TY - GEN
T1 - Hardened CTIDH
T2 - 26th International Conference on Cryptology in India, INDOCRYPT 2025
AU - Banegas, Gustavo
AU - Hellenbrand, Andreas
AU - Saldanha, Matheus
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.
PY - 2026/1/1
Y1 - 2026/1/1
N2 - Isogeny-based cryptography has emerged as a promising post-quantum alternative, with CSIDH and its constant-time variant CTIDH offering efficient group-action protocols. dCTIDH recently introduced a efficient deterministic version. However, CTIDH and dCTIDH rely on dummy operations in differential addition chains (DACs) and Matryoshka-isogenies, which can be exploitable by fault-injection attacks. In this work, we present the first dummy-free implementation of dCTIDH. Our approach combines two recent ideas: DACsHUND, which enforces equal-length DACs within each batch without padding, and a reformulated Matryoshka structure that removes dummy multiplications and validates all intermediate points. Our analysis shows that small primes such as 3, 5, and 7 severely restrict feasible DACsHUND configurations, motivating new parameter sets that exclude them. We implement dummy-free dCTIDH-2048-194 and dCTIDH-2048-205, achieving group action costs of roughly 357, 000 to 362, 000 Fp-multiplications, with median evaluation times of 1.59 to 1.60 (Gcyc). These results do not surpass dCTIDH, but they outperform CTIDH by roughly 5% while eliminating dummy operations entirely. Compared to dCSIDH, our construction is more than 4× faster. To the best of our knowledge, this is the first efficient implementation of a CSIDH-like protocol that is simultaneously deterministic, constant-time, and fully dummy-free.
AB - Isogeny-based cryptography has emerged as a promising post-quantum alternative, with CSIDH and its constant-time variant CTIDH offering efficient group-action protocols. dCTIDH recently introduced a efficient deterministic version. However, CTIDH and dCTIDH rely on dummy operations in differential addition chains (DACs) and Matryoshka-isogenies, which can be exploitable by fault-injection attacks. In this work, we present the first dummy-free implementation of dCTIDH. Our approach combines two recent ideas: DACsHUND, which enforces equal-length DACs within each batch without padding, and a reformulated Matryoshka structure that removes dummy multiplications and validates all intermediate points. Our analysis shows that small primes such as 3, 5, and 7 severely restrict feasible DACsHUND configurations, motivating new parameter sets that exclude them. We implement dummy-free dCTIDH-2048-194 and dCTIDH-2048-205, achieving group action costs of roughly 357, 000 to 362, 000 Fp-multiplications, with median evaluation times of 1.59 to 1.60 (Gcyc). These results do not surpass dCTIDH, but they outperform CTIDH by roughly 5% while eliminating dummy operations entirely. Compared to dCSIDH, our construction is more than 4× faster. To the best of our knowledge, this is the first efficient implementation of a CSIDH-like protocol that is simultaneously deterministic, constant-time, and fully dummy-free.
KW - CSIDH
KW - isogeny-based cryptography
KW - post-quantum cryptography
UR - https://www.scopus.com/pages/publications/105025920604
U2 - 10.1007/978-3-032-13301-4_9
DO - 10.1007/978-3-032-13301-4_9
M3 - Conference contribution
AN - SCOPUS:105025920604
SN - 9783032133007
T3 - Lecture Notes in Computer Science
SP - 194
EP - 215
BT - Progress in Cryptology - INDOCRYPT 2025 - 26th International Conference on Cryptology in India, Proceedings
A2 - Dutta, Ratna
A2 - De Feo, Luca
A2 - Gangopadhyay, Sugata
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 14 December 2025 through 17 December 2025
ER -