Montgomery ladder

E831071

The Montgomery ladder is a scalar multiplication algorithm on elliptic curves that provides efficient, uniform, and side-channel-resistant computation for cryptographic protocols such as those based on Curve25519.

All labels observed (1)

Label Occurrences
Montgomery ladder canonical 1

How this entity was disambiguated

Statements (47)

Predicate Object
instanceOf cryptographic algorithm ⓘ
elliptic curve algorithm ⓘ
scalar multiplication algorithm ⓘ
advantageOver naive double-and-add with secret-dependent branches ⓘ
describedIn "Speeding the Pollard and elliptic curve methods of factorization" ⓘ
designedFor efficient implementation on constrained devices ⓘ
implementation without secret-dependent branches ⓘ
implementation without secret-dependent memory access patterns ⓘ
field cryptography ⓘ
hasProperty amenable to constant-time implementation ⓘ
binary ladder structure ⓘ
bit-by-bit scalar processing ⓘ
constant-time conditional operations ⓘ
iterative algorithm ⓘ
performs one point addition and one point doubling per bit ⓘ
regular structure ⓘ
resistance to simple power analysis ⓘ
resistance to timing attacks ⓘ
side-channel resistance ⓘ
simple control flow ⓘ
uniform execution pattern ⓘ
uses two running points ⓘ
implementedIn BoringSSL ⓘ
OpenSSL ⓘ
TLS libraries ⓘ
libsodium ⓘ
introducedBy Peter L. Montgomery ⓘ
notableApplication Curve25519 ⓘ
RFC 7748 elliptic curves ⓘ
X25519 key exchange ⓘ
operatesOn Montgomery curves ⓘ
elliptic curves over finite fields ⓘ
x-coordinates of points on Montgomery curves ⓘ
publicationYear 1987 ⓘ
relatedTo Montgomery curve ⓘ
linked to: Montgomery curves

constant-time cryptographic implementations ⓘ
double-and-add algorithm ⓘ
windowed scalar multiplication ⓘ
securityGoal mitigation of power analysis side channels ⓘ
mitigation of timing side channels ⓘ
usedFor Curve25519-based key exchange ⓘ
Diffie–Hellman key exchange ⓘ
Elliptic Curve Diffie–Hellman ⓘ
constant-time scalar multiplication ⓘ
key agreement protocols ⓘ
scalar multiplication on elliptic curves ⓘ
side-channel-resistant scalar multiplication ⓘ

How these facts were elicited

Referenced by (1)

Full triples — surface form annotated when it differs from this entity's canonical label.