Paper 2025/1645

Hardened CTIDH: Dummy-Free and Deterministic CTIDH

Gustavo Banegas, Inria Saclay - Île-de-France Research Centre, Laboratoire d’Informatique de l’Ecole polytechnique, Institut Polytechnique de Paris
Andreas Hellenbrand, RheinMain University of Applied Sciences
Matheus Saldanha, Universidade Federal de Santa Catarina
Abstract

Isogeny-based cryptography has emerged as a promising post-quantum alternative, with CSIDH and its constant-time variant CTIDH offering efficient group-action protocols. dCTIDH recently introduced an efficient deterministic version. However, CTIDH and dCTIDH rely on dummy operations in differential addition chains (DACs) and Matryoshka isogenies, which can be exploitable by fault-injection attacks. In this work, we present the first dummy-free implementation of dCTIDH. Our approach combines two recent ideas: DACsHUND, which enforces equal-length DACs within each batch without padding, and a reformulated Matryoshka structure that removes dummy multiplications and validates all intermediate points. Our analysis shows that small primes such as 3, 5, and 7 severely restrict feasible DACsHUND configurations, motivating new parameter sets that exclude them. We implement dummy-free dCTIDH-2048-194 and dCTIDH-2048-205, achieving group action costs of roughly 357,000 to 362,000 finite-field multiplications, with median evaluation times of 1.59 to 1.60 gigacycles. These results do not surpass dCTIDH, but they outperform CTIDH by roughly 5 percent while eliminating dummy operations entirely. Compared to dCSIDH, our construction is more than four times faster. To the best of our knowledge, this is the first efficient implementation of a CSIDH-like protocol that is simultaneously deterministic, constant-time, and fully dummy-free.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published elsewhere. Minor revision. INDOCRYPT 2025
DOI
10.1007/978-3-032-13301-4_9
Keywords
Post-quantum cryptographyIsogeny-based CryptographyCSIDH
Contact author(s)
gustavo @ cryptme in
andreas hellenbrand @ hs-rm de
matheus saldanha @ posgrad ufsc br
History
2026-01-11: revised
2025-09-11: received
See all versions
Short URL
https://ia.cr/2025/1645
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1645,
      author = {Gustavo Banegas and Andreas Hellenbrand and Matheus Saldanha},
      title = {Hardened {CTIDH}: Dummy-Free and Deterministic {CTIDH}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1645},
      year = {2025},
      doi = {10.1007/978-3-032-13301-4_9},
      url = {https://eprint.iacr.org/2025/1645}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.