{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T05:47:56Z","timestamp":1769752076196,"version":"3.49.0"},"reference-count":61,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T00:00:00Z","timestamp":1740096000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2025,3,31]]},"abstract":"<jats:p>\n            A prominent countermeasure against side-channel attacks, the\n            <jats:italic>hiding countermeasure<\/jats:italic>\n            , typically involves shuffling operations using a permutation algorithm. This is especially crucial in the era of Post-quantum Cryptography, where computational characteristics of lattice and code-based cryptography heighten the need for robust defenses. In this context, securely and efficiently generating permutations is critical for an algorithm\u2019s overall security and performance. Among the various approaches, the Fisher-Yates shuffle is widely adopted due to its security and ease of implementation. However, it is limited by a complexity of\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\mathcal {O}(N)\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            due to its sequential nature. In response, we propose a time-area tradeoff swap algorithm,\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\mathsf {FSS}\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            , that leverages a Butterfly Network structure, achieving only\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\log (N)\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            depth,\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\log (N)\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            work, and\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\mathcal {O}(1)\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            operation time in parallel. Our analysis calculates the maximum gain an attacker can achieve through butterfly operations with\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\log (N)\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            depth from a side-channel analysis perspective. Notably, we derive a generalized formula for the attack complexity of higher-order side-channel attacks for arbitrary input sizes, utilizing the fractal structure of the butterfly network. Moreover, our research demonstrates the efficiency and security of this permutation approach across different platforms. We include practical implementation results on ASIC as well as on CPU and GPU architectures, which underscore the algorithm\u2019s performance advantages and robustness across diverse hardware environments. Through this exploration, we show that efficient and secure permutations can indeed be achieved with minimal randomness requirements.\n          <\/jats:p>","DOI":"10.1145\/3715961","type":"journal-article","created":{"date-parts":[[2025,2,3]],"date-time":"2025-02-03T09:53:11Z","timestamp":1738576391000},"page":"1-40","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["A Compact and Parallel Swap-Based Shuffler Based on Butterfly Network and Its Complexity Against Side Channel Analysis"],"prefix":"10.1145","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1892-1698","authenticated-orcid":false,"given":"Jong-Yeon","family":"Park","sequence":"first","affiliation":[{"name":"Samsung Electronics, Hwasung, Korea (the Republic of)"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0139-2224","authenticated-orcid":false,"given":"Seonggyeom","family":"Kim","sequence":"additional","affiliation":[{"name":"Samsung Electronics, Hwasung, Korea (the Republic of)"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-9920-0453","authenticated-orcid":false,"given":"Wonil","family":"Lee","sequence":"additional","affiliation":[{"name":"Samsung Electronics, Hwasung, Korea (the Republic of)"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-9750-641X","authenticated-orcid":false,"given":"Bo Gyeong","family":"Kang","sequence":"additional","affiliation":[{"name":"Samsung Electronics, Hwasung, Korea (the Republic of)"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-2312-7559","authenticated-orcid":false,"given":"Il-Jong","family":"Song","sequence":"additional","affiliation":[{"name":"Samsung Electronics, Hwasung, Korea (the Republic of)"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7040-2586","authenticated-orcid":false,"given":"Jaekeun","family":"Oh","sequence":"additional","affiliation":[{"name":"Samsung Electronics, Hwasung, Korea (the Republic of)"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4621-1674","authenticated-orcid":false,"given":"Kouichi","family":"Sakurai","sequence":"additional","affiliation":[{"name":"Kyushu University, Fukuoka, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,2,21]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"NIST Computer Secuirty Resouce Center. 2022. NIST round 4 submission. Retrieved from https:\/\/csrc.nist.gov\/Projects\/post-quantum-cryptography\/round-4-submissions"},{"key":"e_1_3_1_3_2","article-title":"MergeShuffle: A very fast, parallel random permutation algorithm","author":"Bacher Axel","year":"2015","unstructured":"Axel Bacher, Olivier Bodini, Alexandros Hollender, and J\u00e9r\u00e9mie Lumbroso. 2015. MergeShuffle: A very fast, parallel random permutation algorithm. arXiv preprint arXiv:1508.03167 (2015).","journal-title":"arXiv preprint arXiv:1508.03167"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/2086696.2086699"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","unstructured":"V. E. Bene\u0161. 1964. Optimal rearrangeable multistage connecting networks. In The Bell System Technical Journal 43 4 (1964) 1641\u20131656. DOI:10.1002\/j.1538-7305.1964.tb04103.x","DOI":"10.1002\/j.1538-7305.1964.tb04103.x"},{"key":"e_1_3_1_6_2","first-page":"39","volume-title":"Workshop on Fault Detection and Tolerance in Cryptography (FDTC\u201921)","author":"Bettale Luk","year":"2021","unstructured":"Luk Bettale, Simon Montoya, and Gu\u00e9na\u00ebl Renault. 2021. Safe-error analysis of post-quantum cryptography mechanisms-short paper. In Workshop on Fault Detection and Tolerance in Cryptography (FDTC\u201921). IEEE, 39\u201344."},{"key":"e_1_3_1_7_2","volume-title":"Probability and Measure","author":"Billingsley Patrick","year":"2017","unstructured":"Patrick Billingsley. 2017. Probability and Measure. John Wiley & Sons."},{"key":"e_1_3_1_8_2","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1007\/3-540-45760-7_9","volume-title":"Topics in Cryptology - CT-RSA 2002: The Cryptographers\u2019 Track at the RSA Conference 2002 San Jose, CA, USA, February 18\u201322, 2002 Proceedings","author":"Black John","year":"2002","unstructured":"John Black and Phillip Rogaway. 2002. Ciphers with arbitrary finite domains. In Topics in Cryptology - CT-RSA 2002: The Cryptographers\u2019 Track at the RSA Conference 2002 San Jose, CA, USA, February 18\u201322, 2002 Proceedings. Springer, 114\u2013130."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-28632-5_2"},{"key":"e_1_3_1_10_2","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1007\/3-540-36400-5_3","volume-title":"Cryptographic Hardware and Embedded Systems-CHES 2002: 4th International Workshop","author":"Chari Suresh","year":"2003","unstructured":"Suresh Chari, Josyula R. Rao, and Pankaj Rohatgi. 2003. Template attacks. In Cryptographic Hardware and Embedded Systems-CHES 2002: 4th International Workshop. Springer, 13\u201328."},{"issue":"1","key":"e_1_3_1_11_2","doi-asserted-by":"crossref","first-page":"322","DOI":"10.1109\/TCAD.2022.3174142","article-title":"Low-cost shuffling countermeasures against side-channel attacks for NTT-based post-quantum cryptography","volume":"42","author":"Chen Zhaohui","year":"2022","unstructured":"Zhaohui Chen, Yuan Ma, and Jiwu Jing. 2022. Low-cost shuffling countermeasures against side-channel attacks for NTT-based post-quantum cryptography. IEEE Trans. Comput.-aid. Des. Integ. Circ. Syst. 42, 1 (2022), 322\u2013326.","journal-title":"IEEE Trans. Comput.-aid. Des. Integ. Circ. Syst."},{"key":"e_1_3_1_12_2","first-page":"27","volume-title":"International Conference on Parallel and Distributed Computing and Systems (PDCS\u201905)","author":"Cong Guojing","year":"2005","unstructured":"Guojing Cong and David A. Bader. 2005. An empirical analysis of parallel random permutation algorithms ON SMPs. In International Conference on Parallel and Distributed Computing and Systems (PDCS\u201905). 27\u201334."},{"key":"e_1_3_1_13_2","first-page":"703","volume-title":"47th Annual ACM Symposium on Theory of Computing","author":"Czumaj Artur","year":"2015","unstructured":"Artur Czumaj. 2015. Random permutations using switching networks. In 47th Annual ACM Symposium on Theory of Computing. 703\u2013712."},{"key":"e_1_3_1_14_2","first-page":"38G","article-title":"Recommendation for block cipher modes of operation","volume":"800","author":"Dworkin Morris","year":"2016","unstructured":"Morris Dworkin. 2016. Recommendation for block cipher modes of operation. NIST Spec. Pub. 800 (2016), 38G.","journal-title":"NIST Spec. Pub."},{"key":"e_1_3_1_15_2","volume-title":"Statistical Tables for Biological, Agricultural, and Medical Research","author":"Fisher Ronald Aylmer","year":"1953","unstructured":"Ronald Aylmer Fisher and Frank Yates. 1953. Statistical Tables for Biological, Agricultural, and Medical Research. Hafner Publishing Company."},{"key":"e_1_3_1_16_2","article-title":"Federal information processing standards publication digital signature standard (DSS)","author":"Gallagher P.","year":"2009","unstructured":"P. Gallagher. 2009. Federal information processing standards publication digital signature standard (DSS). FIPS Pub. 186-3 (2009), 23\u201325.","journal-title":"FIPS Pub. 186-3"},{"key":"e_1_3_1_17_2","volume-title":"34th International Conference on Foundation of Software Technology and Theoretical Computer Science (FSTTCS\u201914)","author":"Gelman Efraim","year":"2014","unstructured":"Efraim Gelman and Amnon Ta-Shma. 2014. The Benes network is q*(q-1)\/2n-Almost q-set-wise independent. In 34th International Conference on Foundation of Software Technology and Theoretical Computer Science (FSTTCS\u201914). Schloss-Dagstuhl-Leibniz Zentrum f\u00fcr Informatik."},{"key":"e_1_3_1_18_2","first-page":"426","volume-title":"International Workshop on Cryptographic Hardware and Embedded Systems","author":"Gierlichs Benedikt","year":"2008","unstructured":"Benedikt Gierlichs, Lejla Batina, Pim Tuyls, and Bart Preneel. 2008. Mutual information analysis: A generic side-channel distinguisher. In International Workshop on Cryptographic Hardware and Embedded Systems. Springer, 426\u2013442."},{"key":"e_1_3_1_19_2","first-page":"223","article-title":"Don\u2019t reject this: Key-recovery timing attacks due to rejection-sampling in HQC and BIKE","author":"Guo Qian","year":"2022","unstructured":"Qian Guo, Clemens Hlauschek, Thomas Johansson, Norman Lahr, Alexander Nilsson, and Robin Leander Schr\u00f6der. 2022. Don\u2019t reject this: Key-recovery timing attacks due to rejection-sampling in HQC and BIKE. IACR Trans. Cryptog. Hardw. Embed. Syst. 2022, 3 (2022), 223\u2013263.","journal-title":"IACR Trans. Cryptog. Hardw. Embed. Syst."},{"key":"e_1_3_1_20_2","first-page":"129","volume-title":"International Workshop on Experimental and Efficient Algorithms","author":"Gustedt Jens","year":"2008","unstructured":"Jens Gustedt. 2008. Engineering parallel in-place random generation of integer permutations. In International Workshop on Experimental and Efficient Algorithms. Springer, 129\u2013141."},{"key":"e_1_3_1_21_2","first-page":"1","volume-title":"Advances in Cryptology\u2013CRYPTO 2012: 32nd Annual Cryptology Conference, Santa Barbara, CA, USA, August 19\u201323, 2012. Proceedings","author":"Hoang Viet Tung","year":"2012","unstructured":"Viet Tung Hoang, Ben Morris, and Phillip Rogaway. 2012. An enciphering scheme based on a card shuffle. In Advances in Cryptology\u2013CRYPTO 2012: 32nd Annual Cryptology Conference, Santa Barbara, CA, USA, August 19\u201323, 2012. Proceedings. Springer, 1\u201313."},{"key":"e_1_3_1_22_2","volume-title":"Art of Computer Programming, Volume 2: Seminumerical Algorithms","author":"Knuth Donald E.","year":"2014","unstructured":"Donald E. Knuth. 2014. Art of Computer Programming, Volume 2: Seminumerical Algorithms. Addison-Wesley Professional."},{"key":"e_1_3_1_23_2","doi-asserted-by":"crossref","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","volume-title":"Advances in Cryptology\u2013CRYPTO\u201999: 19th Annual International Cryptology Conference","author":"Kocher Paul","year":"1999","unstructured":"Paul Kocher, Joshua Jaffe, and Benjamin Jun. 1999. Differential power analysis. In Advances in Cryptology\u2013CRYPTO\u201999: 19th Annual International Cryptology Conference. Springer, 388\u2013397."},{"key":"e_1_3_1_24_2","doi-asserted-by":"crossref","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","volume-title":"Advances in Cryptology\u2013CRYPTO\u201996: 16th Annual International Cryptology Conference","author":"Kocher Paul C.","year":"1996","unstructured":"Paul C. Kocher. 1996. Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In Advances in Cryptology\u2013CRYPTO\u201996: 16th Annual International Cryptology Conference. Springer, 104\u2013113."},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","unstructured":"E. Krahmer et\u00a0al. 2024. Correction fault attacks on randomized CRYSTALS-Dilithium. IACR Transactions on Cryptographic Hardware and Embedded Systems 2024 3 (2024) 174\u2013199. DOI:10.46586\/tches.v2024.i3.174-199","DOI":"10.46586\/tches.v2024.i3.174-199"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/2669372"},{"key":"e_1_3_1_27_2","doi-asserted-by":"crossref","first-page":"343","DOI":"10.1007\/3-540-36552-4_24","volume-title":"Information Security and Cryptology\u2013ICISC 2002: 5th International Conference","author":"Mangard Stefan","year":"2003","unstructured":"Stefan Mangard. 2003. A simple power-analysis (SPA) attack on implementations of the AES key expansion. In Information Security and Cryptology\u2013ICISC 2002: 5th International Conference. Springer, 343\u2013358."},{"key":"e_1_3_1_28_2","volume-title":"Power Analysis Attacks: Revealing the Secrets of Smart Cards","author":"Mangard Stefan","year":"2008","unstructured":"Stefan Mangard, Elisabeth Oswald, and Thomas Popp. 2008. Power Analysis Attacks: Revealing the Secrets of Smart Cards. Vol. 31. Springer Science & Business Media."},{"key":"e_1_3_1_29_2","first-page":"238","volume-title":"International Workshop on Cryptographic Hardware and Embedded Systems","author":"Messerges Thomas S.","year":"2000","unstructured":"Thomas S. Messerges. 2000. Using 2nd-order power analysis to attack DPA resistant software. In International Workshop on Cryptographic Hardware and Embedded Systems. Springer, 238\u2013251."},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3505287"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1137\/050636231"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1214\/08-AOP409"},{"issue":"1","key":"e_1_3_1_33_2","doi-asserted-by":"crossref","first-page":"118","DOI":"10.1017\/S0963548312000478","article-title":"Improved mixing time bounds for the Thorp shuffle","volume":"22","author":"Morris Ben","year":"2013","unstructured":"Ben Morris. 2013. Improved mixing time bounds for the Thorp shuffle. Combinat., Probab. Comput. 22, 1 (2013), 118\u2013132.","journal-title":"Combinat., Probab. Comput."},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-017-9262-z"},{"key":"e_1_3_1_35_2","unstructured":"NIST. 2015. SHA-3 Standardization. Retrieved from https:\/\/csrc.nist.gov\/Projects\/Hash-Functions\/SHA-3-Project\/SHA-3-Standardization"},{"key":"e_1_3_1_36_2","volume-title":"FIPS 203 Module-Lattice-based Key-Encapsulation Mechanism Standard","year":"2022","unstructured":"NIST. 2022. FIPS 203 Module-Lattice-based Key-Encapsulation Mechanism Standard. Technical Report. NIST."},{"key":"e_1_3_1_37_2","volume-title":"FIPS 204 Module-Lattice-based Digital Signature Standard","year":"2022","unstructured":"NIST. 2022. FIPS 204 Module-Lattice-based Digital Signature Standard. Technical Report. NIST."},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2024.103797"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/TETC.2024.3478228"},{"key":"e_1_3_1_40_2","article-title":"Engineering shared-memory parallel shuffling to generate random permutations in-place","author":"Penschuck Manuel","year":"2023","unstructured":"Manuel Penschuck. 2023. Engineering shared-memory parallel shuffling to generate random permutations in-place. arXiv preprint arXiv:2302.03317 (2023).","journal-title":"arXiv preprint arXiv:2302.03317"},{"key":"e_1_3_1_41_2","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1007\/978-3-319-49890-4_9","volume-title":"Progress in Cryptology\u2013INDOCRYPT 2016: 17th International Conference on Cryptology in India","author":"Pessl Peter","year":"2016","unstructured":"Peter Pessl. 2016. Analyzing the shuffling side-channel countermeasure for lattice-based signatures. In Progress in Cryptology\u2013INDOCRYPT 2016: 17th International Conference on Cryptology in India. Springer, 153\u2013170."},{"key":"e_1_3_1_42_2","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1007\/978-3-030-30530-7_7","volume-title":"Progress in Cryptology\u2013LATINCRYPT 2019: 6th International Conference on Cryptology and Information Security in Latin America, Santiago de Chile, Chile, October 2\u20134, 2019, Proceedings 6","author":"Pessl Peter","year":"2019","unstructured":"Peter Pessl and Robert Primas. 2019. More practical single-trace attacks on the number theoretic transform. In Progress in Cryptology\u2013LATINCRYPT 2019: 6th International Conference on Cryptology and Information Security in Latin America, Santiago de Chile, Chile, October 2\u20134, 2019, Proceedings 6. Springer, 130\u2013149."},{"key":"e_1_3_1_43_2","doi-asserted-by":"crossref","first-page":"513","DOI":"10.1007\/978-3-319-66787-4_25","volume-title":"Cryptographic Hardware and Embedded Systems\u2013CHES 2017: 19th International Conference, Taipei, Taiwan, September 25\u201328, 2017, Proceedings","author":"Primas Robert","year":"2017","unstructured":"Robert Primas, Peter Pessl, and Stefan Mangard. 2017. Single-trace side-channel attacks on masked lattice-based encryption. In Cryptographic Hardware and Embedded Systems\u2013CHES 2017: 19th International Conference, Taipei, Taiwan, September 25\u201328, 2017, Proceedings. Springer, 513\u2013533."},{"issue":"2","key":"e_1_3_1_44_2","first-page":"37","article-title":"Fault attacks on CCA-secure lattice KEMs","volume":"2021","author":"Prokop Lukas","year":"2021","unstructured":"Lukas Prokop and Peter Pe\u00dfl. 2021. Fault attacks on CCA-secure lattice KEMs. IACR Trans. Cryptog. Hardw. Embed. Syst. 2021, 2 (2021), 37\u201360.","journal-title":"IACR Trans. Cryptog. Hardw. Embed. Syst."},{"key":"e_1_3_1_45_2","article-title":"Single trace is all it takes: Efficient side-channel attack on dilithium","author":"Qiao Zehua","year":"2024","unstructured":"Zehua Qiao, Yuejun Liu, Yongbin Zhou, Yuhan Zhao, and Shuyi Chen. 2024. Single trace is all it takes: Efficient side-channel attack on dilithium. Cryptology ePrint Archive Paper 2024\/512, 2024. https:\/\/eprint.iacr.org\/2024\/512","journal-title":"Cryptology ePrint Archive Paper"},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-66626-2_7"},{"key":"e_1_3_1_47_2","doi-asserted-by":"crossref","first-page":"392","DOI":"10.1007\/978-3-642-40041-4_22","volume-title":"Advances in Cryptology\u2013CRYPTO 2013: 33rd Annual Cryptology Conference, Santa Barbara, CA, USA, August 18\u201322, 2013. Proceedings, Part I","author":"Ristenpart Thomas","year":"2013","unstructured":"Thomas Ristenpart and Scott Yilek. 2013. The mix-and-cut shuffle: Small-domain encryption secure against N queries. In Advances in Cryptology\u2013CRYPTO 2013: 33rd Annual Cryptology Conference, Santa Barbara, CA, USA, August 18\u201322, 2013. Proceedings, Part I. Springer, 392\u2013409."},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"e_1_3_1_49_2","first-page":"1","volume-title":"International Conference for High Performance Computing, Networking, Storage and Analysis","author":"Salmon John K.","year":"2011","unstructured":"John K. Salmon, Mark A. Moraes, Ron O. Dror, and David E. Shaw. 2011. Parallel random numbers: As easy as 1, 2, 3. In International Conference for High Performance Computing, Networking, Storage and Analysis. 1\u201312."},{"issue":"1","key":"e_1_3_1_50_2","first-page":"266","article-title":"Enhancing hardware trojan detection sensitivity using partition-based shuffling scheme","volume":"68","author":"Shabani Ahmad","year":"2020","unstructured":"Ahmad Shabani and Bijan Alizadeh. 2020. Enhancing hardware trojan detection sensitivity using partition-based shuffling scheme. IEEE Trans. Circ. Syst. II: Expr. Briefs 68, 1 (2020), 266\u2013270.","journal-title":"IEEE Trans. Circ. Syst. II: Expr. Briefs"},{"key":"e_1_3_1_51_2","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1948.tb01338.x"},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1994.365700"},{"key":"e_1_3_1_53_2","first-page":"431","volume-title":"26th Annual ACM-SIAM Symposium on Discrete Algorithms","author":"Shun Julian","year":"2014","unstructured":"Julian Shun, Yan Gu, Guy E. Blelloch, Jeremy T. Fineman, and Phillip B. Gibbons. 2014. Sequential random permutation, list contraction and tree contraction are highly parallel. In 26th Annual ACM-SIAM Symposium on Discrete Algorithms. SIAM, 431\u2013448."},{"key":"e_1_3_1_54_2","doi-asserted-by":"crossref","first-page":"183175","DOI":"10.1109\/ACCESS.2020.3029521","article-title":"Single-trace attacks on message encoding in lattice-based KEMs","volume":"8","author":"Sim Bo-Yeon","year":"2020","unstructured":"Bo-Yeon Sim, Jihoon Kwon, Joohee Lee, Il-Ju Kim, Tae-Ho Lee, Jaeseung Han, Hyojin Yoon, Jihoon Cho, and Dong-Guk Han. 2020. Single-trace attacks on message encoding in lattice-based KEMs. IEEE Access 8 (2020), 183175\u2013183191.","journal-title":"IEEE Access"},{"issue":"1","key":"e_1_3_1_55_2","first-page":"3","article-title":"Announcing the advanced encryption standard (AES)","volume":"197","author":"Standard NIST-FIPS","year":"2001","unstructured":"NIST-FIPS Standard. 2001. Announcing the advanced encryption standard (AES). Federal Information Processing Standards Publication 197, 1-51 (2001), 3\u20133.","journal-title":"Federal Information Processing Standards Publication"},{"key":"e_1_3_1_56_2","volume-title":"Computer Networks","author":"Tanenbaum Andrew S.","year":"2003","unstructured":"Andrew S. Tanenbaum. 2003. Computer Networks. Pearson Education India."},{"key":"e_1_3_1_57_2","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1007\/978-3-540-72738-5_10","volume-title":"Applied Cryptography and Network Security: 5th International Conference, ACNS 2007, Zhuhai, China, June 5\u20138, 2007. Proceedings","author":"Tillich Stefan","year":"2007","unstructured":"Stefan Tillich, Christoph Herbst, and Stefan Mangard. 2007. Protecting AES software implementations on 32-bit processors against power analysis. In Applied Cryptography and Network Security: 5th International Conference, ACNS 2007, Zhuhai, China, June 5\u20138, 2007. Proceedings. Springer Berlin, 141\u2013157."},{"key":"e_1_3_1_58_2","doi-asserted-by":"crossref","first-page":"740","DOI":"10.1007\/978-3-642-34961-4_44","volume-title":"Advances in Cryptology\u2013ASIACRYPT 2012: 18th International Conference on the Theory and Application of Cryptology and Information Security, Beijing, China, December 2\u20136, 2012. Proceedings 18","author":"Veyrat-Charvillon Nicolas","year":"2012","unstructured":"Nicolas Veyrat-Charvillon, Marcel Medwed, St\u00e9phanie Kerckhof, and Fran\u00e7ois-Xavier Standaert. 2012. Shuffling against side-channel attacks: A comprehensive study with cautionary note. In Advances in Cryptology\u2013ASIACRYPT 2012: 18th International Conference on the Theory and Application of Cryptology and Information Security, Beijing, China, December 2\u20136, 2012. Proceedings 18. Springer, 740\u2013757."},{"key":"e_1_3_1_59_2","first-page":"1","volume-title":"International Workshop on Cryptographic Hardware and Embedded Systems","author":"Waddle Jason","year":"2004","unstructured":"Jason Waddle and David Wagner. 2004. Towards efficient 2nd-order power analysis. In International Workshop on Cryptographic Hardware and Embedded Systems. Springer, 1\u201315."},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.3390\/app10113804"},{"issue":"9","key":"e_1_3_1_61_2","doi-asserted-by":"crossref","first-page":"967","DOI":"10.1109\/12.869328","article-title":"Checking before output may not be enough against fault-based cryptanalysis","volume":"49","author":"Yen Sung-Ming","year":"2000","unstructured":"Sung-Ming Yen and Marc Joye. 2000. Checking before output may not be enough against fault-based cryptanalysis. IEEE Trans. Comput. 49, 9 (2000), 967\u2013970.","journal-title":"IEEE Trans. Comput."},{"key":"e_1_3_1_62_2","doi-asserted-by":"crossref","first-page":"535","DOI":"10.1007\/978-3-030-35423-7_27","volume-title":"Progress in Cryptology\u2013INDOCRYPT 2019: 20th International Conference on Cryptology in India, Hyderabad, India, December 15\u201318, 2019, Proceedings 20","author":"Zijlstra Timo","year":"2019","unstructured":"Timo Zijlstra, Karim Bigou, and Arnaud Tisserand. 2019. FPGA implementation and comparison of protections against SCAs for RLWE. In Progress in Cryptology\u2013INDOCRYPT 2019: 20th International Conference on Cryptology in India, Hyderabad, India, December 15\u201318, 2019, Proceedings 20. Springer, 535\u2013555."}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3715961","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3715961","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:49Z","timestamp":1750295929000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3715961"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2,21]]},"references-count":61,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,3,31]]}},"alternative-id":["10.1145\/3715961"],"URL":"https:\/\/doi.org\/10.1145\/3715961","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"value":"1539-9087","type":"print"},{"value":"1558-3465","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,2,21]]},"assertion":[{"value":"2024-06-20","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-01-22","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}