\/11935308_38","article-title":"Threshold Implementations Against Side-Channel Attacks and\n  Glitches","volume":"4307","author":"Svetla Nikova","year":"2006"},{"key":"ref27:DBLP:conf\/eurocrypt\/GoudarziR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"567","DOI":"10.1007\/978-3-319-56620-7_20","article-title":"How Fast Can Higher-Order Masking Be in Software?","author":"Dahmun Goudarzi","year":"2017"},{"key":"ref28:DBLP:conf\/islped\/Correale95","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1145\/224081.224095","article-title":"Overview of the power minimization techniques employed in\n  the IBM PowerPC 4xx embedded controllers","author":"Anthony Correale Jr.","year":"1995"},{"key":"ref29:DBLP:conf\/date\/MunchWWMS00","doi-asserted-by":"publisher","first-page":"624","DOI":"10.1109\/DATE.2000.840850","article-title":"Automating RT-Level Operand Isolation to Minimize Power\n  Consumption in Datapaths","author":"Michael M\u00fcnch","year":"2000"},{"key":"ref30:Canal04OperandGating","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1109\/CGO.2004.1281669","article-title":"Software-Controlled Operand-Gating","author":"Ramon Canal","year":"2004"},{"key":"ref31:kulkarni2014implementation","doi-asserted-by":"publisher","DOI":"10.1109\/ECS.2014.6892770","article-title":"Implementation of clock gating technique and performing\n  power analysis for processor engine (ALU) in network processors","author":"Roopa Kulkarni","year":"2014"},{"key":"ref32:kulkarni2020power","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-5558-9_71","article-title":"Power Optimization of a 32-Bit ALU Using Distributed Clock\n  Gating Technique","author":"Roopa R Kulkarni","year":"2020"},{"key":"ref33:vo2024hybrid","article-title":"Hybrid Data Driven Clock Gating and Data Gating Technique\n  for Better Saving Power in ALU RISC-V","author":"Minh Huan Vo","year":"2024","journal-title":"IJEER"},{"key":"ref34:DBLP:journals\/tches\/MullerM22","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2022.i4.311-348","article-title":"PROLEAD A Probing-Based Hardware Leakage Detection\n  Tool","author":"Nicolai M\u00fcller","year":"2022","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref35:scalib","doi-asserted-by":"publisher","first-page":"5196","DOI":"10.21105\/joss.05196","article-title":"SCALib: A Side-Channel Analysis Library","volume":"8","author":"Ga\u00ebtan Cassiers","year":"2023","journal-title":"Journal of Open Source Software"},{"key":"ref36:Armv6ISA","volume-title":"Armv6-M Architecture Reference Manual"},{"key":"ref37:Armv7ISA","volume-title":"Armv7-M Architecture Reference Manual"},{"key":"ref38:RISCVISA","volume-title":"The RISC-V Instruction Set Manual Volume 1: Unprivileged\n  ISA"},{"key":"ref39:DBLP:journals\/jce\/OFlynnC15","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/S13389-014-0087-5","article-title":"Synchronous sampling and clock recovery of internal\n  oscillators for side channel analysis and fault injection","volume":"5","author":"Colin O'Flynn","year":"2015","journal-title":"J. Cryptogr. Eng."},{"key":"ref40:TransposedAES","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/3-540-36400-5_13","article-title":"Efficient Software Implementation of AES on 32-Bit\n  Platforms","author":"Guido Bertoni","year":"2002"},{"key":"ref41:ahmed2009lightweight","article-title":"Lightweight mix columns implementation for AES","author":"Eslam Gamal Ahmed","year":"2009"},{"key":"ref42:hadvzic2025efficient","doi-asserted-by":"publisher","first-page":"656","DOI":"10.46586\/TCHES.V2025.I1.656-683","article-title":"Efficient and Composable Masked AES S-Box Designs Using\n  Optimized Inverters","volume":"2025","author":"Vedad Hadzic","year":"2025","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref43:DBLP:conf\/cardis\/DingZDSF17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1007\/978-3-319-75208-2_7","article-title":"Towards Sound and Optimal Leakage Detection Procedure","author":"A. Adam Ding","year":"2017"},{"key":"ref44:DBLP:conf\/ccs\/SheltonCS0BY21","doi-asserted-by":"publisher","first-page":"685","DOI":"10.1145\/3460120.3485380","article-title":"Rosita++: Automatic Higher-Order Leakage Elimination from\n  Cryptographic Code","author":"Madura A. Shelton","year":"2021"},{"key":"ref45:DBLP:conf\/cardis\/BalaschGGRS14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-319-16763-3_5","article-title":"On the Cost of Lazy Engineering for Masked Software\n  Implementations","author":"Josep Balasch","year":"2014"},{"key":"ref46:avanzi2019crystals","first-page":"1","article-title":"CRYSTALS-Kyber algorithm specifications and supporting\n  documentation","volume":"2","author":"Roberto Avanzi","year":"2019","journal-title":"NIST PQC Round"},{"key":"ref47:fouque2018falcon","first-page":"1","article-title":"Falcon: Fast-Fourier lattice-based compact signatures over\n  NTRU","volume":"36","author":"Pierre-Alain Fouque","year":"2018","journal-title":"Submission to the NIST\u2019s post-quantum cryptography\n  standardization process"},{"key":"ref48:vercauteren2020saber","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1007\/978-3-319-89339-6_16","article-title":"Saber: Module-LWR Based Key Exchange, CPA-Secure Encryption\n  and CCA-Secure KEM","author":"Jan-Pieter D'Anvers","year":"2018"},{"key":"ref49:alkim2020frodokem","first-page":"10","article-title":"FrodoKEM learning with errors key encapsulation","volume":"3","author":"Erdem Alkim","year":"2020","journal-title":"NIST PQC standardization: Round"},{"key":"ref50:chen2019algorithm","article-title":"Algorithm specifications and supporting documentation","author":"Cong Chen","year":"2019","journal-title":"Brown University and Onboard security company, Wilmington\n  USA"},{"key":"ref51:ntruprime-round3","volume-title":"NTRU Prime: Round 3","author":"Daniel J. Bernstein","year":"2020"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T04:03:42Z","timestamp":1778040222000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/3\/1\/27"}},"issued":{"date-parts":[[2026,5,4]]},"references-count":51,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,5,4]]}},"URL":"https:\/\/doi.org\/10.62056\/ana69qdja","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2026,5,4]]},"assertion":[{"value":"2026-02-03","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-28","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc3-1-81"},{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T14:33:47Z","timestamp":1786113227773,"version":"build-2736575974"},"reference-count":21,"publisher":"International Association for Cryptologic Research","issue":"2","license":[{"start":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T00:00:00Z","timestamp":1777248000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Key ranking is a critical subject for evaluators since it measures the remaining complexity after a side-channel attack without the need to implement the key enumeration algorithm. This paper proposes a novel method based on the knapsack counting problem. While the existing literature proposes a solution of this problem with an algorithm originating from linear programming, we propose a new computation inspired by a recent work in statistical physics. The partition function of the knapsack problem, which is equivalent to the key rank, is derived with an analytic expression. This is used to prove the mathematical equivalence between the knapsack and histogram-based methods. In addition, a saddle-point approximation of the key rank is computed from the analytic expression. A very simple mathematical formula is derived.  Simulation results show that the approximation is very tight. In addition, the execution time of the approximation is fast and linear in the key size, making it suitable for scaling to very large keys.<\/jats:p>","DOI":"10.62056\/akmpgy10k","type":"journal-article","created":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T19:02:55Z","timestamp":1785783775000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["An Analytic Expression of the Key Rank and a Saddle-Point Approximation"],"prefix":"10.62056","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4808-738X","authenticated-orcid":false,"given":"Mathieu","family":"Noes","sequence":"first","affiliation":[{"name":"Univ. Grenoble Alpes, CEA, LETI, MINATEC Campus","place":["Grenoble, 38054, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2026,8,3]]},"reference":[{"key":"ref1:SAC:VGRS12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"390","DOI":"10.1007\/978-3-642-35999-6_25","article-title":"An Optimal Key Enumeration Algorithm and Its Application to\n  Side-Channel Attacks","volume":"7707","author":"Nicolas Veyrat-Charvillon","year":"2013"},{"key":"ref2:FSE:GGPSS15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1007\/978-3-662-48116-5_6","article-title":"Simpler and More Efficient Rank Estimation for Side-Channel\n  Security Assessment","volume":"9054","author":"Cezary Glowacz","year":"2015"},{"key":"ref3:AC:MOOS15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1007\/978-3-662-48800-3_13","article-title":"Counting Keys in Parallel After a Side Channel Attack","volume":"9453","author":"Daniel P. Martin","year":"2015"},{"key":"ref4:CHES:ChoPop17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"367","DOI":"10.1007\/978-3-319-66787-4_18","article-title":"Back to Massey: Impressively Fast, Scalable and Tight\n  Security Evaluation Tools","volume":"10529","author":"Marios O. Choudary","year":"2017"},{"key":"ref5:williams2024large","doi-asserted-by":"publisher","first-page":"44151","DOI":"10.1103\/PhysRevE.109.044151","article-title":"Large-W limit of the knapsack problem","volume":"109","author":"Mobolaji Williams","year":"2024","journal-title":"Physical Review E"},{"key":"ref6:RSA:MarMatOsw18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"394","DOI":"10.1007\/978-3-319-76953-0_21","article-title":"Two Sides of the Same Coin: Counting and Enumerating Keys\n  Post Side-Channel Attacks Revisited","volume":"10808","author":"Daniel P. Martin","year":"2018"},{"key":"ref7:EPRINT:BerLanvan15","volume-title":"Tighter, faster, simpler side-channel security evaluations\n  beyond computing power","author":"Daniel J. Bernstein","year":"2015"},{"key":"ref8:grosso2018scalable","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/978-3-030-15462-2_6","article-title":"Scalable key rank estimation (and key enumeration) algorithm\n  for large keys","author":"Vincent Grosso","year":"2018"},{"key":"ref9:PGS15","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1007\/978-3-319-31271-2_8","article-title":"Comparing approaches to rank estimation for side-channel\n  security evaluations","author":"Romain Pousier","year":"2015"},{"key":"ref10:young2022comparing","first-page":"188","article-title":"Comparing key rank estimation methods","author":"Rebecca Young","year":"2022"},{"key":"ref11:david2022rank","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1007\/s13389-021-00269-4","article-title":"Rank estimation with bounded error via exponential\n  sampling","volume":"12","author":"Liron David","year":"2022","journal-title":"Journal of Cryptographic Engineering"},{"key":"ref12:TCHES:ZhaDinFei20","doi-asserted-by":"publisher","first-page":"26","DOI":"10.13154\/tches.v2020.i2.26-48","article-title":"A Fast and Accurate Guessing Entropy Estimation Algorithm\n  for Full-key Recovery","volume":"2020","author":"Ziyue Zhang","year":"2020","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems","ISSN":"https:\/\/id.crossref.org\/issn\/2569-2925","issn-type":"electronic"},{"key":"ref13:camurati2023mcrank","doi-asserted-by":"publisher","first-page":"277","DOI":"10.3929\/ethz-b-000585426","article-title":"MCRank: Monte Carlo Key Rank Estimation for Side-Channel\n  Security Evaluations","volume":"2023","author":"Giovanni Camurati","year":"2023","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref14:hay2024key","doi-asserted-by":"publisher","DOI":"10.62056\/aytxl86bm","article-title":"Key Rank Estimation Methods: Comparisons and Practical\n  Considerations","volume":"1","author":"Rebecca Hay","year":"2024","journal-title":"IACR Communications in Cryptology"},{"key":"ref15:ruadulescu2022ge","doi-asserted-by":"publisher","first-page":"886","DOI":"10.46586\/tches.v2022.i4.886-905","article-title":"GE vs GM: Efficient side-channel security evaluations on\n  full cryptographic keys","author":"Anca R\u0103dulescu","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref16:AC:MMOS16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"548","DOI":"10.1007\/978-3-662-53887-6_20","article-title":"Characterisation and Estimation of the Key Rank Distribution\n  in the Context of Side Channel Evaluations","volume":"10031","author":"Daniel P. Martin","year":"2016"},{"key":"ref17:mezard2009information","doi-asserted-by":"publisher","DOI":"10.1093\/acprof:oso\/9780198570837.001.0001.","volume-title":"Information, physics, and computation","author":"Marc Mezard","year":"2009"},{"key":"ref18:salkin1975knapsack","doi-asserted-by":"publisher","first-page":"127","DOI":"10.1002\/nav.3800220110","article-title":"The knapsack problem: a survey","volume":"22","author":"Harvey M Salkin","year":"1975","journal-title":"Naval Research Logistics Quarterly"},{"key":"ref19:kellerer2004multidimensional","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24777-7_9","volume-title":"Multidimensional knapsack problems","author":"Hans Kellerer","year":"2004"},{"key":"ref20:flajolet2009analytic","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511801655","volume-title":"Analytic Combinatorics","author":"Philippe Flajolet","year":"2009"},{"key":"ref21:olver1974asymptotics","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611973648","volume-title":"Introduction to Asymptotics and Special Functions","author":"Frank Olver","year":"1974"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T18:28:34Z","timestamp":1785954514000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/3\/2\/26"}},"issued":{"date-parts":[[2026,8,3]]},"references-count":21,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2026,8,3]]}},"URL":"https:\/\/doi.org\/10.62056\/akmpgy10k","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2026,8,3]]},"assertion":[{"value":"2026-04-27","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-06-30","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc3-2-33"},{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T14:33:51Z","timestamp":1786113231073,"version":"build-2736575974"},"reference-count":28,"publisher":"International Association for Cryptologic Research","issue":"2","license":[{"start":{"date-parts":[[2026,5,2]],"date-time":"2026-05-02T00:00:00Z","timestamp":1777680000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>\n                    In a TLS session, the user is granted access solely to the encryption and decryption oracles,\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>\u2130<\/mml:mi>\n                        <mml:mo stretchy=\"false\">(<\/mml:mo>\n                        <mml:mi>K<\/mml:mi>\n                        <mml:mo>,<\/mml:mo>\n                        <mml:mi>\u00b7<\/mml:mi>\n                        <mml:mo stretchy=\"false\">)<\/mml:mo>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    and\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>\ud835\udc9f<\/mml:mi>\n                        <mml:mo stretchy=\"false\">(<\/mml:mo>\n                        <mml:mi>K<\/mml:mi>\n                        <mml:mo>,<\/mml:mo>\n                        <mml:mi>\u00b7<\/mml:mi>\n                        <mml:mo stretchy=\"false\">)<\/mml:mo>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    , of a symmetric-key encryption scheme, which are treated as black boxes. Here,\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>\u2130<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    denotes the encryption algorithm,\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>\ud835\udc9f<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    the decryption algorithm, and\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mi>K<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    the secret key. In this paper, by utilizing any secure symmetric-key encryption scheme as a black-box primitive, we demonstrate a method for constructing a symmetric-key encryption scheme that remains secure even in the presence of partial key leakage. This approach can, for example, enhance the security of TLS sessions.\n                  <\/jats:p>\n                  <jats:p>Our construction employs the All-Or-Nothing Transform (AONT) in the pre-processing phase. Therefore we  provide a tighter security analysis of existing AONT constructions, and establish a lower bound on their security. Finally we propose a new AONT construction that achieves security beyond this lower bound.<\/jats:p>","DOI":"10.62056\/andk5w4e-","type":"journal-article","created":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T19:02:55Z","timestamp":1785783775000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Black-Box Construction of Partial Key Exposure Resilient Symmetric-Key Encryption Scheme"],"prefix":"10.62056","volume":"3","author":[{"given":"Reo","family":"Eriguchi","sequence":"first","affiliation":[{"name":"National Institute of Advanced Industrial Science and Technology","place":["Tokyo, Japan"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tetsu","family":"Iwata","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/04chrp450","id-type":"ROR","asserted-by":"publisher"}],"name":"Nagoya University","place":["Furo-cho, Chikusa-ku, Nagoya, 464-8603, Japan"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Goichiro","family":"Hanaoka","sequence":"additional","affiliation":[{"name":"National Institute of Advanced Industrial Science and Technology","place":["Tokyo, Japan"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kaoru","family":"Kurosawa","sequence":"additional","affiliation":[{"name":"ZenmuTech Inc","place":["Tokyo, Japan"]},{"name":"National Institute of Advanced Industrial Science and Technology","place":["Tokyo, Japan"]},{"name":"Research and Development Initiative, Chuo University","place":["Tokyo, Japan"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tomoyuki","family":"Ogawa","sequence":"additional","affiliation":[{"name":"ZenmuTech Inc","place":["Tokyo, Japan"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"SeongHan","family":"Shin","sequence":"additional","affiliation":[{"name":"National Institute of Advanced Industrial Science and Technology","place":["Tokyo, Japan"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2026,8,3]]},"reference":[{"key":"ref1:AB","doi-asserted-by":"publisher","first-page":"546","DOI":"10.1007\/3-540-44448-3_42","article-title":"Increasing the Lifetime of a Key: A Comparative Analysis of\n  the Security of Re-keying Techniques","author":"Michel Abdalla","year":"2000"},{"key":"ref2:ABF","doi-asserted-by":"publisher","first-page":"471","DOI":"10.1007\/978-3-642-40349-1_27","article-title":"Leakage-Resilient Symmetric Encryption via Re-keying","author":"Michel Abdalla","year":"2013"},{"key":"ref3:Canetti","doi-asserted-by":"publisher","first-page":"453","DOI":"10.1007\/978-3-642-19574-7_17","article-title":"Exposure-Resilient Functions and All-or-Nothing\n  Transforms","author":"Ran Canetti","year":"2000"},{"key":"ref4:Rivest","doi-asserted-by":"publisher","first-page":"210","DOI":"10.1007\/3-540-68697-5_7","article-title":"All-or-Nothing Encryption and the Package Transform","author":"Ronald L. Rivest","year":"1997"},{"key":"ref5:TLS","doi-asserted-by":"crossref","DOI":"10.17487\/RFC8446","volume-title":"The Transport Layer Security (TLS) Protocol Version 1.3","author":"Eric Rescorla","year":"2018"},{"key":"ref6:HLW+","doi-asserted-by":"publisher","first-page":"514","DOI":"10.1007\/978-3-642-20465-4_15","article-title":"Leakage-Resilient Cryptography from Minimal Assumptions","volume":"29","author":"Carmit Hazay","year":"2016","journal-title":"Journal of Cryptology"},{"key":"ref7:FPS","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1145\/2810103.2813617","article-title":"Practical Leakage-Resilient Symmetric Cryptography","author":"Sebastian Faust","year":"2012"},{"key":"ref8:SPY","doi-asserted-by":"publisher","first-page":"335","DOI":"10.1007\/978-3-642-55220-5_20","article-title":"Leakage-Resilient Symmetric Cryptography under Empirically\n  Verifiable Assumptions","author":"Fran\u00e7ois-Xavier Standaert","year":"2013"},{"key":"ref9:Desai","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/3-540-44598-6_23","article-title":"The Security of All-or-Nothing Encryption: Protecting\n  against Exhaustive Key Search","author":"Anand Desai","year":"2000"},{"key":"ref10:Shin","doi-asserted-by":"publisher","first-page":"1121","DOI":"10.1587\/transfun.2021EAP1082","article-title":"How to Extend CTRT for AES-256 and AES-192","volume":"105-A","author":"SeongHan Shin","year":"2022","journal-title":"IEICE Transactions on Fundamentals of Electronics,\n  Communications and Computer Sciences"},{"key":"ref11:Kocher","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","article-title":"Timing Attacks on Implementations of Diffie-Hellman,\n  RSA, DSS, and Other Systems","author":"Paul C. Kocher","year":"1996"},{"key":"ref12:KJJ","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","article-title":"Differential Power Analysis","author":"Paul C. Kocher","year":"1999"},{"key":"ref13:QS","doi-asserted-by":"publisher","first-page":"200","DOI":"10.1007\/3-540-48059-5_10","article-title":"ElectroMagnetic Analysis (EMA): Measures and\n  Counter-Measures for Smart Cards","author":"Jean-Jacques Quisquater","year":"2001"},{"key":"ref14:AAR+","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1007\/3-540-36400-5_4","article-title":"The EM Side-Channel(s)","author":"Dakshi Agrawal","year":"2002"},{"key":"ref15:BB","doi-asserted-by":"publisher","first-page":"701","DOI":"10.1016\/j.comnet.2005.01.010","article-title":"Remote Timing Attacks are Practical","volume":"48","author":"David Brumley","year":"2005","journal-title":"Computer Networks"},{"key":"ref16:AP","doi-asserted-by":"publisher","first-page":"526","DOI":"10.1109\/SP.2013.42","article-title":"Lucky Thirteen: Breaking the TLS and DTLS Record\n  Protocols","author":"Nadhem J. AlFardan","year":"2013"},{"key":"ref17:MR","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1007\/978-3-540-24638-1_16","article-title":"Physically Observable Cryptography (Extended Abstract)","author":"Silvio Micali","year":"2004"},{"key":"ref18:NS","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1007\/978-3-540-70936-7_2","article-title":"Public-Key Cryptosystems Resilient to Key Leakage","author":"Moni Naor","year":"2009"},{"key":"ref19:AGV","doi-asserted-by":"publisher","first-page":"474","DOI":"10.1007\/978-3-642-00457-5_28","article-title":"Simultaneous Hardcore Bits and Cryptography against Memory\n  Attacks","author":"Adi Akavia","year":"2009"},{"key":"ref20:KR","doi-asserted-by":"publisher","first-page":"727","DOI":"10.1142\/9789812777334","article-title":"A Survey of Leakage-Resilient Cryptography","author":"Yael Tauman Kalai","year":"2019"},{"key":"ref21:OAEP","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1007\/BFb0053428","article-title":"Optimal Asymmetric Encryption","author":"Mihir Bellare","year":"1994"},{"key":"ref22:Hugo","doi-asserted-by":"publisher","first-page":"136","DOI":"10.1007\/978-3-642-29011-4_14","article-title":"Secret Sharing Made Short","author":"Hugo Krawczyk","year":"1993"},{"key":"ref23:Boyko","doi-asserted-by":"publisher","first-page":"503","DOI":"10.1007\/3-540-48405-1_32","article-title":"On the Security Properties of OAEP as an All-or-Nothing\n  Transform","author":"Victor Boyko","year":"1999"},{"key":"ref24:Bellare","doi-asserted-by":"publisher","first-page":"394","DOI":"10.1109\/SFCS.1997.646128","article-title":"A Concrete Security Treatment of Symmetric Encryption","author":"Mihir Bellare","year":"1997"},{"key":"ref25:Iwata","doi-asserted-by":"publisher","first-page":"310","DOI":"10.1007\/978-3-642-20465-4_18","article-title":"New Blockcipher Modes of Operation with Beyond the Birthday\n  Bound Security","author":"Tetsu Iwata","year":"2006"},{"key":"ref26:BN","doi-asserted-by":"publisher","first-page":"314","DOI":"10.46586\/tosc.v2018.i1.314-335","article-title":"Revisiting Variable Output Length XOR Pseudorandom\n  Function","author":"Srimanta Bhattacharya","year":"2018","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"ref27:Shoup","volume-title":"Sequences of Games: A Tool for Taming Complexity in Security\n  Proofs","author":"Victor Shoup","year":"2006"},{"key":"ref28:gb","volume-title":"Lecture Notes on Cryptography","author":"Shafi Goldwasser","year":"2008"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T18:28:47Z","timestamp":1785954527000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/3\/2\/31"}},"issued":{"date-parts":[[2026,8,3]]},"references-count":28,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2026,8,3]]}},"URL":"https:\/\/doi.org\/10.62056\/andk5w4e-","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2026,8,3]]},"assertion":[{"value":"2026-05-02","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-06-30","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc3-2-61"},{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T08:11:40Z","timestamp":1785831100280,"version":"3.56.0"},"reference-count":56,"publisher":"International Association for Cryptologic Research","issue":"4","license":[{"start":{"date-parts":[[2025,7,8]],"date-time":"2025-07-08T00:00:00Z","timestamp":1751932800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100011033","name":"Agencia Estatal de Investigaci\u00f3n","doi-asserted-by":"publisher","award":["CEX2021-001195-M, PID2021-128521OB-I00"],"award-info":[{"award-number":["CEX2021-001195-M, PID2021-128521OB-I00"]}],"id":[{"id":"10.13039\/501100011033","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004837","name":"Ministerio de Ciencia, Innovaci\u00f3n y Universidades","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004837","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013410","name":"Instituto Nacional de Ciberseguridad","doi-asserted-by":"publisher","award":["C057\/23"],"award-info":[{"award-number":["C057\/23"]}],"id":[{"id":"10.13039\/501100013410","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,12,1]]},"abstract":"<jats:p>Abstract removed due to JATS problems<\/jats:p>","DOI":"10.62056\/ayc3tx4e-","type":"journal-article","created":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T23:39:47Z","timestamp":1767915587000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":1,"title":["FLIP-and-Prove R1CS"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9149-2036","authenticated-orcid":false,"given":"Anca","family":"Nitulescu","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/04abwvq32","id-type":"ROR","asserted-by":"publisher"}],"name":"Input Output (Singapore)","place":["France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-4628-3038","authenticated-orcid":false,"given":"Nikitas","family":"Paslis","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/04n0g0b29","id-type":"ROR","asserted-by":"publisher"}],"name":"Universitat Pompeu Fabra","place":["Spain"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7035-9049","authenticated-orcid":false,"given":"Carla","family":"R\u00e0fols","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/04n0g0b29","id-type":"ROR","asserted-by":"publisher"}],"name":"Universitat Pompeu Fabra","place":["Spain"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2026,1,8]]},"reference":[{"key":"ref1:TCC:BCIOP13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1007\/978-3-642-36594-2_18","article-title":"Succinct Non-interactive Arguments via Linear Interactive\n  Proofs","volume":"7785","author":"Nir Bitansky","year":"2013"},{"key":"ref2:EC:GGPR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"626","DOI":"10.1007\/978-3-642-38348-9_37","article-title":"Quadratic Span Programs and Succinct NIZKs without\n  PCPs","volume":"7881","author":"Rosario Gennaro","year":"2013"},{"key":"ref3:SP:PHGR13","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1109\/SP.2013.47","article-title":"Pinocchio: Nearly Practical Verifiable Computation","author":"Bryan Parno","year":"2013"},{"key":"ref4:AC:Lipmaa13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/978-3-642-42033-7_3","article-title":"Succinct Non-Interactive Zero Knowledge Arguments from Span\n  Programs and Linear Error-Correcting Codes","volume":"8269","author":"Helger Lipmaa","year":"2013"},{"key":"ref5:USENIX:BCTV14","first-page":"781","article-title":"Succinct Non-Interactive Zero Knowledge for a von Neumann\n  Architecture","author":"Eli Ben-Sasson","year":"2014"},{"key":"ref6:EC:Groth16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"305","DOI":"10.1007\/978-3-662-49896-5_11","article-title":"On the Size of Pairing-Based Non-interactive Arguments","volume":"9666","author":"Jens Groth","year":"2016"},{"key":"ref7:ep:zcash-spec","volume-title":"Zcash Protocol Specification","author":"Daira Hopwood","year":"2021"},{"key":"ref8:ep:Mina","volume-title":"Mina Cryptocurrency","author":"Mina","year":"2020"},{"key":"ref9:ep:filecoin","volume-title":"Filecoin","author":"Protocol Labs","year":"2018"},{"key":"ref10:CiC:BonBunFis24","doi-asserted-by":"publisher","first-page":"7","DOI":"10.62056\/av7tudhdj","article-title":"A Survey of Two Verifiable Delay Functions Using Proof of\n  Exponentiation","volume":"1","author":"Dan Boneh","year":"2024","journal-title":"IACR Communications in Cryptology (CiC)"},{"key":"ref11:EC:Wesolowski19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"379","DOI":"10.1007\/978-3-030-17659-4_13","article-title":"Efficient Verifiable Delay Functions","volume":"11478","author":"Benjamin Wesolowski","year":"2019"},{"key":"ref12:ep:Celo","volume-title":"Celo Platform","author":"Celo","year":"2020"},{"key":"ref13:USENIX:OWWB20","first-page":"2075","article-title":"Scaling Verifiable Computation Using Efficient Set\n  Accumulators","author":"Alex Ozdemir","year":"2020"},{"key":"ref14:SAGL","isbn-type":"print","first-page":"339","article-title":"Proving the correct execution of concurrent services in\n  zero-knowledge","author":"Srinath Setty","year":"2018","ISBN":"https:\/\/id.crossref.org\/isbn\/9781939133083"},{"key":"ref15:ep:EVM","volume-title":"Ethereum Virtual Machine","author":"Ethereum","year":"2024"},{"key":"ref16:ep:RiscV","volume-title":"RISC-V","author":"Berkeley University of California","year":"2010"},{"key":"ref17:FC:GaiMalNit22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-3-031-18283-9_10","article-title":"SnarkPack: Practical SNARK Aggregation","volume":"13411","author":"Nicolas Gailly","year":"2022"},{"key":"ref18:AC:BMMTV21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/978-3-030-92078-4_3","article-title":"Proofs for Inner Pairing Products and Applications","volume":"13092","author":"Benedikt B\u00fcnz","year":"2021"},{"key":"ref19:EPRINT:GPPS24","volume-title":"GAPP: Generic Aggregation of Polynomial Protocols","author":"Chaya Ganesh","year":"2024"},{"key":"ref20:C:Thaler13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/978-3-642-40084-1_5","article-title":"Time-Optimal Interactive Proofs for Circuit Evaluation","volume":"8043","author":"Justin Thaler","year":"2013"},{"key":"ref21:CCS:WJBsTW17","doi-asserted-by":"publisher","first-page":"2071","DOI":"10.1145\/3133956.3133984","article-title":"Full Accounting for Verifiable Outsourcing","author":"Riad S. Wahby","year":"2017"},{"key":"ref22:SP:WTSTW18","doi-asserted-by":"publisher","first-page":"926","DOI":"10.1109\/SP.2018.00060","article-title":"Doubly-Efficient zkSNARKs Without Trusted Setup","author":"Riad S. Wahby","year":"2018"},{"key":"ref23:NDSS:TKPS22","article-title":"Transparency Dictionaries with Succinct Proofs of Correct\n  Operation","author":"Ioanna Tzialla","year":"2022"},{"key":"ref24:CCS:ZLWZSX21","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1145\/3460120.3484767","article-title":"Doubly Efficient Interactive Proofs for General Arithmetic\n  Circuits with Linear Prover Time","author":"Jiaheng Zhang","year":"2021"},{"key":"ref25:STOC:GolKalRot08","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1145\/1374376.1374396","article-title":"Delegating computation: interactive proofs for muggles","author":"Shafi Goldwasser","year":"2008"},{"key":"ref26:TCC:Valiant08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-78524-8_1","article-title":"Incrementally Verifiable Computation or Proofs of Knowledge\n  Imply Time\/Space Efficiency","volume":"4948","author":"Paul Valiant","year":"2008"},{"key":"ref27:EPRINT:BowGriHop19","volume-title":"Halo: Recursive Proof Composition without a Trusted Setup","author":"Sean Bowe","year":"2019"},{"key":"ref28:TCC:BCMS20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-030-64378-2_1","article-title":"Recursive Proof Composition from Accumulation Schemes","volume":"12551","author":"Benedikt B\u00fcnz","year":"2020"},{"key":"ref29:C:KotSetTzi22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-031-15985-5_13","article-title":"Nova: Recursive Zero-Knowledge Arguments from Folding\n  Schemes","volume":"13510","author":"Abhiram Kothapalli","year":"2022"},{"key":"ref30:C:KotSet24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1007\/978-3-031-68403-6_11","article-title":"HyperNova: Recursive Arguments for Customizable Constraint\n  Systems","volume":"14929","author":"Abhiram Kothapalli","year":"2024"},{"key":"ref31:AC:BunChe23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/978-981-99-8724-5_3","article-title":"Protostar: Generic Efficient Accumulation\/Folding for\n  Special-Sound Protocols","volume":"14439","author":"Benedikt B\u00fcnz","year":"2023"},{"key":"ref32:LC:RafZac23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1007\/978-3-031-44469-2_12","article-title":"Folding Schemes with Selective Verification","volume":"14168","author":"Carla R\u00e0fols","year":"2023"},{"key":"ref33:C:BonChe25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"327","DOI":"10.1007\/978-3-032-01907-3_11","article-title":"LatticeFold+: Faster, Simpler, Shorter Lattice-Based\n  Folding for Succinct Proof Systems","volume":"16006","author":"Dan Boneh","year":"2025"},{"key":"ref34:C:AFGHO10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1007\/978-3-642-14623-7_12","article-title":"Structure-Preserving Signatures and Commitments to Group\n  Elements","volume":"6223","author":"Masayuki Abe","year":"2010"},{"key":"ref35:C:Setty20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"704","DOI":"10.1007\/978-3-030-56877-1_25","article-title":"Spartan: Efficient and General-Purpose zkSNARKs Without\n  Trusted Setup","volume":"12172","author":"Srinath Setty","year":"2020"},{"key":"ref36:CCS:CamFioQue19","doi-asserted-by":"publisher","first-page":"2075","DOI":"10.1145\/3319535.3339820","article-title":"LegoSNARK: Modular Design and Composition of Succinct\n  Zero-Knowledge Proofs","author":"Matteo Campanelli","year":"2019"},{"key":"ref37:EC:CHMMVW20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"738","DOI":"10.1007\/978-3-030-45721-1_26","article-title":"Marlin: Preprocessing zkSNARKs with Universal and\n  Updatable SRS","volume":"12105","author":"Alessandro Chiesa","year":"2020"},{"key":"ref38:CCS:LaiMalRon19","doi-asserted-by":"publisher","first-page":"2057","DOI":"10.1145\/3319535.3354262","article-title":"Succinct Arguments for Bilinear Group Arithmetic: Practical\n  Structure-Preserving Cryptography","author":"Russell W. F. Lai","year":"2019"},{"key":"ref39:EPRINT:BowGabMie17","volume-title":"Scalable Multi-party Computation for zk-SNARK Parameters\n  in the Random Beacon Model","author":"Sean Bowe","year":"2017"},{"key":"ref40:impl:arkworks","volume-title":"Arkworks for zkSNARK programming","author":"arkwork","year":"2019"},{"key":"ref41:EPRINT:LGZX23","volume-title":"SnarkFold: Efficient SNARK Proof Aggregation from Split\n  Incrementally Verifiable Computation","author":"Xun Liu","year":"2023"},{"key":"ref42:EPRINT:BeaFis24","volume-title":"Mira: Efficient Folding for Pairing-based Arguments","author":"Josh Beal","year":"2024"},{"key":"ref43:EPRINT:NguBonSet23","volume-title":"Revisiting the Nova Proof System on a Cycle of Curves","author":"Wilson Nguyen","year":"2023"},{"key":"ref44:EPRINT:GabWilCio19","volume-title":"PLONK: Permutations over Lagrange-bases for Oecumenical\n  Noninteractive arguments of Knowledge","author":"Ariel Gabizon","year":"2019"},{"key":"ref45:EC:Fisch19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"324","DOI":"10.1007\/978-3-030-17656-3_12","article-title":"Tight Proofs of Space and Replication","volume":"11477","author":"Ben Fisch","year":"2019"},{"key":"ref46:C:KotPar23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"669","DOI":"10.1007\/978-3-031-38551-3_21","article-title":"Algebraic Reductions of Knowledge","volume":"14084","author":"Abhiram Kothapalli","year":"2023"},{"key":"ref47:SP:BBBPWM18","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1109\/SP.2018.00020","article-title":"Bulletproofs: Short Proofs for Confidential Transactions and\n  More","author":"Benedikt B\u00fcnz","year":"2018"},{"key":"ref48:EC:BCCGP16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"327","DOI":"10.1007\/978-3-662-49896-5_12","article-title":"Efficient Zero-Knowledge Arguments for Arithmetic Circuits\n  in the Discrete Log Setting","volume":"9666","author":"Jonathan Bootle","year":"2016"},{"key":"ref49:TCC:Lee21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-030-90453-1_1","article-title":"Dory: Efficient, Transparent Arguments for Generalised Inner\n  Products and Polynomial Commitments","volume":"13043","author":"Jonathan Lee","year":"2021"},{"key":"ref50:IWSEC:ABST23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/978-3-031-41326-1_11","article-title":"aPlonK: Aggregated PlonK from Multi-polynomial\n  Commitment Schemes","volume":"14128","author":"Miguel Ambrona","year":"2023"},{"key":"ref51:C:FucKilLos18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-319-96881-0_2","article-title":"The Algebraic Group Model and its Applications","volume":"10992","author":"Georg Fuchsbauer","year":"2018"},{"key":"ref52:C:Lipmaa24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"170","DOI":"10.1007\/978-3-031-68403-6_6","article-title":"Polymath: Groth16 Is Not the Limit","volume":"14929","author":"Helger Lipmaa","year":"2024"},{"key":"ref53:EPRINT:Guillevic24","volume-title":"More Embedded Curves for SNARK-Pairing-Friendly Curves","author":"Aurore Guillevic","year":"2024"},{"key":"ref54:Sanso2024Families","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/s00145-024-09514-5","article-title":"Families of Prime-Order Endomorphism-Equipped Embedded\n  Curves on Pairing-Friendly Curves","volume":"37","author":"Antonio Sanso","year":"2024","journal-title":"Journal of Cryptology"},{"key":"ref55:TCC:LipParSii23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"363","DOI":"10.1007\/978-3-031-48624-1_14","article-title":"Algebraic Group Model with Oblivious Sampling","volume":"14372","author":"Helger Lipmaa","year":"2023"},{"key":"ref56:AC:MorRafVil16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"729","DOI":"10.1007\/978-3-662-53887-6_27","article-title":"The Kernel Matrix Diffie-Hellman Assumption","volume":"10031","author":"Paz Morillo","year":"2016"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T23:41:12Z","timestamp":1767915672000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/4\/6"}},"issued":{"date-parts":[[2026,1,8]]},"references-count":56,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2026,1,8]]}},"URL":"https:\/\/doi.org\/10.62056\/ayc3tx4e-","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2026,1,8]]},"assertion":[{"value":"2025-07-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-3-86"},{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T14:14:01Z","timestamp":1785420841562,"version":"3.56.0"},"reference-count":54,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,7,9]],"date-time":"2024-07-09T00:00:00Z","timestamp":1720483200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,9,2]]},"abstract":"<jats:p>Masking schemes are key in thwarting side-channel attacks due to their robust theoretical foundation. Transitioning from Boolean to arithmetic (B2A) masking is a necessary step in various cryptography schemes, including hash functions, ARX-based ciphers, and lattice-based cryptography. While there exists a significant body of research focusing on B2A software implementations, studies pertaining to hardware implementations are quite limited, with the majority dedicated solely to creating efficient Boolean masked adders. In this paper, we present first- and second-order secure hardware implementations to perform B2A mask conversion efficiently without using masked adder structures. We first introduce a first-order secure low-latency gadget that executes a B2A2k in a single cycle. Furthermore, we propose a second-order secure B2A2k gadget that has a latency of only 4 clock cycles. Both gadgets are independent of the input word size k. We then show how these new primitives lead to improved B2Aq hardware implementations that perform a B2A mask conversion of integers modulo an arbitrary number. Our results show that our new gadgets outperform comparable solutions by more than a magnitude in terms of resource requirements and are at least 3 times faster in terms of latency and throughput. All gadgets have been formally verified and proven secure in the glitch-robust PINI security model. We additionally confirm the security of our gadgets on an FPGA platform using practical TVLA tests.<\/jats:p>","DOI":"10.62056\/a3c0l2isfg","type":"journal-article","created":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T11:13:33Z","timestamp":1728299613000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":1,"title":["Efficient Boolean-to-Arithmetic Mask Conversion in Hardware"],"prefix":"10.62056","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9549-268X","authenticated-orcid":false,"given":"Aein","family":"Shahmirzadi","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/03sdv7269","id-type":"ROR","asserted-by":"publisher"}],"name":"PQShield","place":["Prama House, 267 Banbury Rd, Summertown, Oxford, OX2 7HT, UK"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9769-7649","authenticated-orcid":false,"given":"Michael","family":"Hutter","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/03sdv7269","id-type":"ROR","asserted-by":"publisher"}],"name":"PQShield","place":["Prama House, 267 Banbury Rd, Summertown, Oxford, OX2 7HT, UK"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2024,10,7]]},"reference":[{"key":"ref1:Koc96","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","article-title":"Timing Attacks on Implementations of Diffie-Hellman,\n  RSA, DSS, and Other Systems","volume":"1109","author":"Paul Kocher","year":"1996"},{"key":"ref2:KJJ99","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","article-title":"Differential Power Analysis","volume":"1666","author":"Paul Kocher","year":"1999"},{"key":"ref3:Aumasson2010SHA3Blake","volume-title":"SHA-3 Proposal BLAKE","author":"Jean-Philippe Aumasson","year":"2010"},{"key":"ref4:Ferguson2010TheSkeinHash","volume-title":"The Skein Hash Function Family","author":"Niels Ferguson","year":"2010"},{"key":"ref5:needham1997tea","volume-title":"TEA Extensions","author":"Roger M. Needham","year":"1997"},{"key":"ref6:Bernstein2008ChaCha","first-page":"3","article-title":"ChaCha, a Variant of Salsa20","author":"Daniel J. Bernstein","year":"2008"},{"key":"ref7:Goubin2001SoundMethodSwitching","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/3-540-44709-1_2","article-title":"A Sound Method for Switching between Boolean and Arithmetic\n  Masking","volume":"2162","author":"Louis Goubin","year":"2001"},{"key":"ref8:Coron2015ConversionFromArithmetic","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1007\/978-3-662-48116-5_7","article-title":"Conversion from Arithmetic to Boolean Masking with\n  Logarithmic Complexity","volume":"8731","author":"Jean-S\u00e9bastien Coron","year":"2015"},{"key":"ref9:Biryukov2017OptimalFirstOrder","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1007\/978-3-319-75208-2_2","article-title":"Optimal First-Order Boolean Masking for Embedded IoT\n  Devices","volume":"10728","author":"Alex Biryukov","year":"2017"},{"key":"ref10:Won2017EfficientConversionMethod","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1007\/978-3-319-64647-3_8","article-title":"Efficient Conversion Method from Arithmetic to Boolean\n  Masking in Constrained Devices","volume":"10348","author":"Yoo-Seung Won","year":"2017"},{"key":"ref11:Komano2019IntegrativeAccelerationOf","doi-asserted-by":"publisher","first-page":"585","DOI":"10.2197\/IPSJJIP.27.585","article-title":"Integrative Acceleration of First-order Boolean Masking for\n  Embedded IoT Devices","volume":"27","author":"Yuichi Komano","year":"2019","journal-title":"Journal of Information Processing"},{"key":"ref12:Barthe2018MaskingTheGLP","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"354","DOI":"10.1007\/978-3-319-78375-8_12","article-title":"Masking the GLP Lattice-Based Signature Scheme at Any\n  Order","volume":"10821","author":"Gilles Barthe","year":"2018"},{"key":"ref13:Schneider2019EfficientlyMaskingBinomial","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"534","DOI":"10.1007\/978-3-030-17259-6_18","article-title":"Efficiently Masking Binomial Sampling at Arbitrary Orders\n  for Lattice-Based Crypto","volume":"11443","author":"Tobias Schneider","year":"2019"},{"key":"ref14:Bache2020HighSpeedMasking","doi-asserted-by":"publisher","first-page":"483","DOI":"10.13154\/TCHES.V2020.I3.483-507","article-title":"High-Speed Masking for Polynomial Comparison in\n  Lattice-based KEMs","volume":"2020","author":"Florian Bache","year":"2020","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref15:Bhasin2021AttackingAndDefending","doi-asserted-by":"publisher","first-page":"334","DOI":"10.46586\/TCHES.V2021.I3.334-359","article-title":"Attacking and Defending Masked Polynomial Comparison for\n  Lattice-Based Cryptography","volume":"2021","author":"Shivam Bhasin","year":"2021","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref16:Bronchain2022BitslicingArithmeticBoolean","doi-asserted-by":"publisher","first-page":"553","DOI":"10.46586\/TCHES.V2022.I4.553-588","article-title":"Bitslicing Arithmetic\/Boolean Masking Conversions for Fun\n  and Profit with Application to Lattice-Based KEMs","volume":"2022","author":"Olivier Bronchain","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref17:Coron2023HigherOrderPolynomial","doi-asserted-by":"publisher","first-page":"153","DOI":"10.46586\/TCHES.V2023.I1.153-192","article-title":"High-order Polynomial Comparison and Masking Lattice-based\n  Encryption","volume":"2023","author":"Jean-S\u00e9bastien Coron","year":"2023","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref18:Hutter2016ConstantTimeHigher","volume-title":"Constant Time Higher-Order Boolean-to-Arithmetic Masking","author":"Michael Hutter","year":"2016"},{"key":"ref19:Hutter2016ConstantTimeHigher_JOCE","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/S13389-018-0191-Z","article-title":"Constant-Time Higher-Order Boolean-to-Arithmetic Masking","volume":"9","author":"Michael Hutter","year":"2019","journal-title":"Journal of Cryptographic Engineering"},{"key":"ref20:Coron2017HigherOrderConversion","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1007\/978-3-319-66787-4_5","article-title":"Higher-Order Conversion from Boolean to Arithmetic\n  Masking","volume":"10529","author":"Jean-S\u00e9bastien Coron","year":"2017"},{"key":"ref21:Bettale2018ImprovedHigherOrder","doi-asserted-by":"publisher","first-page":"22","DOI":"10.13154\/TCHES.V2018.I2.22-45","article-title":"Improved High-Order Conversion From Boolean to Arithmetic\n  Masking","volume":"2018","author":"Luk Bettale","year":"2018","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref22:Coron2023ImprovedGadgetsFor","doi-asserted-by":"publisher","first-page":"110","DOI":"10.46586\/TCHES.V2023.I4.110-145","article-title":"Improved Gadgets for the High-Order Masking of Dilithium","volume":"2023","author":"Jean-S\u00e9bastien Coron","year":"2023","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref23:Schneider2015ArithmeticAdditionOver","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1007\/978-3-319-28166-7_27","article-title":"Arithmetic Addition Over Boolean Masking\u2014Towards First-\n  and Second-Order Resistance in Hardware","volume":"9092","author":"Tobias Schneider","year":"2015"},{"key":"ref24:Gross2016ConcealingSecretsIn","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1007\/978-3-319-54669-8_6","article-title":"Concealing Secrets in Embedded Processors Designs","volume":"10146","author":"Hannes Gro\u00df","year":"2016"},{"key":"ref25:Beirendonck2021ASideChannel","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3429983","article-title":"A Side-Channel-Resistant Implementation of SABER","volume":"17","author":"Michiel Van Beirendonck","year":"2021","journal-title":"ACM Journal on Emerging Technologies in Computing Systems\n  (JETC)"},{"key":"ref26:Fritzmann2022MaskedAcceleratorsAnd","doi-asserted-by":"publisher","first-page":"414","DOI":"10.46586\/TCHES.V2022.I1.414-460","article-title":"Masked Accelerators and Instruction Set Extensions for\n  Post-Quantum Cryptography","volume":"2022","author":"Tim Fritzmann","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref27:Bache2022BooleanMaskingFor","doi-asserted-by":"publisher","DOI":"10.3390\/app12052274","article-title":"Boolean Masking for Arithmetic Additions at Arbitrary Order\n  in Hardware","volume":"12","author":"Florian Bache","year":"2022","journal-title":"Applied Sciences"},{"key":"ref28:Cassiers2023CompressReducingArea","volume-title":"Compress: Reducing Area and Latency of Masked Pipelined\n  Circuits","author":"Ga\u00ebtan Cassiers","year":"2023"},{"key":"ref29:Norga2024MaskConversionFor","volume-title":"Mask Conversions for d+1 Shares in Hardware, with\n  Application to Lattice-based PQC","author":"Quinten Norga","year":"2024"},{"key":"ref30:Cassier2022ComposableAndEfficient","volume-title":"Composable and Efficient Masking Schemes for Side-channel\n  Secure Implementations","author":"Ga\u00ebtan Cassiers","year":"2022"},{"key":"ref31:DBLP:conf\/ches\/GoubinP99","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/3-540-48059-5_15","article-title":"DES and Differential Power Analysis","volume":"1717","author":"Louis Goubin","year":"1999"},{"key":"ref32:DBLP:conf\/ches\/CoronG00","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1007\/3-540-44499-8_18","article-title":"On Boolean and Arithmetic Masking against Differential\n  Power Analysis","volume":"1965","author":"Jean-S\u00e9bastien Coron","year":"2000"},{"key":"ref33:DBLP:conf\/asiacrypt\/BalaschFGPS17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"724","DOI":"10.1007\/978-3-319-70694-8_25","article-title":"Consolidating Inner Product Masking","volume":"10624","author":"Josep Balasch","year":"2017"},{"key":"ref34:DBLP:conf\/ches\/GolicT02","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1007\/3-540-36400-5_16","article-title":"Multiplicative Masking and Power Analysis of AES","volume":"2523","author":"Jovan Dj. Golic","year":"2002"},{"key":"ref35:Ishai2003PrivateCircuits","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-3-540-45146-4_27","article-title":"Private Circuits: Securing Hardware against Probing\n  Attacks","volume":"2729","author":"Yuval Ishai","year":"2003"},{"key":"ref36:DBLP:conf\/ches\/MangardPO05","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1007\/11545262_12","article-title":"Successfully Attacking Masked AES Hardware\n  Implementations","volume":"3659","author":"Stefan Mangard","year":"2005"},{"key":"ref37:DBLP:conf\/ches\/MoradiME10","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1007\/978-3-642-15031-9_9","article-title":"Correlation-Enhanced Power Analysis Collision Attack","volume":"6225","author":"Amir Moradi","year":"2010"},{"key":"ref38:DBLP:journals\/tches\/FaustGPPS18","doi-asserted-by":"publisher","first-page":"89","DOI":"10.13154\/TCHES.V2018.I3.89-120","article-title":"Composable Masking Schemes in the Presence of Physical\n  Defaults & the Robust Probing Model","volume":"2018","author":"Sebastian Faust","year":"2018","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref39:DBLP:conf\/crypto\/ReparazBNGV15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"764","DOI":"10.1007\/978-3-662-47989-6_37","article-title":"Consolidating Masking Schemes","volume":"9215","author":"Oscar Reparaz","year":"2015"},{"key":"ref40:silver","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"787","DOI":"10.1007\/978-3-030-64837-4_26","article-title":"SILVER - Statistical Independence and Leakage\n  Verification","volume":"12491","author":"David Knichel","year":"2020"},{"key":"ref41:Nikova2006ThresholdImplementationsAgainst","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"529","DOI":"10.1007\/11935308_38","article-title":"Threshold Implementations Against Side-Channel Attacks and\n  Glitches","volume":"4307","author":"Svetla Nikova","year":"2006"},{"key":"ref42:DBLP:conf\/ccs\/GrossMK16","doi-asserted-by":"publisher","DOI":"10.1145\/2996366.2996426","article-title":"Domain-Oriented Masking: Compact Masked Hardware\n  Implementations with Arbitrary Protection Order","author":"Hannes Gro\u00df","year":"2016"},{"key":"ref43:DBLP:conf\/eurocrypt\/BartheBDFGS15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"457","DOI":"10.1007\/978-3-662-46800-5_18","article-title":"Verified Proofs of Higher-Order Masking","volume":"9056","author":"Gilles Barthe","year":"2015"},{"key":"ref44:DBLP:conf\/ccs\/BartheBDFGSZ16","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1145\/2976749.2978427","article-title":"Strong Non-Interference and Type-Directed Higher-Order\n  Masking","author":"Gilles Barthe","year":"2016"},{"key":"ref45:DBLP:journals\/tifs\/CassiersS20","doi-asserted-by":"publisher","first-page":"2542","DOI":"10.1109\/TIFS.2020.2971153","article-title":"Trivially and Efficiently Composing Masked Gadgets With\n  Probe Isolating Non-Interference","volume":"15","author":"Ga\u00ebtan Cassiers","year":"2020","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"ref46:DBLP:phd\/dnb\/Knichel23","volume-title":"Formal Verification and Automated Masking of Cryptographic\n  Hardware","author":"David Knichel","year":"2023"},{"key":"ref47:DBLP:journals\/tc\/CassiersGLS21","doi-asserted-by":"publisher","first-page":"1677","DOI":"10.1109\/TC.2020.3022979","article-title":"Hardware Private Circuits: From Trivial Composition to Full\n  Verification","volume":"70","author":"Ga\u00ebtan Cassiers","year":"2021","journal-title":"IEEE Transactions on Computers"},{"key":"ref48:DBLP:journals\/tc\/KoggeS73","doi-asserted-by":"publisher","first-page":"786","DOI":"10.1109\/TC.1973.5009159","article-title":"A Parallel Algorithm for the Efficient Solution of a\n  General Class of Recurrence Equations","volume":"22","author":"Peter M. Kogge","year":"1973","journal-title":"IEEE Transactions on Computers"},{"key":"ref49:DBLP:journals\/tches\/MeyerBR19","doi-asserted-by":"publisher","first-page":"119","DOI":"10.13154\/TCHES.V2019.I3.119-147","article-title":"Consolidating Security Notions in Hardware Masking","volume":"2019","author":"Lauren De Meyer","year":"2019","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref50:Knichel2022AutomatedGenerationOf","doi-asserted-by":"publisher","first-page":"589","DOI":"10.46586\/TCHES.V2022.I1.589-629","article-title":"Automated Generation of Masked Hardware","volume":"2022","author":"David Knichel","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems (TCHES)"},{"key":"ref51:Coron2014SecureConversionBetween","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"188","DOI":"10.1007\/978-3-662-44709-3_11","article-title":"Secure Conversion between Boolean and Arithmetic Masking of\n  Any Order","volume":"8731","author":"Jean-S\u00e9bastien Coron","year":"2014"},{"key":"ref52:cw305","volume-title":"CW305 Artix FPGA Target","author":"NewAE"},{"key":"ref53:TVLA","volume-title":"A Testing Methodology for Side-Channel Resistance\n  Validation","author":"Gilbert Goodwill","year":"2011"},{"key":"ref54:DBLP:conf\/ches\/SchneiderM15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"495","DOI":"10.1007\/978-3-662-48324-4_25","article-title":"Leakage Assessment Methodology - A Clear Roadmap for\n  Side-Channel Evaluations","volume":"9293","author":"Tobias Schneider","year":"2015"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T16:28:47Z","timestamp":1733848127000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/3\/46"}},"issued":{"date-parts":[[2024,10,7]]},"references-count":54,"URL":"https:\/\/doi.org\/10.62056\/a3c0l2isfg","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2024,10,7]]},"assertion":[{"value":"2024-07-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-3-122"},{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T16:08:39Z","timestamp":1785427719090,"version":"3.56.0"},"reference-count":31,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T00:00:00Z","timestamp":1704758400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,3,5]]},"abstract":"<jats:p>Biscuit is a recent multivariate signature scheme based on the MPC-in-the-Head   paradigm. It has been submitted to the NIST competition for additional   signature schemes. Signatures are derived from a zero-knowledge proof of   knowledge of the solution of a structured polynomial system. This extra   structure enables efficient proofs and compact signatures. This short note   demonstrates that it also makes these polynomial systems easier to solve than   random ones. As a consequence, the original parameters of Biscuit failed to   meet the required security levels and had to be upgraded.<\/jats:p>","DOI":"10.62056\/aemp-4c2h","type":"journal-article","created":{"date-parts":[[2024,4,9]],"date-time":"2024-04-09T15:27:10Z","timestamp":1712676430000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":2,"title":["Preliminary Cryptanalysis   of the Biscuit Signature Scheme"],"prefix":"10.62056","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9416-6244","authenticated-orcid":false,"given":"Charles","family":"Bouillaguet","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05krcen59","id-type":"ROR","asserted-by":"publisher"}],"name":"Sorbonne Universit\u00e9, CNRS, LIP6","place":["Paris, F-75005, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-0239-1241","authenticated-orcid":false,"given":"Julia","family":"Sauvage","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05krcen59","id-type":"ROR","asserted-by":"publisher"}],"name":"Sorbonne Universit\u00e9, CNRS, LIP6","place":["Paris, F-75005, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2024,4,9]]},"reference":[{"key":"ref1:NISTPQC-ADS-R1:BISCUIT","article-title":"Biscuit","author":"Luk Bettale","year":"2023"},{"key":"ref2:DBLP:conf\/acns\/BettaleKPV24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"457","DOI":"10.1007\/978-3-031-54770-6_18","article-title":"Biscuit: New MPCitH Signature Scheme from Structured\n  Multivariate Polynomials","volume-title":"Applied Cryptography and Network Security - 22nd\n  International Conference, ACNS 2024, Abu Dhabi, United Arab Emirates, March\n  5-8, 2024, Proceedings, Part I","volume":"14583","author":"Luk Bettale","year":"2024"},{"key":"ref3:DBLP:books\/fm\/GareyJ79","isbn-type":"print","article-title":"Computers and Intractability: A Guide to the Theory of\n  NP-Completeness","author":"M. R. Garey","year":"1979","ISBN":"https:\/\/id.crossref.org\/isbn\/0716710447"},{"key":"ref4:DBLP:journals\/cca\/YasudaDHTS15","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1145\/2850449.2850462","article-title":"A multivariate quadratic challenge toward post-quantum\n  generation cryptography","volume":"49","author":"Takanori Yasuda","year":"2015","journal-title":"ACM Commun. Comput. Algebra"},{"key":"ref5:DBLP:conf\/asiacrypt\/ChenHRSS16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"135","DOI":"10.1007\/978-3-662-53890-6_5","article-title":"From 5-Pass MQ-Based Identification to\n  MQ-Based Signatures","volume-title":"Advances in Cryptology - ASIACRYPT 2016 - 22nd\n  International Conference on the Theory and Application of Cryptology and\n  Information Security, Hanoi, Vietnam, December 4-8, 2016, Proceedings, Part\n  II","volume":"10032","author":"Ming-Shing Chen","year":"2016"},{"key":"ref6:NISTPQC-R2:MQDSS19","article-title":"MQDSS","author":"Simona Samardjiska","year":"2019"},{"key":"ref7:DBLP:journals\/iacr\/BenadjilaFR23","article-title":"MQ on my Mind: Post-Quantum Signatures from the\n  Non-Structured Multivariate Quadratic Problem","author":"Ryad Benadjila","year":"2023"},{"key":"ref8:DBLP:conf\/eurocrypt\/Patarin96","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/3-540-68339-9_4","article-title":"Hidden Fields Equations (HFE) and Isomorphisms of\n  Polynomials (IP): Two New Families of Asymmetric Algorithms","volume-title":"Advances in Cryptology - EUROCRYPT '96, International\n  Conference on the Theory and Application of Cryptographic Techniques,\n  Saragossa, Spain, May 12-16, 1996, Proceeding","volume":"1070","author":"Jacques Patarin","year":"1996"},{"key":"ref9:DBLP:conf\/eurocrypt\/KipnisPG99","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1007\/3-540-48910-X_15","article-title":"Unbalanced Oil and Vinegar Signature Schemes","volume-title":"Advances in Cryptology - EUROCRYPT '99, International\n  Conference on the Theory and Application of Cryptographic Techniques, Prague,\n  Czech Republic, May 2-6, 1999, Proceeding","volume":"1592","author":"Aviad Kipnis","year":"1999"},{"key":"ref10:EPRINT:CouGouPat03","article-title":"SFLASHv3, a fast asymmetric signature scheme","author":"Nicolas T. Courtois","year":"2003"},{"key":"ref11:DBLP:conf\/crypto\/FaugereJ03","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1007\/978-3-540-45146-4_3","article-title":"Algebraic Cryptanalysis of Hidden Field Equation (HFE)\n  Cryptosystems Using Gr\u00f6bner Bases","volume-title":"Advances in Cryptology - CRYPTO 2003, 23rd Annual\n  International Cryptology Conference, Santa Barbara, California, USA, August\n  17-21, 2003, Proceedings","volume":"2729","author":"Jean-Charles Faug\u00e8re","year":"2003"},{"key":"ref12:F5","isbn-type":"print","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1145\/780506.780516","article-title":"A New Efficient Algorithm for Computing Gr\u00f6bner Bases\n  Without Reduction to Zero (F5)","volume-title":"ISSAC '02: Proceedings of the 2002 International Symposium\n  on Symbolic and Algebraic Computation","author":"Jean-Charles Faug\u00e8re","year":"2002","ISBN":"https:\/\/id.crossref.org\/isbn\/1581134843"},{"key":"ref13:DBLP:conf\/cans\/KalesZ20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-65411-5_1","article-title":"An Attack on Some Signature Schemes Constructed from\n  Five-Pass Identification Schemes","volume-title":"Cryptology and Network Security - 19th International\n  Conference, CANS 2020, Vienna, Austria, December 14-16, 2020, Proceedings","volume":"12579","author":"Daniel Kales","year":"2020"},{"key":"ref14:CLO97","isbn-type":"print","article-title":"Ideals, Varieties, and Algorithms: An Introduction to\n  Computational Algebraic Geometry and Commutative Algebra, (Undergraduate\n  Texts in Mathematics)","author":"David A. Cox","year":"1991","ISBN":"https:\/\/id.crossref.org\/isbn\/0387356509"},{"key":"ref15:phdbuchberger","article-title":"Ein Algorithmus zum Auffinden der Basiselemente des\n  Restklassenringes nach einem nulldimensionalen Polynomideal (An Algorithm for\n  Finding the Basis Elements in the Residue Class Ring Modulo a Zero\n  Dimensional Polynomial Ideal)","author":"B. Buchberger","year":"1965"},{"key":"ref16:DBLP:phd\/hal\/Bardet04","article-title":"\u00c9tude des syst\u00e8mes alg\u00e9briques\n  surd\u00e9termin\u00e9s. Applications aux codes correcteurs et \u00e0 la\n  cryptographie","author":"Magali Bardet","year":"2004"},{"key":"ref17:DBLP:journals\/jsc\/BardetFS15","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1016\/j.jsc.2014.09.025","article-title":"On the complexity of the F5 Gr\u00f6bner basis\n  algorithm","volume":"70","author":"Magali Bardet","year":"2015","journal-title":"J. Symb. Comput."},{"key":"ref18:DBLP:journals\/jmc\/BettaleFP09","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1515\/JMC.2009.009","article-title":"Hybrid approach for solving multivariate systems over finite\n  fields","volume":"3","author":"Luk Bettale","year":"2009","journal-title":"J. Math. Cryptol."},{"key":"ref19:DBLP:conf\/issac\/BettaleFP12","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1145\/2442829.2442843","article-title":"Solving polynomial systems over finite fields: improved\n  analysis of the hybrid approach","volume-title":"International Symposium on Symbolic and Algebraic\n  Computation, ISSAC'12, Grenoble, France - July 22 - 25, 2012","author":"Luk Bettale","year":"2012"},{"key":"ref20:DBLP:conf\/africacrypt\/BelliniMSV22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1007\/978-3-031-17433-9_14","article-title":"An Estimator for the Hardness of the MQ Problem","volume-title":"Progress in Cryptology - AFRICACRYPT 2022: 13th\n  International Conference on Cryptology in Africa, AFRICACRYPT 2022, Fes,\n  Morocco, July 18-20, 2022, Proceedings","volume":"13503","author":"Emanuele Bellini","year":"2022"},{"key":"ref21:DBLP:journals\/iacr\/EsserVZB23","article-title":"$\\texttt{CryptographicEstimators}$: a Software Library for\n  Cryptographic Hardness Estimation","author":"Andre Esser","year":"2023"},{"key":"ref22:DBLP:conf\/soda\/AlmanW21","doi-asserted-by":"publisher","first-page":"522","DOI":"10.1137\/1.9781611976465.32","article-title":"A Refined Laser Method and Faster Matrix Multiplication","volume-title":"Proceedings of the 2021 ACM-SIAM Symposium on Discrete\n  Algorithms, SODA 2021, Virtual Conference, January 10 - 13, 2021","author":"Josh Alman","year":"2021"},{"key":"ref23:DBLP:conf\/eurocrypt\/CourtoisKPS00","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"392","DOI":"10.1007\/3-540-45539-6_27","article-title":"Efficient Algorithms for Solving Overdefined Systems of\n  Multivariate Polynomial Equations","volume-title":"Advances in Cryptology - EUROCRYPT 2000, International\n  Conference on the Theory and Application of Cryptographic Techniques, Bruges,\n  Belgium, May 14-18, 2000, Proceeding","volume":"1807","author":"Nicolas T. Courtois","year":"2000"},{"key":"ref24:BW94","first-page":"333","article-title":"Solving Homogeneous Linear Equations Over GF(2) via Block\n  Wiedemann Algorithm","volume":"62","author":"Don Coppersmith","year":"1994","journal-title":"Mathematics of Computation"},{"key":"ref25:DBLP:conf\/ches\/ChengCNY12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"356","DOI":"10.1007\/978-3-642-33027-8_21","article-title":"Solving Quadratic Equations with XL on Parallel\n  Architectures","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2012 -\n  14th International Workshop, Leuven, Belgium, September 9-12, 2012.\n  Proceedings","volume":"7428","author":"Chen-Mou Cheng","year":"2012"},{"key":"ref26:ash1990information","series-title":"Dover books on advanced mathematics","isbn-type":"print","article-title":"Information Theory","author":"R.B. Ash","year":"1990","ISBN":"https:\/\/id.crossref.org\/isbn\/9780486665214"},{"key":"ref27:BardetFSS13","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1016\/J.JCO.2012.07.001","article-title":"On the complexity of solving quadratic Boolean systems","volume":"29","author":"Magali Bardet","year":"2013","journal-title":"J. Complex."},{"key":"ref28:2020SciPy-NMeth","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1038\/s41592-019-0686-2","article-title":"SciPy 1.0: Fundamental Algorithms for Scientific\n  Computing in Python","volume":"17","author":"Pauli Virtanen","year":"2020","journal-title":"Nature Methods"},{"key":"ref29:DBLP:journals\/cca\/AlbrechtCFFP15","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1145\/2815111.2815158","article-title":"Algebraic algorithms for LWE problems","volume":"49","author":"Martin R. Albrecht","year":"2015","journal-title":"ACM Commun. Comput. Algebra"},{"key":"ref30:DBLP:conf\/icalp\/AroraG11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"403","DOI":"10.1007\/978-3-642-22006-7_34","article-title":"New Algorithms for Learning in Presence of Errors","volume-title":"Automata, Languages and Programming - 38th International\n  Colloquium, ICALP 2011, Zurich, Switzerland, July 4-8, 2011, Proceedings,\n  Part I","volume":"6755","author":"Sanjeev Arora","year":"2011"},{"key":"ref31:DBLP:journals\/cca\/ChenDLMXXX11","doi-asserted-by":"publisher","first-page":"166","DOI":"10.1145\/2110170.2110174","article-title":"Computing the real solutions of polynomial systems with the\n  RegularChains library in Maple","volume":"45","author":"Changbo Chen","year":"2011","journal-title":"ACM Commun. Comput. Algebra"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T16:25:12Z","timestamp":1733847912000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/1\/30"}},"issued":{"date-parts":[[2024,4,9]]},"references-count":31,"URL":"https:\/\/doi.org\/10.62056\/aemp-4c2h","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2024,4,9]]},"assertion":[{"value":"2024-01-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-03-05","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-1-97"},{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T16:08:42Z","timestamp":1785427722813,"version":"3.56.0"},"reference-count":6,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,1,7]],"date-time":"2024-01-07T00:00:00Z","timestamp":1704585600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,3,5]]},"abstract":"<jats:p>We prove that isogenies between Drinfeld F[x]-modules over a finite field can be computed in polynomial time. This breaks Drinfeld analogs of isogeny-based cryptosystems.<\/jats:p>","DOI":"10.62056\/avommp-3y","type":"journal-article","created":{"date-parts":[[2024,4,9]],"date-time":"2024-04-09T15:27:10Z","timestamp":1712676430000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Computing isogenies between   finite Drinfeld modules"],"prefix":"10.62056","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1249-6077","authenticated-orcid":false,"given":"Benjamin","family":"Wesolowski","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05n21n105","id-type":"ROR","asserted-by":"publisher"}],"name":"ENS de Lyon, CNRS, UMPA, UMR 5669","place":["Lyon, 69007, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2024,4,9]]},"reference":[{"key":"ref1:JN19","article-title":"Drinfeld modules may not be for isogeny based\n                   cryptography","author":"Antoine Joux","year":"2019"},{"key":"ref2:LS22","article-title":"Hard Homogeneous Spaces from the Class Field Theory\n                   of Imaginary Hyperelliptic Function Fields","author":"Antoine Leudi\u00e8re","year":"2022"},{"key":"ref3:CGS20","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1090\/conm\/754","article-title":"Computing modular polynomials and isogenies of rank\n                   two Drinfeld modules over finite fields","volume-title":"75 Years of Mathematics of Computation: Symposium on\n                   Celebrating 75 Years of Mathematics of Computation,\n                   November 1-3, 2018, the Institute for Computational\n                   and Experimental Research in Mathematics (ICERM)","volume":"754","author":"Perlas Caranay","year":"2020"},{"key":"ref4:Cou06","article-title":"Hard Homogeneous Spaces","author":"Jean Marc Couveignes","year":"2006"},{"key":"ref5:JF11","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-25405-5_2","article-title":"Towards Quantum-Resistant Cryptosystems from\n                   Supersingular Elliptic Curve Isogenies","volume-title":"International Workshop on Post-Quantum Cryptography\n                   \u2013 PQCrypto 2011","author":"David Jao","year":"2011"},{"key":"ref6:CLMPR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","article-title":"CSIDH: An Efficient Post-Quantum Commutative Group\n                   Action","volume-title":"Advances in Cryptology - ASIACRYPT 2018 - 24th\n                   International Conference on the Theory and\n                   Application of Cryptology and Information Security","volume":"11274","author":"Wouter Castryck","year":"2018"}],"container-title":["IACR Communications in Cryptology"],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T16:25:22Z","timestamp":1733847922000},"score":0.0,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/1\/12"}},"issued":{"date-parts":[[2024,4,9]]},"references-count":6,"URL":"https:\/\/doi.org\/10.62056\/avommp-3y","archive":["Internet Archive","Internet Archive"],"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"published":{"date-parts":[[2024,4,9]]},"assertion":[{"value":"2024-01-07","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-03-05","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-1-38"}],"items-per-page":20,"query":{"start-index":0,"search-terms":null}}}