Skew-Frobenius maps on hyperelliptic curves

Size: px
Start display at page:

Download "Skew-Frobenius maps on hyperelliptic curves"

Transcription

1 All rights are reserved and copyright of this manuscript belongs to the authors. This manuscript h been published without reviewing and editing received from the authors: posting the manuscript to SCIS 2007 does not prevent future submissions to any journals or conferences with proceedings. SCIS 2007 The 2007 Symposium on Cryptography and Information Security Sebo, Japan, Jan , 2007 The Institute of Electronics, Information and Communication Engineers Skew-Frobenius maps on hyperelliptic curves Shunji Kozaki Kazuto Matsuo Yutomo Shimbara Abstract The hyperelliptic curve cryptosystems take most of the time for computing a scalar multiplication kd of an element D in the Jacobian J C of a hyperelliptic curve C for an integer k. Therefore its efficiency depends on the scalar multiplications. Among the ft scalar multiplication methods, there is a method using a Frobenius map. It uses a Jacobian defined over an extension field of the definition field of C, so that the Jacobian cannot be a 160 bit prime order. Therefore there is a loss of efficiency in that method. Iijima et al. proposed a method using a Frobeinus map on the quadratic twist of an elliptic curve, which is called a skew-frobenius map in this paper. This paper shows constructions of the skew-frobenius maps on hyperelliptic curves of genus 2 and 3. Keywords: hyperelliptic curves, hyperelliptic curve cryptosystems, Frobenius maps, scalar multiplication, skew-frobenius maps 1 Introduction The hyperelliptic curve cryptosystems [11] have been studied one of the public-key cryptosystems using a plain algebraic curve. They take most of the time for computing a scalar multiplication kd, where k is an integer and D is an element in the Jacobian J C of a hyperelliptic curve C defined over F q. Therefore it requires a ft scalar multiplication to construct efficient hyperelliptic curve cryptosystems. In order to achieve a ft scalar multiplication, one needs speeding up for two of operations i.e. additions of elements and addition chains. The sliding window method [3, Chapter IV.2] is one of the addition chain methods. Besides there is a method using a property of (hyper-)elliptic curves, i.e. the method using a Frobenius map [10, 12, 15]. The cryptosystems using a Frobenius map are constructed on J C (F q n). However J C (F q n) cannot be a prime order, so that one needs to choose C such that J C (F q n)/ J C (F q ) is a prime number in such cryptosystems. Therefore there is a loss of efficiency in the method using a Frobenius map. Iijima et al. proposed a method using a Frobeinus map on the quadratic twist of an elliptic curve [8]. We call this map the skew-frobenius map in this paper. One can construct a prime order Jacobian J Ct (F q n) by using the quadratic twist C t over F q n of C if n = 2 m for a natural number m [9]. For elliptic curves over finite fields of characteristic 2, Furihata et al.[4] and Furukawa et al.[5] proposed ft implementations of scalar multiplications using this method. This paper shows constructions of the skew-frobenius maps on hyperelliptic curves of genus 2 and 3. Institute of Information Security, , Tsuruya-cho Kanagawa-ku, Yokohama , Japan RID at Chuo Univ., , Kuga Bunkyo-ku, Tokyo , Japan 2 Preliminaries This section briefly introduces the definitions and notations required in the following sections. 2.1 Hyperelliptic curves Let C be a hyperelliptic curve of genus g defined over a finite field F q which is of the form C : Y 2 = F (X), F (X) = X 2g+1 + a 2g X 2g + + a 0, a 2g,, a 0 F q, (1) where char(f q ) 2. When g = 1, C is called an elliptic curve. Let J C be the Jacobian of C, and D is an element of J C. D can be represented a finite formal sum of points P i = (x i, y i ) on C follows: D = Σm i P i (Σm i ), (2) P i, C, m i N 0, Σm i g, where P i (x i, y i ) for i j. Moreover, D can be also represented by a couple of polynomials u(x) and v(x). The polynomials u(x) and v(x) satisfy u(x) := Π g i=1 (X x i) = X 2g + u 2g 1 X 2g u 0, (3) v(x i ) = y i, (4) for degv(x) < degu(x) g, u(x) F (X) v 2 (X), P i = (x i, y i ) C, 0 i g [13]. We denote D (u, v) by using the polynomials. The set of D = (u, v) such that u, v K[X] forms a subgroup J C (K) of J C. When g = 1, J C (F q ) = C(F q ). 1

2 2.2 Scalar multiplications Let k be an integer that satisfies k q gn The hyperelliptic curve cryptosystems take most of the time for computing a scalar multiplication kd for such k and D J C (F q n). Therefore, speeding up a scalar multiplication induces speeding up hyperelliptic curve cryptosystems. 2.3 Frobenius maps The q-th power Frobenius map φ on C is defined φ : C(F q ) C(F q ) (x, y) (x q, y q ) O O. where Moreover, C t (F q n) C(F q n). End(C t ) = End(C). (7) Let σ 0 be the isomorphism of (6). The isomorphism φ t : C t (F q 2n) σ 1 0 C(F q 2n) C(F q 2n) φ σ0 C t (F q 2n) (8) can be constructed by using such σ 0 and a q-th power Frobenius map φ over C(F q 2n). The isomorphism σ 0 : C(F q 2n) C t (F q 2n) is given Moreover, φ is an automorphism over J C (F q ), and its characteristic polynomial χ(x) Z[X] is of the form Because χ(x) = X 2g s 1 X 2g 1 + s 2 X 2g 2 χ(φ) = 0, s 1 q g 1 X + q g, s 1,, s g Z. the integer k can be expanded k = Σ s i=0r i φ i, where r i { q g /2 + 1,, q g /2 }, by using φ. Therefore, the scalar multiplication kd can be computed kd = Σ s i=0r i φ i (D). (5) To apply the Frobenius map to the scalar multiplication, the cryptosystems should be constructed on J C (F q n)/j C (F q ), because the map is trivial on J C (F q ). However J C (F q n) q gn cannot be a prime number, so that one needs to choose C such that J C (F q n)/ J C (F q ) q g(n 1) is a prime number in such cryptosystems. Therefore there is a loss of efficiency in the method using a Frobenius map. 3 Skew-Frobenius maps over elliptic curves In order to construct more efficient cryptosystems using a Frobenius map, Iijima et al. proposed a method using a Frobeinus map on the quadratic twist of an elliptic curve [8]. This section shows the construction of skew- Frobenius maps on elliptic curves according to [8]. Let c F q n be a quadratic non-residue over F q n. The quadratic twist C t of an elliptic curve C of the form in (1) is defined C t : Y 2 = X 3 + ca 2 X 2 + c 2 a 1 X + c 3 a 0. It is known that C t (F q 2n) = C(F q 2n), (6) 2 σ 0 : C(F q 2n) C t (F q 2n) (x, y) (x t, y t ) (x, y) (cx, c 3/2 y). Therefore the inversion σ 1 0 is given σ0 1 : C t (F q 2n) C(F q 2n) (x t, y t ) (x, y) (x t, y t ) (c 1 x t, c 3/2 y t ). Consequently, the isomorphism φ t is obtained φ t : C t (F q 2n) C t (F q 2n) (x, y) (c 1 q x q, c 3(1 q)/2 y q ) For the elements in C(F q n), φ t is also an automorphism. Moreover, the map φ t h the same characteristic polynomial φ from (7). Therefore φ t can be used for a scalar multiplication kd = Σ s i=0r i φ i (D) by the same expansion of k in (5). Furthermore, if n = 2 m for m N, one can choose C so that C t (F q n) is a prime order [8, 9]. The computation of φ t needs 2 multiplications and 2 q-th power operations over F q n. However, if C t (F q n) h a prime order, the size of F q n becomes smaller than the size of the definition field used by a naive method using a Frobenius map, so that we expect the scalar multiplication to be ft by using the skew-frobenius map. For elliptic curves over finite fields of characteristic 2, Furihata et al.[4] and Furukawa et al.[5] proposed ft implementations of scalar multiplications using the skew-frobenius maps. 4 Skew-Frobenius maps on hyperelliptic curves This section shows a construction of the skew- Frobenius maps on hyperelliptic curves of genus 2 and 3.

3 4.1 On hyperelliptic curves of g = 2 Let c F q n be a quadratic non-residue over F q n. A quadratic twist C t of an elliptic curve C of the form in (1) for g = 2 over F q n is defined C t : Y 2 = F t (X), F t (X) = X 5 + ca 4 X 4 + c 2 a 3 X 3 + c 3 a 2 X 2 + c 4 a 1 X + c 5 a 0. Let J Ct be the Jacobian of C t, and let D t be an element of J Ct. We denote D t = (u t, v t ) by using the polynomials from (3), (4). An isomorphism of the Jacobians D D t (u, v) (u t, v t ) can be obtained by applying the isomorphism σ 0 : C(F q 2n) C t (F q 2n) (x i, y i ) (x ti, y ti ), to each P i = (x i, y i ) in (2). The isomorphism σ 0 is obtained σ 0 : (x, y) (cx, c 5/2 y). (9) φ t defined (8) can be constructed by using σ and the q-th power Frobenius map φ over J C (F q 2n). Now, we clsify the elements in J C (F q 2n) into the following types, Type I : D = {P } Type II : D = {P 1, P 2 }, P 1 P 2 Type III : D = {P, P }, where P = (x, y), P 1 = (x 1, y 1 ), P 2 = (x 2, y 2 ). The following shows a construction of φ t for each of the types. Type I: The polynomials u(x), v(x), u t (X) and v t (X) are obtained u(x) = X x, u t (X) = X cx, v(x) = y v t (X) = c 5/2 y from (3), (4), (9). (u 0, v 0 ) (c 1 q u q 0, c5(1 q)/2 v q 0 ) by the Lagrange interpolation from (4). The polynomials u t (X) and v t (X) are obtained u t (X) = X 2 c(x 1 + x 2 )X + c 2 x 1 x 2, (12) v t (X) = c 3/2 (y 1 y 2 )/(x 1 x 2 )X +c 5/2 (x 1 y 2 x 2 y 1 )/(x 1 x 2 ) (13) from (3), (4), (9). The isomorphism σ is obtained (u 1, u 0, v 1, v 0 ) (cu 1, c 2 u 0, c 3/2 v 1, c 5/2 v 0 ). from (10), (11), (12), (13). Type III: c 3(1 q)/2 v q 1, c5(1 q)/2 v q 0 ) The polynomial u(x) is obtained u(x) = X 2 2xX + x 2 (14) from (3). The polynomial v(x) is obtained v(x) = (F (x)/2y)x (F (x)/2y)x + y (15) by the Newton iteration from (4), where F denotes the derivative of F in (1). The polynomials u t (X) and v t (X) are obtained u t (X) = X 2 2cxX + c 2 x 2 (16) v t (X) = c 5/2 (F t(cx)/2y)x c 3/2 (F t(cx)/2y)x + c 5/2 y (17) from (3), (4), (9). The isomorphism σ is obtained (u 1, u 0, v 1, v 0 ) (cu 1, c 2 u 0, c 3/2 v 1, c 5/2 v 0 ) from (14), (15), (16), (17), by F t(cx) = c 4 F (x). c 3(1 q)/2 v q 1, c5(1 q)/2 v q 0 ) Type II: The polynomial u(x) is obtained u(x) = X 2 (x 1 + x 2 )X + x 1 x 2 (10) from (3). The polynomial v(x) is obtained v(x) = ((y 1 y 2 )/(x 1 x 2 ))X +(x 1 y 2 x 2 y 1 )/(x 1 x 2 ) (11) 3

4 Consequently, we have the isomorphism φ t over J Ct (F q 2n) of a hyperelliptic curve of genus 2 Type I : Type II, III : (u 0, v 0 ) (c 1 q u q 0, c5(1 q)/2 v q 0 ) c 3(1 q)/2 v q 1, c5(1 q)/2 v q 0 ). φ t is a non-trivial isomorphism even for the elements in J Ct (F q n). The isomorphism φ t on the curves of genus 2 needs at most 4 multiplications and at most 4 q-th power operations over F q n. However, if J Ct (F q n) h a prime order, the size of F q n becomes smaller than the size of the definition field used by a naive method using Frobenius map, so that we expect the scalar multiplication to be ft by using the skew-frobenius map on a curve of genus On hyperelliptic curves of g = 3 It is more important than genus 2 to construct skew- Frobenius maps on hyperelliptic curves of genus 3, because ft implementations [7, 14] of addition algorithms on a hyperelliptic curve of genus 3 is known, moreover, there exist efficient attacks against hyperelliptic curve cryptosystems of genus 2 if n = 2 m [1, 2, 6]. This section shows the construction of skew- Frobenius maps on hyperelliptic curves of genus 3. Let c F q n be a quadratic non-residue over F q n. A quadratic twist C t of an elliptic curve C of the form in (1) for g = 3 over F q n is defined C t : Y 2 =F t (X), F t (X) =X 7 + a 6 cx 6 + a 5 c 2 X 5 + a 4 c 3 X 4 + a 3 c 4 X 3 + a 2 c 5 X 2 + a 1 c 6 X + a 0 c 7. Let J Ct be the Jacobian of C t, and let D t be an element of J Ct. Now we denote D t = (u t, v t ) by using the polynomials from (3), (4). An isomorphism over the Jacobians D D t (u, v) (u t, v t ), can be obtained by applying the isomorphism σ 0 : C C t (x, y) (cx, c 7/2 y) (18) to each point on C The isomorphism φ t is obtained in the similar manner for genus 2 in the section 4.1. Now, we clsify the elements in J C (F q 2n) into the following types, Type I : D = {P } Type II : D = {P 1, P 2 }, P 1 P 2 Type III : D = {P, P } Type IV : D = {P 1, P 2, P 3 }, P 1 P 2 P 3 P 1 Type V : D = {P 1, P 1, P 2 }, P 1 P 2 Type VI : D = {P, P, P } where P = (x, y), P 1 = (x 1, y 1 ), P 2 = (x 2, y 2 ), P 3 = (x 3, y 3 ). The following shows a construction of φ t for each of the types. Type I, II, III: For these types, the isomorphism φ t over J Ct (F q n) is obtained by the similar manner for 2 follows: Type I : Type II, III : Type IV: (u 0, v 0 ) (c 1 q u q 0, c7(1 q)/2 v q 0 ) c 5(1 q)/2 v q 1, c7(1 q)/2 v q 0 ). The polynomial u(x) is obtained u(x) = X 3 (x 1 + x 2 + x 3 )X 2 +(x 1 x 2 + x 2 x 3 + x 3 x 1 )X x 1 x 2 x 3 (19) from (3). The polynomial v(x) is obtained v(x) = X 2 (y 1 (x 3 x 2 ) + y 2 (x 1 x 3 ) + y 3 (x 2 x 1 )) X(y 1 (x 2 3 x 2 2) + y 2 (x 2 1 x 2 3) + y 3 (x 2 2 x 2 1)) +(y 1 x 2 x 3 (x 3 x 2 ) + y 2 x 1 x 3 (x 1 x 3 ) +y 3 x 1 x 2 (x 2 x 1 )) by the Lagrange interpolation from (4). The polynomials u t (X) and v t (X) are obtained u t (X) = X 3 c(x 1 + x 2 + x 3 )X 2 (20) +c 2 (x 1 x 2 + x 2 x 3 + x 3 x 1 )X c 3 x 1 x 2 x 3 (21) v t (X) = X 2 c 3/2 (y 1 (x 3 x 2 ) + y 2 (x 1 x 3 ) + y 3 (x 2 x 1 )) Xc 5/2 (y 1 (x 2 3 x 2 2) + y 2 (x 2 1 x 2 3) + y 3 (x 2 2 x 2 1)) +c 7/2 (y 1 x 2 x 3 (x 3 x 2 ) + y 2 x 1 x 3 (x 1 x 3 ) +y 3 x 1 x 2 (x 2 x 1 )) (22) 4

5 +(x 2 (2x x )x y )/(x x ) 2 from (3), (4), (18). The isomorphism σ is obtained by the Newton iteration from (4). The polynomials u t (X) and v t (X) are obtained (u 2, u 1, u 0, (cu 2, c 2 u 1, c 3 u 0, u t (X) = X 3 3cxX 2 + 3c 2 x 2 X c 3 x 3 (29) v 2, v 1, v 0 ) c 3/2 v 2, c 5/2 v 1, c 7/2 v 0 ). v t (X) = X 2 ((F t (cx)/4c 7/2 y) (F t 2 (cx)/8c 21/2 y 3 )) from (19), (20), (21), (22). +X((F t(cx)/2c 7/2 y) 2x((F t (cx)/4c 7/2 y) (F t 2 (cx)/8c 21/2 y 3 ))) +c 7/2 y (cxf t(cx)/2c 7/2 y) +c 2 x 2 ((F t (cx)/4c 7/2 y) (F t 2 (cx)/8c 21/2 y 3 )) (30) v 2, v 1, v 0 ) c 3(1 q)/2 v q 2, c5(1 q)/2 v q 1, from (3), (4), (18). The isomorphism σ is obtained (u 2, u 1, u 0, (cu 2, c 2 u 1, c 3 u 0, v 2, v 1, v 0 ) c 3/2 v 2, c 5/2 v 1, c 7/2 v 0 ) Type V: The polynomial u(x) is obtained from (27), (28), (29), (30), where F t(cx) = u(x) = X 3 (2x 1 + x 2 )X 2 + (x x 1 x 2 )X x 2 1x 2 (23) c 6 F (x), F t (cx) = c 5 F (x). from (3). The polynomials v(x) is obtained = ((y 2 y 1 )/(x 1 x 2 ) 2 )X 2 +(2x 1 (y 1 y 2 )/(x 1 x 2 ) 2 φ )X t : J Ct (F q n) J Ct (F q n) 1y (24) v 2, v 1, v 0 ) c 3(1 q)/2 v q 2, c5(1 q)/2 v q 1, by the Chinese remainder algorithm from (4). The polynomials u t (X) and v t (X) are obtained u t (X) = X 3 c(2x 1 + x 2 )X 2 +c 2 (x x 1 x 2 )X c 3 x 2 1x 2 (25) v t (X) = c 3/2 ((y 2 y 1 )/(x 1 x 2 ) 2 )X 2 +c 5/2 (2x 1 (y 1 y 2 )/(x 1 x 2 ) 2 )X +c 7/2 (x 2 1y 2 (2x 1 x 2 )x 2 y 1 )/(x 1 x 2 ) 2 (26) from (3), (4), (18). The isomorphism σ is obtained (u 2, u 1, u 0, (cu 2, c 2 u 1, c 3 u 0, v 2, v 1, v 0 ) c 3/2 v 2, c 5/2 v 1, c 7/2 v 0 ). from (23), (24), (25), (26). Type VI: v 2, v 1, v 0 ) c 3(1 q)/2 v q 2, c5(1 q)/2 v q 1, The polynomial u(x) is obtained u(x) = X 3 3xX 2 + 3x 2 X x 3 (27) from 3. The polynomial v(x) is obtained v(x) = X 2 ((F (x)/4y) (F 2 (x)/8y 3 )) +X((F (x)/2y) 2x((F (x)/4y) (F 2 (x)/8y 3 ))) +y (xf (x)/2y) +x 2 ((F (x)/4y) (F 2 (x)/8y 3 )) (28) 5 Consequently, we have the isomorphism φ t J Ct (F q n) of a hyperelliptic curve of genus 3 Type I : Type II, III : (u 0, v 0 ) (c 1 q u q 0, c7(1 q)/2 v q 0 ) Type IV, V, VI: c 5(1 q)/2 v q 1, c7(1 q)/2 v q 0 ) over v 2, v 1, v 0 ) c 3(1 q)/2 v q 2, c5(1 q)/2 v q 1, φ t is a non-trivial isomorphism even for the elements in J Ct (F q n). The isomorphism φ t on the curves of genus 3 needs at most 6 multiplications and 6 q-th power operations over F q n. However, if J Ct (F q n) h a prime order, the size of F q n becomes, small so that we expect the scalar multiplication to be ft by using the skew-frobenius map on a curve of genus 3. Acknowledgements This research w partially supported by The Research on Security and Reliability in Electronic Society, Chuo University 21st Century COE Program.

6 References [1] S. Arita. A Weil descent attack against genus two hyperelliptic curve cryptosystems over quadratic extention fields. Technical Report ISEC , IEICE, Japan, in Japanese. [2] S. Arita, K. Matsuo, K. Nagao, and M. Shimura. A weil descent attack against elliptic curve cryptosystems over quartic extension fields. IEICE Trans., E89-A(5), May [3] I. Blake, G. Seroussi, and N. Smart. Elliptic Curves in Cryptography. Number 265 in London Mathematical Society Lecture Note Series. Cambridge U. P., [13] A. Menezes, Y. Wu, and R. Zuccherato. An elementary introduction to hyperelliptic curve /corr96-19.ps, [14] J. Nyukai, K. Matsuo, J. Chao, and S. Tsujii. On the resultant computation in the addition Harley algorithms on hyperelliptic cureves. (ISEC2006-5), July in Japanese. [15] J. A. Solin. An improved algorihtm for arithmetic on a family of elliptic curves. In Advances in Cryptology - CRYPTO 97, number 1294 in Lecture Notes in Computer Science, pages Springer-Verlag, [4] S. Furihata, T. Kobayhi, and T. Saito. Scalar multiplication on twist elliptic curves over F 2 m. In Proc. of SCIS2003, pages , January [5] K. Furukawa, T. Kobayhi, and K. Aoki. The cost of elliptic operations in oef using a successive extension. In Proc. of SCIS2003, pages , January in Japanese. [6] P. Gaudry. Index calculus for abelian varieties and the elliptic curve discrete logarithm problem. Cryptology eprint Archive, Report 2004/073, [7] M. Gonda, K. Matsuo, K. Aoki, J. Chao, and S. Tsujii. Improvements of addition algorithm on genus 3 hyperelliptic curves and their implementation. IEICE Trans., E88-A(1), January [8] T. Iijima, K. Matsuo, J. Chao, and S. Tsujii. Cnstruction of Frobenius maps of twist elliptic curves and its application to elliptic scalar multiplication. In Proc. of SCIS2002, pages , January [9] N. Kanayama, K. Nagao, and S. Uchiyama. Generating secure genus two hyperelliptic curves using Elkies point counting algorithm. IEICE Japan Trans. Fundamentals, E86-A(4): , [10] T. Kobayhi, H. Morita, K. Kobayhi, and F. Hoshino. Ft elliptic curve algorithm combining Frobenius map and table reference to adapt to higher characteristic. In Advances in Cryptology - EUROCRYPT 99, number 1592 in Lecture Notes in Computer Science, pages Springer-Verlag, [11] N. Koblitz. Hyperelliptic curve cryptosystems. J. Cryptology, 1(3): , [12] N. Koblitz. CM-curves with good cryptographic properties. In Advances in Cryptology - CRYPTO 91, number 576 in Lecture Notes in Computer Science, pages ,

No.6 Selection of Secure HC of g = divisors D 1, D 2 defined on J(C; F q n) over F q n, to determine the integer m such that D 2 = md 1 (if such

No.6 Selection of Secure HC of g = divisors D 1, D 2 defined on J(C; F q n) over F q n, to determine the integer m such that D 2 = md 1 (if such Vol.17 No.6 J. Comput. Sci. & Technol. Nov. 2002 Selection of Secure Hyperelliptic Curves of g = 2 Based on a Subfield ZHANG Fangguo ( ) 1, ZHANG Futai ( Ξ) 1;2 and WANG Yumin(Π±Λ) 1 1 P.O.Box 119 Key

More information

A Note on Scalar Multiplication Using Division Polynomials

A Note on Scalar Multiplication Using Division Polynomials 1 A Note on Scalar Multiplication Using Division Polynomials Binglong Chen, Chuangqiang Hu and Chang-An Zhao Abstract Scalar multiplication is the most important and expensive operation in elliptic curve

More information

Two Efficient Algorithms for Arithmetic of Elliptic Curves Using Frobenius Map

Two Efficient Algorithms for Arithmetic of Elliptic Curves Using Frobenius Map Two Efficient Algorithms for Arithmetic of Elliptic Curves Using Frobenius Map Jung Hee Cheon, Sungmo Park, Sangwoo Park, and Daeho Kim Electronics and Telecommunications Research Institute, 161 Kajong-Dong,Yusong-Gu,

More information

Constructing genus 2 curves over finite fields

Constructing genus 2 curves over finite fields Constructing genus 2 curves over finite fields Kirsten Eisenträger The Pennsylvania State University Fq12, Saratoga Springs July 15, 2015 1 / 34 Curves and cryptography RSA: most widely used public key

More information

Constructing Families of Pairing-Friendly Elliptic Curves

Constructing Families of Pairing-Friendly Elliptic Curves Constructing Families of Pairing-Friendly Elliptic Curves David Freeman Information Theory Research HP Laboratories Palo Alto HPL-2005-155 August 24, 2005* cryptography, pairings, elliptic curves, embedding

More information

On the Optimal Pre-Computation of Window τ NAF for Koblitz Curves

On the Optimal Pre-Computation of Window τ NAF for Koblitz Curves On the Optimal Pre-Computation of Window τ NAF for Koblitz Curves William R. Trost and Guangwu Xu Abstract Koblitz curves have been a nice subject of consideration for both theoretical and practical interests.

More information

Non-generic attacks on elliptic curve DLPs

Non-generic attacks on elliptic curve DLPs Non-generic attacks on elliptic curve DLPs Benjamin Smith Team GRACE INRIA Saclay Île-de-France Laboratoire d Informatique de l École polytechnique (LIX) ECC Summer School Leuven, September 13 2013 Smith

More information

Hyperelliptic-curve cryptography. D. J. Bernstein University of Illinois at Chicago

Hyperelliptic-curve cryptography. D. J. Bernstein University of Illinois at Chicago Hyperelliptic-curve cryptography D. J. Bernstein University of Illinois at Chicago Thanks to: NSF DMS 0140542 NSF ITR 0716498 Alfred P. Sloan Foundation Two parts to this talk: 1. Elliptic curves; modern

More information

Decomposed Attack for the Jacobian of a Hyperelliptic Curve over an Extension Field

Decomposed Attack for the Jacobian of a Hyperelliptic Curve over an Extension Field Decomposed Attack for the Jacobian of a Hyperelliptic Curve over an Extension Field Koh-ichi Nagao nagao@kanto-gakuin.ac.jp Dept. of Engineering, Kanto Gakuin Univ., 1-50-1 Mutsuura Higashi Kanazawa-ku

More information

Elliptic curves: Theory and Applications. Day 4: The discrete logarithm problem.

Elliptic curves: Theory and Applications. Day 4: The discrete logarithm problem. Elliptic curves: Theory and Applications. Day 4: The discrete logarithm problem. Elisa Lorenzo García Université de Rennes 1 14-09-2017 Elisa Lorenzo García (Rennes 1) Elliptic Curves 4 14-09-2017 1 /

More information

Cover and Decomposition Index Calculus on Elliptic Curves made practical

Cover and Decomposition Index Calculus on Elliptic Curves made practical Cover and Decomposition Index Calculus on Elliptic Curves made practical Application to a previously unreachable curve over F p 6 Vanessa VITSE Antoine JOUX Université de Versailles Saint-Quentin, Laboratoire

More information

Formulas for cube roots in F 3 m

Formulas for cube roots in F 3 m Discrete Applied Mathematics 155 (2007) 260 270 www.elsevier.com/locate/dam Formulas for cube roots in F 3 m Omran Ahmadi a, Darrel Hankerson b, Alfred Menezes a a Department of Combinatorics and Optimization,

More information

Two Topics in Hyperelliptic Cryptography

Two Topics in Hyperelliptic Cryptography Two Topics in Hyperelliptic Cryptography Florian Hess, Gadiel Seroussi, Nigel Smart Information Theory Research Group HP Laboratories Palo Alto HPL-2000-118 September 19 th, 2000* hyperelliptic curves,

More information

Elliptic Curve Cryptosystems and Scalar Multiplication

Elliptic Curve Cryptosystems and Scalar Multiplication Annals of the University of Craiova, Mathematics and Computer Science Series Volume 37(1), 2010, Pages 27 34 ISSN: 1223-6934 Elliptic Curve Cryptosystems and Scalar Multiplication Nicolae Constantinescu

More information

High-Performance Scalar Multiplication using 8-Dimensional GLV/GLS Decomposition

High-Performance Scalar Multiplication using 8-Dimensional GLV/GLS Decomposition High-Performance Scalar Multiplication using 8-Dimensional GLV/GLS Decomposition Joppe W. Bos, Craig Costello, Huseyin Hisil, Kristin Lauter CHES 2013 Motivation - I Group DH ECDH (F p1, ) (E F p2, +)

More information

Hyperelliptic Curve Cryptography

Hyperelliptic Curve Cryptography Hyperelliptic Curve Cryptography A SHORT INTRODUCTION Definition (HEC over K): Curve with equation y 2 + h x y = f x with h, f K X Genus g deg h(x) g, deg f x = 2g + 1 f monic Nonsingular 2 Nonsingularity

More information

On Generating Coset Representatives of P GL 2 (F q ) in P GL 2 (F q 2)

On Generating Coset Representatives of P GL 2 (F q ) in P GL 2 (F q 2) On Generating Coset Representatives of P GL 2 F q in P GL 2 F q 2 Jincheng Zhuang 1,2 and Qi Cheng 3 1 State Key Laboratory of Information Security Institute of Information Engineering Chinese Academy

More information

Fast hashing to G2 on pairing friendly curves

Fast hashing to G2 on pairing friendly curves Fast hashing to G2 on pairing friendly curves Michael Scott, Naomi Benger, Manuel Charlemagne, Luis J. Dominguez Perez, and Ezekiel J. Kachisa School of Computing Dublin City University Ballymun, Dublin

More information

COMPRESSION FOR TRACE ZERO SUBGROUPS OF ELLIPTIC CURVES

COMPRESSION FOR TRACE ZERO SUBGROUPS OF ELLIPTIC CURVES COMPRESSION FOR TRACE ZERO SUBGROUPS OF ELLIPTIC CURVES A. SILVERBERG Abstract. We give details of a compression/decompression algorithm for points in trace zero subgroups of elliptic curves over F q r,

More information

A note on López-Dahab coordinates

A note on López-Dahab coordinates A note on López-Dahab coordinates Tanja Lange Faculty of Mathematics, Matematiktorvet - Building 303, Technical University of Denmark, DK-2800 Kgs. Lyngby, Denmark tanja@hyperelliptic.org Abstract López-Dahab

More information

Distributed computation of the number. of points on an elliptic curve

Distributed computation of the number. of points on an elliptic curve Distributed computation of the number of points on an elliptic curve over a nite prime eld Johannes Buchmann, Volker Muller, Victor Shoup SFB 124{TP D5 Report 03/95 27th April 1995 Johannes Buchmann, Volker

More information

A Remark on Implementing the Weil Pairing

A Remark on Implementing the Weil Pairing A Remark on Implementing the Weil Pairing Cheol Min Park 1, Myung Hwan Kim 1 and Moti Yung 2 1 ISaC and Department of Mathematical Sciences, Seoul National University, Korea {mpcm,mhkim}@math.snu.ac.kr

More information

Generating more MNT elliptic curves

Generating more MNT elliptic curves Generating more MNT elliptic curves Michael Scott 1 and Paulo S. L. M. Barreto 2 1 School of Computer Applications Dublin City University Ballymun, Dublin 9, Ireland. mike@computing.dcu.ie 2 Universidade

More information

Efficient Tate Pairing Computation Using Double-Base Chains

Efficient Tate Pairing Computation Using Double-Base Chains Efficient Tate Pairing Computation Using Double-Base Chains Chang an Zhao, Fangguo Zhang and Jiwu Huang 1 Department of Electronics and Communication Engineering, Sun Yat-Sen University, Guangzhou 510275,

More information

Galois fields/1. (M3) There is an element 1 (not equal to 0) such that a 1 = a for all a.

Galois fields/1. (M3) There is an element 1 (not equal to 0) such that a 1 = a for all a. Galois fields 1 Fields A field is an algebraic structure in which the operations of addition, subtraction, multiplication, and division (except by zero) can be performed, and satisfy the usual rules. More

More information

Efficient Doubling on Genus Two Curves over. binary fields.

Efficient Doubling on Genus Two Curves over. binary fields. Efficient Doubling on Genus Two Curves over Binary Fields Tanja Lange 1, and Marc Stevens 2, 1 Institute for Information Security and Cryptology (ITSC), Ruhr-Universität Bochum Universitätsstraße 150 D-44780

More information

Design of Hyperelliptic Cryptosystems in Small Characteristic and a Software Implementation over F 2

Design of Hyperelliptic Cryptosystems in Small Characteristic and a Software Implementation over F 2 Design of Hyperelliptic Cryptosystems in Small Characteristic and a Software Implementation over F 2 n Yasuyuki Sakai 1 and Kouichi Sakurai 2 1 Mitsubishi Electric Corporation, 5-1-1 Ofuna, Kamakura, Kanagawa

More information

New Strategy for Doubling-Free Short Addition-Subtraction Chain

New Strategy for Doubling-Free Short Addition-Subtraction Chain Applied Mathematics & Information Sciences 2(2) (2008), 123 133 An International Journal c 2008 Dixie W Publishing Corporation, U. S. A. New Strategy for Doubling-Free Short Addition-Subtraction Chain

More information

The GHS Attack for Cyclic Extensions of Arbitrary Function Fields

The GHS Attack for Cyclic Extensions of Arbitrary Function Fields The GHS Attack for Cyclic Extensions of Arbitrary Function Fields Tomohiro Nakayama Abstract It is known that the discrete logarithm problem in the Jacobian group of a higher genus curve can be solved

More information

Igusa Class Polynomials

Igusa Class Polynomials , supported by the Leiden University Fund (LUF) Joint Mathematics Meetings, San Diego, January 2008 Overview Igusa class polynomials are the genus 2 analogue of the classical Hilbert class polynomials.

More information

Optimised versions of the Ate and Twisted Ate Pairings

Optimised versions of the Ate and Twisted Ate Pairings Optimised versions of the Ate and Twisted Ate Pairings Seiichi Matsuda 1, Naoki Kanayama 1, Florian Hess 2, and Eiji Okamoto 1 1 University of Tsukuba, Japan 2 Technische Universität Berlin, Germany Abstract.

More information

An introduction to the algorithmic of p-adic numbers

An introduction to the algorithmic of p-adic numbers An introduction to the algorithmic of p-adic numbers David Lubicz 1 1 Universté de Rennes 1, Campus de Beaulieu, 35042 Rennes Cedex, France Outline Introduction 1 Introduction 2 3 4 5 6 7 8 When do we

More information

Speeding up the Scalar Multiplication on Binary Huff Curves Using the Frobenius Map

Speeding up the Scalar Multiplication on Binary Huff Curves Using the Frobenius Map International Journal of Algebra, Vol. 8, 2014, no. 1, 9-16 HIKARI Ltd, www.m-hikari.com http://dx.doi.org/10.12988/ija.2014.311117 Speeding up the Scalar Multiplication on Binary Huff Curves Using the

More information

Security Level of Cryptography Integer Factoring Problem (Factoring N = p 2 q) December Summary 2

Security Level of Cryptography Integer Factoring Problem (Factoring N = p 2 q) December Summary 2 Security Level of Cryptography Integer Factoring Problem (Factoring N = p 2 ) December 2001 Contents Summary 2 Detailed Evaluation 3 1 The Elliptic Curve Method 3 1.1 The ECM applied to N = p d............................

More information

Ordinary Pairing Friendly Curve of Embedding Degree 3 Whose Order Has Two Large Prime Factors

Ordinary Pairing Friendly Curve of Embedding Degree 3 Whose Order Has Two Large Prime Factors Memoirs of the Faculty of Engineering, Okayama University, Vol. 44, pp. 60-68, January 2010 Ordinary Pairing Friendly Curve of Embedding Degree Whose Order Has Two Large Prime Factors Yasuyuki NOGAMI Graduate

More information

Generating more Kawazoe-Takahashi Genus 2 Pairing-friendly Hyperelliptic Curves

Generating more Kawazoe-Takahashi Genus 2 Pairing-friendly Hyperelliptic Curves Generating more Kawazoe-Takahashi Genus 2 Pairing-friendly Hyperelliptic Curves Ezekiel J Kachisa School of Computing Dublin City University Ireland ekachisa@computing.dcu.ie Abstract. Constructing pairing-friendly

More information

APPLICATION OF ELLIPTIC CURVES IN CRYPTOGRAPHY-A REVIEW

APPLICATION OF ELLIPTIC CURVES IN CRYPTOGRAPHY-A REVIEW APPLICATION OF ELLIPTIC CURVES IN CRYPTOGRAPHY-A REVIEW Savkirat Kaur Department of Mathematics, Dev Samaj College for Women, Ferozepur (India) ABSTRACT Earlier, the role of cryptography was confined to

More information

A point compression method for elliptic curves defined over GF (2 n )

A point compression method for elliptic curves defined over GF (2 n ) A point compression method for elliptic curves defined over GF ( n ) Brian King Purdue School of Engineering Indiana Univ. Purdue Univ. at Indianapolis briking@iupui.edu Abstract. Here we describe new

More information

Elliptic Curves I. The first three sections introduce and explain the properties of elliptic curves.

Elliptic Curves I. The first three sections introduce and explain the properties of elliptic curves. Elliptic Curves I 1.0 Introduction The first three sections introduce and explain the properties of elliptic curves. A background understanding of abstract algebra is required, much of which can be found

More information

A Generalized Brezing-Weng Algorithm for Constructing Pairing-Friendly Ordinary Abelian Varieties

A Generalized Brezing-Weng Algorithm for Constructing Pairing-Friendly Ordinary Abelian Varieties A Generalized Brezing-Weng Algorithm for Constructing Pairing-Friendly Ordinary Abelian Varieties David Freeman Department of Mathematics University of California, Berkeley Berkeley, CA 94720-3840, USA

More information

SEMINAR SECURITY - REPORT ELLIPTIC CURVE CRYPTOGRAPHY

SEMINAR SECURITY - REPORT ELLIPTIC CURVE CRYPTOGRAPHY SEMINAR SECURITY - REPORT ELLIPTIC CURVE CRYPTOGRAPHY OFER M. SHIR, THE HEBREW UNIVERSITY OF JERUSALEM, ISRAEL FLORIAN HÖNIG, JOHANNES KEPLER UNIVERSITY LINZ, AUSTRIA ABSTRACT. The area of elliptic curves

More information

Modular Multiplication in GF (p k ) using Lagrange Representation

Modular Multiplication in GF (p k ) using Lagrange Representation Modular Multiplication in GF (p k ) using Lagrange Representation Jean-Claude Bajard, Laurent Imbert, and Christophe Nègre Laboratoire d Informatique, de Robotique et de Microélectronique de Montpellier

More information

Fast Simultaneous Scalar Multiplication on Elliptic Curve with Montgomery Form

Fast Simultaneous Scalar Multiplication on Elliptic Curve with Montgomery Form Fast Simultaneous Scalar Multiplication on Elliptic Curve with Montgomery Form Toru Akishita Sony Corporation, 6-7-35 Kitashinagawa Shinagawa-ku, Tokyo, 141-0001, Japan akishita@pal.arch.sony.co.jp Abstract.

More information

Hyperelliptic Jacobians in differential Galois theory (preliminary report)

Hyperelliptic Jacobians in differential Galois theory (preliminary report) Hyperelliptic Jacobians in differential Galois theory (preliminary report) Jerald J. Kovacic Department of Mathematics The City College of The City University of New York New York, NY 10031 jkovacic@member.ams.org

More information

Summation polynomials and the discrete logarithm problem on elliptic curves

Summation polynomials and the discrete logarithm problem on elliptic curves Summation polynomials and the discrete logarithm problem on elliptic curves Igor Semaev Department of Mathematics University of Leuven,Celestijnenlaan 200B 3001 Heverlee,Belgium Igor.Semaev@wis.kuleuven.ac.be

More information

QUADRATIC TWISTS OF AN ELLIPTIC CURVE AND MAPS FROM A HYPERELLIPTIC CURVE

QUADRATIC TWISTS OF AN ELLIPTIC CURVE AND MAPS FROM A HYPERELLIPTIC CURVE Math. J. Okayama Univ. 47 2005 85 97 QUADRATIC TWISTS OF AN ELLIPTIC CURVE AND MAPS FROM A HYPERELLIPTIC CURVE Masato KUWATA Abstract. For an elliptic curve E over a number field k we look for a polynomial

More information

Counting points on hyperelliptic curves

Counting points on hyperelliptic curves University of New South Wales 9th November 202, CARMA, University of Newcastle Elliptic curves Let p be a prime. Let X be an elliptic curve over F p. Want to compute #X (F p ), the number of F p -rational

More information

output H = 2*H+P H=2*(H-P)

output H = 2*H+P H=2*(H-P) Ecient Algorithms for Multiplication on Elliptic Curves by Volker Muller TI-9/97 22. April 997 Institut fur theoretische Informatik Ecient Algorithms for Multiplication on Elliptic Curves Volker Muller

More information

Solving Elliptic Curve Discrete Logarithm Problems Using Weil Descent

Solving Elliptic Curve Discrete Logarithm Problems Using Weil Descent Solving Elliptic Curve Discrete Logarithm Problems Using Weil Descent Michael Jacobson University of Manitoba jacobs@cs.umanitoba.ca Alfred Menezes Certicom Research & University of Waterloo ajmeneze@uwaterloo.ca

More information

of elliptic curves dened over F 2 155, the probability of nding one where the GHS attac is applicable is negligible. In this paper we extend the GHS a

of elliptic curves dened over F 2 155, the probability of nding one where the GHS attac is applicable is negligible. In this paper we extend the GHS a Extending the GHS Weil Descent Attac No Author Given No Institute Given Abstract. In this paper we extend the Weil descent attac due to Gaudry, Hess and Smart (GHS) to a much larger class of elliptic curves.

More information

Public-key Cryptography: Theory and Practice

Public-key Cryptography: Theory and Practice Public-key Cryptography Theory and Practice Department of Computer Science and Engineering Indian Institute of Technology Kharagpur Chapter 2: Mathematical Concepts Divisibility Congruence Quadratic Residues

More information

TEST CODE: PMB SYLLABUS

TEST CODE: PMB SYLLABUS TEST CODE: PMB SYLLABUS Convergence and divergence of sequence and series; Cauchy sequence and completeness; Bolzano-Weierstrass theorem; continuity, uniform continuity, differentiability; directional

More information

Elliptic curves in Huff s model

Elliptic curves in Huff s model Elliptic curves in Huff s model Hongfeng Wu 1, Rongquan Feng 1 College of Sciences, North China University of Technology, Beijing 1001, China whfmath@gmailcom LMAM, School of Mathematical Sciences, Peking

More information

Genus 2 Curves of p-rank 1 via CM method

Genus 2 Curves of p-rank 1 via CM method School of Mathematical Sciences University College Dublin Ireland and Claude Shannon Institute April 2009, GeoCrypt Joint work with Laura Hitt, Michael Naehrig, Marco Streng Introduction This talk is about

More information

Introduction to Elliptic Curve Cryptography. Anupam Datta

Introduction to Elliptic Curve Cryptography. Anupam Datta Introduction to Elliptic Curve Cryptography Anupam Datta 18-733 Elliptic Curve Cryptography Public Key Cryptosystem Duality between Elliptic Curve Cryptography and Discrete Log Based Cryptography Groups

More information

Computing Elliptic Curve Discrete Logarithms with the Negation Map

Computing Elliptic Curve Discrete Logarithms with the Negation Map Computing Elliptic Curve Discrete Logarithms with the Negation Map Ping Wang and Fangguo Zhang School of Information Science and Technology, Sun Yat-Sen University, Guangzhou 510275, China isszhfg@mail.sysu.edu.cn

More information

Minal Wankhede Barsagade, Dr. Suchitra Meshram

Minal Wankhede Barsagade, Dr. Suchitra Meshram International Journal of Scientific & Engineering Research, Volume 5, Issue 4, April-2014 467 Overview of History of Elliptic Curves and its use in cryptography Minal Wankhede Barsagade, Dr. Suchitra Meshram

More information

The Number of the Irreducible Cubic Polynomials in the Form of x 3 + ax + b with a Certain Fixed Element a

The Number of the Irreducible Cubic Polynomials in the Form of x 3 + ax + b with a Certain Fixed Element a Memoirs of the Faculty of Engineering, Okayama University, Vol41, pp1-10, January, 007 The Number of the Irreducible Cubic Polynomials in the Form of x + ax + b with a Certain Fixed Element a Yasuyuki

More information

Elliptic Curve of the Ring F q [ɛ]

Elliptic Curve of the Ring F q [ɛ] International Mathematical Forum, Vol. 6, 2011, no. 31, 1501-1505 Elliptic Curve of the Ring F q [ɛ] ɛ n =0 Chillali Abdelhakim FST of Fez, Fez, Morocco chil2015@yahoo.fr Abstract Groups where the discrete

More information

Explicit isogenies and the Discrete Logarithm Problem in genus three

Explicit isogenies and the Discrete Logarithm Problem in genus three Explicit isogenies and the Discrete Logarithm Problem in genus three Benjamin Smith INRIA Saclay Île-de-France Laboratoire d informatique de l école polytechnique (LIX) EUROCRYPT 2008 : Istanbul, April

More information

An Algorithm for Solving the Discrete Log Problem on Hyperelliptic Curves

An Algorithm for Solving the Discrete Log Problem on Hyperelliptic Curves An Algorithm for Solving the Discrete Log Problem on Hyperelliptic Curves Pierrick Gaudry LIX, École Polytechnique, 91128 Palaiseau Cedex, France gaudry@lix.polytechnique.fr Abstract. We present an index-calculus

More information

Pairings for Cryptographers

Pairings for Cryptographers Pairings for Cryptographers Steven D. Galbraith 1, Kenneth G. Paterson 1, and Nigel P. Smart 2 1 Information Security Group, Royal Holloway, University of London, Egham, Surrey, TW20 0EX, United Kingdom.

More information

On the Discrete Logarithm Problem on Algebraic Tori

On the Discrete Logarithm Problem on Algebraic Tori On the Discrete Logarithm Problem on Algebraic Tori R. Granger 1 and F. Vercauteren 2 1 University of Bristol, Department of Computer Science, Merchant Venturers Building, Woodland Road, Bristol, BS8 1UB,

More information

Efficient Computation of Tate Pairing in Projective Coordinate Over General Characteristic Fields

Efficient Computation of Tate Pairing in Projective Coordinate Over General Characteristic Fields Efficient Computation of Tate Pairing in Projective Coordinate Over General Characteristic Fields Sanjit Chatterjee, Palash Sarkar and Rana Barua Cryptology Research Group Applied Statistics Unit Indian

More information

Efficient Computation of Roots in Finite Fields

Efficient Computation of Roots in Finite Fields Efficient Computation of Roots in Finite Fields PAULO S. L. M. BARRETO (pbarreto@larc.usp.br) Laboratório de Arquitetura e Redes de Computadores (LARC), Escola Politécnica, Universidade de São Paulo, Brazil.

More information

Implementing Pairing-Based Cryptosystems

Implementing Pairing-Based Cryptosystems Implementing Pairing-Based Cryptosystems Zhaohui Cheng and Manos Nistazakis School of Computing Science, Middlesex University White Hart Lane, London N17 8HR, UK. {m.z.cheng, e.nistazakis}@mdx.ac.uk Abstract:

More information

Generation Methods of Elliptic Curves

Generation Methods of Elliptic Curves Generation Methods of Elliptic Curves by Harald Baier and Johannes Buchmann August 27, 2002 An evaluation report for the Information-technology Promotion Agency, Japan Contents 1 Introduction 1 1.1 Preface.......................................

More information

Pollard s Rho Algorithm for Elliptic Curves

Pollard s Rho Algorithm for Elliptic Curves November 30, 2015 Consider the elliptic curve E over F 2 k, where E = n. Assume we want to solve the elliptic curve discrete logarithm problem: find k in Q = kp. Partition E into S 1 S 2 S 3, where the

More information

Hyperelliptic curves

Hyperelliptic curves 1/40 Hyperelliptic curves Pierrick Gaudry Caramel LORIA CNRS, Université de Lorraine, Inria ECC Summer School 2013, Leuven 2/40 Plan What? Why? Group law: the Jacobian Cardinalities, torsion Hyperelliptic

More information

Fast Cryptography in Genus 2

Fast Cryptography in Genus 2 Fast Cryptography in Genus 2 Joppe W. Bos, Craig Costello, Huseyin Hisil and Kristin Lauter EUROCRYPT 2013 Athens, Greece May 27, 2013 Fast Cryptography in Genus 2 Recall that curves are much better than

More information

Constructive and destructive facets of Weil descent on elliptic curves

Constructive and destructive facets of Weil descent on elliptic curves Constructive and destructive facets of Weil descent on elliptic curves Pierrick Gaudry, Florian Hess, Nigel Smart To cite this version: Pierrick Gaudry, Florian Hess, Nigel Smart. Constructive and destructive

More information

Polynomial Interpolation in the Elliptic Curve Cryptosystem

Polynomial Interpolation in the Elliptic Curve Cryptosystem Journal of Mathematics and Statistics 7 (4): 326-331, 2011 ISSN 1549-3644 2011 Science Publications Polynomial Interpolation in the Elliptic Curve Cryptosystem Liew Khang Jie and Hailiza Kamarulhaili School

More information

On Partial Lifting and the Elliptic Curve Discrete Logarithm Problem

On Partial Lifting and the Elliptic Curve Discrete Logarithm Problem On Partial Lifting and the Elliptic Curve Discrete Logarithm Problem Qi Cheng 1 and Ming-Deh Huang 2 1 School of Computer Science The University of Oklahoma Norman, OK 73019, USA. Email: qcheng@cs.ou.edu.

More information

Low complexity bit-parallel GF (2 m ) multiplier for all-one polynomials

Low complexity bit-parallel GF (2 m ) multiplier for all-one polynomials Low complexity bit-parallel GF (2 m ) multiplier for all-one polynomials Yin Li 1, Gong-liang Chen 2, and Xiao-ning Xie 1 Xinyang local taxation bureau, Henan, China. Email:yunfeiyangli@gmail.com, 2 School

More information

Elliptic and Hyperelliptic Curve Cryptography

Elliptic and Hyperelliptic Curve Cryptography Elliptic and Hyperelliptic Curve Cryptography Renate Scheidler Research supported in part by NSERC of Canada Comprehensive Source Handbook of Elliptic and Hyperelliptic Curve Cryptography Overview Motivation

More information

Deterministic Polynomial Time Equivalence between Factoring and Key-Recovery Attack on Takagi s RSA

Deterministic Polynomial Time Equivalence between Factoring and Key-Recovery Attack on Takagi s RSA Deterministic Polynomial Time Equivalence between Factoring and Key-Recovery Attack on Takagi s RSA Noboru Kunihiro 1 and Kaoru Kurosawa 2 1 The University of Electro-Communications, Japan kunihiro@iceuecacjp

More information

A SIMPLE GENERALIZATION OF THE ELGAMAL CRYPTOSYSTEM TO NON-ABELIAN GROUPS

A SIMPLE GENERALIZATION OF THE ELGAMAL CRYPTOSYSTEM TO NON-ABELIAN GROUPS Communications in Algebra, 3: 3878 3889, 2008 Copyright Taylor & Francis Group, LLC ISSN: 0092-7872 print/132-12 online DOI: 10.1080/0092787080210883 A SIMPLE GENERALIZATION OF THE ELGAMAL CRYPTOSYSTEM

More information

COMPUTING MODULAR POLYNOMIALS

COMPUTING MODULAR POLYNOMIALS COMPUTING MODULAR POLYNOMIALS DENIS CHARLES AND KRISTIN LAUTER 1. Introduction The l th modular polynomial, φ l (x, y), parameterizes pairs of elliptic curves with a cyclic isogeny of degree l between

More information

Constructing Abelian Varieties for Pairing-Based Cryptography

Constructing Abelian Varieties for Pairing-Based Cryptography for Pairing-Based CWI and Universiteit Leiden, Netherlands Workshop on Pairings in Arithmetic Geometry and 4 May 2009 s MNT MNT Type s What is pairing-based cryptography? Pairing-based cryptography refers

More information

Affine Precomputation with Sole Inversion in Elliptic Curve Cryptography

Affine Precomputation with Sole Inversion in Elliptic Curve Cryptography Affine Precomputation with Sole Inversion in Elliptic Curve Cryptography Erik Dahmen, 1 Katsuyuki Okeya, 2 and Daniel Schepers 1 1 Technische Universität Darmstadt, Fachbereich Informatik, Hochschulstr.10,

More information

Mapping an Arbitrary Message to an Elliptic Curve when Defined over GF (2 n )

Mapping an Arbitrary Message to an Elliptic Curve when Defined over GF (2 n ) International Journal of Network Security, Vol8, No2, PP169 176, Mar 2009 169 Mapping an Arbitrary Message to an Elliptic Curve when Defined over GF (2 n ) Brian King Indiana University - Purdue University

More information

Introduction to Elliptic Curves

Introduction to Elliptic Curves IAS/Park City Mathematics Series Volume XX, XXXX Introduction to Elliptic Curves Alice Silverberg Introduction Why study elliptic curves? Solving equations is a classical problem with a long history. Starting

More information

An Alternate Decomposition of an Integer for Faster Point Multiplication on Certain Elliptic Curves

An Alternate Decomposition of an Integer for Faster Point Multiplication on Certain Elliptic Curves An Alternate Decomposition of an Integer for Faster Point Multiplication on Certain Elliptic Curves Young-Ho Park 1,, Sangtae Jeong 2, Chang Han Kim 3, and Jongin Lim 1 1 CIST, Korea Univ., Seoul, Korea

More information

ELLIPTIC CURVES OVER FINITE FIELDS

ELLIPTIC CURVES OVER FINITE FIELDS Further ELLIPTIC CURVES OVER FINITE FIELDS FRANCESCO PAPPALARDI #4 - THE GROUP STRUCTURE SEPTEMBER 7 TH 2015 SEAMS School 2015 Number Theory and Applications in Cryptography and Coding Theory University

More information

ACCELERATING THE SCALAR MULTIPLICATION ON GENUS 2 HYPERELLIPTIC CURVE CRYPTOSYSTEMS

ACCELERATING THE SCALAR MULTIPLICATION ON GENUS 2 HYPERELLIPTIC CURVE CRYPTOSYSTEMS ACCELERATING THE SCALAR MULTIPLICATION ON GENUS 2 HYPERELLIPTIC CURVE CRYPTOSYSTEMS by Balasingham Balamohan A thesis submitted to the Faculty of Graduate and Postdoctoral Studies in partial fulfillment

More information

Fast arithmetic and pairing evaluation on genus 2 curves

Fast arithmetic and pairing evaluation on genus 2 curves Fast arithmetic and pairing evaluation on genus 2 curves David Freeman University of California, Berkeley dfreeman@math.berkeley.edu November 6, 2005 Abstract We present two algorithms for fast arithmetic

More information

Quadratic Equations from APN Power Functions

Quadratic Equations from APN Power Functions IEICE TRANS. FUNDAMENTALS, VOL.E89 A, NO.1 JANUARY 2006 1 PAPER Special Section on Cryptography and Information Security Quadratic Equations from APN Power Functions Jung Hee CHEON, Member and Dong Hoon

More information

A New Algorithm to Compute Terms in Special Types of Characteristic Sequences

A New Algorithm to Compute Terms in Special Types of Characteristic Sequences A New Algorithm to Compute Terms in Special Types of Characteristic Sequences Kenneth J. Giuliani 1 and Guang Gong 2 1 Dept. of Mathematical and Computational Sciences University of Toronto at Mississauga

More information

High-Performance Scalar Multiplication using 8-Dimensional GLV/GLS Decomposition

High-Performance Scalar Multiplication using 8-Dimensional GLV/GLS Decomposition High-Performance Scalar Multiplication using 8-Dimensional GLV/GLS Decomposition Joppe W. Bos 1, Craig Costello 1, Huseyin Hisil 2, and Kristin Lauter 1 1 Microsoft Research, Redmond, USA 2 Yasar University,

More information

GENERATION OF RANDOM PICARD CURVES FOR CRYPTOGRAPHY. 1. Introduction

GENERATION OF RANDOM PICARD CURVES FOR CRYPTOGRAPHY. 1. Introduction GENERATION OF RANDOM PICARD CURVES FOR CRYPTOGRAPHY ANNEGRET WENG Abstract. Combining the ideas in [BTW] [GS], we give a efficient, low memory algorithm for computing the number of points on the Jacobian

More information

Calcul d indice et courbes algébriques : de meilleures récoltes

Calcul d indice et courbes algébriques : de meilleures récoltes Calcul d indice et courbes algébriques : de meilleures récoltes Alexandre Wallet ENS de Lyon, Laboratoire LIP, Equipe AriC Alexandre Wallet De meilleures récoltes dans le calcul d indice 1 / 35 Today:

More information

Mechanizing Elliptic Curve Associativity

Mechanizing Elliptic Curve Associativity Mechanizing Elliptic Curve Associativity Why a Formalized Mathematics Challenge is Useful for Verification of Crypto ARM Machine Code Joe Hurd Computer Laboratory University of Cambridge Galois Connections

More information

On the complexity of computing discrete logarithms in the field F

On the complexity of computing discrete logarithms in the field F On the complexity of computing discrete logarithms in the field F 3 6 509 Francisco Rodríguez-Henríquez CINVESTAV-IPN Joint work with: Gora Adj Alfred Menezes Thomaz Oliveira CINVESTAV-IPN University of

More information

Gurgen Khachatrian Martun Karapetyan

Gurgen Khachatrian Martun Karapetyan 34 International Journal Information Theories and Applications, Vol. 23, Number 1, (c) 2016 On a public key encryption algorithm based on Permutation Polynomials and performance analyses Gurgen Khachatrian

More information

Public Key Cryptography with a Group of Unknown Order

Public Key Cryptography with a Group of Unknown Order Public Key Cryptography with a Group of Unknown Order Richard P. Brent 1 Oxford University rpb@comlab.ox.ac.uk Programming Research Group Report PRG TR 02 00 5 June 2000 Abstract We present algorithms

More information

On Orders of Elliptic Curves over Finite Fields

On Orders of Elliptic Curves over Finite Fields Rose-Hulman Undergraduate Mathematics Journal Volume 19 Issue 1 Article 2 On Orders of Elliptic Curves over Finite Fields Yujin H. Kim Columbia University, yujin.kim@columbia.edu Jackson Bahr Eric Neyman

More information

Arithmetic of split Kummer surfaces: Montgomery endomorphism of Edwards products

Arithmetic of split Kummer surfaces: Montgomery endomorphism of Edwards products 1 Arithmetic of split Kummer surfaces: Montgomery endomorphism of Edwards products David Kohel Institut de Mathématiques de Luminy International Workshop on Codes and Cryptography 2011 Qingdao, 2 June

More information

Isogenies in a quantum world

Isogenies in a quantum world Isogenies in a quantum world David Jao University of Waterloo September 19, 2011 Summary of main results A. Childs, D. Jao, and V. Soukharev, arxiv:1012.4019 For ordinary isogenous elliptic curves of equal

More information

Pairing computation on Edwards curves with high-degree twists

Pairing computation on Edwards curves with high-degree twists Pairing computation on Edwards curves with high-degree twists Liangze Li 1, Hongfeng Wu 2, Fan Zhang 1 1 LMAM, School of Mathematical Sciences, Peking University, Beijing 100871, China 2 College of Sciences,

More information