{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,27]],"date-time":"2026-07-27T04:10:31Z","timestamp":1785125431636,"version":"3.55.0"},"reference-count":25,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:00:00Z","timestamp":1622592000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:00:00Z","timestamp":1622592000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["No.61632020"],"award-info":[{"award-number":["No.61632020"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["No.U1936209"],"award-info":[{"award-number":["No.U1936209"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["No.62002353"],"award-info":[{"award-number":["No.62002353"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Beijing Natural Science Foundation","award":["No.4192067"],"award-info":[{"award-number":["No.4192067"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2021,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Due to its provable security and remarkable device-independence, masking has been widely accepted as a noteworthy algorithmic-level countermeasure against side-channel attacks. However, relatively high cost of masking severely limits its applicability. Considering the high tackling complexity of non-linear operations, most masked AES implementations focus on the security and cost reduction of masked S-boxes. In this paper, we focus on linear operations, which seems to be underestimated, on the contrary. Specifically, we discover some security flaws and redundant processes in popular first-order masked AES linear operations, and pinpoint the underlying root causes. Then we propose a provably secure and highly efficient masking scheme for AES linear operations. In order to show its practical implications, we replace the linear operations of state-of-the-art first-order AES masking schemes with our proposal, while keeping their original non-linear operations unchanged. We implement four newly combined masking schemes on an Intel Core i7-4790 CPU, and the results show they are roughly 20% faster than those original ones. Then we select one masked implementation named RSMv2 due to its popularity, and investigate its security and efficiency on an AVR ATMega163 processor and four different FPGA devices. The results show that no exploitable first-order side-channel leakages are detected. Moreover, compared with original masked AES implementations, our combined approach is nearly 25% faster on the AVR processor, and at least 70% more efficient on four FPGA devices.<\/jats:p>","DOI":"10.1186\/s42400-021-00082-w","type":"journal-article","created":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:04:21Z","timestamp":1622592261000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["A secure and highly efficient first-order masking scheme for AES linear operations"],"prefix":"10.1186","volume":"4","author":[{"given":"Jingdian","family":"Ming","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yongbin","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huizhong","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qian","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,6,2]]},"reference":[{"key":"82_CR1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-12060-7_14","volume-title":"Security, Privacy, and Applied Cryptography Engineering. SPACE 2014. Lecture Notes in Computer Science, vol 8804","author":"S Bhasin","year":"2014","unstructured":"Bhasin, S, Bruneau N, Danger J, Guilley S, Najm Z (2014) Analysis and improvements of the DPA contest v4 implementation. In: Chakraborty RS, Matyas V, Schaumont P (eds)Security, Privacy, and Applied Cryptography Engineering. SPACE 2014. Lecture Notes in Computer Science, vol 8804.. Springer, Cham. https:\/\/doi.org\/10.1007\/978-3-319-12060-7_14."},{"key":"82_CR2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-55220-5_25","volume-title":"Advances in Cryptology - EUROCRYPT 2014. EUROCRYPT 2014. Lecture Notes in Computer Science, vol 8441","author":"J Coron","year":"2014","unstructured":"Coron, J (2014) Higher order masking of look-up tables. In: Nguyen PQ Oswald E (eds)Advances in Cryptology - EUROCRYPT 2014. EUROCRYPT 2014. Lecture Notes in Computer Science, vol 8441.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-642-55220-5_25."},{"key":"82_CR3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74735-2_3","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2007. CHES 2007. Lecture Notes in Computer Science, vol 4727","author":"J Coron","year":"2007","unstructured":"Coron, J, Prouff E, Rivain M (2007) Side channel cryptanalysis of a higher order masking scheme. In: Paillier P Verbauwhede I (eds)Cryptographic Hardware and Embedded Systems - CHES 2007. CHES 2007. Lecture Notes in Computer Science, vol 4727.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-540-74735-2_3."},{"key":"82_CR4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44709-3_10","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2014. CHES 2014. Lecture Notes in Computer Science, vol 8731","author":"J Coron","year":"2014","unstructured":"Coron, J, Roy A, Vivek S (2014) Fast evaluation of polynomials over binary finite fields and application to side-channel countermeasures. In: Batina L Robshaw M (eds)Cryptographic Hardware and Embedded Systems - CHES 2014. CHES 2014. Lecture Notes in Computer Science, vol 8731.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-662-44709-3_10."},{"key":"82_CR5","doi-asserted-by":"publisher","first-page":"40","DOI":"10.46586\/tches.v2018.i1.40-72","volume":"1","author":"J Coron","year":"2018","unstructured":"Coron, J, Rondepierre F, Zeitoun R (2018) High order masking of look-up tables with common shares. IACR Trans Cryptogr Hardw Embed Syst 1:40\u201372. https:\/\/doi.org\/10.13154\/tches.v2018.i1.40-72.","journal-title":"IACR Trans Cryptogr Hardw Embed Syst"},{"issue":"4","key":"82_CR6","doi-asserted-by":"publisher","first-page":"1263","DOI":"10.1007\/s00145-018-9277-0","volume":"32","author":"A Duc","year":"2019","unstructured":"Duc, A, Faust S, Standaert F (2019) Making masking security proofs concrete (or how to evaluate the security of any leaking device), extended version. J Cryptol 32(4):1263\u20131297. https:\/\/doi.org\/10.1007\/s00145-018-9277-0.","journal-title":"J Cryptol"},{"issue":"21","key":"82_CR7","first-page":"49","volume":"25","author":"J Fang","year":"2009","unstructured":"Fang, J (2009) Mixcolumn round transformation optimization and improvement in the aes algorithm. Microcomput Inf 25(21):49\u201351.","journal-title":"Microcomput Inf"},{"key":"82_CR8","unstructured":"FIPS Publication 140-3 (2019) Security Requirements for Cryptographic Modules. The National Institute of Standards and Technology. https:\/\/nvlpubs.nist.gov\/nistpubs\/FIPS\/NIST.FIPS.140-3.pdf."},{"key":"82_CR9","unstructured":"Gilbert Goodwill, BJ, Jaffe J, Rohatgi P, et al. (2011) A testing methodology for side-channel resistance validation In: NIST non-invasive attack testing workshop, vol 7, 115\u2013136.. NIST. https:\/\/csrc.nist.gov\/csrc\/media\/events\/non-invasive-attack-testing-workshop\/documents\/08_goodwill.pdf."},{"key":"82_CR10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45146-4_27","volume-title":"Advances in Cryptology - CRYPTO 2003. CRYPTO 2003. Lecture Notes in Computer Science, vol 2729","author":"Y Ishai","year":"2003","unstructured":"Ishai, Y, Sahai A, Wagner DA (2003) Private circuits: Securing hardware against probing attacks. In: Boneh D (ed)Advances in Cryptology - CRYPTO 2003. CRYPTO 2003. Lecture Notes in Computer Science, vol 2729.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-540-45146-4_27."},{"key":"82_CR11","unstructured":"JTC, I (2016) Iso\/iec 17825:2016 information technology - security techniques - testing methods for the mitigation of non-invasive attack classes against cryptographic modules. https:\/\/www.iso.org\/standard\/60612.html."},{"key":"82_CR12","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-68697-5_9","volume-title":"Advances in Cryptology - CRYPTO \u201996. CRYPTO 1996. Lecture Notes in Computer Science, vol 1109","author":"P Kocher","year":"1996","unstructured":"Kocher, P (1996) Timing Attacks on Implementations of Diffie-Hellman, RSA, DSS, and Other Systems. In: Koblitz N (ed)Advances in Cryptology - CRYPTO \u201996. CRYPTO 1996. Lecture Notes in Computer Science, vol 1109.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/3-540-68697-5_9."},{"key":"82_CR13","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48405-1_25","volume-title":"Advances in Cryptology ? CRYPTO? 99. CRYPTO 1999. Lecture Notes in Computer Science, vol 1666","author":"PC Kocher","year":"1999","unstructured":"Kocher, PC, Jaffe J, Jun B (1999) Differential power analysis. In: Wiener M (ed)Advances in Cryptology ? CRYPTO? 99. CRYPTO 1999. Lecture Notes in Computer Science, vol 1666.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/3-540-48405-1_25."},{"key":"82_CR14","doi-asserted-by":"publisher","first-page":"3694","DOI":"10.1109\/TIFS.2020.2994775","volume":"15","author":"J Ming","year":"2020","unstructured":"Ming, J, Zhou Y, Cheng W, Li H, Yang G, Zhang Q (2020) Mind the balance: Revealing the vulnerabilities in low entropy masking schemes. IEEE Trans Inf Forensics Secur 15:3694\u20133708. https:\/\/doi.org\/10.1109\/TIFS.2020.2994775.","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"82_CR15","doi-asserted-by":"publisher","unstructured":"Nassar, M, Souissi Y, Guilley S, Danger J (2012) RSM: A small and fast countermeasure for aes, secure against 1st and 2nd-order zero-offset scas In: 2012 Design, Automation & Test in Europe Conference & Exhibition, DATE 2012, Dresden, Germany, March 12-16, 2012, 1173\u20131178. https:\/\/doi.org\/10.1109\/DATE.2012.6176671.","DOI":"10.1109\/DATE.2012.6176671"},{"key":"82_CR16","unstructured":"ParisTech, T (2015) Dpa contest v4.2. documentation. http:\/\/www.dpacontest.org\/v4\/42_doc.php. Accessed 27 Aug 2015."},{"key":"82_CR17","unstructured":"Prouff, E, Strullu R, Benadjila R, Cagli E, Dumas C (2018) Study of deep learning techniques for side-channel analysis and introduction to ASCAD database. IACR Cryptol ePrint Arch 53. http:\/\/eprint.iacr.org\/2018\/053."},{"key":"82_CR18","doi-asserted-by":"publisher","unstructured":"Prout, A, Arcand W, Bestor D, Bergeron B, Byun C, Gadepally V, Houle M, Hubbell M, Jones M, Klein A, Michaleas P, Milechin L, Mullen J, Rosa A, Samsi S, Yee C, Reuther A, Kepner J (2018) Measuring the impact of spectre and meltdown In: 2018 IEEE High Performance Extreme Computing Conference, HPEC 2018, Waltham, MA, USA, September 25-27, 2018, 1\u20135. https:\/\/doi.org\/10.1109\/HPEC.2018.8547554.","DOI":"10.1109\/HPEC.2018.8547554"},{"key":"82_CR19","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45418-7_17","volume-title":"Smart Card Programming and Security. E-smart 2001. Lecture Notes in Computer Science, vol 2140","author":"J Quisquater","year":"2001","unstructured":"Quisquater, J, Samyde D (2001) Electromagnetic analysis (EMA): measures and counter-measures for smart cards. In: Attali I Jensen T (eds)Smart Card Programming and Security. E-smart 2001. Lecture Notes in Computer Science, vol 2140.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/3-540-45418-7_17."},{"key":"82_CR20","doi-asserted-by":"publisher","unstructured":"Rivain, M (2008) On the exact success rate of side channel analysis in the gaussian model In: Selected Areas in Cryptography, 15th International Workshop, SAC 2008, Sackville, New Brunswick, Canada, August 14-15, Revised Selected Papers, 165\u2013183. https:\/\/doi.org\/10.1007\/978-3-642-04159-4_11.","DOI":"10.1007\/978-3-642-04159-4_11"},{"key":"82_CR21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15031-9_28","volume-title":"Cryptographic Hardware and Embedded Systems, CHES 2010. CHES 2010. Lecture Notes in Computer Science, vol 6225","author":"M Rivain","year":"2010","unstructured":"Rivain, M, Prouff E (2010) Provably secure higher-order masking of AES. In: Mangard S Standaert FX (eds)Cryptographic Hardware and Embedded Systems, CHES 2010. CHES 2010. Lecture Notes in Computer Science, vol 6225.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-642-15031-9_28."},{"key":"82_CR22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04138-9_13","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2009. CHES 2009. Lecture Notes in Computer Science, vol 5747","author":"M Rivain","year":"2009","unstructured":"Rivain, M, Prouff E, Doget J (2009) Higher-order masking and shuffling for software implementations of block ciphers. In: Clavier C Gaj K (eds)Cryptographic Hardware and Embedded Systems - CHES 2009. CHES 2009. Lecture Notes in Computer Science, vol 5747.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-642-04138-9_13."},{"key":"82_CR23","doi-asserted-by":"publisher","unstructured":"Schneider, PH, Krishnamoorthy S (1996) Effects of correlations on accuracy of power analysis - an experimental study In: Proceedings of the 1996 International Symposium on Low Power Electronics and Design, 1996, Monterey, California, USA, August 12-14, 1996, 113\u2013116. https:\/\/doi.org\/10.1109\/LPE.1996.547490.","DOI":"10.1109\/LPE.1996.547490"},{"key":"82_CR24","doi-asserted-by":"publisher","DOI":"10.1007\/11605805_14","volume-title":"Topics in Cryptology - CT-RSA 2006. CT-RSA 2006. Lecture Notes in Computer Science, vol 3860","author":"K Schramm","year":"2006","unstructured":"Schramm, K, Paar C (2006) Higher order masking of the AES. In: Pointcheval D (ed)Topics in Cryptology - CT-RSA 2006. CT-RSA 2006. Lecture Notes in Computer Science, vol 3860.. Springer, Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/11605805_14."},{"issue":"6","key":"82_CR25","doi-asserted-by":"publisher","first-page":"356","DOI":"10.1049\/iet-ifs.2016.0475","volume":"11","author":"N Veshchikov","year":"2017","unstructured":"Veshchikov, N, Guilley S (2017) Implementation flaws in the masking scheme of DPA contest v4. IET Inf Secur 11(6):356\u2013362. https:\/\/doi.org\/10.1049\/iet-ifs.2016.0475.","journal-title":"IET Inf Secur"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00082-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-021-00082-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00082-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:09:08Z","timestamp":1622592548000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-021-00082-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,2]]},"references-count":25,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,12]]}},"alternative-id":["82"],"URL":"https:\/\/doi.org\/10.1186\/s42400-021-00082-w","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,6,2]]},"assertion":[{"value":"2 October 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 February 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 June 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"14"}}