Arithmetic of Split Kummer Surfaces: Montgomery Endomorphism of Edwards Products
نویسنده
چکیده
Let E be an elliptic curve, K1 its Kummer curve E/{±1}, E its square product, and K2 the split Kummer surface E /{±1}. The addition law on E gives a large endomorphism ring, which induce endomorphisms of K2. With a view to the practical applications to scalar multiplication on K1, we study the explicit arithmetic of K2.
منابع مشابه
The arithmetic of characteristic 2 Kummer surfaces and of elliptic Kummer lines
The purpose of this paper is a description of a model of Kummer surfaces in characteristic 2, together with the associated formulas for the pseudo-group law. Since the classical model has bad reduction, a renormalization of the parameters is required, that can be justified using the theory of algebraic theta functions. The formulas that are obtained are very efficient and may be useful in crypt...
متن کاملqDSA: Small and Secure Digital Signatures with Curve-Based Diffie-Hellman Key Pairs
qDSA is a high-speed, high-security signature scheme that facilitates implementations with a very small memory footprint, a crucial requirement for embedded systems and IoT devices, and that uses the same public keys as modern Diffie–Hellman schemes based on Montgomery curves (such as Curve25519) or Kummer surfaces. qDSA resembles an adaptation of EdDSA to the world of Kummer varieties, which a...
متن کاملThe arithmetic of characteristic 2 Kummer surfaces
The purpose of this paper is a description of a model of Kummer surfaces in characteristic 2, together with the associated formulas for the pseudo-group law. Since the classical model has bad reduction, a renormalization of the parameters is required, that can be justified using the theory of algebraic theta functions. The formulas that are obtained are very efficient and may be useful in crypt...
متن کاملArithmetic on abelian and Kummer varieties
A Kummer variety is obtained as the quotient of an abelian variety by the automorphism (−1) acting on it. Kummer varieties can be seen as a higher dimensional generalisation of the xcoordinate representation of a point of an elliptic curve given by its Weierstrass model. Although there is no group law on the set of points of a Kummer variety, the multiplication of a point by a scalar still make...
متن کاملOn hybrid SIDH schemes using Edwards and Montgomery curve arithmetic
Supersingular isogeny Diffie-Hellman (SIDH) is a proposal for a quantumresistant key exchange. The state-of-the-art implementation works entirely with Montgomery curves and basically can be divided into elliptic curve arithmetic and isogeny arithmetic. It is well known that twisted Edwards curves can provide a more efficient elliptic curve arithmetic. Therefore it was hinted by Costello and His...
متن کامل