Hardware Masking

Begül Bilgin, Lauren De Meyer · 2025

This chapter starts with an example on hardware where the ideal circuit assumption does not hold, which can cause an undesired leakage. It then provides an abstraction of this behavior, which leads to an extended adversary model. Fortunately, it is possible to create hardware implementations that are also secured under this extended adversary model. The chapter presents several secure gadgets and discusses the properties that bring this security, with a focus mostly on Boolean masking. It concludes by looking at trade-offs between area footprint, latency and randomness cost. The trade-off between area and latency is one that is known even from unmasked hardware design. However, masking brings several new choices to make in this respect. As with unmasked hardware design, one way to trade area and latency is to play with the number of parallel copies of the same block.

Read the paper · More papers on PaperTik