A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2019; you can also visit the original URL.
The file type is
Lecture Notes in Computer Science
The cost of higher-order masking as a countermeasure against side-channel attacks is often considered too high for practical scenarios, as protected implementations become very slow. At Eurocrypt 2017, the bounded moment leakage model was proposed to study the (theoretical) security of parallel implementations of masking schemes  . Work at CHES 2017 then brought this to practice by considering an implementation of AES with 32 shares  , bitsliced inside 32-bit registers of ARM Cortex-Mdoi:10.1007/978-3-319-89641-0_2 fatcat:nrowmdwtb5azrguqh3xgwna7pq