Differential Addition on Edwards Curves
نویسندگان
چکیده
We give two parametrizations of points on Edwards curves that omit the X coordinate. The first parametrization leads to a differential addition formula that has the cost 5M + 4S, a doubling formula that has the cost 5S and a tripling formula that costs 4M+7S. The second one yields a differential addition formula with cost 5M + 2S and a doubling formula with cost 5S both even on generalized Edwards curves. The price to pay for this representation is the extraction of two square roots in the ground field. For both parametrizations the formula for recovering the missing coordinate is also provided. In addition, we give an addition chain for computing the scalar multiple of a point on the Edwards curve.
منابع مشابه
Differential Addition in Generalized Edwards Coordinates
We use two parametrizations of points on elliptic curves in generalized Edwards form x + y = c(1 + dxy) that omit the xcoordinate. The first parametrization leads to a differential addition formula that can be computed using 6M + 4S, a doubling formula using 1M + 4S and a tripling formula using 4M + 7S. The second one yields a differential addition formula that can be computed using 5M + 2S and...
متن کاملA complete set of addition laws for incomplete Edwards curves
Edwards curves were the first curves shown to have a complete addition law. However, the completeness of the addition law depends on the curve parameters and even a complete Edwards curve becomes incomplete over a quadratic field extension. This paper covers arbitrary Edwards curves and gives a set of two addition laws that for any pair of input points P1, P2 produce the sum P1 + P2.
متن کاملFaster Addition and Doubling on Elliptic Curves
Edwards recently introduced a new normal form for elliptic curves. Every elliptic curve over a non-binary field is birationally equivalent to a curve in Edwards form over an extension of the field, and in many cases over the original field. This paper presents fast explicit formulas (and register allocations) for group operations on an Edwards curve. The algorithm for doubling uses only 3M+ 4S,...
متن کاملSame Value Analysis on Edwards Curves
Recently, several research groups in cryptography have presented new elliptic curve model based on Edwards curves. These new curves were selected for their good performance and security perspectives. Cryptosystems based on elliptic curves in embedded devices can be vulnerable to Side-Channel Attacks (SCA), such as the Simple Power Analysis (SPA) or the Differential Power Analysis (DPA). In this...
متن کاملFaster Pairing Computation
This paper proposes new explicit formulas for the doubling and addition step in Miller’s algorithm to compute pairings. For Edwards curves the formulas come from a new way of seeing the arithmetic. We state the first geometric interpretation of the group law on Edwards curves by presenting the functions which arise in the addition and doubling. Computing the coefficients of the functions and th...
متن کامل