CSIDH is an isogeny-based Non-Interactive Key Exchange (NIKE) proposed at ASIACRYPT'18. In this work, we present the first masked version of CSIDH and, in fact, any isogeny-based scheme. We develop gadgets to efficiently mask all arithmetics in the underlying finite field and prove them secure in the
d
-probing model. In particular, we develop new gadgets for the Montgomery ladder using the fact that projective values already represent a multiplicative sharing in two variables. The technique (dubbed quotient masking) might be of independent interest. Lastly, we provide an efficient implementation based on High-Security CSIDH (Communications in Cryptology 2024). We show that the relative computational overhead of masking the latter—compared to other state-of-the-art CSIDH implementations—is similar to other masked implementations of post-quantum cryptography primitives.
Jonas Meers, Anna Guinet, Georg Land et al.· IACR Communications in Crypt...· 0 citations
Masking is a widely adopted countermeasure to protect cryptographic implementations from side-channel attacks. Subsequent research has focused on designing masking schemes and formally proving their security, notably through the development of automated tools, within models abstracting the reality of a sidechannel analysis. These designs rely on an external source of randomness; however, there is currently no consensus on the choice of (pseudo-)random number generators for masking. To the best of our knowledge, existing formal proofs for masking security do not consider particular choices of random number generators, but rather assume that they yield uniformly distributed and independent random variables. In that context, we introduce the first verification framework that jointly analyzes a pseudorandom number generator— specifically, but not limited to, a linear feedback shift register—and a masking scheme, in the d-probing model. Our framework relies on the Walsh-Hadamard transform by drawing on techniques from linear cryptanalysis, which we extend to the robust probing model. We demonstrate our method on 4-bit and 8-bit S-boxes, provide a detailed analysis of the formal verification outcomes, and corroborate the findings with practical evaluations on an FPGA.
Anna Guinet, J. Schoone, Niklas Höher et al.· IACR Transactions on Cryptog...· 0 citations