DOI: 10.62056/a6qjp2c2h ISSN: 3006-5496

Side-Channel Secure CSIDH with Projective Coordinates

Jonas Meers, Anna Guinet, Georg Land, Elisabeth Krahmer, Tim Güneysu

CSIDH is an isogeny-based Non-Interactive Key Exchange (NIKE) proposed at ASIACRYPT'18. In this work, we present the first masked version of CSIDH and, in fact, any isogeny-based scheme. We develop gadgets to efficiently mask all arithmetics in the underlying finite field and prove them secure in the d -probing model. In particular, we develop new gadgets for the Montgomery ladder using the fact that projective values already represent a multiplicative sharing in two variables. The technique (dubbed quotient masking) might be of independent interest. Lastly, we provide an efficient implementation based on High-Security CSIDH (Communications in Cryptology 2024). We show that the relative computational overhead of masking the latter—compared to other state-of-the-art CSIDH implementations—is similar to other masked implementations of post-quantum cryptography primitives.

More from our Archive