Faster computation of isogenies of large prime degree

03/23/2020
by   Daniel Bernstein, et al.
0

Let E/F_q be an elliptic curve, and P a point in E(F_q) of prime order ℓ. Vélu's formulae let us compute a quotient curve E' = E/〈P〉 and rational maps defining a quotient isogeny ϕ: E→E' in Õ(ℓ)F_q-operations, where the Õ is uniform in q.This article shows how to compute E', and ϕ(Q) for Q in E(F_q), using only Õ(√(ℓ))F_q-operations, where the Õ is again uniform in q.As an application, this article speeds up some computations used in the isogeny-based cryptosystems CSIDH and CSURF.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/13/2020

Cover attacks for elliptic curves with prime order

We give a new approach to the elliptic curve discrete logarithm problem ...
research
02/02/2020

Exceptional scatteredness in prime degree

Let q be an odd prime power and n be a positive integer. Let ℓ∈F_q^n[x] ...
research
06/18/2021

Extending the GLS endomorphism to speed up GHS Weil descent using Magma

Let q = 2^n, and let E / 𝔽_q^ℓ be a generalized Galbraith–Lin–Scott (GLS...
research
08/06/2021

The Differential Spectrum of the Power Mapping x^p^n-3

Let n be a positive integer and p a prime. The power mapping x^p^n-3 ove...
research
07/23/2018

Two Algorithms to Find Primes in Patterns

Let k> 1 be an integer, and let (f_1(x), ..., f_k(x) ) be k admissible l...
research
11/15/2017

Set complexity of construction of a regular polygon

Given a subset of C containing x,y, one can add x + y or x - y or xy or...
research
02/10/2022

Faulty isogenies: a new kind of leakage

In SIDH and SIKE protocols, public keys are defined over quadratic exten...

Please sign up or login with your details

Forgot password? Click here to reset