“…Although these attacks are implementation-specific, the proposed countermeasures impact our attack too. Typically, real isogenies are computed prior to dummy isogenies, but the order of real and dummy isogenies can be randomized [10,28] with essentially no computational overhead. When applied to dummy-based implementations, e.g., from [30,32], this randomization means dummy isogenies can appear in different rounds for each run, which makes the definitions of the curves E r,± almost obsolete.…”