EDBT 2026 Demo / reviewers in the wild / expert
Jingdian Ming
dblp:225/9870
· DBLP profile ↗
25ranked-venue papers
5as first author
20since 2021 · last 2026
0000-0001-8791-1576ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 3 first-author · 12 since 2021Systems, architecture and hardware · 9 · 2 first-author · 8 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Memory-Optimized Masked CRYSTALS-Kyber Implementation on ARM Cortex-M4
Ruiqi Hou, Yiwen Gao 0001, Wei Cheng 0003, Yuejun Liu, Jingdian Ming, Yongbin Zhou |
ICDCS | 5 |
| 2026 | SERP-SCA: A Strengthened Side-Channel Attack Framework for FALCON SignatureabstractNIST has selected Falcon as one of the standardized post-quantum digital signature algorithms, making the security of Falcon against side-channel attacks (SCAs) a critical area of concern. This paper introduces SERP-SCA, a strengthened SCA framework for Falcon, which exploits leakage from floating-point multiplications to recover secret floating-point values, which can subsequently be mapped to the coefficients of the secret key. The framework adopts a divide-and-conquer strategy to target the mantissa, exponent, and sign bit of floating-point values, with specialized optimizations for attacks on the mantissa and exponent. For mantissa attacks, SERP-SCA integrates bit segmentation with a sequential attack strategy to fully exploit the leakage from mantissa multiplication and incorporates an error-correction mechanism to further enhance attack efficiency. For exponent attacks, SERP-SCA leverages Fast Fourier Transform (FFT) properties to narrow the enumeration space, significantly improving time efficiency. We conduct practical attacks on Falcon-512 and Falcon-1024 implementations running on ARM Cortex-M4. Compared to state-of-the-art methods, SERP-SCA achieves an improvement of 22.11% in success rate for Falcon-512 and 18.64% for Falcon-1024, with remarkable time efficiency gains of around 195,369× and 183,175× for mantissa attacks, and 180× and 185× for exponent attacks, respectively. Honglin Shao, Jingdian Ming, Yuejun Liu, Yiwen Gao 0001, Yongbin Zhou |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2025 | Breaking the Shield: Novel Fault Attacks on CRYSTALS-Dilithium
Dixiao Du, Yuejun Liu, Yiwen Gao 0001, Jingdian Ming, Yongbin Zhou |
ACISP (2) | 4 |
| 2025 | Side-Channel Collision Attacks Against ASCONabstractSide-channel attack poses a significant threat to the security of electronic devices, particularly IoT/AIoT terminals. By leveraging side-channel leakages, collision attacks can efficiently extract the secret keys from cryptographic devices while requiring considerably less computational effort. In this paper, we investigate side-channel collision attacks against ASCON, a lightweight crypto designed for resource-constrained devices, which has been standardized by the NIST. For the first time, we propose a side-channel key recovery attack against ASCON by identifying the collisions in the linear diffusion layer. Using Pearson correlation coefficient and Euclidean distance for internal collision detections, our attack successfully recovers the secret key with approximately 5,000 power traces from an 8-bit software implementation on an AVR device. To further reduce attack complexity, we introduce a novel metric, Locally-Weighted Sum (LWS), which focuses on the most likely points of leakage, thereby decreasing the number of required power traces for successful attack. Our experiment on the same target demonstrates that the LWS-based collision attack can recover the full secret key with approximately 3,000 power traces, a reduction of 40 percent. Our study indicates that ASCON is susceptible to side-channel collision attacks, and bitslice implementations remain vulnerable to such threats. Hao Zhang 0009, Yiwen Gao 0001, Yongbin Zhou, Jingdian Ming |
DATE | 4 |
| 2025 | MEML-KEM: A Memory-Efficient Implementation of ML-KEM for IoT Devices
Ruiqi Hou, Yiwen Gao 0001, Yuejun Liu, Jingdian Ming, Yongbin Zhou |
ICA3PP (7) | 4 |
| 2025 | Masked Gadgets for Integer-Floating-Point Conversion with Applications to FalconabstractFalcon has been selected by the National Institute of Standards and Technology (NIST) as one of the standardized post-quantum digital signature algorithms. Unlike other candidate algorithms, Falcon relies heavily on floating-point operations, which are known to be vulnerable to side-channel attacks (SCAs). Although recent research proposes masking schemes for basic floating-point operations, secure conversion between integer and floating-point representations remains unaddressed. These conversions operate directly on the private key or other sensitive variables and therefore constitute a potential attack surface. This paper proposes new masking gadgets that securely perform conversions between integers and floating-point representations, addressing this previously unprotected surface. As part of the design, we optimize existing normalization and floating-point composition components to support the conversion process. We formally prove that our gadgets satisfy$t$-Non-Interference$(t-\text{NI})$or$t$-Strong Non-Interference ($t$-SNI) in the probing model and evaluate their side-channel resistance using Test Vector Leakage Assessment (TVLA) on an Arm Cortex-M4 processor. We also assess performance on an Intel Core CPU, where the optimized normalization and floating-point composition components demonstrate improvements of approximately 47.6 % and 10.8 %, respectively, over prior work. Jingdian Ming, Yuejun Liu, Yiwen Gao 0001, Yongbin Zhou |
ICCD | 2 |
| 2025 | Multi-Channel Attacks on Dilithium: Bridging Power Gaps with EM-Guided Synthetic TracesabstractMulti-Channel Fusion Attacks (MCFAs) boosts the effectiveness of side-channel cryptanalysis by combining information leakages from multiple channels such as power and electromagnetic (EM) leakages. However, current MFCAs require the same number of traces across the channels, which poses a critical constraint that does not necessarily hold in practical scenarios. For instance, acquiring contactless EM traces is considerably easier than obtaining power traces. Consequently, an attacker can collect many more EM traces, but a considerable portion of them must be discarded due to this constraint. To address the constraint of requiring equal numbers of traces across channels while fully utilizing the otherwise discarded EM traces, we propose a novel multi-channel fusion framework. This framework leverages a machine learning model to synthesize the missing power traces, thereby aligning the number of traces in the power and EM channels. As a result, it maximizes the utilization efficiency of the available traces. Specifically, we introduce GTL, a hybrid generative adversarial network that integrates Transformer and LSTM architectures for effective trace synthesis. We present the first MCFAs against the postquantum cryptographic scheme CRYSTALS-Dilithium. Experimental results show that, compared with existing MCFAs, our approach reduces the required number of traces by more than 50%. Qikang Fan, Jingdian Ming, Yiwen Gao 0001, Yongbin Zhou |
TrustCom | 2 |
| 2025 | Diverse Fault Attacks on Dilithium and Variant Implementation: Skipping, Aborting and ZeroingabstractAs one of the first post-quantum digital signature schemes standardized by NIST, Dilithium has gained significant attention due to its potential role in securing communication in the quantum era. However, ensuring the security of its practical implementations, particularly against fault attacks, remains a significant challenge. Despite various proposed countermeasures, their effectiveness remains inadequately explored. This paper presents a comprehensive analysis of fault attacks on Dilithium, introducing five distinct attack techniques across three fault types: instruction-skipping, loop-aborting, and zeroing, which target the polynomial structure and Number Theoretic Transform (NTT) operations in Dilithium. These attacks are shown to significantly reduce the number of faulty signatures required for private key recovery, with the most efficient technique requiring as few as one faulty signature. Our methods successfully compromise both the reference and the protected implementation designed to resist skip-addition attacks. Experimental validation on an ARM Cortex-M4 platform demonstrates the effectiveness of these attacks, with success rates ranging from 29% to 63%, enabling full private key recovery in both deterministic and randomized Dilithium implementations. These findings underscore the need for more robust, fault-resilient post-quantum cryptographic implementations. Yuejun Liu, Jingdian Ming, Yongbin Zhou |
TrustCom | 3 |
| 2024 | Towards High-Quality Electromagnetic Leakage Acquisition in Side-Channel AnalysisabstractSide-channel leakage acquisition plays a crucial role in side-channel analysis against cryptographic implementations, since it usually has a decisional impact on the security claims of the target devices. While most existing research has concentrated on power consumption acquisition settings, the exploration of electromagnetic (EM) radiation leakage acquisition remains limited and surprisingly under-discussed. In this study, we systematically investigate the parameter setting for EM leakage acquisition across two devices of different architectures. We specifically examine the effects of the amplifier, coupling mode, sampling rate, and EM probe on the quality of collected EM traces. For the first device STM32F405, our proposed optimal acquisition settings enhance the signal-to-noise ratio by a factor of 16 compared to the reference settings and reduce the number of EM traces required to achieve a success rate of 90% by a factor of 38. For the second device ATmega2560, the optimal settings improve the signal-to-noise ratio by a factor of 400 compared to the reference settings and reduce the number of EM traces required to achieve a success rate of 90% by a factor of 320. In summary, this work offers a comprehensive investigation into high-quality EM leakage acquisition. While some conclusions may be specific to certain devices, we believe that the proposed guidelines can be applied to EM trace acquisition in other devices as well. Xiaoran Huang, Yiwen Gao 0001, Wei Cheng 0003, Yuejun Liu, Jingdian Ming, Yongbin Zhou, Jian Weng 0001 |
TrustCom | 5 |
| 2024 | Attacking High-Performance SBCs: A Generic Preprocessing Framework for EMAabstractFor the high-performance single-board computers (SBCs) running an operating system, side-channel attacks usually come at high analytical costs, requiring millions of traces. This work uses the case of electromagnetic attacks on encryption services in real-world SBCs to explore how various preprocessing methods can reduce the attack costs for such devices. Specifically, we propose a general preprocessing framework that effectively combines multiple preprocessing methods based on their inherent characteristics. Utilizing this framework, we design a four-layer preprocessing scheme that significantly reduces the number of traces for key recovery. The experimental results show that, when the attack success rate reaches 80 percent, the proposed preprocessing scheme reduces the number of traces required by a factor of approximately 10 compared to the latest alignment algorithm on the Raspberry Pi 2B. Our research demonstrates the feasibility of conducting low-cost side-channel attacks on SBCs, further emphasizing the need to protect sensitive applications running on these devices. Debao Wang, Yiwen Gao 0001, Jingdian Ming, Yongbin Zhou |
TrustCom | 3 |
| 2024 | Enhancing Higher-Order Masking: A Faster and Secure Implementation to Mitigate Bit Interaction LeakageabstractHigher-order masking is an effective countermeasure against side-channel attacks but is often perceived as impractical due to its cost. Recent advancements in parallelization technologies have made higher-order masking more feasible. However, the security of these implementations can be jeopardized by the parallelization methods used, as their theoretical assurances may not hold in real-world scenarios. In this paper, we improve the security and efficiency of higher-order masking schemes for block ciphers through a refined bit-sliced implementation. Our method addresses lower-order leakage caused by bit interactions, which are prevalent in current schemes. We evaluated the efficiency of our approach across various widely used ARM and AVR platforms, demonstrating efficiency improvements across all test platforms. By optimizing the masking gadgets, our approach reduces the required clock cycles by 30% to 50% compared to the original implementation, across share numbers from 2 to 32 on the 32-bit ARM platform. We validate the enhanced security of our method through both theoretical analysis and practical leakage detection, proving its effectiveness against bit interaction leakage. Yuejun Liu, Jingdian Ming, Yiwen Gao 0001, Yongbin Zhou, Debao Wang |
TrustCom | 3 |
| 2024 | Statistical Higher-Order Correlation Attacks Against Code-Based MaskingabstractMasking is one of the most well-established methods to thwart side-channel attacks. Many masking schemes have been proposed in the literature, and code-based masking emerges and unifies several masking schemes in a coding-theoretic framework. In this work, we investigate the side-channel resistance of code-based masking from a non-profiling perspective by utilizing correlation-based side-channel attacks. We present a systematic evaluation of correlation attacks with various higher-order (centered) moments and then present the form of optimal correlation attacks. Interestingly, the Pearson correlation coefficient between the hypothetical leakage and the measured traces is connected to the signal-to-noise ratio in higher-order moments, and it turns out to be easy to evaluate rather than launch repeated attacks. We also identify some ineffective higher-order correlation attacks at certain orders when the device leaks under the Hamming weight leakage model. Our theoretical findings are verified through both simulated and real-world measurements. Wei Cheng 0003, Jingdian Ming, Sylvain Guilley, Jean-Luc Danger |
IEEE Trans. Computers | 2 |
| 2023 | Table Re-Computation Based Low Entropy Inner Product Masking Schemeabstractis a popular countermeasure due to its provable security. Table re-computation based Boolean masking (BM) is efficient at small masking share number, and addition chain based inner product masking (IPM) provides higher security order than BM. As a result, the natural question is: can we design a masking scheme that costs close to that of re-computation based BM while providing security comparable to that of addition chain based IPM? In this paper, we propose a table re-computation based IPM scheme that provides 3rd-order security while being slightly more expensive than table re-computation based BM. Furthermore, we improve the side-channel security of IPM by randomly selecting the parameter$L$from an elaborated low entropy set, which we call low entropy inner product masking (LE-IPM). In an Intel Core i7-4790 CPU and ARM Cortex M4 based MCU for AES, we implemented four masking schemes, namely the addition chain based IPM and table re-computation based BM, IPM, and LE-IPM. Our proposals perform slightly slower (by about 0.8 times) than table re-computation based BM but significantly faster (at least 30 times) than addition chain based IPM. Furthermore, we assess the security of our proposals using a standard method named test vector leakage assessment methodology (TVLA). Our proposals provide the expected security against side-channel attacks according to the evaluation. Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li |
DATE | 1 |
| 2023 | Practical Public Template Attack Attacks on CRYSTALS-Dilithium With Randomness LeakagesabstractSide-channel security has become a significant concern in the NIST post-quantum cryptography standardization process. The lattice-based CRYSTALS-Dilithium (abbr. Dilithium) becomes the primary signature standard algorithm recommended by NIST for most use cases in July 2022 due to its excellent performance in security and efficiency. Compared to Dilithium’s rich theoretical security analysis results, the side-channel security of its physical implementations needs to be further explored. In 2021, Liu et al. proposed a two-stage randomness leakage attack against Dilithium, in which only one randomness bit with a probability$> 0.5$per signature is enough to recover the private key. However, they only carried out proof-of-concept experiments on “research-oriented” reference implementation of polynomial addition. Whether this method applies to complete real-world implementations of Dilithium is unknown. In this paper, we put this randomness leakage attack into real-world and recover the private key of unprotected and masked Dilithium on Arm Cortex-M4 processor using non-profiled power analysis attacks. Since randomness is introduced in the signing process, it is challenging to recover the randomness bit of Dilithium with high success rate in only one trace. Inspired by Liu et al., we propose a new non-profiled attack called Public Template Attack (PTA), a template-attack-like method that builds templates using public information. With PTA, we recover the randomness bit of unprotected and masked Dilithium with a success rate of 95% and 62% in one power trace, respectively. To demonstrate practicality, we perform practical power analysis attacks against different security levels of round 3 unprotected and masked Dilithium on STM32F405 microprocessor. Using 10,000 traces, the private key of unprotected Dilithium2 is recovered in 0.5 hours with an ordinary PC desktop. Our attack is 240 times faster than the state-of-the-art non-profiled attack. Moreover, the private key of masked Dilithium2 is recovered using 680,000 traces in 38 hours. To the best of our knowledge, we are the first to successfully attack masked Dilithium using non-profiled attacks. Zehua Qiao, Yuejun Liu, Yongbin Zhou, Jingdian Ming, Chengbin Jin, Huizhong Li |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Fast Fourier Orthogonalization over NTRU Lattices
Yongbin Zhou, Rui Zhang 0002, Yang Tao 0001, Zehua Qiao, Jingdian Ming |
ICICS | 6 |
| 2022 | Optimizing Higher-Order Correlation Analysis Against Inner Product Masking SchemeabstractIn recent years, inner product masking (IPM) has been proposed as a promising code based masking scheme against side-channel attacks. However, most studies mainly focus on leakages in terms of information-theoretic metrics, and simulated experiments utilizing profiled attacks (with known templates). In this paper, we investigate the security of IPM scheme against one typical non-profiled side-channel attack, namely higher-order correlation analysis. We demonstrate that three factors mainly influence the efficiency of higher-order correlation analysis against IPM, and they are the attack order vector, output size of the target function and attack model. In particular, we propose a new method to measure the efficiency of higher-order correlation analyses. Generally speaking, this method is based on the correlation coefficient between leakage expectations with certain shares and sensitive values under the attack model. We validate our method by both simulation-based experiments and practical one with different attack factors. All experiments are running on the IPM in the different noise scenarios. The results demonstrate that our method works well as an indicator for higher-order correlation analyses against IPM. Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | APT: Efficient Side-Channel Analysis Framework against Inner Product Masking SchemeabstractDue to its provable security and remarkable device-independence, masking has been widely accepted as a good algorithmic-level countermeasure against side-channel attacks. Subsequently, several code-based masking schemes are proposed to strengthen the original Boolean masking (BM) scheme, and Inner Product Masking (IPM) scheme is typically one of those. In this paper, we provide a framework, named analysis with predicted template (APT), for side-channel analysis against the IPM scheme. Following this framework, we propose two attacks based on maximum likelihood and Euclidean distance, respectively. To evaluate their efficiency, we perform simulated experiments on first-order BM and an optimal IPM scheme. The results show that our proposals are equivalent to a second-order CPA against BM scheme, but they are significantly efficient against an optimal IPM. In practical experiments based on an ARM Cortex-M4 architecture, the results of our proposals do not turn out well because of a few outliers in collected leakages. After filtering out these outliers, our proposals perform efficiently as expected. Finally, we argue that the side-channel security of IPM can be improved by keeping the vector L to be randomly selected from an elaborated small set. Jingdian Ming, Wei Cheng 0003, Yongbin Zhou, Huizhong Li |
ICCD | 1 |
| 2021 | Transparency order versus confusion coefficient: a case study of NIST lightweight cryptography S-BoxesabstractAbstract Side-channel resistance is nowadays widely accepted as a crucial factor in deciding the security assurance level of cryptographic implementations. In most cases, non-linear components (e.g. S-Boxes) of cryptographic algorithms will be chosen as primary targets of side-channel attacks (SCAs). In order to measure side-channel resistance of S-Boxes, three theoretical metrics are proposed and they are reVisited transparency order (VTO), confusion coefficients variance (CCV), and minimum confusion coefficient (MCC), respectively. However, the practical effectiveness of these metrics remains still unclear. Taking the 4-bit and 8-bit S-Boxes used in NIST Lightweight Cryptography candidates as concrete examples, this paper takes a comprehensive study of the applicability of these metrics. First of all, we empirically investigate the relations among three metrics for targeted S-boxes, and find that CCV is almost linearly correlated with VTO, while MCC is inconsistent with the other two. Furthermore, in order to verify which metric is more effective in which scenarios, we perform simulated and practical experiments on nine 4-bit S-Boxes under the non-profiled attacks and profiled attacks, respectively. The experiments show that for quantifying side-channel resistance of S-Boxes under non-profiled attacks, VTO and CCV are more reliable while MCC fails. We also obtain an interesting observation that none of these three metrics is suitable for measuring the resistance of S-Boxes against profiled SCAs. Finally, we try to verify whether these metrics can be applied to compare the resistance of S-Boxes with different sizes. Unfortunately, all of them are invalid in this scenario. Huizhong Li, Guang Yang 0042, Jingdian Ming, Yongbin Zhou, Chengbin Jin |
Cybersecur. | 3 |
| 2021 | A secure and highly efficient first-order masking scheme for AES linear operationsabstractAbstract Due to its provable security and remarkable device-independence, masking has been widely accepted as a noteworthy algorithmic-level countermeasure against side-channel attacks. However, relatively high cost of masking severely limits its applicability. Considering the high tackling complexity of non-linear operations, most masked AES implementations focus on the security and cost reduction of masked S-boxes. In this paper, we focus on linear operations, which seems to be underestimated, on the contrary. Specifically, we discover some security flaws and redundant processes in popular first-order masked AES linear operations, and pinpoint the underlying root causes. Then we propose a provably secure and highly efficient masking scheme for AES linear operations. In order to show its practical implications, we replace the linear operations of state-of-the-art first-order AES masking schemes with our proposal, while keeping their original non-linear operations unchanged. We implement four newly combined masking schemes on an Intel Core i7-4790 CPU, and the results show they are roughly 20% faster than those original ones. Then we select one masked implementation named RSMv2 due to its popularity, and investigate its security and efficiency on an AVR ATMega163 processor and four different FPGA devices. The results show that no exploitable first-order side-channel leakages are detected. Moreover, compared with original masked AES implementations, our combined approach is nearly 25% faster on the AVR processor, and at least 70% more efficient on four FPGA devices. Jingdian Ming, Yongbin Zhou, Huizhong Li, Qian Zhang 0042 |
Cybersecur. | 1 |
| 2021 | On the Security of Lattice-Based Fiat-Shamir Signatures in the Presence of Randomness LeakageabstractLeakages during the signing process, including partial key exposure and partial (or complete) randomness exposure, may be devastating for the security of digital signatures. In this work, we investigate the security of lattice-based Fiat-Shamir signatures in the presence of randomness leakage. To this end, we present a generic key recovery attack that relies on minimum leakage of randomness, and then theoretically connect it to a variant of Integer-LWE (ILWE) problem. The ILWE problem, introduced by Bootle et al. at Asiacrypt 2018, is to recover the secret vector s given polynomially many samples of the form (a, 〈a〉, s)+e) ϵ ℤn+1, and it is solvable if the error e ϵ ℤ is not superpolynomially larger than the inner product (a, s). However, in our variant (we call the variant FS-ILWE problem in this paper), a ϵ ℤnis a sparse vector whose coefficients are NOT independent any more, and e is related to a and s as well. We prove that the FS-ILWE problem can be solved in polynomial time, and present an efficient algorithm to solve it. Our generic key recovery method directly implies that many lattice-based Fiat-Shamir signatures will be totally broken with one (deterministic or probabilistic) bit of randomness leakage per signature. Our attack has been validated by experiments on two NIST PQC signatures Dilithium and qTESLA. For example, as to Dilithium-III of 125-bit quantum security, the secret key will be recovered within 10 seconds over an ordinary PC desktop, with about one million signatures. Similarly, key recovery attacks on Dilithium under other parameters and qTESLA will be completed within 20 seconds and 31 minutes respectively. In addition, we also present a non-profiled attack to show how to obtain the required randomness bit in practice through power analysis attacks on a proof-of-concept implementation of polynomial addition. The experimental results confirm the practical feasibility of our method. Yuejun Liu, Yongbin Zhou, Tianyu Wang 0021, Rui Zhang 0002, Jingdian Ming |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2020 | The Notion of Transparency Order, RevisitedabstractAbstract We revisit the definition of transparency order (TO) and that of modified transparency order (MTO) as well, which were proposed to measure the resistance of substitution boxes (S-boxes) against differential power analysis (DPA). We spot a definitional flaw in original TO, which is proved to significantly affect the soundness of TO. Regretfully, MTO overlooks this flaw, yet it happens to incur no bad effects on the correctness of MTO, even though the start point of this formulation is highly questionable. It is also this neglect that made MTO consider a variant of multi-bit DPA attack, which was mistakenly thought to appropriately serve as an alternative powerful attack. This implies the soundness of MTO is also more or less arguable. Therefore, we fix this definitional flaw and provide a revised definition named reVisited TO (VTO). For demonstrating validity and soundness of VTO, we present simulated and practical DPA attacks on implementations of $4\times 4$ and $8\times 8$ S-boxes. In addition, we also illustrate the soundness of VTO in masked S-boxes. Furthermore, as a concrete application of VTO, we present the distribution of VTO values of optimal affine equivalence classes of $4\times 4$ S-boxes and give some recommended guidelines on how to select $4\times 4$ S-boxes with higher DPA resistance at the identical level of implementation cost. Huizhong Li, Yongbin Zhou, Jingdian Ming, Guang Yang 0042, Chengbin Jin |
Comput. J. | 3 |
| 2020 | Mind the Balance: Revealing the Vulnerabilities in Low Entropy Masking SchemesabstractLow Entropy Masking Schemes (LEMS) have attracted wide attention due to their implementations simplicity and relatively good performance in protecting cryptographic implementations against Side-Channel-Attacks (SCAs). To achieve desired security, it is necessary (but not sufficient) to find proper low entropy mask sets to protect all sensitive secret-dependant intermediate variables. However, one crucial problem concerning this intuitive idea is that what `proper' mask sets should be. To formally capture such crucial qualification, we introduce the notion of balancedness to characterize this natural attribute of mask sets themselves. Considering that this notion is limited to characterize first-order security, we generalize it to d-dimension balancedness to accommodate dth-order security, then we exhibit lower and upper bounds on d-dimension balancedness for any d. With the help of these essential definitions, we prove that no balanced low entropy mask set really exists, which implies that LEMS implementations always have vulnerabilities in theory due to the unbalancedness of underlying mask sets. In order to further demonstrate the practical implications of balancedness, we show 4 different kinds of attacks on three state-of-the-art LEMS implementations. Specifically, the distribution attack proposed in this paper is a general first-order attack on LEMS. The results demonstrate that unbalanced mask sets actually do lead to serious vulnerabilities. Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li, Guang Yang 0042, Qian Zhang 0042 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | CDAE: Towards Empowering Denoising in Side-Channel Analysis
Guang Yang 0042, Huizhong Li, Jingdian Ming, Yongbin Zhou |
ICICS | 3 |
| 2018 | Convolutional Neural Network Based Side-Channel Attacks in Time-Frequency Representations
Guang Yang 0042, Huizhong Li, Jingdian Ming, Yongbin Zhou |
CARDIS | 3 |
| 2018 | A Compact AES Hardware Implementation Secure Against 1st-Order Side-Channel AttacksabstractEfficient cryptographic implementations with desired side-channel attacks (SCA) resistance are highly required, especially for those resources-constrained devices. In this paper, we propose a very compact AES hardware implementation scheme provably secure against 1st-order SCAs. Basically, our scheme is inspired by ideas of Redundant Tower Field (RTF for short) circuit due to Ueno et al. and of private circuits due to Ishai, Sahai and Wagner (ISW for short), and is therefore named ISW-RTF. In terms of security, practical attacks on real leakages from prototype implementation show that ISW-RTF scheme is secure against 1st-order attacks and 2nd-order zero-offset attacks as well. Results of t-test leakage detection of these leakages also verify this observation. In terms of efficiency, compared with the state-of-the-art 1st-order masking scheme, our scheme outperforms at least 55.08% decreases in area, and 34.87% decreases in area-time product on three popular FPGA/ASIC devices. To the best of our knowledge, the proposed ISW-RTF scheme is the most compact one provably secure against SCA. Qian Zhang 0042, Yongbin Zhou, Shuang Qiu 0004, Wei Cheng 0003, Jingdian Ming, Rui Zhang 0002 |
ICCD | 5 |