Side-channel evaluation of FPGA implementations of binary Edwards curves
Lejla Batina, Jip Hogenboom, Nele Mentens, Joren Moelans, Jo Vliegen · 2010
Bernstein and Lange recently proposed to use Edwards coordinates for ECC (Elliptic Curve Cryptography). They claimed them to be more efficient, not only in terms of operation count but also in terms of side-channel security. The latter is thanks to unified point addition and doubling. This work takes on this claim about improved side-channel security of Edwards curves using unified formulas. Our analysis targets an implementation of Edwards curves with a random order execution countermeasure on a Virtex-II Pro FPGA. We find that the random order execution countermeasure increases the resistance against common DPA attacks, but not against PCA (Principal Component Analysis).