What a lovely hat

Is it made out of tin foil?

Paper 2026/161

Compact and Low Latency First-Order AES Implementations with Low Randomness

Feng Zhou, University of Chinese Academy of Sciences, TCA Laboratory, Institute of Software, Chinese Academy of Sciences, Zhongguancun Laboratory
Hua Chen, TCA Laboratory, Institute of Software, Chinese Academy of Sciences
Limin Fan, TCA Laboratory, Institute of Software, Chinese Academy of Sciences
Junhuai Yang, University of Chinese Academy of Sciences, TCA Laboratory, Institute of Software, Chinese Academy of Sciences
Abstract

Recent years have witnessed significant progress in first-order hardware masking of AES. However, most of the work focus on the optimizations over solely one of the metrics: chip area, latency or randomness. The optimizations for one metric often leads to increasing overheads of the other metrics. Consequently, few work focus on optimizations over all three metrics of first-order AES at the same time. To bridge this gap, we introduce two compact round-based first-order AES-128 encryption implementations with the latency of 31 cycles and 40 cycles, respectively. They are provably secure in the glitch-extended probing model with relatively low consumption of randomness. To achieve this, we first introduce a method to design first-order low-latency $d+1$ TI (Threshold Implementations) for multi-output Boolean functions with a latency of only one clock cycle. Moreover, the random bits used in the low-latency TI cancels out in the expressions of output shares, which enables the applications of a COTG-based concept to significantly reduce the randomness consumption. Finally, we apply our method to design first-order implementations for AES-128 with two shares, which allows the designs to be compact. As a result, our implementations achieve a excellent trade-off over latency, area, and randomness. Compared to the 10-cycle and 20-cycle AES-128 implementations provided respectively in TCHES 2020 and TCHES 2025, the area and randomness demands of our implementations are significantly less. We also use formal verification tools, PROLEAD, and TLVA to validate the security of our designs for S-Box and round-based AES-128 implementations, respectively.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published by the IACR in TCHES 2026
Keywords
MaskingAESHardwareGlitch-extended Probing SecurityLow RandomnessLow LatencyProver
Contact author(s)
zhoufeng2021 @ iscas ac cn
chenhua @ iscas ac cn
fanlimin @ iscas ac cn
yangjunhuai2023 @ iscas ac cn
History
2026-02-04: approved
2026-01-31: received
See all versions
Short URL
https://ia.cr/2026/161
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/161,
      author = {Feng Zhou and Hua Chen and Limin Fan and Junhuai Yang},
      title = {Compact and Low Latency First-Order {AES} Implementations with Low Randomness},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/161},
      year = {2026},
      url = {https://eprint.iacr.org/2026/161}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.
Morty Proxy This is a proxified and sanitized view of the page, visit original site.