“…In 2016, De Cnudde et al . [19] introduced a general method to protect AES‐128 against d th‐order DPA attacks using masking shares. In particular, to implement the second‐order masking of AES‐128, this approach uses 162 random bits per round and the cost of hardware implementation is around 10 kGE.…”