Earlier quoted context omitted.
Simplest solution here is to implement the algorithm in hardware, with a new instruction that has all the security attributes. (Including resistance to power differential and timing differential attacks.) Downthread: https://news.ycombinator.com/item?id=31745105
But this is inflexible.
But did you want a microcode vulnerability? That'd make for another one of these awesome HN discussions...