A comparison of MNT curves and supersingular curves
نویسندگان
چکیده
منابع مشابه
Constructing Supersingular Elliptic Curves
We give an algorithm that constructs, on input of a prime power q and an integer t, a supersingular elliptic curve over Fq with trace of Frobenius t in case such a curve exists. If GRH holds true, the expected run time of our algorithm is e O((log q)). We illustrate the algorithm by showing how to construct supersingular curves of prime order. Such curves can readily be used for pairing based c...
متن کاملSupersingular Curves in Cryptography
Frey and Rück gave a method to transform the discrete logarithm problem in the divisor class group of a curve over Fq into a discrete logarithm problem in some finite field extension Fqk . The discrete logarithm problem can therefore be solved using index calculus algorithms as long as k is small. In the elliptic curve case it was shown by Menezes, Okamoto and Vanstone that for supersingular cu...
متن کاملGenerating More MNT Elliptic Curves
In their seminal paper, Miyaji, Nakabayashi and Takano [12] describe a simple method for the creation of elliptic curves of prime order with embedding degree 3, 4, or 6. Such curves are important for the realisation of pairing-based cryptosystems on ordinary (non-supersingular) elliptic curves. We provide an alternative derivation of their results, and extend them to allow for the generation of...
متن کامل5.1 Ordinary and Supersingular Curves
Theorem 15.1. Let E/Fq be an elliptic curve over a finite field, and let πE be the Frobenius endomorphism of E. Then E is supersingular if and only if trπE ≡ 0 mod p. Proof. Let q = pn and let π be the p-power Frobenius map π(x, y) = (xp, yp) (note that π is an isogeny, but not necessarily an endomorphism, since E need not be defined over Fp). We have π̂π = [p], where [p] denotes the multiplicat...
متن کاملMinimal Cm Liftings of Supersingular Elliptic Curves
In this paper, we give a ‘direct’ construction of the endomorphism ring of supersingular elliptic curves over a prime field Fp from ‘ideal classes’ of Q( √−p). We use the result to prove that the result of Kaneko on ‘minimal’ CM liftings of such supersingular elliptic curves is a best possible result. We also prove that the result of Elkies on ‘minimal’ CM liftings of all supersingular elliptic...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Applicable Algebra in Engineering, Communication and Computing
سال: 2006
ISSN: 0938-1279,1432-0622
DOI: 10.1007/s00200-006-0017-6