International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

UP TO 50% OFF:

Efficient Implementation of Polynomial Masking


Jorge Andresen
Institute for IT Security, University of Luebeck, Luebeck

Paula Arnold
Institute for IT Security, University of Luebeck, Luebeck

Sebastian Berndt
Department of Electrical Engineering and Computer Science, Technische Hochschule Lübeck, Luebeck; Institute for IT Security, University of Luebeck, Luebeck

Thomas Eisenbarth
Institute for IT Security, University of Luebeck, Luebeck

Sebastian Faust
Technical University of Darmstadt, Darmstadt

Marc Gourjon
Max Planck Institute for Security and Privacy, Bochum

Eric Landthaler
Institute for IT Security, University of Luebeck, Luebeck

Elena Micheli
Technical University of Darmstadt, Darmstadt

Maximilian Orlt
UCLouvain, Louvain-la-Neuve, Belgium; Technical University of Darmstadt, Darmstadt

Pajam Pauls
Institute for IT Security, University of Luebeck, Luebeck

Kathrin Wirschem
Technical University of Darmstadt, Darmstadt

Liang Zhao
Technical University of Darmstadt, Darmstadt


Keywords: Polynomial Masking, Leakage and Fault Resilience, TVLA


Abstract

While passive probing attacks and active fault attacks have been studied for multiple decades, research has only started to consider combined attacks that use both probes and faults relatively recently. During this period, polynomial masking became a promising, provably secure countermeasure to protect cryptographic computations against such combined attacks. Unlike other countermeasures, such as duplicated additive masking, polynomial masking can be implemented using a linear number of shares, as shown by Berndt et al. at CRYPTO ’23. Based upon this fact, Arnold et al. noted at CHES ’24 that polynomial masking is particularly well-suited for parallel computation. This characteristic is especially effective in scenarios involving multiple circuits with identical structures, such as the 16 SBoxes in AES. Just recently, Faust et al. showed at CHES ’25 that one can also incorporate the technique of packed secret sharing into these masking schemes, given that the state-of-the-art polynomial masking scheme is secure against combined attacks.In this work, we present provably secure advancements regarding this state-of-the-art scheme in both computational and randomness efficiency, reducing the randomness complexity by up to 50% and the computational complexity even more by going from a quadratic term to a linear one for many parameters. Moreover, we present the first implementation of a polynomial masking scheme against combined attacks along with an extensive experimental evaluation for a wide range of parameters and configurations as well as a statistical leakage detection to evaluate the security of the implementation on an Arm Cortex-M processor. Our implementation is publicly available to encourage further research in practical combined resilience.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 1

Paper

Artifact

Artifact number
tches/2026/a23

Artifact published
June 02, 2026

Badge
IACR CHES Artifacts Functional

README

ZIP (4308974 Bytes)  

View on Github

License
This work is licensed under the MIT License.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Jorge Andresen, Paula Arnold, Sebastian Berndt, Thomas Eisenbarth, Sebastian Faust, Marc Gourjon, Eric Landthaler, Elena Micheli, Maximilian Orlt, Pajam Pauls, Kathrin Wirschem, Liang Zhao. (2026). UP TO 50% OFF: Efficient Implementation of Polynomial Masking. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(1), 688–731. https://doi.org/10.46586/tches.v2026.i1.688-731. Artifact at https://artifacts.iacr.org/tches/2026/a23.