Description
The talk will be concerned with arithmetic on elliptic and hyperelliptic curves. We show how fast the arithmetic can get by clever choices of the coordinates and present special kinds of curves which allow even faster arithmetic using the Frobenius endomorphism. For elliptic curves this has been used to achieve fast arithmetic for the past years. However, so far arithmetic in the ideal class group of hyperelliptic curves was performed using Cantor's algorithm which needs several inversions per group operation.<br/> Starting with the work of Harley and improved by Miyamoto, Doi, Matsuo, Chao, and Tsuji and by Takahashi efficient explicit formulae are at hand. Meanwhile inversion-free systems have been studied allowing even hardware implementations and depending on the system, hyperelliptic curves can even be faster than elliptic curves. Curve-endomorphisms allow to obtain further speed-up. We shortly present Koblitz curves, the generalized GLV method and trace zero subvarieties.
Next sessions
-
Polytopes in the Fiat-Shamir with Aborts Paradigm
Speaker : Hugo Beguinet - ENS Paris / Thales
The Fiat-Shamir with Aborts paradigm (FSwA) uses rejection sampling to remove a secret’s dependency on a given source distribution. Recent results revealed that unlike the uniform distribution in the hypercube, both the continuous Gaussian and the uniform distribution within the hypersphere minimise the rejection rate and the size of the proof of knowledge. However, in practice both these[…]-
Cryptography
-
Asymmetric primitive
-
Mode and protocol
-
-
Post-quantum Group-based Cryptography
Speaker : Delaram Kahrobaei - The City University of New York