E cient Scalar Multiplication by Isogeny Decompositions
نویسندگان
چکیده
On an elliptic curve, the degree of an isogeny corresponds essentially to the degrees of the polynomial expressions involved in its application. The multiplication by ` map [`] has degree `, therefore the complexity to directly evaluate [`](P ) is O(`). For a small prime ` (= 2, 3) such that the additive binary representation provides no better performance, this represents the true cost of application of scalar multiplication. If an elliptic curves admits an isogeny φ of degree ` then the costs of computing φ(P ) should in contrast be O(`) eld operations. Since we then have a product expression [`] = φ̂φ, the existence of an `-isogeny φ on an elliptic curve yields a theoretical improvement from O(`) to O(`) eld operations for the evaluation of [`](P ) by naïve application of the de ning polynomials. In this work we investigate actual improvements for small ` of this asymptotic complexity. For this purpose, we describe the general construction of families of curves with a suitable decomposition [`] = φ̂φ, and provide explicit examples of such a family of curves with simple decomposition for [3]. Finally we derive a new tripling algorithm to nd complexity improvements to triplication on a curve in certain projective coordinate systems, then combine this new operation to non-adjacent forms for `-adic expansions in order to obtain an improved strategy for scalar multiplication on elliptic curves.
منابع مشابه
Efficient Scalar Multiplication by Isogeny Decompositions
On an elliptic curve, the degree of an isogeny corresponds essentially to the degrees of the polynomial expressions involved in its application. The multiplication–by– map [ ] has degree , therefore the complexity to directly evaluate [ ](P ) is O( ). For a small prime (= 2, 3) such that the additive binary representation provides no better performance, this represents the true cost of applicat...
متن کاملOn the Optimal Parameter Choice for Elliptic Curve Cryptosystems Using Isogeny
The isogeny for elliptic curve cryptosystems was initially used for the efficient improvement of order counting methods. Recently, Smart proposed the countermeasure using isogeny for resisting the refined differential power analysis by Goubin (Goubin’s attack). In this paper, we examine the countermeasure using isogeny against zero-value point (ZVP) attack that is generalization of Goubin’s att...
متن کاملEasy scalar decompositions for efficient scalar multiplication on elliptic curves and genus 2 Jacobians
The first step in elliptic curve scalar multiplication algorithms based on scalar decompositions using efficient endomorphisms— including Gallant–Lambert–Vanstone (GLV) and Galbraith–Lin–Scott (GLS) multiplication, as well as higher-dimensional and higher-genus constructions—is to produce a short basis of a certain integer lattice involving the eigenvalues of the endomorphisms. The shorter the ...
متن کاملElliptic Curves Scalar Multiplication Combining Mbnr with Point Halving
Elliptic curves scalar multiplication over some nite elds, attractive research area, which paid much attention by researchers in the recent years. Researchs still in progress to improve elliptic curves cryptography implementation and reducing its complexity. Elliptic curve point-halving algorithm proposed in [11] and later double-base chain [3] and step multi-base chain [19] are among e¢ cie...
متن کاملB -AND B - COMPLETENESS IN LOCALLY CONVEX ALGEBRAS AND THE E x THEOREM
Let E be a B-complete (B -complete) locally convex algebra and $ the topological direct sum of countably many copies of the scalar field with a jointly continuous algebra multiplication. It has been shown that E is also B-complete (B -complete) for componentwise multiplication on E . B-and Br-completeness of E , the unitization of E, and also of E x for other multiplications on E ...
متن کامل