{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T16:09:36Z","timestamp":1780675776543,"version":"3.54.1"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2020,6,19]],"date-time":"2020-06-19T00:00:00Z","timestamp":1592524800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2020,6,19]],"date-time":"2020-06-19T00:00:00Z","timestamp":1592524800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"ISRAEL SCIENCE FOUNDATION","award":["923\/16"],"award-info":[{"award-number":["923\/16"]}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["Po 1220\/7-2"],"award-info":[{"award-number":["Po 1220\/7-2"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2021,6]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Cryptographic hardware becomes increasingly vulnerable to physical attacks\u2014both passive side-channel analysis and active fault injections\u2014performed by skillful and well-equipped adversaries. In this paper, we introduce a technique that provides very high security against both types of attacks. It combines inner product masking (IPM), which offers higher-order side-channel attack resistance on word level and on bit level, with nonlinear security-oriented error-detection codes that provide robustness, i.e., strong detection guarantees for arbitrary faults. We prove that our scheme has the same security against side-channel attacks that an earlier, non-robust IPM-based solution has and in addition preserves robustness during addition and multiplication (and therefore arbitrary computations). Moreover, we prove that the information leakage from the checker is small and that the attack will be detected far before the attacker will gain significant information.<\/jats:p>","DOI":"10.1007\/s13389-020-00229-4","type":"journal-article","created":{"date-parts":[[2020,6,19]],"date-time":"2020-06-19T17:03:59Z","timestamp":1592586239000},"page":"147-160","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["IPM-RED: combining higher-order masking with robust error detection"],"prefix":"10.1007","volume":"11","author":[{"given":"Osnat","family":"Keren","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ilia","family":"Polian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,6,19]]},"reference":[{"key":"229_CR1","first-page":"49","volume-title":"Proceedings of 8th Workshop on Security Proofs for Embedded Systems","author":"O Keren","year":"2019","unstructured":"Keren, O., Polian, I.: A comment on information leakage from robust code-based checkers detecting fault attacks on cryptographic primitives. In: Heydemann, K., K\u00fchne, U., Li, L. (eds.) Proceedings of 8th Workshop on Security Proofs for Embedded Systems, vol. 11, pp. 49\u201363. Kalpa Publications in Computing, EasyChair (2019)"},{"issue":"8","key":"229_CR2","doi-asserted-by":"publisher","first-page":"1283","DOI":"10.1109\/JPROC.2014.2335155","volume":"102","author":"M Rostami","year":"2014","unstructured":"Rostami, M., Koushanfar, F., Karri, R.: A primer on hardware security: models, methods, and metrics. Proc. IEEE 102(8), 1283\u20131295 (2014)","journal-title":"Proc. IEEE"},{"key":"229_CR3","doi-asserted-by":"crossref","unstructured":"Regazzoni, F., Breveglieri, L., Ienne, P., Koren, I.: Interaction between fault attack countermeasures and the resistance against power analysis attacks. In: Fault Analysis in Cryptography, (2012)","DOI":"10.1007\/978-3-642-29656-7_15"},{"key":"229_CR4","doi-asserted-by":"crossref","unstructured":"Schneider, T., Moradi, A., G\u00fcneysu, T.: ParTI - towards combined hardware countermeasures against side-channel and fault-injection attacks. In: Robshaw, M., Katz, J. (eds.), Advances in Cryptology\u2014CRYPTO 2016. Annual International Cryptology Conference (CRYPTO-2016), August 14\u201318, Santa Barbara, CA, United States , Lecture Notes in Computer Science (LNCS), vol.\u00a09815, pp. 302\u2013332, Springer, (2016)","DOI":"10.1007\/978-3-662-53008-5_11"},{"key":"229_CR5","first-page":"486","volume-title":"Advances in Cryptology\u2013EUROCRYPT","author":"J Balasch","year":"2015","unstructured":"Balasch, J., Faust, S., Gierlichs, B.: Inner product masking revisited. In: Oswald, E., Fischlin, M. (eds.) Advances in Cryptology\u2013EUROCRYPT, pp. 486\u2013510. Springer, Berlin (2015)"},{"key":"229_CR6","unstructured":"Karpovsky, M.G., Kulikowski, K.J., Wang, Z.: Robust error detection in communication and computational channels. In: Spectral Methods and Multirate Signal Processing. SMMSP\u20192007. 2007 International Workshop on, Citeseer, (2007)"},{"key":"229_CR7","first-page":"17","volume-title":"proceddings of 8th International Workshop on Security Proofs for Embedded Systems","author":"W Cheng","year":"2019","unstructured":"Cheng, W., Carlet, C., Goli, K., Danger, J.-L., Guilley, S.: Detecting faults in inner-product masking scheme\u2013IPM-FD: IPM with fault detection. In: Heydemann, K., K\u00fchne, U., Li, L. (eds.) proceddings of 8th International Workshop on Security Proofs for Embedded Systems, vol. 11, pp. 17\u201332. Kalpa Publications in Computing, New York (2019)"},{"issue":"1","key":"229_CR8","first-page":"25","volume":"2019","author":"L De Meyer","year":"2019","unstructured":"De Meyer, L., Arribas, V., Nikova, S., Nikov, V., Rijmen, V.: M&M: Masks and macs against physical attacks. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2019(1), 25\u201350 (2019)","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"issue":"2","key":"229_CR9","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1007\/s001450010016","volume":"14","author":"D Boneh","year":"2001","unstructured":"Boneh, D., DeMillo, R.A., Lipton, R.J.: On the importance of eliminating errors in cryptographic computations. J. Cryptol. 14(2), 101\u2013119 (2001)","journal-title":"J. Cryptol."},{"issue":"11","key":"229_CR10","doi-asserted-by":"publisher","first-page":"3056","DOI":"10.1109\/JPROC.2012.2188769","volume":"100","author":"A Barenghi","year":"2012","unstructured":"Barenghi, A., Breveglieri, L., Koren, I., Naccache, D.: Fault injection attacks on cryptographic devices: Theory, practice, and countermeasures. Proc. IEEE 100(11), 3056\u20133076 (2012)","journal-title":"Proc. IEEE"},{"key":"229_CR11","doi-asserted-by":"crossref","unstructured":"Polian, I., Regazzoni, F.: Counteracting malicious faults in cryptographic circuits. In: ETS, pp.\u00a01\u201310, IEEE, (2017)","DOI":"10.1109\/ETS.2017.7968230"},{"key":"229_CR12","doi-asserted-by":"crossref","unstructured":"Tunstall, M., Mukhopadhyay, D., Ali, S.: Differential fault analysis of the advanced encryption standard using a single fault. In: WISTP, vol.\u00a06633 of Lecture Notes in Computer Science, pp.\u00a0224\u2013233, Springer, (2011)","DOI":"10.1007\/978-3-642-21040-2_15"},{"key":"229_CR13","doi-asserted-by":"crossref","unstructured":"Jovanovic, P., Kreuzer, M., Polian, I.: A fault attack on the LED block cipher. In: COSADE, vol.\u00a07275 of Lecture Notes in Computer Science, pp.\u00a0120\u2013134, Springer, (2012)","DOI":"10.1007\/978-3-642-29912-4_10"},{"key":"229_CR14","doi-asserted-by":"crossref","unstructured":"Tajik, S., Lohrke, H., Ganji, F., Seifert, J., Boit, C.: Laser fault attack on physically unclonable functions. In: 2015 Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC), pp.\u00a085\u201396, (2015)","DOI":"10.1109\/FDTC.2015.19"},{"key":"229_CR15","doi-asserted-by":"crossref","unstructured":"Li, Y., Sakiyama, K., Gomisawa, S., Fukunaga, T., Takahashi, J., Ohta, K.: Fault sensitivity analysis. In: CHES, vol.\u00a06225 of Lecture Notes in Computer Science, pp.\u00a0320\u2013334, Springer, (2010)","DOI":"10.1007\/978-3-642-15031-9_22"},{"key":"229_CR16","doi-asserted-by":"crossref","unstructured":"Ghalaty, N.F., Yuce, B., Taha, M.M.I., Schaumont, P.: Differential fault intensity analysis. In: FDTC, pp.\u00a049\u201358, IEEE Computer Society, (2014)","DOI":"10.1109\/FDTC.2014.15"},{"key":"229_CR17","volume-title":"Power Analysis Attacks: Revealing the Secrets of Smart Cards (Advances in Information Security)","author":"S Mangard","year":"2007","unstructured":"Mangard, S., Oswald, E., Popp, T.: Power Analysis Attacks: Revealing the Secrets of Smart Cards (Advances in Information Security). Springer, Berlin (2007)"},{"issue":"1","key":"229_CR18","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1007\/s13389-011-0006-y","volume":"1","author":"P Kocher","year":"2011","unstructured":"Kocher, P., Jaffe, J., Jun, B., Rohatgi, P.: Introduction to differential power analysis. J. Cryptogr. Eng. 1(1), 5\u201327 (2011)","journal-title":"J. Cryptogr. Eng."},{"issue":"2","key":"229_CR19","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1007\/s13389-011-0010-2","volume":"1","author":"J Doget","year":"2011","unstructured":"Doget, J., Prouff, E., Rivain, M., Standaert, F.: Univariate side channel attacks and leakage modeling. J. Cryptogr. Eng. 1(2), 123\u2013144 (2011)","journal-title":"J. Cryptogr. Eng."},{"issue":"2","key":"229_CR20","doi-asserted-by":"publisher","first-page":"269","DOI":"10.1007\/s00145-010-9084-8","volume":"24","author":"L Batina","year":"2011","unstructured":"Batina, L., Gierlichs, B., Prouff, E., Rivain, M., Standaert, F., Veyrat-Charvillon, N.: Mutual information analysis: a comprehensive study. J. Cryptol. 24(2), 269\u2013291 (2011)","journal-title":"J. Cryptol."},{"key":"229_CR21","first-page":"463","volume-title":"Advances in Cryptology\u2013CRYPTO","author":"Y Ishai","year":"2003","unstructured":"Ishai, Y., Sahai, A., Wagner, D.: Private circuits: Securing hardware against probing attacks. In: Boneh, D. (ed.) Advances in Cryptology\u2013CRYPTO, pp. 463\u2013481. Springer, Berlin (2003)"},{"key":"229_CR22","doi-asserted-by":"publisher","first-page":"413","DOI":"10.1007\/978-3-642-15031-9_28","volume-title":"Cryptographic Hardware and Embedded Systems, CHES 2010","author":"M Rivain","year":"2010","unstructured":"Rivain, M., Prouff, E.: Provably secure higher-order masking of AES. In: Mangard, S., Standaert, F.-X. (eds.) Cryptographic Hardware and Embedded Systems, CHES 2010, pp. 413\u2013427. Springer, Berlin (2010)"},{"key":"229_CR23","first-page":"79","volume-title":"Cryptographic Hardware and Embedded Systems\u2013CHES","author":"L Goubin","year":"2011","unstructured":"Goubin, L., Martinelli, A.: Protecting AES with shamir\u2019s secret sharing scheme. In: Preneel, B., Takagi, T. (eds.) Cryptographic Hardware and Embedded Systems\u2013CHES, pp. 79\u201394. Springer, Berlin (2011)"},{"key":"229_CR24","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/s13389-012-0033-3","volume":"2","author":"T Roche","year":"2012","unstructured":"Roche, T., Prouff, E.: Higher-order glitch free implementation of the AES using secure multi-party computation protocols. J. Cryptogr. Eng. 2, 111\u2013127 (2012)","journal-title":"J. Cryptogr. Eng."},{"key":"229_CR25","first-page":"157","volume-title":"Cryptographic Hardware and Embedded Systems\u2013CHES","author":"S Mangard","year":"2005","unstructured":"Mangard, S., Pramstaller, N., Oswald, E.: Successfully attacking masked AES hardware implementations. In: Rao, J.R., Sunar, B. (eds.) Cryptographic Hardware and Embedded Systems\u2013CHES, pp. 157\u2013171. Springer, Berlin (2005)"},{"key":"229_CR26","doi-asserted-by":"publisher","first-page":"529","DOI":"10.1007\/11935308_38","volume-title":"Information and Communications Security","author":"S Nikova","year":"2006","unstructured":"Nikova, S., Rechberger, C., Rijmen, V.: Threshold implementations against side-channel attacks and glitches. In: Ning, P., Qing, S., Li, N. (eds.) Information and Communications Security, pp. 529\u2013545. Springer, Berlin (2006)"},{"key":"229_CR27","doi-asserted-by":"crossref","unstructured":"Ngo, X.T., Bhasin, S., Danger, J., Guilley, S., Najm, Z.: Linear complementary dual code improvement to strengthen encoded circuit against hardware trojan horses. In: IEEE International Symposium on Hardware Oriented Security and Trust, HOST, Washington, DC, 5\u20137 May, 2015, pp.\u00a082\u201387, (2015)","DOI":"10.1109\/HST.2015.7140242"},{"key":"229_CR28","first-page":"40","volume-title":"Information Security Theory and Practice","author":"J Bringer","year":"2014","unstructured":"Bringer, J., Carlet, C., Chabanne, H., Guilley, S., Maghrebi, H.: Orthogonal direct sum masking. In: Naccache, D., Sauveron, D. (eds.) Information Security Theory and Practice, pp. 40\u201356. Securing the Internet of Things, Springer, Berlin (2014)"},{"issue":"9","key":"229_CR29","doi-asserted-by":"publisher","first-page":"4160","DOI":"10.1109\/TIT.2006.880036","volume":"52","author":"TP Berger","year":"2006","unstructured":"Berger, T.P., Canteaut, A., Charpin, P., Laigle-Chapuy, Y.: On almost perfect nonlinear functions over $$ \\mathbb{F}_{2}^{n}$$. IEEE Trans. Inf. Theory 52(9), 4160\u20134170 (2006)","journal-title":"IEEE Trans. Inf. Theory"},{"issue":"2\u20133","key":"229_CR30","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1016\/j.jco.2003.08.008","volume":"20","author":"C Carlet","year":"2004","unstructured":"Carlet, C., Ding, C.: Highly nonlinear mappings. J. Complex. 20(2\u20133), 205\u2013244 (2004)","journal-title":"J. Complex."},{"issue":"12","key":"229_CR31","doi-asserted-by":"publisher","first-page":"8007","DOI":"10.1109\/TIT.2011.2162718","volume":"57","author":"S Engelberg","year":"2011","unstructured":"Engelberg, S., Keren, O.: A comment on the Karpovsky-Taubin code. IEEE Trans. Inf. Theory 57(12), 8007\u20138010 (2011)","journal-title":"IEEE Trans. Inf. Theory"},{"issue":"2","key":"229_CR32","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1155\/1998\/37237","volume":"1998","author":"F Busaba","year":"1998","unstructured":"Busaba, F., Lala, P.K., Walker, A.: On self-checking design of CMOS circuits for multiple faults. VLSI Des. 1998(2), 151\u2013161 (1998)","journal-title":"VLSI Des."},{"issue":"5\u20136","key":"229_CR33","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1080\/19393555.2014.891275","volume":"22","author":"A Burg","year":"2013","unstructured":"Burg, A., Keren, O.: On the efficiency of berger codes against error injection attacks on parallel asynchronous communication channels. Inf. Secur. J. A Glob. Perspect. 22(5\u20136), 208\u2013215 (2013)","journal-title":"Inf. Secur. J. A Glob. Perspect."},{"key":"229_CR34","doi-asserted-by":"crossref","unstructured":"Rivain, M.: Differential fault analysis on DES middle rounds. In: CHES, (2009)","DOI":"10.1007\/978-3-642-04138-9_32"},{"key":"229_CR35","doi-asserted-by":"crossref","unstructured":"Derbez, P., Fouque, P.-A., Leresteux, D.: Meet-in-the-middle and impossible differential fault analysis on AES. In: International Workshop on Cryptographic Hardware and Embedded Systems, pp.\u00a0274\u2013291, (2011)","DOI":"10.1007\/978-3-642-23951-9_19"},{"key":"229_CR36","doi-asserted-by":"publisher","unstructured":"Rabii, H., Neumeier, Y., Keren, O.: High rate robust codes with low implementation complexity. IEEE Transactions on Dependable and Secure Computing, https:\/\/doi.org\/10.1109\/TDSC.2018.2816638, (2018)","DOI":"10.1109\/TDSC.2018.2816638"},{"issue":"2","key":"229_CR37","doi-asserted-by":"publisher","first-page":"49","DOI":"10.46586\/tches.v2019.i2.49-79","volume":"2019","author":"E de Ch\u00e9risey","year":"2019","unstructured":"de Ch\u00e9risey, E., Guilley, S., Rioul, O., Piantanida, P.: Best information is most successful mutual information and success rate in side-channel analysis. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2019(2), 49\u201379 (2019)","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-020-00229-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13389-020-00229-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-020-00229-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,6,18]],"date-time":"2021-06-18T23:50:08Z","timestamp":1624060208000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13389-020-00229-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,19]]},"references-count":37,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2021,6]]}},"alternative-id":["229"],"URL":"https:\/\/doi.org\/10.1007\/s13389-020-00229-4","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"value":"2190-8508","type":"print"},{"value":"2190-8516","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,6,19]]},"assertion":[{"value":"15 November 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 April 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 June 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}