Faster compact Diffie-Hellman: Endomorphisms on the x-line

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

We describe an implementation of fast elliptic curve scalar multiplication, optimized for Diffie-Hellman Key Exchange at the 128-bit security level. The algorithms are compact (using only x-coordinates), run in constant time with uniform execution patterns, and do not distinguish between the curve and its quadratic twist; they thus have a built-in measure of side-channel resistance. (For comparison, we also implement two faster but non-constant-time algorithms.) The core of our construction is a suite of two-dimensional differential addition chains driven by efficient endomorphism decompositions, built on curves selected from a family of ℚ-curve reductions over double-struck F p2 with p = 2127 - 1. We include state-of-the-art experimental results for twist-secure, constant-time, x-coordinate-only scalar multiplication.

Original languageEnglish
Title of host publicationAdvances in Cryptology, EUROCRYPT 2014 - 33rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Proceedings
PublisherSpringer Verlag
Pages183-200
Number of pages18
ISBN (Print)9783642552199
DOIs
Publication statusPublished - 1 Jan 2014
Event33rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2014 - Copenhagen, Denmark
Duration: 11 May 201415 May 2014

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8441 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference33rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2014
Country/TerritoryDenmark
CityCopenhagen
Period11/05/1415/05/14

Keywords

  • Elliptic curve cryptography
  • Kummer variety
  • Montgomery curve
  • addition chains
  • endomorphism
  • scalar multiplication
  • side channel attacks
  • twist-secure

Fingerprint

Dive into the research topics of 'Faster compact Diffie-Hellman: Endomorphisms on the x-line'. Together they form a unique fingerprint.

Cite this