International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

MAGNET:

MAsked Gaussian Now Efficient and Table-less


Mert Yassi
Monash University, Melbourne, Australia

Soundes Marzougui
Deutsches Elektronen-Synchrotron, Hamburg, Germany

Raymond K. Zhao
ExeQuantum, Melbourne, Australia

Muhammed F. Esgin
Monash University, Melbourne, Australia

Amin Sakzad
Monash University, Melbourne, Australia

Ron Steinfeld
Monash University, Melbourne, Australia


Keywords: Lattice-Based Cryptography, Discrete Gaussian Sampling, Masking, Side-Channel Attacks, Implementation


Abstract

Discrete Gaussian sampling (DGS) is a fundamental method for generating random noise in various post-quantum cryptographic key generation and signature schemes. However, DGS has been shown to be highly susceptible to side-channel analysis, and several countermeasures have been developed. Masking, a robust countermeasure, is widely employed to secure these schemes against side-channel attacks. Due to the non-linear arithmetic operations involved, DGS has traditionally been considered unsuitable for efficient masked implementations. In this work, we propose MAGNET: an efficient masking design for the novel discrete Gaussian sampler based on Boolean circuits introduced byWei et al. at ACM CCS 2023. With MAGNET, we demonstrate that DGS can be implemented in a masking-friendly manner. Previous masked DGS approaches in the literature have relied on computation-intensive floating point operations or table-lookup-based techniques using Cumulative Distribution Tables (CDT). In contrast, we show that DGS can be efficiently masked for moderate orders without relying on heavy computation or precomputed large lookup tables. In addition to delivering good performance at a small standard deviation σ, the efficiency of MAGNET becomes increasingly significant in large σ settings. MAGNET achieves up to 17x speed-up at σ = 256, and 56x speed-up at σ = 1024 over the CDT-based sampler of Gérard and Rossi (2019). We provide an arbitrary-order C implementation and a first-order ARM Cortex-M4 implementation of MAGNET. We validate the practical security of the first-order implementation through Test Vector Leakage Assessment (TVLA) and systematic hardening of gadgets that exhibit side-channel leakage.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3

Paper

Artifact

Artifact number
tches/2026/a51

Artifact published
September 21, 2026

Badge
✅ IACR CHES Artifacts Functional

README

ZIP (2932512 Bytes)  

View on Github

License
This work is licensed under the Apache License, Version 2.0.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Mert Yassi, Soundes Marzougui, Raymond K. Zhao, Muhammed F. Esgin, Amin Sakzad, Ron Steinfeld. (2026). MAGNET: MAsked Gaussian Now Efficient and Table-less. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 769–804. https://doi.org/10.46586/tches.v2026.i3.769-804. Artifact at https://artifacts.iacr.org/tches/2026/a51.