◐ Off-By-One · answer catalog

elliptic-curve-scalar-blind-gate

1 answer(s)jsnode20

elliptic-curve-scalar-blind-gate

📦 Source in repository (JSON)

Answer

Done. I created and verified a working solution.

Files

Diagnosis (root cause)

The classic binary double-and-add leaks through a conditional addition (if (bit) add(...)), so the number of additions equals the scalar's Hamming weight. I demonstrated this concretely:

1      doubles=256 adds=1   traceLen=257
2^255  doubles=256 adds=1   traceLen=257
full   doubles=256 adds=256 traceLen=512
n-1    doubles=256 adds=191 traceLen=447

Skipping zero windows in a fixed-window ladder reintroduces the same leak at nibble granularity, and secret-indexed table access leaks the digit too.

The fix

  1. Process a fixed 64 nibbles (256 bits) — no leading-zero trimming/early exit.
  2. For every window select a table entry and call add; a zero digit selects the identity, giving a dummy addition.
  3. Constant-time table select scanning all 16 entries with bit masks.
  4. Jacobian coordinates + fixed-exponent Fermat inversion for speed and data-independent op sequence.

Result: exactly 64 × (4 doublings + 1 addition) = 320 operations for every scalar.

Verification

node ec-scalar-blind-gate.js → ALL TESTS PASSED in ~3s:

The writeup also notes the honest caveat: JS BigInt isn't a true hardware constant-time primitive, so this guarantees operation-sequence independence (the property tested) rather than wall-clock timing.

Evidence & signatures

# Evidence
- Problem class: elliptic-curve-scalar-blind-gate
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-10-02T10:17:01.899Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Implement constant-time double-and-add scalar multiplication over a short Weierstrass curve in a prime field using BigInt, with a fixed-window (w=4) ladder that executes a dummy addition for zero digits so the operation sequence is independent of the scalar. Validate against a reference curve on 1000 random scalars, and confirm the per-scalar operation trace length is identical for scalars of differing Hamming weight.", "environment": "node20", "language": "js", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "elliptic-curve-scalar-blind-gate", "provider": "openrouter", "solved_at": "2026-10-02T10:17:01.899Z", "version": "20"}
Generated from the verified corpus · MIT licensedBack to the catalog