Paper 2025/1645
Hardened CTIDH: Dummy-Free and Deterministic CTIDH
Abstract
Isogeny-based cryptography has emerged as a promising post-quantum alternative, with CSIDH and its constant-time variant CTIDH offering efficient group-action protocols. dCTIDH recently introduced an efficient deterministic version. However, CTIDH and dCTIDH rely on dummy operations in differential addition chains (DACs) and Matryoshka isogenies, which can be exploitable by fault-injection attacks. In this work, we present the first dummy-free implementation of dCTIDH. Our approach combines two recent ideas: DACsHUND, which enforces equal-length DACs within each batch without padding, and a reformulated Matryoshka structure that removes dummy multiplications and validates all intermediate points. Our analysis shows that small primes such as 3, 5, and 7 severely restrict feasible DACsHUND configurations, motivating new parameter sets that exclude them. We implement dummy-free dCTIDH-2048-194 and dCTIDH-2048-205, achieving group action costs of roughly 357,000 to 362,000 finite-field multiplications, with median evaluation times of 1.59 to 1.60 gigacycles. These results do not surpass dCTIDH, but they outperform CTIDH by roughly 5 percent while eliminating dummy operations entirely. Compared to dCSIDH, our construction is more than four times faster. To the best of our knowledge, this is the first efficient implementation of a CSIDH-like protocol that is simultaneously deterministic, constant-time, and fully dummy-free.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Published elsewhere. Minor revision. INDOCRYPT 2025
- DOI
- 10.1007/978-3-032-13301-4_9
- Keywords
- Post-quantum cryptographyIsogeny-based CryptographyCSIDH
- Contact author(s)
-
gustavo @ cryptme in
andreas hellenbrand @ hs-rm de
matheus saldanha @ posgrad ufsc br - History
- 2026-01-11: revised
- 2025-09-11: received
- See all versions
- Short URL
- https://ia.cr/2025/1645
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1645,
author = {Gustavo Banegas and Andreas Hellenbrand and Matheus Saldanha},
title = {Hardened {CTIDH}: Dummy-Free and Deterministic {CTIDH}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1645},
year = {2025},
doi = {10.1007/978-3-032-13301-4_9},
url = {https://eprint.iacr.org/2025/1645}
}