Cryptographic processing method, corresponding electronic device and corresponding computer program
Patent Information
- Application Number
- DE602021034955
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-06-26
- Filing Date
- 2021-06-18
- Publication Date
- 2025-07-30
- Estimated Expiration
- 2041-06-18
AI Technical Summary
Existing cryptographic methods are vulnerable to attacks, particularly profiled side-channel attacks, when attackers choose a low-value secret key, leading to identical cryptographic algorithm implementations and compromising the security of the system.
A cryptographic processing method that involves adding the order or a multiple of the order to a first number, determining a random number, and performing Euclidean division to generate a second element through a series of group operations, ensuring the quotient by the random number is non-zero, thereby enhancing security even with low-value secret keys.
The method effectively counters attacks by ensuring the second element remains unchanged and secure, even when attackers attempt to impose low-value secret keys, maintaining the integrity of cryptographic operations.
Description
[0001] The present invention relates to the technical field of cryptography.
[0002] It relates more particularly to a cryptographic processing method, as well as an associated electronic device and computer program.
[0003] In this technical field, elements of a finite order group equipped with an operation are manipulated in different applications.
[0004] For example, for signing or decrypting a message using a secret key, a first element of the group is associated with the message and a second element is determined equal to the combination, by means of said operation, of elements equal to the first element and in number equal to a first number linked to the secret key.
[0005] Determining such a second element is relatively simple; for well-chosen groups, however, it is very difficult (in practice: impossible in a reasonable time) to determine the first number on the basis of the first element and the second element (discrete logarithm problem), which allows the secret nature of the first number to be preserved.
[0006] The calculations used to determine the second element are, however, subject to attacks by malicious people seeking, for example, to know the secret key.
[0007] In order to make such attacks more difficult or even prevent them, it has already been proposed (as described for example in "(Virtually) Free Randomization Techniques for Elliptic Curve Cryptography", by M. Ciet and M. Joye, ICICS 2003, LNCS 2836, pp. 348-359, 2003) that the determination of the second element be carried out by different calculations for each implementation of the cryptographic algorithm; to do this: a quotient and a remainder are determined by Euclidean division of the first number by a random number (different for each implementation of the cryptographic algorithm); a third element is determined equal to the combination, by means of said operation, of elements equal to the first element and in number equal to the product of the quotient and the random number; a fourth element is determined equal to the combination, by means of said operation, of elements equal to the first element and in number equal to the remainder; the second element is determined by combination, by means of said operation, of the third element and the fourth element.
[0008] Such a countermeasure can, however, be circumvented when the attacker can choose the secret key used by the relevant cryptographic algorithm.
[0009] Indeed, by choosing in this case a secret key of low value, the quotient obtained during the execution of the cryptographic algorithm is almost systematically zero and the different implementations of the cryptographic algorithm are therefore ultimately identical.
[0010] The attacker can thus improve his knowledge of the operations performed during the execution of the cryptographic algorithm and use this knowledge to attack other uses of the cryptographic algorithm, with another secret key (profiled side-channel attack or "Profiled Side Channel Attack").
[0011] In this context, the invention proposes a cryptographic processing method comprising the determination, in a finite order group provided with an operation and from a first element of this group, of a second element equal to the combination, by means of said operation, of elements (of this group) equal to the first element and in number equal to a first number, characterized by the following steps: obtaining a second determined number by adding to the first number said order or a multiple of said order; determining a random number; determining a quotient and a remainder using the Euclidean division of the second number by the random number; obtaining a third element equal to the combination, by means of said operation, of elements (of this group) equal to the first element and in number equal to the product of the quotient and the random number; obtaining a fourth element equal to the combination, by means of said operation, of elements (of this group) equal to the first element and in number equal to the remainder; determining the second element by combining the third element and the fourth element by means of said operation.
[0012] By adding the order or a multiple of the order, the second number always has a large value and its quotient by the random number will be non-zero. The countermeasure described above will therefore be effective even if an attacker imposes a small value on the first number.
[0013] The desired result (second element) will however be unchanged due to the fact that the combination, by said operation, of elements equal to a given element (here the first element) and in number equal to the order of the group produces the neutral element of the group (due to the cyclical nature of the group).
[0014] Le method may comprise a step of determining another random number, and the second number may then be obtained by adding to the first number the product of the other random number and said order.
[0015] The method is for example implemented within an electronic device comprising a storage module. The first number and / or said order can then be stored in the storage module in masked form. The second number can in this case also be stored, possibly in masked form.
[0016] The method may further comprise a step of constructing a mask equal to the sum of a first intermediate number and the product of a second intermediate number by said random number. The step of obtaining the second number may then comprise a step of applying the constructed mask. Thus, the quotient may be determined using the second intermediate number and the remainder may be determined using the first intermediate number.
[0017] According to a first embodiment, the first intermediate number and the second intermediate number can be determined by random drawing.
[0018] According to a second possible embodiment, when the first number is stored masked by an initial mask, the second intermediate number and the first intermediate number can respectively be determined as the quotient and remainder of the Euclidean division of the initial mask by a power of two (this power of two being for example equal to 2 k< where k is the length in bits of the random number).
[0019] In some embodiments, the aforementioned group may be the multiplicative group ℤ / p ℤ − 0 , where p is a prime number, the order being then equal to (p-1). The operation in this case is modular multiplication modulo p.
[0020] In other embodiments, the group is a subgroup of points of an elliptic curve, said operation being an addition of points of the elliptic curve.
[0021] In still other embodiments, the group is a multiplicative subgroup of ℤ / p ℤ − 0 , where p is a prime number. The order is then a divisor of (p-1). The operation in this case is modular multiplication modulo p.
[0022] The invention also provides an electronic device comprising a processor and a storage module storing computer program instructions designed, when these instructions are executed by the processor, to determine, in a finite order group provided with an operation and from a first element of this group, a second element equal to the combination, by means of said operation, of elements equal to the first element and in number equal to a first number, by means of the following steps: obtaining a second determined number by adding to the first number said order or a multiple of said order; determining a random number; determining a quotient and a remainder using the Euclidean division of the second number by the random number; obtaining a third element equal to the combination, by means of said operation, of elements equal to the first element and in number equal to the product of the quotient and the random number; obtaining a fourth element equal to the combination, by means of said operation, of elements equal to the first element and in number equal to the remainder; determining the second element by combining the third element and the fourth element by means of said operation.
[0023] The invention finally provides a computer program comprising instructions designed to implement a method as presented above when these instructions are executed by a processor.
[0024] Of course, the various features, variants and embodiments of the invention may be combined with each other in various combinations to the extent that they are not incompatible or mutually exclusive.
[0025] In addition, various other characteristics of the invention emerge from the appended description given with reference to the drawings which illustrate non-limiting embodiments of the invention and where: there figure 1 schematically represents an electronic device in accordance with the invention, the figure 2 is a flowchart representing the main steps of a cryptographic processing method in accordance with the invention, the figure 3 is a flowchart representing steps implemented during the cryptographic processing process of the figure 2 , and the figure 4 is a flowchart representing a cryptographic processing method according to another embodiment of the invention.
[0026] There figure 1 schematically represents an electronic device 2 comprising a processor 4 (for example a microprocessor), a storage module 6, a RAM 8 and a communication module 10.
[0027] The storage module 6 stores computer program instructions designed to implement a cryptographic processing method such as at least one of those described below with reference to figures 2, 3 et 4 when these instructions are executed by the processor 4. The storage module 6 is for example in practice a hard disk or a non-volatile memory (possibly rewritable).
[0028] The RAM 8 can memorize at least some of the elements manipulated during the various treatments carried out during this cryptographic processing process.
[0029] The communication module 10 is connected to the processor 4 so as to allow the processor 4 to receive data from another electronic device (not shown) and / or to transmit data to another electronic device (not shown).
[0030] There figure 2 represents the main steps of a cryptographic processing method according to a first embodiment of the invention.
[0031] This method begins in step E2 by the reception of a message M by the processor 4 and via the communication module 10. In the context described here, the message M has a length of at least 1024 bits, for example a size of 1024 bits, 2048 bits, 3072 bits or 4096 bits (here a length between 1024 bits and 4096 bits).
[0032] The process of the figure 2 aims to determine the signature S of the message M by means of an RSA CRT type algorithm. (Alternatively, the message M could be an encrypted message and the application of the RSA CRT type algorithm of the figure 2 would then allow the decryption of the encrypted message M into a decrypted message S.)
[0033] To do this, the storage module 6 stores data representative of the elements p, q, dp, dq, iq of the private key to be used (with the notations usually used for the RSA CRT algorithm and iq = q -1 < mod p), where p and q are prime numbers. Each of the elements here has a length in bits equal to half the size of the message M, i.e. here a length in bits of at least 512 bits, for example between 512 bits and 2048 bits.
[0034] In the example described here, these elements are stored (in storage module 6) in hidden form, i.e. storage module 6 stores: p ′ = p + m p q ′ = q + m q d p ′ = d p + m dp d q ′ = d q + m dq i q ′ = i q + m iq as well as the masks md , mq , M dp , m dq , M iq .
[0035] Each mask here has a length equal to that of the element it masks, i.e. here a length of at least 512 bits, for example between 512 bits and 2048 bits. Each masked value requires 1 bit more for its storage than the element and the mask concerned (to store a possible carry) and therefore has here a length of at least 513 bits, for example between 513 bits and 2049 bits.
[0036] The process of the figure 2 includes a step E4 of determining a first partial result S p such that S p = M dp< mod p.
[0037] In the case where the values are manipulated masked as described here, the step E4 of determining the first partial result determines in practice S p ' = M dp< mod kp .p, where kp is a random number and where kp .p is determined by the operation kp .p'-kp .mp . This step E4 is implemented in accordance with the method described later with reference to the figure 3 .
[0038] The process of the figure 2 also includes a step E6 of determining a second partial result S q such that S q = M dq< mod q.
[0039] In the case where the values are manipulated masked as described here, the step E6 of determining the second partial result determines in practice S q ' = M dq < mod kq .q, where kq is a random number and where kq .q is determined by the operation kq .q'-kq .mq .
[0040] This step E6 can be implemented by a method analogous to that described below with reference to the figure 3 (replacing p by q, dp by dq and therefore kp by kq, p' by q', dp ' by dq ', mp by mq and m dp by m dq in the description of the figure 3 ).
[0041] The process of the figure 2 then includes a step E8 of determining the result S of the RSA CRT algorithm (i.e. here determining the signature S) by combining the first partial result S p and the second partial result S q in accordance with the Chinese remainder theorem: S = S q + q.[iq .(S p -S q ) mod p].
[0042] In the implementation used here where the private key elements are stored hidden as shown above, the result S is obtained as follows: we first determine W = (S p '-S q ').iq '-(S p '-S q ').m iq mod kp .p ; then we determine S by S = Wq' - Wm q + S q ' mod N, where N = (kp .pk q .q) / (kp .kq ).
[0043] There figure 3 represents the steps of a cryptographic processing method according to the invention. This method aims to carry out the modular exponentiation of a value M to the power dp modulo p. In the following, the number dp is designated "exponent". In the example described here, it is applied to carry out step E4 (or step E6) described above, as already indicated. This method could, however, be applied in other cases where a modular exponentiation is used.
[0044] The modular exponentiation M dp< mod p returns, in the multiplicative group ℤ / p ℤ − 0 , to combine, by means of modular multiplication modulo p, elements equal to the element M and in number equal to the exponent dp . The order of the multiplicative group Z / pZ - {0} is (p-1).
[0045] The process of the figure 3 begins with a step E10 of updating the exponent dp by adding the order (p-1) to it.
[0046] In the example described here, where the prime number p and the exponent dp are stored in masked form as already indicated, the processor 4 adds, in step E10, the masked order (p'-1) to the masked exponent dp' and stores the result as the current exponent dp". Furthermore, so that the current exponent dp" is also masked by the mask m dp, the value of the mask mp is also subtracted from the current exponent dp".
[0047] This current exponent dp " is therefore worth dp '+(p'-1) - mp = [dp + (p-1)] + m dp .
[0048] In practice, the current exponent dp " can be stored in place of the exponent dp' in the storage module 6 (for use during subsequent implementations of the cryptographic processing method), or only stored in the RAM 8 (for use only during the present implementation of the method).
[0049] In any case, if some implementations provide that the user can choose the value of the exponent dp (and that an attacker can thus choose an exponent dp of small value as explained in the introduction), the value of the prime number p is on the contrary not configurable and is chosen sufficiently high by the system designers (the value of p being coded on at least 512 bits). The current exponent dp " used in the following will therefore necessarily have a high value.
[0050] As a variant for step E10, it is possible to update the exponent dp by adding to it a multiple of the order (p-1). Step E10 comprises for example in this case the drawing of a random number a' and the updating of the exponent dp by adding to it the product of the random number a' and the order (p-1). The length in bits of the random number a' is for example between 32 bits and 128 bits. In the embodiment described here storing the elements of the private key in masked form, so that the current exponent dp " (obtained after updating the masked exponent dp ') is also masked by the mask m dp , the product of the random number a' and the value of the mask mp is also subtracted here from the current exponent dp ".
[0051] The current exponent dp " obtained during step E10 is therefore in this case: d p ′ + a ′ . p ′ − 1 − a ′ . m p = d p + a ′ . p − 1 + m dp .
[0052] The process of the figure 3 continues to step E12 in which the processor 4 determines a number a (for example having a length k greater than 16 bits, here a length k of 32 bits) by random drawing.
[0053] The processor 4 then determines at step E14 the quotient Q' and the remainder R' of the Euclidean division of the current exponent dp " by the random number a. We therefore have: d p " = Q ′ . a + R ′ .
[0054] In the example described here where the current exponent dp " is masked, the masking is further removed by subtracting m dp / a from the masked quotient Q' so as to obtain the unmasked quotient Q, and by subtracting (m dp mod a) from the masked remainder R' to obtain the unmasked remainder R: Q = Q ′ − m dp / a R = R ′ − m dp mod a .
[0055] In the case where the remainder R is negative (R < 0), the processor 4 further performs a corrective step during which the random value a is added to the remainder R and the quotient Q is decremented by one.
[0056] We then have: Q . a + R = d " p − m dp = d p .
[0057] The processor 4 can thus determine at step E16 a first modular exponent E 1 by carrying out the modular exponentiation modulo p (or modulo kp .p in the case of the use of masked values as indicated above) of the element M to the power Qa (that is to say to a power equal to the product of the quotient Q and the random number a): E 1 = M Q . a mod p ou E 1 = M Q . a mod k p . p dans le cas de l ′ utilisation de valeurs masquées .
[0058] In the multiplicative group ℤ / p ℤ − 0 , this modular exponentiation operation amounts to combining, by means of modular multiplication modulo p (or modulo kp .p in the case of using masked values), elements equal to the element M and in number equal to the product of the quotient Q and the random number a.
[0059] The processor 4 can thus determine at step E18 a second modular exponent E 2 , by carrying out the modular exponentiation modulo p (or modulo kp .p in the case of the use of masked values) of the element M to the power R: E 2 = M R mod p ou E 2 = M R mod k p . p dans le cas de valeurs masquées
[0060] In the multiplicative group ℤ / p ℤ − 0 , this modular exponentiation operation amounts to combining, by means of modular multiplication modulo p (or modulo kp .p in the case of masked values), elements equal to the element M and in number equal to the remainder R.
[0061] The processor then determines in step E20 the desired result S p (S p = M dp< mod p, or S p ' = M dp< mod kp .p in the case of using masked values) by combining the first modular exponent E 1 and the second modular exponent E 2 by modular multiplication modulo p (or modulo kp .p in the case of masked values): S p = E 1 .E 2 mod p (or S p ' = E 1 .E 2 mod kp .p).
[0062] We now describe two variants that make it possible to avoid having to calculate the value m dp / a in step E14.
[0063] According to a first variant, step E12 is simultaneous or prior to step E10 and comprises, in addition to the determination of the number a by random drawing, the determination of two numbers a Q , a R by random drawing and the construction of a replacement mask m' equal to the sum of the random number a R and the product of the random number a and the random number a Q : m' = a R + aa Q .
[0064] Step E10 in this case includes, in addition to the operations described above, the replacement of the mask m dp by the replacement mask m': the current exponent dp " is then dp ' + (p'-1) - mp + m' - m dp = [dp + (p-1)] + m' .
[0065] Noting as above Q' = dp " / a and R' = dp " mod a (i.e. dp "=Q'.a+R'), obtaining the unmasked quotient Q and the unmasked remainder R at step E14 can then be achieved by: Q = Q' - a Q and R = R' - a R .
[0066] According to a second variant, step E12 is simultaneous or prior to step E10 and comprises, in addition to the determination of the number a by random drawing, the determination of a first number m R equal to m dp mod 2 k< and of a second number m Q equal to m dp / 2 k< (where k is as already indicated the length in bits of the random number a), and the construction of a replacement mask m' equal to the sum of the first number m R and the product of the random number a and the second number m Q: m' = m R + am Q . (Compared to the first variant, this second variant avoids the drawing of two random numbers; moreover, the division by a power of 2 used here is inexpensive in terms of computation time since it can be carried out by a shift of k bits to the right of the mask m dp ).
[0067] As for the first variant, step E10 then comprises, in addition to the operations described above, the replacement of the mask m dp by the replacement mask m': the current exponent dp " is then worth dp '+(p'-1) - mp + m' - m dp = [dp + (p-1)] + m' .
[0068] Obtaining the unmasked quotient Q and the unmasked remainder R at step E14 can then be done by: Q = Q' - m Q and R = R' - m R (still with Q' = dp " / a and R' = dp " mod a).
[0069] There figure 4 represents a cryptographic processing method according to a second embodiment of the invention.
[0070] This method implements operations in a finite group G of order n equipped with an operation noted here "*". This group G is for example a subgroup of finite order n of points of an elliptic curve E and the operation * is in this case the addition of two points of the elliptic curve E.
[0071] The process of the figure 4 aims to determine, from a first element M of the group G (here from a point M of the elliptic curve E), a second element P equal to the combination, by means of the operation *, of elements (of the group G) equal to the first element M and in number equal to an integer d. The first element M can be for example at least part of a message.
[0072] In the case described here where the group G is a subgroup of points of an elliptic curve E, we note this: P = [d] M.
[0073] For example, we seek to determine in this way a second element P in the context of a Diffie-Hellman type key exchange (the integer d then playing the role of private key), in particular: when the first element M is a generator of the group G, the second element P then being transmitted (here via the communication module 10) to a communication partner (with which the key exchange is carried out); when the first element M is received (here via the communication module 10) from a communication partner (with which the key exchange is carried out), the second element P then being the shared secret.
[0074] The storage module 6 stores the number d in masked form, that is to say that the masked number d' and the mask md are stored in the storage module 6 such that d' = d + md .
[0075] The order n, the number d and the mask md have for example a length (in bits) of at least 160 bits, for example between 160 bits and 512 bits (the masked number having a length increased by 1 bit compared to the length of the number d and the mask md in order to be able to memorize a possible carry, i.e. a length of at least 161 bits, for example between 161 bits and 513 bits).
[0076] The process of the figure 4 begins with a step E30 of determining a number a by random drawing.
[0077] The process of the figure 4 continues with a step E32 of determining a number d" by adding to the number d (here in practice to its masked version d') the order n.
[0078] Thus, even when the intended implementation allows d to be chosen and an attacker could deliberately choose a low value for d, the number d" will be high (the order n being high and generally not modifiable by the user).
[0079] In the masking implementation described here, we therefore have: d" = d' + n.
[0080] According to an alternative embodiment of step E32, a multiple of order n could be added to the number d (or here to its masked version d'). This multiple can possibly be determined by drawing a random number a' (of length between 32 bits and 128 bits, for example) and multiplying the order n by this random number a' (the multiple being in this case a'.n).
[0081] The process of the figure 4 continues with a step E34 of determining a quotient q and a remainder r using the Euclidean division of the number d" obtained in step E32 by the random number a.
[0082] In the example described here, to take masking into account, this step includes, for example, the following operations: c = 1 si d " mod a < m d mod a , sinon c = 0 q = d " / a − m d / a − c r = d " mod a − m d mod a + c . a
[0083] The use of the variable c makes it possible to avoid having in certain cases a negative remainder r due to the unmasking operation (i.e. subtraction of md mod a).
[0084] The process of the figure 4 then comprises a step E36 of obtaining (that is to say here of determining) a third element I equal to the combination, by means of the operation *, of elements equal to the first element M and in number equal to the product qa of the quotient q and the random number a.
[0085] In the case described here (where the group G is a subgroup of points of an elliptic curve E), the third element I is therefore: [qa] M.
[0086] The process of the figure 4 then comprises a step E38 of obtaining (that is to say here of determining) a fourth element J equal to the combination, by means of the operation *, of elements equal to the first element M and in number equal to the remainder r.
[0087] In the case described here (where the group G is a subgroup of points of an elliptic curve E), the fourth element J is therefore: [r] M.
[0088] The process of the figure 4 then ends with a step E40 of determining the second element P by combining the third element I and the fourth element J by means of the operation *. In other words, the second element P is determined such that P = I * J.
[0089] According to a possible variant for the method which has just been described, in order to avoid the calculation of md / a during step E34, it is possible to replace the mask md by a mask m' equal to the sum of a first intermediate number r' and the product of a second intermediate number q' by the random number a.
[0090] The mask replacement is for example carried out when determining the number of " in step E32. The operation carried out during this step is in this case: d " = d ′ + n + m ′ − m d .
[0091] According to a first possibility, the first intermediate number r' and the second intermediate number q' can be determined (for example during step E30) by random drawing.
[0092] According to a second possibility, the first intermediate number r' is determined (for example during step E30) as equal to (md mod 2 k< ) and the second intermediate number q' is determined (for example during step E30) as equal to md / 2 k< (this division by 2 k< can be carried out by k shifts of one bit to the right of the binary representation of md ), where k is the length in bits of the random number a.
[0093] According to the variant proposed here (whether we use the first possibility or the second possibility just mentioned), the quotient q is determined in step E34 by using the second intermediate number q' (to remove the masking), here by subtracting the second intermediate number q' from the masked quotient d" / a; the remainder r is determined by using the first intermediate number r' (to remove the masking), here by subtracting the first intermediate number r' from the masked remainder (d" mod a). In other words, we determine here in step E34: q = d " / a − q ′ r = d " mod a − r ′ .
[0094] The second embodiment has been described above in the case where the group G is a subgroup of points of an elliptic curve E (group whose operation * is the addition of two points of the elliptic curve E).
[0095] Alternatively, the group G could be, for example, a multiplicative subgroup of ℤ / p ℤ − {0}, a subgroup whose order n is a divisor of (p-1), where p is a prime number. The operation * in this case is modular multiplication modulo p.
[0096] Alternatively, the group G could be the multiplicative group Z / pZ -{0}, where p is a prime number, the order of the group G being in this case equal to (p-1). The operation * is in this case modular multiplication modulo p.
Claims
1. Cryptographic processing method comprising determining, in a group of finite order provided with an operation and from a first element (M) of this group, a second element (Sp; P) which is equal to the combination, by means of said operation, of elements which are equal to the first element (M) and which are equal in number to a first number (dp), the method being implemented within an electronic device (2) comprising a storage module (6), the first number (dp) being stored in the storage module (6) in masked form, the method being characterized by the following steps: - obtaining (E10; E32) a second number (d") determined by adding said order or a multiple of said order to the first number (dp); - determining (E12; E30) a random number (a); - determining (E14; E34) a quotient (Q; q) and a remainder (R; r) using the Euclidean division of the second number (d") by the random number (a); - obtaining (E16; E36) a third element (E1; I) which is equal to the combination, by means of said operation, of elements which are equal to the first element (M) and which are equal in number to the product of the quotient (Q; q) and the random number (a); - obtaining (E18; E38) a fourth element (E2; J) which is equal to the combination, by means of said operation, of elements which are equal to the first element (M) and which are equal in number to the remainder (R; r); - determining (E20; E40) the second element (Sp; P) by combining the third element (E1; I) and the fourth element (E2; J) by means of said operation, the method comprising a step of constructing a mask which is equal to the sum of a first intermediate number and the product of a second intermediate number and said random number; wherein the step of obtaining the second number (d") comprises a step of applying the constructed mask, wherein the quotient (Q; q) is determined using the second intermediate number and wherein the remainder (R; r) is determined using the first intermediate number.
2. Method according to Claim 1, comprising a step of determining another random number, wherein the second number (d") is obtained by adding the product of the other random number and said order to the first number (dp).
3. Method according to Claim 1 or 2, wherein the first intermediate number and the second intermediate number are determined by random selection.
4. Method according to Claim 1 or 2, wherein the first number (dp) is stored masked by an initial mask and wherein the second intermediate number and the first intermediate number are determined as the quotient and remainder, respectively, of the Euclidean division of the initial mask by a power of two.
5. Method according to one of Claims 1 to 4, wherein said group is the multiplicative group Z / pZ - {0}, where p is a prime number, said order being equal to (p-1).
6. Method according to one of Claims 1 to 4, wherein said group is a subgroup of points of an elliptic curve, said operation being an addition of points of the elliptic curve.
7. Method according to one of Claims 1 to 4, wherein said group is a multiplicative subgroup of Z / pZ - {0}, where p is a prime number, and wherein said order is a divisor of (p-1).
8. Electronic device (2) comprising a processor (4) and a storage module (6) storing computer program instructions which are designed, when these instructions are executed by the processor (4), to determine, in a group of finite order provided with an operation and from a first element (M) of this group, a second element (Sp; P) which is equal to the combination, by means of said operation, of elements which are equal to the first element (M) and which are equal in number to a first number (dp) stored in the storage module (6) in masked form, by means of a method comprising the following steps: - obtaining (E10; E32) a second number (d") determined by adding said order or a multiple of said order to the first number (dp); - determining (E12; E30) a random number (a); - determining (E14; E34) a quotient (Q; q) and a remainder (R; r) using the Euclidean division of the second number (d") by the random number (a); - obtaining (E16; E36) a third element (E1; I) which is equal to the combination, by means of said operation, of elements which are equal to the first element (M) and which are equal in number to the product of the quotient (Q; q) and the random number (a); - obtaining (E18; E38) a fourth element (E2; J) which is equal to the combination, by means of said operation, of elements which are equal to the first element (M) and which are equal in number to the remainder (R; r); - determining (E20; E40) the second element (Sp; P) by combining the third element (E1; I) and the fourth element (E2; J) by means of said operation, said method comprising a step of constructing a mask which is equal to the sum of a first intermediate number and the product of a second intermediate number and said random number; the step of obtaining the second number (d") comprising a step of applying the constructed mask, the quotient (Q; q) being determined using the second intermediate number and the remainder (R; r) being determined using the first intermediate number.
9. Computer program comprising instructions which are designed to implement a method according to one of Claims 1 to 7 when these instructions are executed by a processor (4).