2026-08-19 京都大学

サイドチャネル攻撃の概要。攻撃者は暗号デバイスの物理的漏えいL(Z) から暗号演算内部の秘密情報Zを推測して、秘密鍵Kを詐取する。(この図では国際標準暗号AESのような暗号を想定している。)
<関連情報>
- https://www.kyoto-u.ac.jp/ja/research-news/2026-08-19-0
- https://link.springer.com/chapter/10.1007/978-3-032-35415-0_11
マスキングの形式的安全性証明:強雑音漏えいからプロービングモデルへの乱択プロービングを用いない帰着と漏えい耐性プリミティブへの応用 A Formal Security Proof of Masking: Reduction from Strong Noisy Leakage to Probing Model without Random Probing and Application to LR Primitive
Rei Ueno,Akiko Inoue,Kazuhiko Minematsu,Akira Ito & Naofumi Homma
Proceedings of Annual International Cryptology Conference (CRYPTO 2026)
DOI:https://doi.org/10.1007/978-3-032-35415-0_11
Abstract
This paper provides upper bounds on the success rate (SR) of side-channel attacks (SCAs) on masked implementations. We present a formal security proof of additive masking over any finite abelian group—including Boolean and arithmetic maskings—through new reductions from strong noisy leakage (SNL) to the probing model. Unlike existing proofs relying on noisy leakage (NL) and random probing (RP), our proof introduces a novel security notion named leakage energy (LE), which enables a stronger bound. Our proof reveals the necessary and sufficient condition for asymptotic security of additive masking in both the NL and mutual information frameworks, which includes a resolution to an open problem in TCC 2016. Our claims are validated through numerical evaluations. As an application of our theorems, we propose a binary block-cipher based leakage-resilient primitive based on a variant of XEX, which claims d-th order SCA security of arithmetic masking by design under some assumptions, enabling efficient OCB-style authenticated encryption with implementation cost of O(d).

