{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,17]],"date-time":"2026-08-17T15:07:15Z","timestamp":1786979235078,"version":"3.56.0"},"publisher-location":"Singapore","reference-count":41,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819544332","type":"print"},{"value":"9789819544349","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T00:00:00Z","timestamp":1762992000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T00:00:00Z","timestamp":1762992000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-4434-9_4","type":"book-chapter","created":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T23:02:30Z","timestamp":1762988550000},"page":"70-92","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["To Extend or\u00a0Not to\u00a0Extend: Agile Masking Instructions for\u00a0PQC"],"prefix":"10.1007","author":[{"given":"Markus","family":"Krausz","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Georg","family":"Land","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Florian","family":"Stolz","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jan","family":"Richter-Brockmann","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tim","family":"G\u00fcneysu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,11,13]]},"reference":[{"key":"4_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-662-53140-2_2","volume-title":"Cryptographic Hardware and Embedded Systems \u2013 CHES 2016","author":"A Battistello","year":"2016","unstructured":"Battistello, A., Coron, J.-S., Prouff, E., Zeitoun, R.: Horizontal side-channel attacks and countermeasures on the ISW masking scheme. In: Gierlichs, B., Poschmann, A.Y. (eds.) CHES 2016. LNCS, vol. 9813, pp. 23\u201339. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53140-2_2"},{"key":"4_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1007\/978-3-319-72565-9_12","volume-title":"Selected Areas in Cryptography \u2013 SAC 2017","author":"DJ Bernstein","year":"2018","unstructured":"Bernstein, D.J., Chuengsatiansup, C., Lange, T., van Vredendaal, C.: NTRU prime: reducing attack surface at low cost. In: Adams, C., Camenisch, J. (eds.) SAC 2017. LNCS, vol. 10719, pp. 235\u2013260. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-72565-9_12"},{"key":"4_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"260","DOI":"10.1007\/BFb0052352","volume-title":"Fast Software Encryption","author":"E Biham","year":"1997","unstructured":"Biham, E.: A fast new DES implementation in software. In: Biham, E. (ed.) FSE 1997. LNCS, vol. 1267, pp. 260\u2013272. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/BFb0052352"},{"key":"4_CR4","doi-asserted-by":"crossref","unstructured":"Bos, J.W., et al.: Frodo: take off the ring! practical, quantum-secure key exchange from LWE. In: Weippl, E.R., Katzenbeisser, S., Kruegel, C., Myers, A.C., Halevi, S. (eds.) ACM CCS 2016, pp. 1006\u20131018. ACM Press (2016)","DOI":"10.1145\/2976749.2978425"},{"issue":"4","key":"4_CR5","doi-asserted-by":"publisher","first-page":"553","DOI":"10.46586\/tches.v2022.i4.553-588","volume":"2022","author":"O Bronchain","year":"2022","unstructured":"Bronchain, O., Cassiers, G.: Bitslicing arithmetic\/boolean masking conversions for fun and profit with application to lattice-based KEMs. IACR TCHES 2022(4), 553\u2013588 (2022)","journal-title":"IACR TCHES"},{"key":"4_CR6","series-title":"LNCS","first-page":"402","volume-title":"SAC 2013","author":"J Buchmann","year":"2014","unstructured":"Buchmann, J., Cabarcas, D., G\u00f6pfert, F., H\u00fclsing, A., Weiden, P.: Discrete ziggurat: a time-memory trade-off for sampling from a Gaussian distribution over the integers. In: Lange, T., Lauter, K., Lisonek, P. (eds.) SAC 2013. LNCS, vol. 8282, pp. 402\u2013417. Springer, Berlin, Heidelberg (2014)"},{"key":"4_CR7","unstructured":"Budroni, A., Canales-Mart\u00ednez, I.A., Perin, L.P.: SoK: methods for sampling random permutations in post-quantum cryptography. Cryptology ePrint Archive, Report 2024\/008 (2024)"},{"key":"4_CR8","series-title":"Part V, volume 14008 of LNCS","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/978-3-031-30589-4_15","volume-title":"EUROCRYPT 2023","author":"W Castryck","year":"2023","unstructured":"Castryck, W., Decru, T.: An efficient key recovery attack on SIDH. In: Hazay, C., Stam, M. (eds.) EUROCRYPT 2023. Part V, volume 14008 of LNCS, pp. 423\u2013447. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_15"},{"issue":"3","key":"4_CR9","doi-asserted-by":"publisher","first-page":"97","DOI":"10.46586\/tches.v2021.i3.97-124","volume":"2021","author":"M-S Chen","year":"2021","unstructured":"Chen, M.-S., Chou, T., Krausz, M.: Optimizing BIKE for the intel haswell and ARM Cortex-M4. IACR TCHES 2021(3), 97\u2013124 (2021)","journal-title":"IACR TCHES"},{"issue":"2","key":"4_CR10","doi-asserted-by":"publisher","first-page":"329","DOI":"10.46586\/tches.v2024.i2.329-358","volume":"2024","author":"H Cheng","year":"2024","unstructured":"Cheng, H., Page, D., Wang, W.: eLIMInate: a leakage-focused ISE for masked implementation. IACR TCHES 2024(2), 329\u2013358 (2024)","journal-title":"IACR TCHES"},{"issue":"3","key":"4_CR11","doi-asserted-by":"publisher","first-page":"25","DOI":"10.46586\/tches.v2024.i3.25-75","volume":"2024","author":"JH Cheon","year":"2024","unstructured":"Cheon, J.H., et al.: HAETAE: shorter lattice-based fiat-shamir signatures. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2024(3), 25\u201375 (2024)","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"4_CR12","doi-asserted-by":"publisher","unstructured":"Cheon, J.H., Choe, H., Hong, D., Yi, M.J.: SMAUG: pushing lattice-based key encapsulation mechanisms to the limits. In: Carlet, C., Mandal, K., Rijmen, V. (eds.) Selected Areas in Cryptography - SAC 2023 - 30th International Conference, Fredericton, Canada, 14\u201318 August 2023, Revised Selected Papers, vol. 14201 of Lecture Notes in Computer Science, pp. 127\u2013146. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-53368-6_7","DOI":"10.1007\/978-3-031-53368-6_7"},{"key":"4_CR13","series-title":"Part I, volume 13905 of LNCS","doi-asserted-by":"publisher","first-page":"725","DOI":"10.1007\/978-3-031-33488-7_27","volume-title":"ACNS 23International Conference on Applied Cryptography and Network Security","author":"A Cheriere","year":"2023","unstructured":"Cheriere, A., Aragon, N., Richmond, T., G\u00e9rard, B.: BIKE key-recovery: combining power consumption analysis and information-set decoding. In: Tibouchi, M., Wang, X. (eds.) ACNS 23International Conference on Applied Cryptography and Network Security. Part I, volume 13905 of LNCS, pp. 725\u2013748. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-33488-7_27"},{"key":"4_CR14","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/978-3-662-53140-2_14","volume-title":"CHES 2016","author":"T Chou","year":"2016","unstructured":"Chou, T.: QcBits: constant-time small-key code-based cryptography. In: Gierlichs, B., Poschmann, A.Y. (eds.) CHES 2016. LNCS, vol. 9813, pp. 280\u2013300. Springer, Berlin, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53140-2_14"},{"issue":"2","key":"4_CR15","doi-asserted-by":"publisher","first-page":"180","DOI":"10.46586\/tches.v2023.i2.180-211","volume":"2023","author":"J-S Coron","year":"2023","unstructured":"Coron, J.-S., G\u00e9rard, F., Trannoy, M., Zeitoun, R.: High-order masking of NTRU. IACR TCHES 2023(2), 180\u2013211 (2023)","journal-title":"IACR TCHES"},{"key":"4_CR16","unstructured":"Drucker, G., Kostic.: Additional Implementation of BIKE (Bit Flipping Key Encapsulation). https:\/\/github.com\/awslabs\/bike-kem. Accessed 20 May 2023"},{"key":"4_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1007\/978-3-030-44223-1_3","volume-title":"Post-Quantum Cryptography","author":"N Drucker","year":"2020","unstructured":"Drucker, N., Gueron, S., Kostic, D.: QC-MDPC decoders with several shades of gray. In: Ding, J., Tillich, J.-P. (eds.) PQCrypto 2020. LNCS, vol. 12100, pp. 35\u201350. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-44223-1_3"},{"key":"4_CR18","doi-asserted-by":"crossref","unstructured":"Dubrova, E., Ngo, K., G\u00e4rtner, J., Wang, R.: Breaking a fifth-order masked implementation of crystals-kyber by copy-paste. In: Fukumitsu, M., Hasegawa, S. (eds.) Proceedings of the 10th ACM Asia Public-Key Cryptography Workshop, APKC 2023, Melbourne, VIC, Australia, 10\u201314 July 2023, pp. 10\u201320. ACM (2023)","DOI":"10.1145\/3591866.3593072"},{"key":"4_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1007\/978-3-642-40041-4_3","volume-title":"Advances in Cryptology \u2013 CRYPTO 2013","author":"L Ducas","year":"2013","unstructured":"Ducas, L., Durmus, A., Lepoint, T., Lyubashevsky, V.: Lattice signatures and bimodal Gaussians. In: Canetti, R., Garay, J.A. (eds.) CRYPTO 2013. LNCS, vol. 8042, pp. 40\u201356. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-40041-4_3"},{"key":"4_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"415","DOI":"10.1007\/978-3-642-34961-4_26","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2012","author":"L Ducas","year":"2012","unstructured":"Ducas, L., Nguyen, P.Q.: Faster gaussian lattice sampling using lazy floating-point arithmetic. In: Wang, X., Sako, K. (eds.) ASIACRYPT 2012. LNCS, vol. 7658, pp. 415\u2013432. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34961-4_26"},{"key":"4_CR21","doi-asserted-by":"publisher","unstructured":"Ducas, L., Postlethwaite, E.W., Pulles, L.N., van Woerden, W.P.J.: Hawk: module LIP makes lattice signatures fast, compact and simple. In: Agrawal, S., Lin, D. (eds.) ASIACRYPT 2022. Part IV. LNCS, vol. 13794, pp. 65\u201394. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22972-5_3","DOI":"10.1007\/978-3-031-22972-5_3"},{"key":"4_CR22","doi-asserted-by":"crossref","unstructured":"Fritzmann, T., et al.: Masked accelerators and instruction set extensions for post-quantum cryptography. In: TCHES 2022 (2021)","DOI":"10.46586\/tches.v2022.i1.414-460"},{"issue":"1","key":"4_CR23","first-page":"414","volume":"2022","author":"T Fritzmann","year":"2022","unstructured":"Fritzmann, T., et al.: Masked accelerators and instruction set extensions for post-quantum cryptography. IACR TCHES 2022(1), 414\u2013460 (2022)","journal-title":"IACR TCHES"},{"issue":"4","key":"4_CR24","doi-asserted-by":"publisher","first-page":"283","DOI":"10.46586\/tches.v2021.i4.283-325","volume":"2021","author":"S Gao","year":"2021","unstructured":"Gao, S., Gro\u00dfsch\u00e4dl, J., Marshall, B., Page, D., Pham, T., Regazzoni, F.: An instruction set extension to support software-based masking. IACR TCHES 2021(4), 283\u2013325 (2021)","journal-title":"IACR TCHES"},{"issue":"3","key":"4_CR25","doi-asserted-by":"publisher","first-page":"223","DOI":"10.46586\/tches.v2022.i3.223-263","volume":"2022","author":"Q Guo","year":"2022","unstructured":"Guo, Q., Hlauschek, C., Johansson, T., Lahr, N., Nilsson, A., Schr\u00f6der, R.L.: Don\u2019t reject this: key-recovery timing attacks due to rejection-sampling in HQC and BIKE. IACR TCHES 2022(3), 223\u2013263 (2022)","journal-title":"IACR TCHES"},{"key":"4_CR26","unstructured":"Heinz, D., Kannwischer, M.J., Land, G., P\u00f6ppelmann, T., Schwabe, P., Sprenkels, A.: First-order masked Kyber on ARM Cortex-M4. Cryptology ePrint Archive, Report 2022\/058 (2022)"},{"key":"4_CR27","doi-asserted-by":"crossref","unstructured":"Hermelink, J., Ning, K.C., Petri, R., Strieder, E.: The insecurity of masked comparisons: SCAs on ML-KEM\u2019s FO-transform. In: Luo, B., Liao, X., Xu, J., Kirda, E., Lie, D. (eds.) ACM CCS 2024, pp. 2430\u20132444. ACM Press (2024)","DOI":"10.1145\/3658644.3690339"},{"key":"4_CR28","unstructured":"NewAE\u00a0Technology Inc. ChipWhisperer. https:\/\/www.newae.com\/chipwhisperer. Accessed 25 June 2023"},{"key":"4_CR29","unstructured":"Kannwischer, M.J., Rijneveld, J., Schwabe, P., Stoffelen, K.: pqm4: testing and benchmarking nist PQC on ARM Cortex-M4. Cryptology ePrint Archive, Report 2019\/844 (2019)"},{"key":"4_CR30","doi-asserted-by":"crossref","unstructured":"Karabulut, E., Alkim, E., Aysu, A.: Single-trace side-channel attacks on $$\\omega $$-small polynomial sampling: With applications to ntru, NTRU prime, and CRYSTALS-DILITHIUM. In: IEEE International Symposium on Hardware Oriented Security and Trust, HOST 2021, Tysons Corner, VA, USA, 12\u201315 December 2021, pp. 35\u201345. IEEE (2021)","DOI":"10.1109\/HOST49136.2021.9702284"},{"key":"4_CR31","series-title":"Part II, volume 13941 of LNCS","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1007\/978-3-031-31371-4_4","volume-title":"PKC 2023","author":"M Krausz","year":"2023","unstructured":"Krausz, M., Land, G., Richter-Brockmann, J., G\u00fcneysu, T.: A holistic approach towards side-channel secure fixed-weight polynomial sampling. In: Boldyreva, A., Kolesnikov, V. (eds.) PKC 2023. Part II, volume 13941 of LNCS, pp. 94\u2013124. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-31371-4_4"},{"key":"4_CR32","unstructured":"Marshall, B., Page, D.: SME: Scalable masking extensions. Cryptology ePrint Archive, Report 2021\/1416 (2021)"},{"issue":"1","key":"4_CR33","first-page":"175","volume":"2022","author":"B Marshall","year":"2022","unstructured":"Marshall, B., Page, D., Webb, J.: MIRACLE: MIcRo-ArChitectural leakage evaluation a study of micro-architectural power leakage across many devices. IACR TCHES 2022(1), 175\u2013220 (2022)","journal-title":"IACR TCHES"},{"key":"4_CR34","doi-asserted-by":"publisher","unstructured":"Marzougui, S., Kabin, I., Kr\u00e4mer, J., Aulbach, T., Seifert, J.P.: On the feasibility of single-trace attacks on the gaussian sampler using a CDT. In: Kavun, E.B., Pehl, M. (eds.) Constructive Side-Channel Analysis and Secure Design - 14th International Workshop, COSADE 2023, Munich, Germany, 3\u20134 April 2023, Proceedings. LNCS, vol. 13979, pp. 149\u2013169. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-29497-6_8","DOI":"10.1007\/978-3-031-29497-6_8"},{"key":"4_CR35","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/978-3-642-14623-7_5","volume-title":"CRYPTO 2010","author":"C Peikert","year":"2010","unstructured":"Peikert, C.: An efficient and parallel Gaussian sampler for lattices. In: Rabin, T. (ed.) CRYPTO 2010. LNCS, vol. 6223, pp. 80\u201397. Springer, Berlin, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-14623-7_5"},{"key":"4_CR36","unstructured":"Thomas Pornin. Why Constant-Time Crypto? https:\/\/www.bearssl.org\/constanttime.html. Accessed 30 June 2023"},{"key":"4_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/978-3-642-38348-9_9","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2013","author":"E Prouff","year":"2013","unstructured":"Prouff, E., Rivain, M.: Masking against side-channel attacks: a formal security proof. In: Johansson, T., Nguyen, P.Q. (eds.) EUROCRYPT 2013. LNCS, vol. 7881, pp. 142\u2013159. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38348-9_9"},{"key":"4_CR38","unstructured":"Sendrier, N.: Secure sampling of constant-weight words \u2013 application to BIKE. Cryptology ePrint Archive, Report 2021\/1631 (2021)"},{"key":"4_CR39","unstructured":"KpqC team. Final algorithms from the kpqc competition. Google Groups: KpqC-bulletin. Message posted to Google Groups. Accessed 22 Jan 2025"},{"issue":"4","key":"4_CR40","doi-asserted-by":"publisher","first-page":"133","DOI":"10.46586\/tches.v2024.i4.133-155","volume":"2024","author":"F Uhle","year":"2024","unstructured":"Uhle, F., Stolz, F., Moradi, A.: Another evidence to not employ customized masked hardware identifying and fixing flaws in SCARV. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2024(4), 133\u2013155 (2024)","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"4_CR41","unstructured":"Zhang, L., Ding, A.A., Durvaux, F., Standaert, F.X., Fei, Y.: Towards sound and optimal leakage detection procedure. Cryptology ePrint Archive, Report 2017\/287 (2017)"}],"container-title":["Lecture Notes in Computer Science","Cryptology and Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-4434-9_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,31]],"date-time":"2026-01-31T10:02:08Z","timestamp":1769853728000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-4434-9_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,13]]},"ISBN":["9789819544332","9789819544349"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-4434-9_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,13]]},"assertion":[{"value":"13 November 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CANS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Cryptology and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Osaka","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 November 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 November 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cans2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/cy2sec.comm.eng.osaka-u.ac.jp\/miyaji-lab\/event\/cans2025\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}