{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T02:26:24Z","timestamp":1783650384144,"version":"3.55.0"},"reference-count":20,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2015,11,4]],"date-time":"2015-11-04T00:00:00Z","timestamp":1446595200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"German Federal Ministry of Economics and Technology","award":["01ME12025 SecMobil"],"award-info":[{"award-number":["01ME12025 SecMobil"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Reconfigurable Technol. Syst."],"published-print":{"date-parts":[[2015,11,24]]},"abstract":"<jats:p>For security-critical embedded applications Elliptic Curve Cryptography (ECC) has become the predominant cryptographic system for efficient key agreement and digital signatures. However, ECC still involves complex modular arithmetic that is a particular burden for small processors. In this context, Bernstein proposed the highly efficient ECC instance Curve25519 that particularly enables efficient software implementations at a security level comparable to AES-128 with inherent resistance to simple power analysis (SPA) and timing attacks. In this work, we show that Curve25519 is likewise competitive on FPGAs even when countermeasures to thwart side-channel power analysis are included. Our basic multicore DSP-based architectures achieves a maximal performance of more than 32,000 point multiplications per second on a Xilinx Zynq 7020 FPGA. Including a mix of side-channel countermeasures to impede simple and differential power analysis, we still achieve more than 27,500 point multiplications per second with a moderate increase in logic resources.<\/jats:p>","DOI":"10.1145\/2700834","type":"journal-article","created":{"date-parts":[[2015,11,5]],"date-time":"2015-11-05T16:19:01Z","timestamp":1446740341000},"page":"1-15","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":29,"title":["Implementing Curve25519 for Side-Channel--Protected Elliptic Curve Cryptography"],"prefix":"10.1145","volume":"9","author":[{"given":"Pascal","family":"Sasdrich","sequence":"first","affiliation":[{"name":"Horst G\u00f6rtz Institute for IT-Security, Ruhr-Universit\u00e4t Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tim","family":"G\u00fcneysu","sequence":"additional","affiliation":[{"name":"Horst G\u00f6rtz Institute for IT-Security, Ruhr-Universit\u00e4t Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2015,11,4]]},"reference":[{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/11745853_14"},{"key":"e_1_2_1_3_1","volume-title":"Cryptographic Hardware and Embedded Systems","author":"Coron Jean-S\u00e9bastien"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2006.09.002"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2007.05.009"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1985.1057074"},{"key":"e_1_2_1_9_1","volume-title":"Cryptography and Security: From Theory to Applications","author":"Fan Junfeng"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-85053-3_5"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1090\/S0025-5718-1987-0866109-5"},{"key":"e_1_2_1_12_1","volume-title":"Advances in Cryptology CRYPTO99","author":"Kocher Paul"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-001-0009-4"},{"key":"e_1_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Yuan Ma Zongbin Liu Wuqiong Pan and Jiwu Jing. 2013. A High-speed elliptic curve cryptographic processor for generic curves over mathrm p. In Selected Areas in Cryptography. 421--437.  Yuan Ma Zongbin Liu Wuqiong Pan and Jiwu Jing. 2013. A High-speed elliptic curve cryptographic processor for generic curves over mathrm p. In Selected Areas in Cryptography. 421--437.","DOI":"10.1007\/978-3-662-43414-7_21"},{"key":"e_1_2_1_15_1","unstructured":"Stefan Mangard Elisabeth Oswald and Thomas Popp. 2008. Power Analysis Attacks: Revealing the Secrets of Smart Cards. Vol. 31. Springer.   Stefan Mangard Elisabeth Oswald and Thomas Popp. 2008. Power Analysis Attacks: Revealing the Secrets of Smart Cards. Vol. 31. Springer."},{"key":"e_1_2_1_16_1","volume-title":"Irish Signals and Systems Conference (ISSC). 589--594","author":"McIvor C."},{"key":"e_1_2_1_17_1","volume-title":"Advances in Cryptology \u2014 CRYPTO'85","author":"Miller V."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1090\/S0025-5718-1987-0866113-7"},{"key":"e_1_2_1_19_1","volume-title":"Cryptographic Hardware and Embedded Systems (CHES)","volume":"2162","author":"Orlando G."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASAP.2003.1212866"},{"key":"e_1_2_1_21_1","volume-title":"ARC (Lecture Notes in Computer Science), Koen Bertels, Jo\u00e3o M","author":"Sakiyama Kazuo"},{"key":"e_1_2_1_22_1","volume-title":"Reconfigurable Computing: Architectures, Tools, and Applications, Diana Goehringer, MarcoDomenico Santambrogio, JooM","author":"Sasdrich Pascal"}],"container-title":["ACM Transactions on Reconfigurable Technology and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2700834","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2700834","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T05:48:27Z","timestamp":1750225707000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2700834"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,11,4]]},"references-count":20,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2015,11,24]]}},"alternative-id":["10.1145\/2700834"],"URL":"https:\/\/doi.org\/10.1145\/2700834","relation":{},"ISSN":["1936-7406","1936-7414"],"issn-type":[{"value":"1936-7406","type":"print"},{"value":"1936-7414","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,11,4]]},"assertion":[{"value":"2014-07-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2014-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2015-11-04","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}