Differential Addition in Generalized Edwards Coordinates

نویسندگان

  • Benjamin Justus
  • Daniel Loebenberger
چکیده

We use two parametrizations of points on elliptic curves in generalized Edwards form x + y = c(1 + dxy) that omit the xcoordinate. The first parametrization leads to a differential addition formula that can be computed using 6M + 4S, a doubling formula using 1M + 4S and a tripling formula using 4M + 7S. The second one yields a differential addition formula that can be computed using 5M + 2S and a doubling formula using 5S. All formulas apply also for the case c 6= 1 and arbitrary curve parameter d. This generalizes formulas from the literature for the special case c = 1. For both parametrizations the formula for recovering the missing Xcoordinate is also provided.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Generalized Differential Quadrature Method for Vibration Analysis of Cantilever Trapezoidal FG Thick Plate

This paper presents a numerical solution for vibration analysis of a cantilever trapezoidal thick plate. The material of the plate is considered to be graded through the thickness from a metal surface to a ceramic one according to a power law function. Kinetic and strain energies are derived based on the Reissner-Mindlin theory for thick plates and using Hamilton's principle, the governing equa...

متن کامل

Fault Attacks against the Miller's Algorithm in Edwards Coordinates

Initially, the use of pairings did not involve any secret entry. However in an Identity Based Cryptographic protocol, one of the two entries of the pairing is secret, so fault attack can be applied to Pairing Based Cryptography to nd it. In [18], the author shows that Pairing Based Cryptography in Weierstrass coordinates is vulnerable to a fault attack. The addition law in Edwards coordinates i...

متن کامل

Differential Addition on Edwards Curves

We give two parametrizations of points on Edwards curves that omit the X coordinate. The first parametrization leads to a differential addition formula that has the cost 5M + 4S, a doubling formula that has the cost 5S and a tripling formula that costs 4M+7S. The second one yields a differential addition formula with cost 5M + 2S and a doubling formula with cost 5S both even on generalized Edwa...

متن کامل

Inverted Edwards Coordinates

Edwards curves have attracted great interest for several reasons. When curve parameters are chosen properly, the addition formulas use only 10M+1S. The formulas are strongly unified, i.e., work without change for doublings; even better, they are complete, i.e., work without change for all inputs. Dedicated doubling formulas use only 3M + 4S, and dedicated tripling formulas use only 9M + 4S. Thi...

متن کامل

Another Approach to Pairing Computation in Edwards Coordinates

The recent introduction of Edwards curves has significantly reduced the cost of addition on elliptic curves. This paper presents new explicit formulae for pairing implementation in Edwards coordinates. We prove our method gives performances similar to those of Miller’s algorithm in Jacobian coordinates and is thus of cryptographic interest when one chooses Edwards curve implementations of proto...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2009  شماره 

صفحات  -

تاریخ انتشار 2009