A Closed-Form Hamming-Weight Variance Formula for Cyclic LCD Codes in Orthogonal Direct Sum Masking
Guillermo Sosa-GómezOrthogonal direct sum masking (ODSM) protects embedded cryptographic implementations against side-channel attacks by splitting the ambient space into a source code C carrying sensitive data and a complementary masking code D carrying fresh randomness; when D=C⊥, C must be a linear complementary dual (LCD) code. Much of the literature evaluates the masking code primarily through the minimum distance d(D⊥)=d(C) of its dual, treating this parameter as the quantitative summary of leakage resistance under a Hamming-weight leakage model. We show, first computationally and then via a general algebraic theorem, that this one parameter does not determine the variance of the masking code’s Hamming-weight distribution: cyclic codes with identical d(C) can differ by close to an order of magnitude in this variance. We prove, for an arbitrary cyclic code C⊆GF(q)n with nonzero dual D=C⊥ and defining set T (the LCD property is not required for this algebraic result and is invoked only for the ODSM application), a closed-form theorem expressing Varc∈D[wt(c)] exactly as (q−1)n2/(q2L(T)), where L(T) is an intrinsically defined, representative-independent arithmetic invariant of T, computable via a single least-common-multiple of greatest-common-divisors and requiring no exponential-sum or Gauss-period evaluation. We verify the formula, with an explicit worked example, reproducible from the displayed defining sets, and zero discrepancies, against 64 independently constructed LCD cyclic codes spanning two finite fields and three code lengths. We are explicit that this variance is a second-order algebraic descriptor of leakage dispersion under an idealized leakage model, not a complete side-channel security metric; the connection to physical Hamming-weight leakage is direct for q=2; for q>2, the result stands as an exact coding-theoretic characterization whose relevance to physical bit-level leakage depends on an explicit bit-encoding model not developed here. We discuss its role as a design diagnostic for ODSM masking codes. This paper is, at its core, a contribution to the algebraic theory of cyclic codes: the reduction of the variance to a weight-two-codeword count is the classical Pless moment identity, and our closed-form arithmetic characterization of that count via L(T) is algebraically equivalent, on its domain, to a 2024 result of Coelho and Brochero Martínez; we extend it to arbitrary cyclic length and arbitrary prime-power base fields, and position it as a complement to, not a replacement for, the more operational dual-distance/kissing-number methodology already used in the code-based masking literature.