Paper 2026/1881

Constant-Time Conditions for Left-to-Right Scalar Multiplication

Sergey Agievich, Belarusian State University
Abstract

We consider methods for scalar multiplication on an elliptic curve where the scalar digits are processed from left to right, that is, from most significant to least significant. We analyze exceptions that may arise during point addition and doubling throughout the multiplication. Eliminating such exceptions is critical for achieving constant-time execution and preventing timing attacks. We establish conditions under which exceptions occur only at the final addition or not at all. Guided by these conditions, one can ensure constant-time behavior by performing all doublings and all intermediate additions using fast formulas that require no exception handling. We examine three variants of the Comb method: SAB-Set, LSB-Set, and MSB-Set. For all three variants, we prove that the constant-time conditions are satisfied under mild restrictions on the base point order and Comb parameters. Additionally, we propose a convenient scalar recoding algorithm for the SAB-Set variant.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
elliptic curve cryptographyscalar multiplicationconstant-timeComb method
Contact author(s)
agievich @ bsu by
History
2026-09-07: approved
2026-09-03: received
See all versions
Short URL
https://ia.cr/2026/1881
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1881,
      author = {Sergey Agievich},
      title = {Constant-Time Conditions for Left-to-Right Scalar Multiplication},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1881},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1881}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.