Stronger and Faster Side-Channel Protections for CSIDH

Stronger and Faster Side-Channel Protections for CSIDH
复制标题

为 CSIDH 提供更强、更快的侧通道保护

DOI:
10.1007/978-3-030-30530-7_9
复制
发表时间:
2019
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Benjamin A. Smith
Benjamin A. Smith
中科院分区:
--
文献类型:
--
作者:
Daniel Cervantes;Mathilde Chenu;Jesús;L. D. Feo;F. Rodríguez;Benjamin A. Smith

文献摘要

被引文献

相似文献

CSIDH是一种最近的抗量子基元,它基于在超奇异曲线之间找到等距路径的困难。最近,已经提出了两个恒定时间版本的CSIDH:首先由Meyer,Campos和Reith,然后由Onuki,Aikawa,Yamazaki和Takagi提出。虽然两者都提供了针对定时攻击的保护和简单的功耗分析,但它们容易受到更强大的攻击,如故障注入。在这项工作中,我们识别并修复了这些算法中损害其恒时特性的两个疏忽。通过利用爱德华兹算法和最优加法链,我们产生了最快的恒定时间版本的CSIDH的日期。然后,我们考虑故障注入,这是相关的CSIDH静态密钥在嵌入式硬件中的安全性更强的攻击场景。我们提出并评估了一个无哑元的CSIDH算法。虽然这些CSIDH变体较慢,但它们的性能仍然在受保护较少的变体的一个小的恒定因子内。最后,我们讨论了去随机化的CSIDH算法。
CSIDH is a recent quantum-resistant primitive based on the difficulty of finding isogeny paths between supersingular curves. Recently, two constant-time versions of CSIDH have been proposed: first by Meyer, Campos and Reith, and then by Onuki, Aikawa, Yamazaki and Takagi. While both offer protection against timing attacks and simple power consumption analysis, they are vulnerable to more powerful attacks such as fault injections. In this work, we identify and repair two oversights in these algorithms that compromised their constant-time character. By exploiting Edwards arithmetic and optimal addition chains, we produce the fastest constant-time version of CSIDH to date. We then consider the stronger attack scenario of fault injection, which is relevant for the security of CSIDH static keys in embedded hardware. We propose and evaluate a dummy-free CSIDH algorithm. While these CSIDH variants are slower, their performance is still within a small constant factor of less-protected variants. Finally, we discuss derandomized CSIDH algorithms.