32
T. Oder et al.
0
q
2
q
4
3q
4
−
q
4
0
q
2
q
4
3q
4
Transform to 2
15
0
2
14
q
4
3q
4
−
q
2
0
2
14
−
q
4
q
4
Fig. 2.3 First three steps when decoding one coefficient
MSB(y 1 + y 2 mod 2
bits ) =
0 m = 0
1 m = 1
,
as the distributions are equally distant to zero which prevents an increase in the
error probability of the decoding. In the last step, we again perform an A2B
transformation A2B(y 1 , y 2 ) = (y
1 , y
2 ) to easily extract a sharing of m with
MSB(y
1 ) ⊕ MSB(y
2 ) = m 1 ⊕ m 2 = m.
For four related coefficients, one possible approach is to perform the aforementioned masked decoding for each coefficient separately and then combine them
via a masked majority function. However, a more efficient solution is described in
Algorithm 2, where (a 1 , a 2 ), (b 1 , b 2 ), (c 1 , c 2 ), and (d 1 , d 2 ) are four related shared
coefficients (i.e., encode the same m). Our main idea is to combine the coefficients
before the final A2B. To perform this combination without losing information and
T. Oder et al.
0
q
2
q
4
3q
4
−
q
4
0
q
2
q
4
3q
4
Transform to 2
15
0
2
14
q
4
3q
4
−
q
2
0
2
14
−
q
4
q
4
Fig. 2.3 First three steps when decoding one coefficient
MSB(y 1 + y 2 mod 2
bits ) =
0 m = 0
1 m = 1
,
as the distributions are equally distant to zero which prevents an increase in the
error probability of the decoding. In the last step, we again perform an A2B
transformation A2B(y 1 , y 2 ) = (y
1 , y
2 ) to easily extract a sharing of m with
MSB(y
1 ) ⊕ MSB(y
2 ) = m 1 ⊕ m 2 = m.
For four related coefficients, one possible approach is to perform the aforementioned masked decoding for each coefficient separately and then combine them
via a masked majority function. However, a more efficient solution is described in
Algorithm 2, where (a 1 , a 2 ), (b 1 , b 2 ), (c 1 , c 2 ), and (d 1 , d 2 ) are four related shared
coefficients (i.e., encode the same m). Our main idea is to combine the coefficients
before the final A2B. To perform this combination without losing information and
