Paper 2026/1226
Changing of the Guards with Two Shares - Security Flaws, Corrrections, and Application to Low-Latency AES
Abstract
Masking stands as one of the most effective countermeasures against side-channel attacks. While a number of recent works have investigated first-order masking schemes that eliminate the need for fresh randomness, most existing solutions trade off this randomness reduction against increased latency or area overhead. This paper targets the simultaneous achievement of low latency and zero fresh randomness. To this end, we make the following contributions. First, we identify a security flaw in the round-based design proposed by Askeland et al.\ at CARDIS 2022, which builds upon the Changing of the Guards (COTG) technique. Second, we propose a revised construction that rectifies this vulnerability without incurring any additional randomness or latency penalty. Finally, by integrating the Time Sharing Masking (TSM) S-box introduced at CHES 2025, we present a first-order masked AES implementation with a latency of 20 clock cycles that requires no fresh randomness.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Preprint.
- Keywords
- MaskingAESHardwareGlitch-extended Probing SecurityFresh Randomness
- Contact author(s)
-
zhoufeng2021 @ iscas ac cn
yanggehui2024 @ iscas ac cn
yangjunhuai2023 @ iscas ac cn
chenhua @ iscas ac cn
fanlimin @ iscas ac cn - History
- 2026-06-11: approved
- 2026-06-10: received
- See all versions
- Short URL
- https://ia.cr/2026/1226
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1226,
author = {Feng Zhou and Gehui Yang and Junhuai Yang and Hua Chen and Limin Fan},
title = {Changing of the Guards with Two Shares - Security Flaws, Corrrections, and Application to Low-Latency {AES}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1226},
year = {2026},
url = {https://eprint.iacr.org/2026/1226}
}