Machine-Checked Cardinality Bounds for Masked Barrett Reduction: A 1-Bit Side-Channel Leakage Barrier in Post-Quantum Cryptographic Hardware

πŸ“… 2026-04-27
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This work addresses the absence of a formal characterization of information leakage in first-order masked Barrett reduction over prime fields under side-channel attacks. The authors propose and machine-verify a β€œ1-bit barrier” property, establishing that each internal wire leaks at most one bit of information for any modulus. They formulate a trichotomy theorem on the cardinalities of preimages under internal wire mappings and prove that the maximum multiplicity does not exceed two. Furthermore, they introduce the PF-PINI security model and demonstrate that the implementation satisfies PF-PINI(2). Using Lean 4 and Mathlib, they formally verify twelve theorems, providing the first general, machine-checked bounds on mask cardinalities and leakage analysis for Barrett reduction applicable to both ML-KEM and ML-DSA.

Technology Category

Application Category

πŸ“ Abstract
Barrett reduction is the nonlinear core of every practical NTT-based post-quantum cryptography implementation. Existing composition frameworks (ISW, t-SNI, PINI, DOM) address Boolean masking over GF(2); none provides a machine-checked characterization of Barrett's leakage under first-order arithmetic masking and the first-order probing model over prime fields. Building on our prior series, QANARY [15], partial-NTT-masking margins [14], algebraic foundations [16], and butterfly composition [18], we close this gap. We prove a trichotomy: for any $q > 0$ and shift $s$, the Barrett internal wire map $f_x(m) = ((x + 2^s - m) \bmod 2^s) \bmod q$ has preimage cardinality in $\{0, 1, 2\}$, never more. We call this the 1-Bit Barrier: max-multiplicity 2 implies at most 1 bit of min-entropy loss per internal wire, universal over all moduli. The count-zero cases, unreachable output values, reveal that actual leakage is often strictly less than 1 bit, making the bound conservative. We introduce PF-PINI (Prime-Field PINI): Barrett satisfies PF-PINI(2); the Cooley-Tukey butterfly satisfies PF-PINI(1). We observe (not yet proved) that with fresh inter-stage masking, the composed pipeline has max-multiplicity $\max(k_1, k_2)$, so the 1-Bit Barrier propagates. The trichotomy, the PF-PINI instantiations, and cardinality results are machine-checked in Lean 4 with Mathlib: 12 proved results, zero sorry, universal over all $q > 0$ (the min-entropy bound follows by standard definitions). Adams Bridge lacks fresh inter-stage masking, violating PF-PINI composition and explaining why Papers 1 [15] and 2 [14] found vulnerabilities. NIST IR 8547 recommends formal methods for PQC implementation validation. The 1-Bit Barrier provides the first universal machine-checked cardinality bound for masked Barrett reduction in ML-KEM (FIPS 203) and ML-DSA (FIPS 204), with a corresponding 1-bit leakage interpretation.
Problem

Research questions and friction points this paper is trying to address.

Barrett reduction
side-channel leakage
arithmetic masking
post-quantum cryptography
machine-checked proof
Innovation

Methods, ideas, or system contributions that make the work stand out.

Barrett reduction
side-channel leakage
machine-checked proof
arithmetic masking
PF-PINI
R
Ray Iskander
Verdict Security
K
Khaled Kirah
Faculty of Engineering, Ain Shams University, Cairo, Egypt