Low-delay anti-power consumption analysis hardware mask method for finite field inversion operation

Through the collaborative design of modules A, L1, B1 to C4 and the integration of masking schemes, the problems of high latency and large random number requirements in finite field inversion operations in AES and SM4 encryption algorithms are solved, achieving low latency and low area anti-side channel protection.

CN120929047APending Publication Date: 2025-11-11INST OF SOFTWARE - CHINESE ACAD OF SCI +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510958692.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing finite field inversion operations suffer from high latency and large random number requirements in power consumption analysis, making it particularly difficult to achieve low latency and low area side-channel protection in the protection of nonlinear components of AES and SM4 encryption algorithms.

Method used

By combining DOM-indep and DOM-dep mask multipliers and through the collaborative design of modules A, L1, B1 to C4, the inversion operation over a finite field is achieved. Combined with module integration and an improved masking scheme, the requirements for random numbers and chip area are reduced.

Benefits of technology

It achieves d-order inversion operation within three clock cycles, reducing random number requirements and chip area, and meeting the security requirements of power consumption analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120929047A_ABST
    Figure CN120929047A_ABST
Patent Text Reader

Abstract

The invention discloses a low-delay anti-power consumption analysis hardware mask method for finite field inversion operation. The scheme comprises a mask multiplication module A protected by a DOM-index multiplication mask scheme, a mask multiple square module L1, two mask multiplication modules B1 and B3 protected by the DOM-dep multiplication mask scheme, a mask multiplication module B2 protected by the DOM-dep multiplication mask scheme, a mask multiple square module L2 and four mask multiplication modules C1 and C2 protected by the DOM-dep multiplication mask scheme. C3 and C4. According to the mask provided by the invention, the side channel security capability of d-order anti-power-consumption analysis can be provided, the requirements on random numbers and chip area are remarkably reduced, and the mask can be applied to side channel protection of encryption algorithms adopting inversion as nonlinear components such as AES and SM4.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power analysis robustness masking, and particularly to a low-latency power analysis robustness hardware masking method for finite field inversion operations, which can be used in AES and SM4, etc. Side-channel protection for encryption algorithms that use inversion as a nonlinear component. Background Technology

[0002] Power analysis attacks are among the most effective attacks for recovering sensitive information stored in IoT and embedded systems. Various protection techniques have been proposed to resist power analysis attacks. Masking is one of the most effective techniques. Masking uses a standard probe model as the theoretical model for information leakage and has provable security. However, in the design of high-order masking, the new module obtained by combining two modules that satisfy probe security may not necessarily satisfy probe security. To address the limitations of probe security in module combination, Barthe et al. proposed the stronger composability security concepts of Strong Non-Interference (SNI) and Non-Interference (NI) and a series of combination rules, ensuring that SNI circuits and NI circuits combined under the combination rules still satisfy the NI property, thus satisfying the probe security property. Cassiers et al. subsequently proposed the security concept of Probe Isolation Non-Interference (PINI), which allows the combination of modules to be independent of specific rules. Specifically, any two circuits that satisfy the PINI property, when combined, will still satisfy the PINI property.

[0003] The standard probing model does not account for information leakage caused by glitches in hardware circuits, meaning that mask protection secure under the standard probing model may not be secure in hardware implementations. In 2018, Faust et al. proposed the extended glitch probing model (hereinafter referred to as the glitch probing model), which more comprehensively characterizes the information leakage features caused by glitches. Since its introduction, the glitch probing model has been widely used in mask protection design. Regarding the composable security properties under the glitch probing model, Faust et al. extended the properties of SNI to the glitch probing model, and Cassiers et al. extended the properties of PINI to the extended glitch probing model. Meanwhile, Cassiers et al. proposed several hardware private circuits (HPCs) that conform to the PINI properties under the glitch probing model. Existing hardware private circuits include HPC1, HPC2, HPC3, HPC3o, HPC3.1, HPC3.2, and HPC4. Among them, HPC1 and HPC2 have high latency but low requirements for random numbers, while other HPC variants have low latency but higher requirements for random numbers.

[0004] In 2016, Gross et al. proposed a domain-oriented masking scheme (DOM scheme) to resist glitch attacks, and presented two multiplicative masking schemes, DOM-indep and DOM-dep. Compared with HPC schemes, DOM schemes do not have trivial composability, but DOM schemes have lower requirements for random numbers and can construct power analysis-resistant masking protection schemes with arbitrary order security under certain conditions.

[0005] AES and SM4 encryption algorithms are two extremely important symmetric cryptography algorithms. The S-boxes of both algorithms contain finite fields. The inverse operation on. As the only nonlinear component in the algorithm, inversion presents both a key challenge and a significant difficulty in side-channel protection. Currently, [the following is a list of methods / technologies]... Most side-channel protection schemes for inverse operations employ HPC masking, with only the scheme proposed by Gross et al. in 2016 using DOM masking. HPC-based... Side-channel protection based on arbitrary order inversion suffers from drawbacks such as large area and high random number requirements, while the protection proposed by Gross et al. suffers from high latency. On the other hand, currently... Most masking protection schemes for inversion are designed to mask composite field implementations with a multiplication depth of 4, as proposed by Canright in 2005, thus incurring a delay of at least 4 clock cycles. Hadzic et al. proposed a method with a multiplication depth of 3 in 2024. A method for implementing the inverse composite field is proposed, along with a corresponding HPC-based mask protection scheme. Although the delay of this scheme is reduced to three clock cycles, the consumption of random numbers and chip area are still not optimal. Summary of the Invention

[0006] To address the technical problems existing in the prior art, the present invention aims to provide a low-latency, power-efficient hardware masking method for finite field inversion operations. This scheme can provide corresponding resistance to d-order side-channel attacks based on the side-channel attack order d (an arbitrary positive integer). Hardware mask inversion implementation. This invention provides... The inverse mask implementation requires three clock cycles to complete and has relatively low requirements for random numbers and chip area.

[0007] The low-latency, arbitrary-order power consumption robustness analysis hardware masking method provided by this invention includes the following modules:

[0008] 1) Module A, whose function is to perform finite field multiplication using a DOM-indep mask multiplier. The masked multiplication operation takes d+1 shares of two multipliers x and y as input and outputs d+1 shares of the product f, where x and y are the inverses of the multipliers f and f, respectively. The lower four bits and the higher four bits of an element. The d+1 shares of x and y are (x0, y0), ..., (x... d ,y d ), where (x0,y0),…,(x d-1 ,y d-1 Generated using a random number generator.

[0009] in This represents a bitwise XOR operation on multiple elements;

[0010] 2) Module L1, its function is to complete the finite field... The mask power operation takes the input as the result of XORing the d+1 shares of x and y by share, and performs a process on each XOR result. The result of the doubling operation is used as d+1 shares of output e;

[0011] 3) Module B1, whose function is to perform finite field multiplication using a DOM-dep mask multiplier. The mask multiplication operation has two inputs: d+1 shares of x, d+1 shares of u (the result of XORing e and f by shares), and output: d+1 shares of w.

[0012] 4) Module B2, whose function is to perform finite field multiplication using a DOM-dep mask multiplier. The multiplication operation takes two inputs: the higher two bits 'a' and the lower two bits 'b' of the result of the fractional XOR operation of e and f, and the output is the d+1th bit of h.

[0013] 5) Module B3, whose function is to perform finite field multiplication using a DOM-dep mask multiplier. The mask multiplication operation takes d+1 shares of y as input and d+1 shares of u, the XOR result of e and f, as input, and outputs d+1 shares of z.

[0014] 6) Module L2, its function is to complete finite field... The mask power operation divides e and f into d+1 shares (high two bits a and low two bits b) by XORing the result u. Then, the result of XORing a and b by share is further processed... The power-doubling operation yields d+1 shares of the output g.

[0015] 7) Module C1, whose function is to perform finite field multiplication using a DOM-dep mask multiplier. The mask multiplication operation has two inputs: the lower two bits of w, k+1 shares, and g and h XORed by shares, resulting in v+1 shares. The output is r+1 shares.

[0016] 8) Module C2, whose function is to perform finite field multiplication using a DOM-dep mask multiplier. The mask multiplication operation has two inputs: the high two bits of w, the d+1 shares of l, and the d+1 shares of v, which are XORed by g and h. The output is the d+1 shares of s.

[0017] 9) Module C3, whose function is to perform finite field multiplication using a DOM-dep mask multiplier. The mask multiplication operation takes two inputs: the lower two bits of z, m+1 shares, and g and h XORed by shares, resulting in v+1 shares. The output is p+1 shares.

[0018] 10) Module C4, whose function is to perform finite field multiplication using a DOM-dep mask multiplier. The mask multiplication operation takes two inputs: the lower two bits of z, n+1 shares, and g and h, XORed by shares, resulting in v+1 shares. The output is q+1 shares.

[0019] The modules work together to achieve The inverse operation of the element α = (x, y) in the field yields the result of α in the finite field. The multiplicative inverse β = (p, q, r, s) in the equation possesses the ability to resist d-order power consumption analysis. The input to the inversion operation is... The d+1 shares of elements x and y represented in the field are output as follows: The domain represents the d+1 shares of elements p, q, r, and s. Here, x and y are the lower four bits and higher four bits of α, and p, q, r, and s are the lower two bits, second-lower two bits, second-highest two bits, and highest two bits of the inverse β, respectively. Module A is protected using a DOM-indep mask; modules B1 to B3 and C1 to C4 are also protected using a DOM-dep mask. The d+1 shares of the input u of modules B1 and B3 need to be connected to the blinded input port Y of the DOM-dep mask multiplier. In addition to the two multiplier inputs, each of the aforementioned DOM-indep mask multipliers requires a set of random numbers for mask updates, a set of random numbers Z for mask updates, and a set of blinded random numbers B. The update random numbers and blinded random numbers required for each DOM-indep mask multiplier and each instance of the DOM-dep mask multiplier are different. The blinded random number B is used to perform a fractional XOR operation with the blinded input port Y of the DOM-dep mask multiplier. The blinded result needs to be stored in a register. Modules L1 and L2 are protected using a linear structure scheme.

[0020] Preferably, modules B1 and B3 share the random numbers required for blinding and the registers storing the blinding results.

[0021] Preferably, among modules C1, C2, C3, and C4, only one module needs to blind the d+1 shares of operand v, while the other modules can share the blinded random number and the register storing the blinding result.

[0022] Preferably, module A and module L1, and their XOR result, can be integrated into a single implementation using an improved DOM-indep mask multiplier; that is, module A calculates d+1 shares of the result f, module L1 calculates d+1 shares of the result e, and the next calculation process is the XOR of d+1 shares of f with d+1 shares of e. This invention merges these three calculation processes into one module to achieve integration. Module L1... Each share accomplish Linear operation on the square Algorithm 1 is an improved DOM-indep masking multiplier. Algorithm 1 masks a multiplication function Q = X·Y + L(X,Y) over any finite field, where X and Y are elements in the finite field, X·Y represents the multiplication operation over the finite field, and L(X,Y) is a linear function of X and Y. Algorithm 1 uses d+1 shares X = (X,Y) of two elements X and Y in the finite field. i ) 0≤i≤d and Y = (Y i ) 0≤i≤d , Mask random number Z = (Z ij ) 0≤i<j≤dAs input, the result of the multiplication function Q is d+1 shares of Q = (Q i ) 0≤i≤d The output is a random number Z. ij Backup to Z ji Then X i Y i +L(X i ,Y i (where 0≤i≤d) The result of (where 0≤i, j≤d and i≠j) is stored in register t. ii ,t ij In the middle, the final calculation

[0023] Compared to Algorithm 1, the original DOM-indep multiplication masking scheme does not contain the linear function term L(X,Y) of X and Y. Algorithm 1 stores the linear function L(X... i ,Y i The register of the result and the storage of multiplication X i Y i The resulting registers are merged into a single register t. ii By integrating multiplication and linear functions in this way, storage of L(X) can be saved. i ,Y i The result is stored in the register. In the implementation of the inverse operation, the three operations of XORing module A, module L1, and e (output of module A) and f (output of module L1) can be combined. The function jointly accomplished by module A, module L1, and their XOR operations is: This applies to the scope of Algorithm 1. Therefore, X·Y+L(X,Y) in Algorithm 1 can be instantiated as... Algorithm 1 is then applied to complete the integrated masking implementation for module A, module L1, and the XOR result.

[0024]

[0025]

[0026] Preferably, module B2 and module L2, and their XOR result, can be integrated into a single implementation using an improved DOM-dep mask multiplier. Module L2... Each share accomplish Linear operation on the square Algorithm 2 is an improved DOM-dep mask multiplier.

[0027] Algorithm 2 masks the multiplication function Q = X·Y + L(X,Y) over any finite field, where X and Y are elements in the finite field, X·Y represents the multiplication operation over the finite field, and L(X,Y) is a linear function of X and Y. Algorithm 2 uses d+1 shares X = (X,Y) of two elements X and Y in the finite field. i ) 0≤i≤d and Y = (Y i ) 0≤i≤d , Mask update random number Z = (Z ij ) 0≤i<j≤d Blinded random number B = (B i ) 0≤i≤d As input, the result of the multiplication function Q is d+1 shares of Q = (Q i ) 0≤i≤d The output is a random number Z. ij Backup to Z ji Then X i , X i B i +L(X i ,Y i (where 0≤i≤d) The result of (where 0 ≤ i, j ≤ d and i ≠ j) is stored in register X. i U i t ii ,t ij In the middle, the calculations are performed sequentially at the end. and Q i =X i U+V i .

[0028] Compared to Algorithm 2, the original DOM-dep multiplication masking scheme does not contain the linear function term L(X,Y) of X and Y. Algorithm 2 stores the linear function L(X... i ,y i The register of the result and the storage of multiplication X i B i The resulting registers are merged into a single register t. ii By integrating multiplication and linear functions in this way, storage of L(X) can be saved. i ,Y i The result is stored in the register. In the implementation of the inverse operation, the XOR operation of module B2, module L2, and h (output of module B2) and g (output of module L2) can be combined. The function jointly accomplished by module B2, module L3, and their XOR operations is as follows: This applies to the scope of Algorithm 2. Therefore, X·Y+L(X,Y) in Algorithm 1 can be instantiated as... Algorithm 2 is then applied to complete the integrated masking implementation for module A, module L1, and the XOR result.

[0029]

[0030]

[0031] Preferably, the integrated implementation of module A and module L1 is implemented using a multiplication mask scheme that satisfies the anti-glitch SNI property, and the DOM-dep implementation of modules B1 and B3 is replaced by DOM-indep implementation.

[0032] Preferably, the integrated implementation of modules B2 and L2 is implemented using a multiplication mask scheme that satisfies the anti-glitch SNI property, and modules C1 to C4 implemented by DOM-dep are replaced with DOM-indep.

[0033] Preferably, any multiplication module (A, B1, B1, B2, C1, C2, C3 or C4) is implemented using a multiplication mask scheme that satisfies the anti-glitch PNI property.

[0034] Preferably, the integrated implementation of module A and module L1 or the integrated implementation of module B2 and module L2 is implemented using a multiplication mask scheme that satisfies the anti-glitch PNI property.

[0035] The present invention also provides a chip or processing unit for encryption operations, configured to perform the methods described in the claims.

[0036] Compared with the prior art, the technical solution of the present invention has the following advantages:

[0037] 1. The d-order given in this invention The number of random numbers required for the inversion scheme is relatively small. Existing three-period d-order... The number of random bits required for the inversion scheme is 16d(d+1). This invention provides a d-order... The number of random bits required to find the inverse scheme is 11d(d+1)+6f(d), where f(1)=1 and f(d)=d+1.

[0038] 2. By integrating A and L1, as well as B2 and L2, using multiplication mask modules that satisfy the SNI property and replacing the remaining modules with DOM-indep implementations, the area required for the low-order mask implementation of this invention is significantly reduced. Using Yosys tools in the Nangate 45nm process standard library for mask implementation synthesis, the chip area occupied by first-order and second-order protection is only 1642GE and 3896GE, respectively, significantly lower than the 1875GE and 4176GE reported by Hadzic et al.

[0039] GE. Attached Figure Description

[0040] Figure 1 This is a schematic diagram of the basic scheme of the present invention.

[0041] Figure 2 This is a schematic diagram of a solution that integrates some modules into a single unit.

[0042] Figure 3 This is a schematic diagram of a scheme that uses a masking scheme with anti-glitch SNI properties for some modules.

[0043] Figure 4 This is a schematic diagram of a scheme that uses a masking method with anti-glitch PINI properties for some modules. Detailed Implementation

[0044] The following examples illustrate specific solutions of the present invention, but do not limit the scope of the invention in any way.

[0045] The basic scheme of the present invention is as follows Figure 1 As shown in the diagram. The register stages are marked with gray dividing lines. In this scheme, multiplier A is implemented using DOM-indep, while the other multipliers are implemented using DOM-dep. Modules A and L1, as well as modules B2 and L2, are not integrated into a single implementation. Therefore, the d+1 shares of the result e from module L1 and the d+1 shares of the result g from module L2 need to be stored in separate registers. Furthermore, the d+1 components of the input u from modules B1 and B3 must be connected to the Y port of the DOM-dep masked multiplier; otherwise, security issues will occur.

[0046] The masking scheme after integrating modules A and L1 and their XOR, and modules B2 and L2 and their XOR, into a single implementation (the integrated modules are labeled A and B2 in the diagram, respectively) is as follows: Figure 2 As shown. This scheme saves the 4(d+1) bit register required to store d+1 shares of e and g.

[0047] Modules A and L1 and their XOR, as well as modules B2 and L2 and their XOR, are integrated into a single implementation (the integrated modules are labeled A and B2 in the diagram, respectively). The masking scheme after the module implementation satisfies the SNI property is as follows: Figure 3 As shown. This scheme avoids the use of the DOM-dep mask multiplication module, which has a large area overhead, and instead uses DOM-indep to implement modules B1, B3, C1, C2, C3 and C4, which can effectively reduce the area.

[0048] The integrated module A and L1, and their XOR (the integrated module is labeled A in the diagram), can be implemented using a glitch-resistant PNI mask similar to HPC3.2. The method involves storing the linear terms in L1 into the storage x of module A implemented by HPC3.2. i y i The registers are used. Meanwhile, B1 and B3 can be implemented using HPC1 (where Refresh1 and B1, and Refresh2 and B3 each constitute an HPC1). Refresh1 and Refresh2 perform mask update operations on the d+1 shares of the inputs x and y, respectively. If this implementation method is adopted, then... Finding the inverse of inputs x and y by their d+1 shares does not require storing them in registers. This scheme is as follows: Figure 4 As shown. This invention can be integrated as an S-box module into the symmetric cryptographic algorithms AES or SM4 to provide side-channel protection for the nonlinear components of AES and SM4 algorithms.

[0049] Although specific embodiments of the invention have been disclosed for illustrative purposes to aid in understanding and implementing the invention, those skilled in the art will understand that various substitutions, variations, and modifications are possible without departing from the spirit and scope of the invention and the appended claims. Therefore, the invention should not be limited to the content disclosed in the preferred embodiments, and the scope of protection claimed by the invention is defined by the claims.

Claims

1. A low-latency, power-efficient hardware masking method for finite field inversion operations, comprising the following steps: 1) Module A uses a DOM-indep mask multiplier to perform d+1 shares of two multipliers x and y in a finite field. The masked multiplication operation on the product f outputs d+1 shares of the product f, where x is the inverse to be calculated. The lower four bits of element α, and y is the inverse to be found. The high four bits of element α; d+1 shares of x, y (x0, y0), ..., (x d ,y d ), where (x0,y0),…,(x d-1 ,y d-1 Generated using a random number generator. in This represents a bitwise XOR operation on multiple elements; 2) Module L1 performs a bitwise XOR operation on the d+1 shares of x and y, and calculates the XOR result for each share in a finite field. Perform a mask power-multiplication operation on the above to obtain d+1 shares of e; 3) Module B1 uses a DOM-dep mask multiplier to perform the multiplication of the (d+1)th share of x, the (d+1)th share of u resulting from the XOR operation of e and f by share, within a finite field. The mask multiplication operation on the mask yields d+1 shares of w; 4) Module B2 uses a DOM-dep mask multiplier to perform a fractional XOR operation on e and f, where the higher two bits 'a' and the lower two bits 'b' are d+1 shares of the result and are within a finite field. The multiplication operation on h yields d+1 shares of h; 5) Module B3 uses a DOM-dep mask multiplier to perform the (d+1)th share of y and the (d+1)th share of u, the XOR result of e and f, in a finite field. The mask multiplication operation yields d+1 shares of z; 6) Module L2 divides the result u of the XOR operation of e and f into d+1 shares of the higher two bits a and d+1 shares of the lower two bits b, and then XORs the result of a and b in a finite field. Perform a power-multiplication operation on the above to obtain d+1 shares of g; 7) Module C1 uses a DOM-dep mask multiplier to perform the multiplication of the lower two bits k of w, the (d+1)th share of g and h by share, and the (d+1)th share of v in the finite field. The mask multiplication operation on the above yields d+1 shares of r; 8) Module C2 uses a DOM-dep mask multiplier to perform the (d+1)th share of the high two bits of w, and the (d+1)th share of the result v obtained by XORing g and h by share in a finite field. The mask multiplication operation on the mask yields d+1 shares of s; 9) Module C3 uses a DOM-dep mask multiplier to perform the (d+1)th share of the lower two bits m of z, and the (d+1)th share of the result v of the XOR operation of g and h by share in a finite field. The mask multiplication operation on the top yields d+1 shares of p; 10) Module C4 uses a DOM-dep mask multiplier to perform the (d+1)th share of the lower two bits n of z, and the (d+1)th share of the result v of the XOR operation of g and h by share in a finite field. The mask multiplication operation on the mask yields d+1 shares of q; 11) Treat (p, q, r, s) as the inverse to be found. The multiplicative inverse β of element α.

2. The method according to claim 1, characterized in that, The DOM-indep mask multiplier operates on the d+1 shares of two multipliers x and y within a finite field. During the mask multiplication operation, a set of masks is used to update the required random numbers.

3. The method according to claim 2, characterized in that, During the mask multiplication operation of the DOM-dep mask multiplier on two multipliers, a set of random numbers Z required for mask update and a set of blind random numbers B are used. The blind random numbers B are used to perform a fractional XOR operation with the blind port Y of the DOM-dep mask multiplier.

4. The method according to claim 3, characterized in that, The random number required for mask update in the DOM-indep mask multiplier is different from the random number for mask update and blinding required by the DOM-dep mask multiplier.

5. The method according to claim 3, characterized in that, Module B1 and Module B3 share the random numbers required for blinding and the registers that store the blinding results.

6. The method according to claim 1, characterized in that, Modules L1 and L2 are protected using linear structure schemes.

7. The method according to claim 1, characterized in that, The modules C1, C2, C3, and C4 blind the d+1 shares of the operand v and share the blinded random number and the register storing the blinding result.

8. The method according to claim 1, characterized in that, The module L1 for each share x⊕y i ⊕y i accomplish Linear operations on squarer-scaler(x) i ⊕y i ).

9. The method according to claim 1, characterized in that, Modules A and L1, and their XOR result, are integrated into a single implementation using an improved DOM-indep masking multiplier. This improved DOM-indep masking multiplier uses a multiplication function Q = X·Y + L(X,Y) over a finite field for masking, where X and Y are elements in the finite field, X·Y represents the multiplication operation over the finite field, and L(X,Y) is a linear function of X and Y. The improved DOM-indep masking multiplier uses d+1 shares X = (X... i ) 0≤i≤d and Y = (Y i ) 0≤i≤d , Mask random number Z = (Z ij ) 0≤i<j≤d As input, the result of the multiplication function Q is d+1 shares of Q = (Q i ) 0≤i≤d For output; the DOM-indep mask multiplier will use the random number Z ij Backup to Z ji Then X i Y i +L(X i ,Y i ), X i Y j ⊕Z ij The result is stored in register t ii ,t ij In the middle, the final calculation 0≤i≤d, 0≤i,j≤d and i≠j.

10. The method according to claim 1, characterized in that, The module L2 for each share a⊕b i ⊕b i accomplish Linear operations on squarer-scaler(a) i ⊕b i ).

11. The method according to claim 1, characterized in that, Modules B2 and L2, and their XOR result, are integrated into a single implementation using an improved DOM-dep masking multiplier. This improved DOM-dep masking multiplier masks the multiplication function Q = X·Y + L(X,Y) over a finite field, where X and Y are elements in the finite field, X·Y represents the multiplication operation over the finite field, and L(X,Y) is a linear function of X and Y. The improved DOM-dep masking multiplier uses d+1 shares X = (X... i ) 0≤i≤d and Y = (Y i ) 0≤i≤d , Mask update random number Z = (Z ij ) 0≤i<j≤d Blinded random number B = (B i ) 0≤i≤d As input, the result of the multiplication function Q is d+1 shares of Q = (Q i ) 0≤i≤d For output; the improved DOM-dep mask multiplier will use a random number Z ij Backup to Z ji Then X i Y i ⊕B i X i B i +L(X i ,Y i ), X i B j ⊕Z ij The result is stored in register X i U i t ii ,t ij In the middle, the calculations are performed sequentially at the end. and Q i =X i U+V i ; 0≤i≤d, 0≤i,j≤d and i≠j.

12. A chip or processing unit for encryption operations, configured to perform the method of any one of claims 1 to 11.