{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T18:05:23Z","timestamp":1785953123639,"version":"3.56.0"},"reference-count":49,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2021,4,23]],"date-time":"2021-04-23T00:00:00Z","timestamp":1619136000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"CyberSecurity Research Flanders","award":["VR20192203"],"award-info":[{"award-number":["VR20192203"]}]},{"name":"Horizon 2020 ERC Advanced","award":["695305 Cathedra"],"award-info":[{"award-number":["695305 Cathedra"]}]},{"name":"Research Council KU Leuven","award":["C16\/15\/058"],"award-info":[{"award-number":["C16\/15\/058"]}]},{"name":"SRC","award":["2909.001"],"award-info":[{"award-number":["2909.001"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["J. Emerg. Technol. Comput. Syst."],"published-print":{"date-parts":[[2021,4,30]]},"abstract":"<jats:p>The candidates for the NIST Post-Quantum Cryptography standardization have undergone extensive studies on efficiency and theoretical security, but research on their side-channel security is largely lacking. This remains a considerable obstacle for their real-world deployment, where side-channel security can be a critical requirement. This work describes a side-channel-resistant instance of Saber, one of the lattice-based candidates, using masking as a countermeasure. Saber proves to be very efficient to masking due to two specific design choices: power-of-two moduli and limited noise sampling of learning with rounding. A major challenge in masking lattice-based cryptosystems is the integration of bit-wise operations with arithmetic masking, requiring algorithms to securely convert between masked representations. The described design includes a novel primitive for masked logical shifting on arithmetic shares and adapts an existing masked binomial sampler for Saber. An implementation is provided for an ARM Cortex-M4 microcontroller, and its side-channel resistance is experimentally demonstrated. The masked implementation features a 2.5x overhead factor, significantly lower than the 5.7x previously reported for a masked variant of NewHope. Masked key decapsulation requires less than 3,000,000 cycles on the Cortex-M4 and consumes less than 12kB of dynamic memory, making it suitable for deployment in embedded platforms.<\/jats:p>","DOI":"10.1145\/3429983","type":"journal-article","created":{"date-parts":[[2021,4,23]],"date-time":"2021-04-23T16:09:57Z","timestamp":1619194197000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":56,"title":["A Side-Channel-Resistant Implementation of SABER"],"prefix":"10.1145","volume":"17","author":[{"given":"Michiel Van","family":"Beirendonck","sequence":"first","affiliation":[{"name":"imec-COSIC KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jan-Pieter","family":"D\u2019anvers","sequence":"additional","affiliation":[{"name":"imec-COSIC KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Angshuman","family":"Karmakar","sequence":"additional","affiliation":[{"name":"imec-COSIC KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Josep","family":"Balasch","sequence":"additional","affiliation":[{"name":"imec-COSIC KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ingrid","family":"Verbauwhede","sequence":"additional","affiliation":[{"name":"imec-COSIC KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,4,23]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Ricardini","author":"Alkim Erdem","year":"2019","unstructured":"Erdem Alkim , Paulo S. L. M. Barreto , Nina Bindel , Juliane Kramer , Patrick Longa , and Jefferson E . Ricardini . 2019 . The Lattice-Based Digital Signature Scheme qTESLA. Cryptology ePrint Archive, Report 2019\/085. Erdem Alkim, Paulo S. L. M. Barreto, Nina Bindel, Juliane Kramer, Patrick Longa, and Jefferson E. Ricardini. 2019. The Lattice-Based Digital Signature Scheme qTESLA. Cryptology ePrint Archive, Report 2019\/085."},{"key":"e_1_2_1_2_1","volume-title":"USENIX Security Symposium (USENIX Security\u201916)","author":"Alkim Erdem","year":"2016","unstructured":"Erdem Alkim , L\u00e9o Ducas , Thomas P\u00f6ppelmann , and Peter Schwabe . 2016 . Post-quantum key exchange - A new hope . In USENIX Security Symposium (USENIX Security\u201916) , Thorsten Holz and Stefan Savage (Eds.). USENIX Association, 327--343. Erdem Alkim, L\u00e9o Ducas, Thomas P\u00f6ppelmann, and Peter Schwabe. 2016. Post-quantum key exchange - A new hope. In USENIX Security Symposium (USENIX Security\u201916), Thorsten Holz and Stefan Savage (Eds.). USENIX Association, 327--343."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2018.8383894"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2020.i3.483-507"},{"key":"e_1_2_1_5_1","volume-title":"Smart Card Research and Advanced Applications - 13th International Conference (CARDIS\u201914). Revised Selected Papers (Lecture Notes in Computer Science)","author":"Balasch Josep","unstructured":"Josep Balasch , Benedikt Gierlichs , Vincent Grosso , Oscar Reparaz , and Fran\u00e7ois-Xavier Standaert . 2014. On the cost of lazy engineering for masked software implementations . In Smart Card Research and Advanced Applications - 13th International Conference (CARDIS\u201914). Revised Selected Papers (Lecture Notes in Computer Science) , Marc Joye and Amir Moradi (Eds.), Vol. 8968 . Springer , 64--81. Josep Balasch, Benedikt Gierlichs, Vincent Grosso, Oscar Reparaz, and Fran\u00e7ois-Xavier Standaert. 2014. On the cost of lazy engineering for masked software implementations. In Smart Card Research and Advanced Applications - 13th International Conference (CARDIS\u201914). Revised Selected Papers (Lecture Notes in Computer Science), Marc Joye and Amir Moradi (Eds.), Vol. 8968. Springer, 64--81."},{"key":"e_1_2_1_6_1","volume-title":"Advances in Cryptology (EUROCRYPT\u201912) (Lecture Notes in Computer Science)","author":"Banerjee Abhishek","unstructured":"Abhishek Banerjee , Chris Peikert , and Alon Rosen . 2012. Pseudorandom functions and lattices . In Advances in Cryptology (EUROCRYPT\u201912) (Lecture Notes in Computer Science) , Vol. 7237 . Springer , 719--737. Abhishek Banerjee, Chris Peikert, and Alon Rosen. 2012. Pseudorandom functions and lattices. In Advances in Cryptology (EUROCRYPT\u201912) (Lecture Notes in Computer Science), Vol. 7237. Springer, 719--737."},{"key":"e_1_2_1_7_1","volume-title":"Advances in Cryptology (EUROCRYPT\u201918) (Lecture Notes in Computer Science)","author":"Barthe Gilles","unstructured":"Gilles Barthe , Sonia Bela\u00efd , Thomas Espitau , Pierre-Alain Fouque , Benjamin Gr\u00e9goire , M\u00e9lissa Rossi , and Mehdi Tibouchi . 2018. Masking the GLP lattice-based signature scheme at any order . In Advances in Cryptology (EUROCRYPT\u201918) (Lecture Notes in Computer Science) , Jesper Buus Nielsen and Vincent Rijmen (Eds.). Springer International Publishing , Cham , 354--384. Gilles Barthe, Sonia Bela\u00efd, Thomas Espitau, Pierre-Alain Fouque, Benjamin Gr\u00e9goire, M\u00e9lissa Rossi, and Mehdi Tibouchi. 2018. Masking the GLP lattice-based signature scheme at any order. In Advances in Cryptology (EUROCRYPT\u201918) (Lecture Notes in Computer Science), Jesper Buus Nielsen and Vincent Rijmen (Eds.). Springer International Publishing, Cham, 354--384."},{"key":"e_1_2_1_8_1","first-page":"2","article-title":"Time-memory trade-off in Toom-Cook multiplication: An application to module-lattice based cryptography","volume":"2020","author":"Bermudo Mera Jose Maria","year":"2020","unstructured":"Jose Maria Bermudo Mera , Angshuman Karmakar , and Ingrid Verbauwhede . 2020 . Time-memory trade-off in Toom-Cook multiplication: An application to module-lattice based cryptography . IACR Trans. Cryptogr. Hardw. Embed. Syst. 2020 , 2 (Mar. 2020), 222--244. Jose Maria Bermudo Mera, Angshuman Karmakar, and Ingrid Verbauwhede. 2020. Time-memory trade-off in Toom-Cook multiplication: An application to module-lattice based cryptography. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2020, 2 (Mar. 2020), 222--244.","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"e_1_2_1_9_1","volume-title":"2nd SHA-3 Candidate Conference","author":"Bertoni Guido","unstructured":"Guido Bertoni , Joan Daemen , Micha\u00ebl Peeters , and Gilles Van Assche . 2010. Building power analysis resistant implementations of Keccak . In 2nd SHA-3 Candidate Conference , Vol. 142 . Citeseer . Guido Bertoni, Joan Daemen, Micha\u00ebl Peeters, and Gilles Van Assche. 2010. Building power analysis resistant implementations of Keccak. In 2nd SHA-3 Candidate Conference, Vol. 142. Citeseer."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2018.i2.22-45"},{"key":"e_1_2_1_11_1","volume-title":"Advances in Cryptology (CRYPTO\u201999) (LNCS), Michael J","author":"Chari Suresh","unstructured":"Suresh Chari , Charanjit S. Jutla , Josyula R. Rao , and Pankaj Rohatgi . 1999. Towards sound approaches to counteract power-analysis attacks . In Advances in Cryptology (CRYPTO\u201999) (LNCS), Michael J . Wiener (Ed.), Vol. 1666 . Springer , 398--412. Suresh Chari, Charanjit S. Jutla, Josyula R. Rao, and Pankaj Rohatgi. 1999. Towards sound approaches to counteract power-analysis attacks. In Advances in Cryptology (CRYPTO\u201999) (LNCS), Michael J. Wiener (Ed.), Vol. 1666. Springer, 398--412."},{"key":"e_1_2_1_12_1","volume-title":"19th International Conference, Proceedings (Lecture Notes in Computer Science), Wieland Fischer and Naofumi Homma (Eds.)","volume":"10529","author":"Coron Jean-S\u00e9bastien","year":"2017","unstructured":"Jean-S\u00e9bastien Coron . 2017 . High-order conversion from Boolean to arithmetic masking. In Cryptographic Hardware and Embedded Systems (CHES\u201917) - 19th International Conference, Proceedings (Lecture Notes in Computer Science), Wieland Fischer and Naofumi Homma (Eds.) , Vol. 10529 . Springer, 93--114. Jean-S\u00e9bastien Coron. 2017. High-order conversion from Boolean to arithmetic masking. In Cryptographic Hardware and Embedded Systems (CHES\u201917) - 19th International Conference, Proceedings (Lecture Notes in Computer Science), Wieland Fischer and Naofumi Homma (Eds.), Vol. 10529. Springer, 93--114."},{"key":"e_1_2_1_13_1","volume-title":"Fast Software Encryption - 22nd International Workshop (FSE\u201915), Revised Selected Papers (Lecture Notes in Computer Science)","author":"Coron Jean-S\u00e9bastien","unstructured":"Jean-S\u00e9bastien Coron , Johann Gro\u00dfsch\u00e4dl , Mehdi Tibouchi , and Praveen Kumar Vadnala . 2015. Conversion from arithmetic to Boolean masking with logarithmic complexity . In Fast Software Encryption - 22nd International Workshop (FSE\u201915), Revised Selected Papers (Lecture Notes in Computer Science) , Gregor Leander (Ed.), Vol. 9054 . Springer , 130--149. Jean-S\u00e9bastien Coron, Johann Gro\u00dfsch\u00e4dl, Mehdi Tibouchi, and Praveen Kumar Vadnala. 2015. Conversion from arithmetic to Boolean masking with logarithmic complexity. In Fast Software Encryption - 22nd International Workshop (FSE\u201915), Revised Selected Papers (Lecture Notes in Computer Science), Gregor Leander (Ed.), Vol. 9054. Springer, 130--149."},{"key":"e_1_2_1_14_1","volume-title":"Cryptographic Hardware and Embedded Systems (CHES\u201914) (LNCS)","author":"Coron Jean-S\u00e9bastien","unstructured":"Jean-S\u00e9bastien Coron , Johann Gro\u00dfsch\u00e4dl , and Praveen Kumar Vadnala . 2014. Secure conversion between Boolean and arithmetic masking of any order . In Cryptographic Hardware and Embedded Systems (CHES\u201914) (LNCS) , Lejla Batina and Matthew Robshaw (Eds.), Vol. 8731 . Springer , 188--205. Jean-S\u00e9bastien Coron, Johann Gro\u00dfsch\u00e4dl, and Praveen Kumar Vadnala. 2014. Secure conversion between Boolean and arithmetic masking of any order. In Cryptographic Hardware and Embedded Systems (CHES\u201914) (LNCS), Lejla Batina and Matthew Robshaw (Eds.), Vol. 8731. Springer, 188--205."},{"key":"e_1_2_1_15_1","volume-title":"5th International Workshop, Proceedings (Lecture Notes in Computer Science), Colin D. Walter, \u00c7etin Kaya Ko\u00e7, and Christof Paar (Eds.)","volume":"2779","author":"Coron Jean-S\u00e9bastien","year":"2003","unstructured":"Jean-S\u00e9bastien Coron and Alexei Tchulkine . 2003 . A new algorithm for switching from arithmetic to Boolean masking. In Cryptographic Hardware and Embedded Systems (CHES\u201903) , 5th International Workshop, Proceedings (Lecture Notes in Computer Science), Colin D. Walter, \u00c7etin Kaya Ko\u00e7, and Christof Paar (Eds.) , Vol. 2779 . Springer, 89--97. Jean-S\u00e9bastien Coron and Alexei Tchulkine. 2003. A new algorithm for switching from arithmetic to Boolean masking. In Cryptographic Hardware and Embedded Systems (CHES\u201903), 5th International Workshop, Proceedings (Lecture Notes in Computer Science), Colin D. Walter, \u00c7etin Kaya Ko\u00e7, and Christof Paar (Eds.), Vol. 2779. Springer, 89--97."},{"key":"e_1_2_1_16_1","volume-title":"Sujoy Sinha Roy, and Frederik Vercauteren","author":"D\u2019Anvers Jan-Pieter","year":"2018","unstructured":"Jan-Pieter D\u2019Anvers , Angshuman Karmakar , Sujoy Sinha Roy, and Frederik Vercauteren . 2018 . Saber : Module-LWR based key exchange, CPA-secure encryption and CCA-secure KEM. In Progress in Cryptology (AFRICACRYPT\u201918) (LNCS), Antoine Joux, Abderrahmane Nitaj, and Tajjeeddine Rachidi (Eds.), Vol. 10831 . Springer , 282--305. Jan-Pieter D\u2019Anvers, Angshuman Karmakar, Sujoy Sinha Roy, and Frederik Vercauteren. 2018. Saber: Module-LWR based key exchange, CPA-secure encryption and CCA-secure KEM. In Progress in Cryptology (AFRICACRYPT\u201918) (LNCS), Antoine Joux, Abderrahmane Nitaj, and Tajjeeddine Rachidi (Eds.), Vol. 10831. Springer, 282--305."},{"key":"e_1_2_1_17_1","volume-title":"Public-Key Cryptography (PKC\u201919) (Lecture Notes in Computer Science)","author":"D\u2019Anvers Jan-Pieter","unstructured":"Jan-Pieter D\u2019Anvers , Qian Guo , Thomas Johansson , Alexander Nilsson , Frederik Vercauteren , and Ingrid Verbauwhede . 2019. Decryption failure attacks on IND-CCA secure lattice-based schemes . In Public-Key Cryptography (PKC\u201919) (Lecture Notes in Computer Science) , Vol. 11443 . Springer , 565--598. Jan-Pieter D\u2019Anvers, Qian Guo, Thomas Johansson, Alexander Nilsson, Frederik Vercauteren, and Ingrid Verbauwhede. 2019. Decryption failure attacks on IND-CCA secure lattice-based schemes. In Public-Key Cryptography (PKC\u201919) (Lecture Notes in Computer Science), Vol. 11443. Springer, 565--598."},{"key":"e_1_2_1_18_1","volume-title":"Sujoy Sinha Roy, and Frederik Vercauteren","author":"D\u2019Anvers Jan-Pieter","year":"2019","unstructured":"Jan-Pieter D\u2019Anvers , Angshuman Karmakar , Sujoy Sinha Roy, and Frederik Vercauteren . 2019 . SABER. Technical Report. National Institute of Standards and Technology . Jan-Pieter D\u2019Anvers, Angshuman Karmakar, Sujoy Sinha Roy, and Frederik Vercauteren. 2019. SABER. Technical Report. National Institute of Standards and Technology."},{"key":"e_1_2_1_19_1","volume-title":"14th International Workshop, Proceedings (Lecture Notes in Computer Science), Emmanuel Prouff and Patrick Schaumont (Eds.)","volume":"7428","author":"Debraize Blandine","year":"2012","unstructured":"Blandine Debraize . 2012 . Efficient and provably secure methods for switching from arithmetic to Boolean masking. In Cryptographic Hardware and Embedded Systems (CHES\u201912) - 14th International Workshop, Proceedings (Lecture Notes in Computer Science), Emmanuel Prouff and Patrick Schaumont (Eds.) , Vol. 7428 . Springer, 107--121. Blandine Debraize. 2012. Efficient and provably secure methods for switching from arithmetic to Boolean masking. In Cryptographic Hardware and Embedded Systems (CHES\u201912) - 14th International Workshop, Proceedings (Lecture Notes in Computer Science), Emmanuel Prouff and Patrick Schaumont (Eds.), Vol. 7428. Springer, 107--121."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2018.i1.238-268"},{"key":"e_1_2_1_22_1","volume-title":"Technical Report","author":"Garcia-Morchon Oscar","unstructured":"Oscar Garcia-Morchon , Zhenfei Zhang , Sauvik Bhattacharya , Ronald Rietman , Ludo Tolhuizen , Jose-Luis Torre-Arce , Hayo Baan , Markku-Juhani O. Saarinen , Scott Fluhrer , Thijs Laarhoven , and Rachel Player . 2019. Round5. Technical Report . National Institute of Standards and Technology . Oscar Garcia-Morchon, Zhenfei Zhang, Sauvik Bhattacharya, Ronald Rietman, Ludo Tolhuizen, Jose-Luis Torre-Arce, Hayo Baan, Markku-Juhani O. Saarinen, Scott Fluhrer, Thijs Laarhoven, and Rachel Player. 2019. Round5. Technical Report. National Institute of Standards and Technology."},{"key":"e_1_2_1_23_1","volume-title":"An efficient and provable masked implementation of qTESLA","author":"G\u00e9rard Fran\u00e7ois","unstructured":"Fran\u00e7ois G\u00e9rard and M\u00e9lissa Rossi . 2020. An efficient and provable masked implementation of qTESLA . In Smart Card Research and Advanced Applications, Sonia Bela\u00efd and Tim G\u00fcneysu (Eds.). Springer International Publishing , Cham , 74--91. Fran\u00e7ois G\u00e9rard and M\u00e9lissa Rossi. 2020. An efficient and provable masked implementation of qTESLA. In Smart Card Research and Advanced Applications, Sonia Bela\u00efd and Tim G\u00fcneysu (Eds.). Springer International Publishing, Cham, 74--91."},{"key":"e_1_2_1_24_1","volume-title":"NIST Non-Invasive Attack Testing Workshop (NIAT\u201911)","author":"Goodwill Gilbert","year":"2011","unstructured":"Gilbert Goodwill , Benjamin Jun , Josh Jaffe , and Pankaj Rohatgi . 2011 . A testing methodology for side-channel resistance validation . In NIST Non-Invasive Attack Testing Workshop (NIAT\u201911) . Gilbert Goodwill, Benjamin Jun, Josh Jaffe, and Pankaj Rohatgi. 2011. A testing methodology for side-channel resistance validation. In NIST Non-Invasive Attack Testing Workshop (NIAT\u201911)."},{"key":"e_1_2_1_25_1","volume-title":"Cryptographic Hardware and Embedded Systems (CHES\u201901) (LNCS), \u00c7etin Kaya Ko\u00e7","author":"Goubin Louis","unstructured":"Louis Goubin . 2001. A sound method for switching between Boolean and arithmetic masking . In Cryptographic Hardware and Embedded Systems (CHES\u201901) (LNCS), \u00c7etin Kaya Ko\u00e7 , David Naccache, and Christof Paar (Eds.), Vol. 2162 . Springer , 3--15. Louis Goubin. 2001. A sound method for switching between Boolean and arithmetic masking. In Cryptographic Hardware and Embedded Systems (CHES\u201901) (LNCS), \u00c7etin Kaya Ko\u00e7, David Naccache, and Christof Paar (Eds.), Vol. 2162. Springer, 3--15."},{"key":"e_1_2_1_26_1","volume-title":"Cryptographic Hardware and Embedded Systems (CHES\u201912) (Lecture Notes in Computer Science)","author":"G\u00fcneysu Tim","unstructured":"Tim G\u00fcneysu , Vadim Lyubashevsky , and Thomas P\u00f6ppelmann . 2012. Practical lattice-based cryptography: A signature scheme for embedded systems . In Cryptographic Hardware and Embedded Systems (CHES\u201912) (Lecture Notes in Computer Science) , Emmanuel Prouff and Patrick Schaumont (Eds.). Springer , Berlin , 530--547. Tim G\u00fcneysu, Vadim Lyubashevsky, and Thomas P\u00f6ppelmann. 2012. Practical lattice-based cryptography: A signature scheme for embedded systems. In Cryptographic Hardware and Embedded Systems (CHES\u201912) (Lecture Notes in Computer Science), Emmanuel Prouff and Patrick Schaumont (Eds.). Springer, Berlin, 530--547."},{"key":"e_1_2_1_27_1","volume-title":"Theory of Cryptography (TCC'17)","author":"Hofheinz Dennis","unstructured":"Dennis Hofheinz , Kathrin H\u00f6velmanns , and Eike Kiltz . 2017. A modular analysis of the Fujisaki-Okamoto transformation . In Theory of Cryptography (TCC'17) , Y. Kalai and L. Reyzin (Eds.). Lecture Notes in Computer Science, vol. 10677 . Springer , Cham. https:\/\/doi.org\/10.1007\/978-3-319-70500-2_12 10.1007\/978-3-319-70500-2_12 Dennis Hofheinz, Kathrin H\u00f6velmanns, and Eike Kiltz. 2017. A modular analysis of the Fujisaki-Okamoto transformation. In Theory of Cryptography (TCC'17), Y. Kalai and L. Reyzin (Eds.). Lecture Notes in Computer Science, vol. 10677. Springer, Cham. https:\/\/doi.org\/10.1007\/978-3-319-70500-2_12"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-018-0191-z"},{"key":"e_1_2_1_29_1","unstructured":"Matthias J. Kannwischer Joost Rijneveld Peter Schwabe and Ko Stoffelen. [n.d.]. PQM4: Post-quantum crypto library for the ARM Cortex-M4.  Matthias J. Kannwischer Joost Rijneveld Peter Schwabe and Ko Stoffelen. [n.d.]. PQM4: Post-quantum crypto library for the ARM Cortex-M4."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2018.i3.243-266"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2018.2814587"},{"key":"e_1_2_1_32_1","volume-title":"RSA, DSS, and other systems. In Advances in Cryptology (CRYPTO\u201996) (LNCS)","author":"Kocher Paul C.","unstructured":"Paul C. Kocher . 1996. Timing attacks on implementations of Diffie-Hellman , RSA, DSS, and other systems. In Advances in Cryptology (CRYPTO\u201996) (LNCS) , Neal Koblitz (Ed.), Vol. 1109 . Springer , 104--113. Paul C. Kocher. 1996. Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In Advances in Cryptology (CRYPTO\u201996) (LNCS), Neal Koblitz (Ed.), Vol. 1109. Springer, 104--113."},{"key":"e_1_2_1_33_1","volume-title":"Advances in Cryptology (CRYPTO\u201999) (LNCS), Michael J","author":"Kocher Paul C.","unstructured":"Paul C. Kocher , Joshua Jaffe , and Benjamin Jun . 1999. Differential power analysis . In Advances in Cryptology (CRYPTO\u201999) (LNCS), Michael J . Wiener (Ed.), Vol. 1666 . Springer , 388--397. Paul C. Kocher, Joshua Jaffe, and Benjamin Jun. 1999. Differential power analysis. In Advances in Cryptology (CRYPTO\u201999) (LNCS), Michael J. Wiener (Ed.), Vol. 1666. Springer, 388--397."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10623-014-9938-4"},{"key":"e_1_2_1_35_1","volume-title":"Proceedings (Lecture Notes in Computer Science), Robert H. Deng, Val\u00e9rie Gauthier-Uma\u00f1a, Mart\u00edn Ochoa, and Moti Yung (Eds.)","volume":"11464","author":"Migliore Vincent","year":"2019","unstructured":"Vincent Migliore , Beno\u00eet G\u00e9rard , Mehdi Tibouchi , and Pierre-Alain Fouque . 2019 . Masking Dilithium - Efficient implementation and side-channel evaluation. In Applied Cryptography and Network Security - 17th International Conference (ACNS\u201919) , Proceedings (Lecture Notes in Computer Science), Robert H. Deng, Val\u00e9rie Gauthier-Uma\u00f1a, Mart\u00edn Ochoa, and Moti Yung (Eds.) , Vol. 11464 . Springer, 344--362. Vincent Migliore, Beno\u00eet G\u00e9rard, Mehdi Tibouchi, and Pierre-Alain Fouque. 2019. Masking Dilithium - Efficient implementation and side-channel evaluation. In Applied Cryptography and Network Security - 17th International Conference (ACNS\u201919), Proceedings (Lecture Notes in Computer Science), Robert H. Deng, Val\u00e9rie Gauthier-Uma\u00f1a, Mart\u00edn Ochoa, and Moti Yung (Eds.), Vol. 11464. Springer, 344--362."},{"key":"e_1_2_1_36_1","volume-title":"Technical Report","author":"Naehrig Michael","unstructured":"Michael Naehrig , Erdem Alkim , Joppe Bos , L\u00e9o Ducas , Karen Easterbrook , Brian LaMacchia , Patrick Longa , Ilya Mironov , Valeria Nikolaenko , Christopher Peikert , Ananth Raghunathan , and Douglas Stebila . 2019. Frodo KEM. Technical Report . National Institute of Standards and Technology . Michael Naehrig, Erdem Alkim, Joppe Bos, L\u00e9o Ducas, Karen Easterbrook, Brian LaMacchia, Patrick Longa, Ilya Mironov, Valeria Nikolaenko, Christopher Peikert, Ananth Raghunathan, and Douglas Stebila. 2019. FrodoKEM. Technical Report. National Institute of Standards and Technology."},{"key":"e_1_2_1_37_1","volume-title":"6th International Workshop, Proceedings (Lecture Notes in Computer Science), Marc Joye and Jean-Jacques Quisquater (Eds.)","volume":"3156","author":"Nei\u00dfe Olaf","year":"2004","unstructured":"Olaf Nei\u00dfe and J\u00fcrgen Pulkus . 2004 . Switching blindings with a view towards IDEA. In Cryptographic Hardware and Embedded Systems (CHES\u201904) : 6th International Workshop, Proceedings (Lecture Notes in Computer Science), Marc Joye and Jean-Jacques Quisquater (Eds.) , Vol. 3156 . Springer, 230--239. Olaf Nei\u00dfe and J\u00fcrgen Pulkus. 2004. Switching blindings with a view towards IDEA. In Cryptographic Hardware and Embedded Systems (CHES\u201904): 6th International Workshop, Proceedings (Lecture Notes in Computer Science), Marc Joye and Jean-Jacques Quisquater (Eds.), Vol. 3156. Springer, 230--239."},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2018.i1.142-174"},{"key":"e_1_2_1_39_1","volume-title":"Progress in Cryptology (LATINCRYPT\u201919), Peter Schwabe and Nicolas Th\u00e9riault (Eds.)","author":"Pessl Peter","unstructured":"Peter Pessl and Robert Primas . 2019. More practical single-trace attacks on the number theoretic transform . In Progress in Cryptology (LATINCRYPT\u201919), Peter Schwabe and Nicolas Th\u00e9riault (Eds.) . Springer International Publishing , Cham , 130--149. Peter Pessl and Robert Primas. 2019. More practical single-trace attacks on the number theoretic transform. In Progress in Cryptology (LATINCRYPT\u201919), Peter Schwabe and Nicolas Th\u00e9riault (Eds.). Springer International Publishing, Cham, 130--149."},{"key":"e_1_2_1_40_1","volume-title":"Smart","author":"Poppelmann Thomas","year":"2019","unstructured":"Thomas Poppelmann , Erdem Alkim , Roberto Avanzi , Joppe Bos , L\u00e9o Ducas , Antonio de la Piedra , Peter Schwabe , Douglas Stebila , Martin R. Albrecht , Emmanuela Orsini , Valery Osheter , Kenneth G. Paterson , Guy Peer , and Nigel P . Smart . 2019 . NewHope. Technical Report. National Institute of Standards and Technology . Thomas Poppelmann, Erdem Alkim, Roberto Avanzi, Joppe Bos, L\u00e9o Ducas, Antonio de la Piedra, Peter Schwabe, Douglas Stebila, Martin R. Albrecht, Emmanuela Orsini, Valery Osheter, Kenneth G. Paterson, Guy Peer, and Nigel P. Smart. 2019. NewHope. Technical Report. National Institute of Standards and Technology."},{"key":"e_1_2_1_41_1","volume-title":"Cryptographic Hardware and Embedded Systems (CHES\u201917)","author":"Primas Robert","unstructured":"Robert Primas , Peter Pessl , and Stefan Mangard . 2017. Single-trace side-channel attacks on masked lattice-based encryption . In Cryptographic Hardware and Embedded Systems (CHES\u201917) , Wieland Fischer and Naofumi Homma (Eds.). Springer International Publishing , Cham , 513--533. Robert Primas, Peter Pessl, and Stefan Mangard. 2017. Single-trace side-channel attacks on masked lattice-based encryption. In Cryptographic Hardware and Embedded Systems (CHES\u201917), Wieland Fischer and Naofumi Homma (Eds.). Springer International Publishing, Cham, 513--533."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2020.i3.307-335"},{"key":"e_1_2_1_43_1","volume-title":"New Lattice-Based Cryptographic Constructions","author":"Regev Oded","unstructured":"Oded Regev . 2004. New Lattice-Based Cryptographic Constructions . Vol. 51- 6 . ACM , 899--942. Oded Regev. 2004. New Lattice-Based Cryptographic Constructions. Vol. 51-6. ACM, 899--942."},{"key":"e_1_2_1_44_1","volume-title":"Frederik Vercauteren, and Ingrid Verbauwhede.","author":"Reparaz Oscar","year":"2016","unstructured":"Oscar Reparaz , Ruan de Clercq , Sujoy Sinha Roy , Frederik Vercauteren, and Ingrid Verbauwhede. 2016 . Additively homomorphic ring-LWE masking. In Post-Quantum Cryptography (PQCrypto\u201916) (LNCS), Tsuyoshi Takagi (Ed.), Vol. 9606 . Springer , 233--244. Oscar Reparaz, Ruan de Clercq, Sujoy Sinha Roy, Frederik Vercauteren, and Ingrid Verbauwhede. 2016. Additively homomorphic ring-LWE masking. In Post-Quantum Cryptography (PQCrypto\u201916) (LNCS), Tsuyoshi Takagi (Ed.), Vol. 9606. Springer, 233--244."},{"key":"e_1_2_1_45_1","volume-title":"17th International Workshop, Proceedings. 683--702","author":"Reparaz Oscar","year":"2015","unstructured":"Oscar Reparaz , Sujoy Sinha Roy , Frederik Vercauteren , and Ingrid Verbauwhede . 2015 . A masked ring-LWE implementation. In Cryptographic Hardware and Embedded Systems (CHES\u201915) - 17th International Workshop, Proceedings. 683--702 . Oscar Reparaz, Sujoy Sinha Roy, Frederik Vercauteren, and Ingrid Verbauwhede. 2015. A masked ring-LWE implementation. In Cryptographic Hardware and Embedded Systems (CHES\u201915) - 17th International Workshop, Proceedings. 683--702."},{"key":"e_1_2_1_46_1","volume-title":"Public-Key Cryptography (PKC\u201919)","author":"Schneider Tobias","unstructured":"Tobias Schneider , Clara Paglialonga , Tobias Oder , and Tim G\u00fcneysu . 2019. Efficiently masking binomial sampling at arbitrary orders for lattice-based crypto . In Public-Key Cryptography (PKC\u201919) , Dongdai Lin and Kazue Sako (Eds.). Springer International Publishing , Cham , 534--564. Tobias Schneider, Clara Paglialonga, Tobias Oder, and Tim G\u00fcneysu. 2019. Efficiently masking binomial sampling at arbitrary orders for lattice-based crypto. In Public-Key Cryptography (PKC\u201919), Dongdai Lin and Kazue Sako (Eds.). Springer International Publishing, Cham, 534--564."},{"key":"e_1_2_1_47_1","volume-title":"Technical Report","author":"Schwabe Peter","unstructured":"Peter Schwabe , Roberto Avanzi , Joppe Bos , L\u00e9o Ducas , Eike Kiltz , Tancr\u00e8de Lepoint , Vadim Lyubashevsky , John M. Schanck , Gregor Seiler , and Damien Stehl\u00e9 . 2019. CRYSTALS- KYBER. Technical Report . National Institute of Standards and Technology . Peter Schwabe, Roberto Avanzi, Joppe Bos, L\u00e9o Ducas, Eike Kiltz, Tancr\u00e8de Lepoint, Vadim Lyubashevsky, John M. Schanck, Gregor Seiler, and Damien Stehl\u00e9. 2019. CRYSTALS-KYBER. Technical Report. National Institute of Standards and Technology."},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1137\/S0097539795293172"},{"key":"e_1_2_1_49_1","volume-title":"Post-Quantum Security of the Fujisaki-Okamoto and OAEP Transforms","author":"Targhi Ehsan Ebrahimi","unstructured":"Ehsan Ebrahimi Targhi and Dominique Unruh . 2016. Post-Quantum Security of the Fujisaki-Okamoto and OAEP Transforms . Springer Berlin , Berlin ,192--216. Ehsan Ebrahimi Targhi and Dominique Unruh. 2016. Post-Quantum Security of the Fujisaki-Okamoto and OAEP Transforms. Springer Berlin, Berlin,192--216."},{"key":"e_1_2_1_50_1","unstructured":"Henry S. Warren. 2013. Hackers Delight. Addison-Wesley.  Henry S. Warren. 2013. Hackers Delight. Addison-Wesley."}],"container-title":["ACM Journal on Emerging Technologies in Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3429983","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3429983","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:31:46Z","timestamp":1750195906000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3429983"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,4,23]]},"references-count":49,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2021,4,30]]}},"alternative-id":["10.1145\/3429983"],"URL":"https:\/\/doi.org\/10.1145\/3429983","relation":{},"ISSN":["1550-4832","1550-4840"],"issn-type":[{"value":"1550-4832","type":"print"},{"value":"1550-4840","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,4,23]]},"assertion":[{"value":"2020-06-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-10-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-04-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}