Paper 2026/1614
LFSRs and Boolean Masking: An In-depth Security Analysis
Abstract
Masking is a widely adopted countermeasure to protect cryptographic implementations from side-channel attacks. Subsequent research has focused on designing masking schemes and formally proving their security, notably through the development of automated tools, within models abstracting the reality of a sidechannel analysis. These designs rely on an external source of randomness; however, there is currently no consensus on the choice of (pseudo-)random number generators for masking. To the best of our knowledge, existing formal proofs for masking security do not consider particular choices of random number generators, but rather assume that they yield uniformly distributed and independent random variables. In that context, we introduce the first verification framework that jointly analyzes a pseudorandom number generator— specifically, but not limited to, a linear feedback shift register—and a masking scheme, in the d-probing model. Our framework relies on the Walsh-Hadamard transform by drawing on techniques from linear cryptanalysis, which we extend to the robust probing model. We demonstrate our method on 4-bit and 8-bit S-boxes, provide a detailed analysis of the formal verification outcomes, and corroborate the findings with practical evaluations on an FPGA.
Note: Extended version of the accepted paper at TCHES 2026, Issue 3. Additions: - New theoretical security results for the second-order masked implementation of the 4-bit SKINNY S-box; - New side-channel evaluations of the first-order masked 8-bit SKINNY S-box hardware implementation; - Additional side-channel evaluations of the first-order masked 4-bit SKINNY S-box for selected LFSR lengths. We also corrected some typos throughout the text.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- A major revision of an IACR publication in TCHES 2026
- DOI
- 10.46586/tches.v2026.i3.426-464
- Keywords
- probing modelmaskingPRNGLFSRWalsh-Hadamard transform
- Contact author(s)
-
anna guinet @ rub de
jan schoone @ proton me
niklas hoeher @ rub de
dina hesse @ rub de
tim gueneysu @ rub de - History
- 2026-08-06: approved
- 2026-08-05: received
- See all versions
- Short URL
- https://ia.cr/2026/1614
- License
-
CC BY-NC
BibTeX
@misc{cryptoeprint:2026/1614,
author = {Anna Guinet and Jan Schoone and Niklas Höher and Dina Hesse and Tim Güneysu},
title = {{LFSRs} and Boolean Masking: An In-depth Security Analysis},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1614},
year = {2026},
doi = {10.46586/tches.v2026.i3.426-464},
url = {https://eprint.iacr.org/2026/1614}
}