Transactions on Cryptographic Hardware and Embedded Systems 2026
Formal Verification, Integration and Physical Evaluation of Prime-Field Masking on Silicon
Gaëtan Cassiers
CryptoExperts, Paris, France; UCLouvain, Louvain-la-Neuve, Belgium
Thorben Moos
UCLouvain, Louvain-la-Neuve, Belgium
Amir Moradi
Technische Universität Darmstadt, Darmstadt, Germany
Nicolai Müller
Technische Universität Darmstadt, Darmstadt, Germany
François-Xavier Standaert
UCLouvain, Louvain-la-Neuve, Belgium
Keywords: Prime-Field Masking, FPM, Tweakable Block Cipher, small-pSquare, Privium, ASIC, Formal Verification, SILVER, MATCHI, PROLEAD
Abstract
The resistance of provably secure masked circuits to physical attacks depends in part on the underlying algebraic group and recombination function. Masking over finite fields of odd prime order has been demonstrated, both in theory and in practice, to provide increased natural resistance to side-channel and fault attacks. Its instantiation with a simple additive encoding and implementation-friendly prime modulus was suggested to lead to favorable tradeoffs between security and performance in prior works. To most efficiently leverage these advantages, a family of lightweight Tweakable Block Ciphers (TBCs) called Feistel for Prime Masking (FPM) has been introduced by Grassi et al. at Eurocrypt’24, together with a first hardware-oriented instance called small-pSquare. Yet, barriers for the use and further development of prime-field masking continue to exist and include the lack of automated verification tools compatible with arithmetic over Fp, as well as efficient methods for constant-time generation of uniformly distributed randomness over the field. In this work we tackle these barriers and present our findings from formally verifying, securely integrating and physically evaluating higher-order masked implementations of small-pSquare as an exemplary case study. Our integration includes the tape-out of an Application-Specific Integrated Circuit (ASIC) manufactured in 65nm technology and a custom Printed Circuit Board (PCB). We demonstrate how to securely verify prime-field masked circuits with existing tools such as SILVER, MATCHI and PROLEAD and certify the glitch+transition robustness of our concrete implementations. Along the way we discover and solve a 0-issue originating from incomplete modulo reductions which is present in public source codes of masked prime-field ciphers but has never been discussed. We also introduce Privium, a Bivium-inspired primitive, to efficiently produce random values uniformly distributed over Fp without the need for rejection sampling. We then describe our efficient serialized pipelined small-pSquare architecture enabling an attractive tradeoff between area and latency and compare its pre- and post-layout implementation figures. Finally, we experimentally demonstrate the strong leakage resistance of our formally verified circuits on real silicon.
Publication
IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3
PaperArtifact
Artifact number
tches/2026/a45
Artifact published
September 21, 2026
Badge
✅ IACR CHES Artifacts Available
Note that license information is supplied by the authors and has not been confirmed by the IACR.
BibTeX How to cite
Gaëtan Cassiers, Thorben Moos, Amir Moradi, Nicolai Müller, François-Xavier Standaert. (2026). Formal Verification, Integration and Physical Evaluation of Prime-Field Masking on Silicon. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 1310–1336. https://doi.org/10.46586/tches.v2026.i3.1310-1336. Artifact at https://artifacts.iacr.org/tches/2026/a45.