Paper 2026/1881
Constant-Time Conditions for Left-to-Right Scalar Multiplication
Abstract
We consider methods for scalar multiplication on an elliptic curve where the scalar digits are processed from left to right, that is, from most significant to least significant. We analyze exceptions that may arise during point addition and doubling throughout the multiplication. Eliminating such exceptions is critical for achieving constant-time execution and preventing timing attacks. We establish conditions under which exceptions occur only at the final addition or not at all. Guided by these conditions, one can ensure constant-time behavior by performing all doublings and all intermediate additions using fast formulas that require no exception handling. We examine three variants of the Comb method: SAB-Set, LSB-Set, and MSB-Set. For all three variants, we prove that the constant-time conditions are satisfied under mild restrictions on the base point order and Comb parameters. Additionally, we propose a convenient scalar recoding algorithm for the SAB-Set variant.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Preprint.
- Keywords
- elliptic curve cryptographyscalar multiplicationconstant-timeComb method
- Contact author(s)
- agievich @ bsu by
- History
- 2026-09-07: approved
- 2026-09-03: received
- See all versions
- Short URL
- https://ia.cr/2026/1881
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1881,
author = {Sergey Agievich},
title = {Constant-Time Conditions for Left-to-Right Scalar Multiplication},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1881},
year = {2026},
url = {https://eprint.iacr.org/2026/1881}
}