The 1-Bit Barrier is Universal: k-Stage Pipeline Composition and Unified Leakage Bounds for Standard Modular Reductions in PQC Hardware
Ray Iskander, Khaled Kirah

TL;DR
This paper provides formal, machine-verified bounds on information leakage in masked NTT hardware for post-quantum cryptography, extending previous results to arbitrary pipeline depths and specific reduction techniques.
Contribution
It generalizes leakage bounds to k-stage pipelines, verifies tight bounds for Montgomery reduction, and consolidates these into a comprehensive security framework.
Findings
Per-observation probability bound is 2/q, independent of pipeline depth.
Montgomery reduction satisfies PF-PINI(2) with tight max-multiplicity 2.
End-to-end leakage bound is 2 * q^{2k-2} for any pipeline depth k.
Abstract
This is Paper 7 of a series of formally-verified analyses of masked NTT hardware for post-quantum cryptography; Paper 1 [1] established structural dependency analysis of the QANARY platform, and Paper 2 [2] quantified security margins under partial NTT masking. Arbitrary-depth -stage masked NTT pipelines with fresh inter-stage masking and per-stage PF-PINI() gadgets satisfy a per-observation cardinality bound of on the preimage of any output value, machine-checked in Lean 4 with zero \texttt{sorry}. Under the standard (informal) semantic translation that divides this cardinality by the total mask-tuple space size , the per-observation conditional probability bound is , independent of pipeline depth . The QANARY program has previously established machine-checked cardinality bounds on the per-observation leakage of masked NTT hardware:…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
