


















, University of Chinese Academy of Sciences, TCA Laboratory, Institute of Software, Chinese Academy of Sciences, Zhongguancun Laboratory
Hua Chen, TCA Laboratory, Institute of Software, Chinese Academy of Sciences
Limin Fan, TCA Laboratory, Institute of Software, Chinese Academy of Sciences
Junhuai Yang, University of Chinese Academy of Sciences, TCA Laboratory, Institute of Software, Chinese Academy of Sciences
Recent years have witnessed significant progress in first-order hardware masking of AES. However, most of the work focus on the optimizations over solely one of the metrics: chip area, latency or randomness. The optimizations for one metric often leads to increasing overheads of the other metrics. Consequently, few work focus on optimizations over all three metrics of first-order AES at the same time. To bridge this gap, we introduce two compact round-based first-order AES-128 encryption implementations with the latency of 31 cycles and 40 cycles, respectively. They are provably secure in the glitch-extended probing model with relatively low consumption of randomness. To achieve this, we first introduce a method to design first-order low-latency $d+1$ TI (Threshold Implementations) for multi-output Boolean functions with a latency of only one clock cycle. Moreover, the random bits used in the low-latency TI cancels out in the expressions of output shares, which enables the applications of a COTG-based concept to significantly reduce the randomness consumption. Finally, we apply our method to design first-order implementations for AES-128 with two shares, which allows the designs to be compact. As a result, our implementations achieve a excellent trade-off over latency, area, and randomness. Compared to the 10-cycle and 20-cycle AES-128 implementations provided respectively in TCHES 2020 and TCHES 2025, the area and randomness demands of our implementations are significantly less. We also use formal verification tools, PROLEAD, and TLVA to validate the security of our designs for S-Box and round-based AES-128 implementations, respectively.
BibTeX
@misc{cryptoeprint:2026/161,
author = {Feng Zhou and Hua Chen and Limin Fan and Junhuai Yang},
title = {Compact and Low Latency First-Order {AES} Implementations with Low Randomness},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/161},
year = {2026},
url = {https://eprint.iacr.org/2026/161}
}
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。