Differential Addition in Generalized Edwards Coordinates
نویسندگان
چکیده
We use two parametrizations of points on elliptic curves in generalized Edwards form x + y = c(1 + dxy) that omit the xcoordinate. The first parametrization leads to a differential addition formula that can be computed using 6M + 4S, a doubling formula using 1M + 4S and a tripling formula using 4M + 7S. The second one yields a differential addition formula that can be computed using 5M + 2S and a doubling formula using 5S. All formulas apply also for the case c 6= 1 and arbitrary curve parameter d. This generalizes formulas from the literature for the special case c = 1. For both parametrizations the formula for recovering the missing Xcoordinate is also provided.
منابع مشابه
Generalized Differential Quadrature Method for Vibration Analysis of Cantilever Trapezoidal FG Thick Plate
This paper presents a numerical solution for vibration analysis of a cantilever trapezoidal thick plate. The material of the plate is considered to be graded through the thickness from a metal surface to a ceramic one according to a power law function. Kinetic and strain energies are derived based on the Reissner-Mindlin theory for thick plates and using Hamilton's principle, the governing equa...
متن کاملFault Attacks against the Miller's Algorithm in Edwards Coordinates
Initially, the use of pairings did not involve any secret entry. However in an Identity Based Cryptographic protocol, one of the two entries of the pairing is secret, so fault attack can be applied to Pairing Based Cryptography to nd it. In [18], the author shows that Pairing Based Cryptography in Weierstrass coordinates is vulnerable to a fault attack. The addition law in Edwards coordinates i...
متن کاملDifferential Addition on Edwards Curves
We give two parametrizations of points on Edwards curves that omit the X coordinate. The first parametrization leads to a differential addition formula that has the cost 5M + 4S, a doubling formula that has the cost 5S and a tripling formula that costs 4M+7S. The second one yields a differential addition formula with cost 5M + 2S and a doubling formula with cost 5S both even on generalized Edwa...
متن کاملInverted Edwards Coordinates
Edwards curves have attracted great interest for several reasons. When curve parameters are chosen properly, the addition formulas use only 10M+1S. The formulas are strongly unified, i.e., work without change for doublings; even better, they are complete, i.e., work without change for all inputs. Dedicated doubling formulas use only 3M + 4S, and dedicated tripling formulas use only 9M + 4S. Thi...
متن کاملAnother Approach to Pairing Computation in Edwards Coordinates
The recent introduction of Edwards curves has significantly reduced the cost of addition on elliptic curves. This paper presents new explicit formulae for pairing implementation in Edwards coordinates. We prove our method gives performances similar to those of Miller’s algorithm in Jacobian coordinates and is thus of cryptographic interest when one chooses Edwards curve implementations of proto...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- IACR Cryptology ePrint Archive
دوره 2009 شماره
صفحات -
تاریخ انتشار 2009