Computing isogenies between Montgomery curves using the action of (0, 0)

Computing isogenies between Montgomery curves using the action of (0, 0)
复制标题

使用 (0, 0) 的作用计算蒙哥马利曲线之间的同源性

DOI:
--
复制
发表时间:
2018
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Joost Renes
Joost Renes
中科院分区:
--
文献类型:
--
作者:
Joost Renes

文献摘要

被引文献

相似文献

Costello和Hisil最近在Asiacrypt ' 17上发表的一篇论文提出了计算Montgomery曲线上具有奇次循环核的等同源的有效公式。我们对该定理的一个推广给出了建设性的证明,证明了等同性的形状与点((0,0))的简单作用之间的联系。这种推广消除了循环核的限制,并允许核不包含((0,0))的任何可分离同质。作为一个特殊的例子,我们提供了Montgomery曲线之间的2-同基因的有效公式,并证明这些公式可以用于基于同基因的密码系统,而不需要昂贵的平方根计算和不知道特殊的8阶点。我们还考虑了含有3阶显式点的三角形椭圆曲线。
A recent paper by Costello and Hisil at Asiacrypt’17 presents efficient formulas for computing isogenies with odd-degree cyclic kernels on Montgomery curves. We provide a constructive proof of a generalization of this theorem which shows the connection between the shape of the isogeny and the simple action of the point ((0,0)). This generalization removes the restriction of a cyclic kernel and allows for any separable isogeny whose kernel does not contain ((0,0)). As a particular case, we provide efficient formulas for 2-isogenies between Montgomery curves and show that these formulas can be used in isogeny-based cryptosystems without expensive square root computations and without knowledge of a special point of order 8. We also consider elliptic curves in triangular form containing an explicit point of order 3.