• Home
  • Search
  • Protecting the Most Significant Bits in Scalar Multiplication Algorithms
  • Cite Icon1
  • https://doi.org/10.1007/978-3-031-22829-2_7Copy DOI Icon

Protecting the Most Significant Bits in Scalar Multiplication Algorithms

  • Jan 1, 2022
  • Estuardo Alpirez Bock +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Abstract The Montgomery Ladder is widely used for implementing the scalar multiplication in elliptic curve cryptographic designs. This algorithm is efficient and provides a natural robustness against (simple) side-channel attacks. Previous works however showed that implementations of the Montgomery Ladder using Lopez-Dahab projective coordinates easily leak the value of the most significant bits of the secret scalar, which led to a full key recovery in an attack known as LadderLeak [3]. In light of such leakage, we analyse further popular methods for implementing the Montgomery Ladder. We first consider open source software implementations of the X25519 protocol which implement the Montgomery Ladder based on the ladderstep algorithm from Düll et al. [15]. We confirm via power measurements that these implementations also easily leak the most significant scalar bits, even when implementing Z-coordinate randomisations. We thus propose simple modifications of the algorithm and its handling of the most significant bits and show the effectiveness of our modifications via experimental results. Particularly, our re-designs of the algorithm do not incurring significant efficiency penalties. As a second case study, we consider open source hardware implementations of the Montgomery Ladder based on the complete addition formulas for prime order elliptic curves, where we observe the exact same leakage. As we explain, the most significant bits in implementations of the complete addition formulas can be protected in an analogous way as we do for Curve25519 in our first case study.KeywordsECCMontgomery LadderCurve25519Complete addition formulasSide-channel analysis

Similar Papers
  • Conference Article

Parallelized Side-Channel Attack Resisted Scalar Multiplication Using q-Based Addition-Subtraction k-Chains

  • Nov 01, 2016
  • Kittiphop Phalakarn +2
  • Conference Article
  • Citations11

Secure and Efficient RNS Software Implementation for Elliptic Curve Cryptography

  • Apr 01, 2017
  • Apostolos P Fournaris +2
  • PDF
  • Research Article
  • Citations19

Faster Montgomery and double-add ladders for short Weierstrass curves

  • Aug 26, 2020
  • IACR Transactions on Cryptographic Hardware and Embedded Systems
  • Mike Hamburg
  • Book Chapter
  • Citations9

Delaying and Merging Operations in Scalar Multiplication: Applications to Curve-Based Cryptosystems

  • Aug 17, 2006
  • Roberto Maria Avanzi
  • Conference Article
  • Citations3

New Results for Partial Key Exposure on RSA with Exponent Blinding

  • Jan 01, 2015
  • Stelvio Cimato +2
  • Conference Article
  • Citations1

An Elliptic Curve Crypto-Processor Secured by Randomized Windows

  • Aug 01, 2014
  • Simon Pontie +2
  • Book Chapter
  • Citations5

Securing Color Image Using Combined Elliptic Curve Crypto-System and Hill Cipher Encryption Along with Least Significant Bit - Steganography

  • Nov 03, 2019
  • N Faizal +3
  • Research Article
  • Citations23

High-performance Public-key Cryptoprocessor for Wireless Mobile Applications

  • Oct 03, 2007
  • Mobile Networks and Applications
  • Kazuo Sakiyama +3
  • Book Chapter
  • Citations11

Efficient Arithmetic on Elliptic Curves in Characteristic 2

  • Jan 01, 2012
  • David Kohel
  • Conference Article
  • Citations25

Simple power analysis attack against elliptic curve cryptography processor on FPGA implementation

  • Jul 01, 2011
  • Sahbuddin Abdul Kadir +2
  • Research Article
  • Citations46

High-speed hardware architecture of scalar multiplication for binary elliptic curve cryptosystems

  • Mar 28, 2016
  • Microelectronics Journal
  • Bahram Rashidi +2
  • Research Article
  • Citations6

EMD-based steganography techniques for JPEG2000 encoded images

  • Feb 09, 2017
  • International Journal of Wavelets, Multiresolution and Information Processing
  • Geeta Kasana +2
  • Book Chapter
  • Citations20

A New Elliptic Curve Scalar Multiplication Algorithm to Resist Simple Power Analysis

  • Jan 01, 2002
  • Yvonne Hitchcock +1
  • Book Chapter
  • Citations19

Partial Key Exposure on RSA with Private Exponents Larger Than N

  • Jan 01, 2012
  • Marc Joye +1
  • Research Article
  • Citations32

Four-Dimensional Gallant–Lambert–Vanstone Scalar Multiplication

  • Jan 16, 2013
  • Journal of Cryptology
  • Patrick Longa +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.