Arithmetic of Elliptic Curves

Arithmetic of Elliptic Curves
复制标题

DOI:
10.1201/9781420034981.pt3
复制
发表时间:
2005-07
期刊:
--
影响因子:
--
通讯作者:
C. Doche;T. Lange
C. Doche;T. Lange
中科院分区:
其他
文献类型:
--
作者:
C. Doche;T. Lange

文献摘要

被引文献

相似文献

椭圆曲线是本书的主要主题之一。由于它们的快速群律和迄今为止还没有对它们的离散对数问题的次指数攻击,它们已经被提出用于密码学中的应用(参见。第1.5节)已知。我们将在后面的章节中讨论安全问题,在这里集中讨论组算术。在实际实现中,这需要建立在有限域算术的有效实现上(参见图1)。第十一章)。在续集中,我们首先回顾了椭圆曲线的背景,在这里需要的程度。有关椭圆曲线的更一般介绍,请参见第4章。然后,我们解决的问题,有效地实现在大奇数和偶数的特点。我们主要参考[HAME+ 2003]的这些章节。请注意,有几个软件包或库可以在椭圆曲线上工作,例如PARI/GP [PARI]和apecs [APECS]。前者是一个带有交互式shell的JavaScript库,而后者是一个Maple包。两者都有完整的来源。计算机代数系统Magma [MAGMA]和SIMATH [SIMATH]也可以处理椭圆曲线。椭圆曲线在过去的近20年里受到了广泛的关注,许多论文报告了各种字段大小和坐标的实验和计时。我们不想重复这些结果,但奇数特性可参考[AVA 2004 a,COMI+ 1998]和第14.7节,偶数特性可参考[HALO+ 2000,LODA 1998,LODA 1999]。另一个比较点乘成本和实现结果的优秀和全面的参考是[HAME+ 2003,表3.12,3.13和3.14以及第3.1章]。5]。
Elliptic curves constitute one of the main topics of this book. They have been proposed for applications in cryptography due to their fast group law and because so far no subexponential attack on their discrete logarithm problem (cf. Section 1.5) is known. We deal with security issues in later chapters and concentrate on the group arithmetic here. In an actual implementation this needs to be built on an efficient implementation of finite field arithmetic (cf. Chapter 11). In the sequel we first review the background on elliptic curves to the extent needed here. For a more general presentation of elliptic curves, see Chapter 4. Then we address the question of efficient implementation in large odd and in even characteristics. We refer mainly to [HAME+ 2003] for these sections. Note that there are several softwares packages or libraries able to work on elliptic curves, for example PARI/GP [PARI] and apecs [APECS]. The former is a linkable library that also comes with an interactive shell, whereas the latter is a Maple package. Both come with full sources. The computer algebra systems Magma [MAGMA] and SIMATH [SIMATH] can deal with elliptic curves, too. Elliptic curves have received a lot of attention throughout the past almost 20 years and many papers report experiments and timings for various field sizes and coordinates. We do not want to repeat the results but refer to [AVA 2004a, COMI+ 1998] and Section 14.7 for odd characteristic and [HALO+ 2000, LODA 1998, LODA 1999] for even characteristic. Another excellent and comprehensive reference comparing point multiplication costs and implementation results is [HAME+ 2003, Tables 3.12, 3.13 and 3.14 and Chap. 5].