Twisting Edwards curves with isogenies
نویسنده
چکیده
Edwards’ elliptic curve form is popular in modern cryptographic implementations thanks to their fast, strongly unified addition formulas. Twisted Edwards curves with a = −1 are slightly faster, but their addition formulas are not complete over Fp where p ≡ 3 (mod 4). In this short note, we propose that designers specify Edwards curves, but implement scalar multiplications and the like using an isogenous twisted Edwards curve.
منابع مشابه
Isogenies on Edwards and Huff curves
Isogenies of elliptic curves over finite fields have been well-studied, in part because there are several cryptographic applications. Using Vélu’s formula, isogenies can be constructed explicitly given their kernel. Vélu’s formula applies to elliptic curves given by a Weierstrass equation. In this paper we show how to similarly construct isogenies on Edwards curves and Huff curves. Edwards and ...
متن کاملTwisted Edwards Curves
This paper introduces “twisted Edwards curves,” a generalization of the recently introduced Edwards curves; shows that twisted Edwards curves include more curves over finite fields, and in particular every elliptic curve in Montgomery form; shows how to cover even more curves via isogenies; presents fast explicit formulas for twisted Edwards curves in projective and inverted coordinates; and sh...
متن کاملAnalogues of Vélu's formulas for isogenies on alternate models of elliptic curves
Isogenies are the morphisms between elliptic curves, and are accordingly a topic of interest in the subject. As such, they have been wellstudied, and have been used in several cryptographic applications. Vélu’s formulas show how to explicitly evaluate an isogeny, given a specification of the kernel as a list of points. However, Vélu’s formulas only work for elliptic curves specified by a Weiers...
متن کاملA Simple and Compact Algorithm for SIDH with Arbitrary Degree Isogenies
We derive a new formula for computing arbitrary odd-degree isogenies between elliptic curves in Montgomery form. The formula lends itself to a simple and compact algorithm that can efficiently compute any low odd-degree isogenies inside the supersingular isogeny Diffie-Hellman (SIDH) key exchange protocol. Our implementation of this algorithm shows that, beyond the commonly used 3-isogenies, th...
متن کاملDiffie-Hellman type key exchange protocols based on isogenies
In this paper, we propose some Diffie-Hellman type key exchange protocols using isogenies of elliptic curves. The first method which uses the endomorphism ring of an ordinary elliptic curve $ E $, is a straightforward generalization of elliptic curve Diffie-Hellman key exchange. The method uses commutativity of the endomorphism ring $ End(E) $. Then using dual isogenies, we propose...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- IACR Cryptology ePrint Archive
دوره 2014 شماره
صفحات -
تاریخ انتشار 2014