the univariate case. The second-order BCA offers the
best trade-off between the execution time and trace
complexity and hence it is a good alternative to the
second-order MIA. Finally, when masking is involved
then the DCA is better than the collision attack. In-
deed, the collision attack (w.r.t. to Eq. (3)) can be
seen as a particular case of the DCA where the corre-
lation is only computed when a collision is detected.
However, the collision attack remains a good candi-
date to consider in an unmasked context as demon-
strated in (Rivain and Wang, 2019).
7 CONCLUSION
In this work, we considered the evaluation of higher-
order masked white-box implementations. Indeed,
we extended some well-known computational attacks
to the higher-order context. The practical evaluation
of these attacks had shown their efﬁciency to defeat
masked white-box implementations.
As a future work, we intend to study these higher-
order computational attacks when relaxing the as-
sumptions formulated in Sec. 2.2.
REFERENCES
