Research Article

Exploiting Small Leakages in Masks to Turn a Second-Order Attack into a First-Order Attack and Improved Rotating Substitution Box Masking with Linear Code Cosets

Figure 1

AES-256 with the Rotating S-Box Masking (RSM) protection. RSM is a Low Entropy Masking Scheme. The dashed boxes represent the operations added by RSM to AES.