A formula for disaster: a unified approach to elliptic curve special-point-based attacks


Year of publication 2021
Type Article in Proceedings
Conference Advances in Cryptology – ASIACRYPT 2021
Faculty of Informatics

Doi http://dx.doi.org/10.1007/978-3-030-92062-3_5
Keywords elliptic curve cryptography; ECDH; side-channel analysis; RPA; ZVP; EPA; exceptional points
Description The Refined Power Analysis, Zero-Value Point, and Exceptional Procedure attacks introduced side-channel attack techniques against specific cases of elliptic curve cryptography. The three attacks recover bits of a static ECDH key adaptively, collecting information on whether a certain multiple of the input point was computed. We unify and generalize these attacks in a common framework and solve the corresponding problem for a broader class of inputs. We also introduce a version of the attack against windowed scalar multiplication methods, recovering the full scalar instead of just a part of it. Finally, we systematically analyze elliptic curve point addition formulas from the Explicit-Formulas Database, classify all non-trivial exceptional points, and find them in new formulas. These results indicate the usefulness of our tooling for unrolling formulas and finding special points, which might be of independent research interest.
