2008 | OriginalPaper | Buchkapitel
Binary Edwards Curves
verfasst von : Daniel J. Bernstein, Tanja Lange, Reza Rezaeian Farashahi
Erschienen in: Cryptographic Hardware and Embedded Systems – CHES 2008
Verlag: Springer Berlin Heidelberg
Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.
Wählen Sie Textabschnitte aus um mit Künstlicher Intelligenz passenden Patente zu finden. powered by
Markieren Sie Textabschnitte, um KI-gestützt weitere passende Inhalte zu finden. powered by
This paper presents a new shape for ordinary elliptic curves over fields of characteristic 2. Using the new shape, this paper presents the first complete addition formulas for binary elliptic curves, i.e., addition formulas that work for all pairs of input points, with no exceptional cases. If
n
≥ 3 then the complete curves cover all isomorphism classes of ordinary elliptic curves over
.
This paper also presents dedicated doubling formulas for these curves using 2
M
+ 6
S
+ 3
D
, where
M
is the cost of a field multiplication,
S
is the cost of a field squaring, and
D
is the cost of multiplying by a curve parameter. These doubling formulas are also the first complete doubling formulas in the literature, with no exceptions for the neutral element, points of order 2, etc.
Finally, this paper presents complete formulas for differential addition, i.e., addition of points with known difference. A differential addition and doubling, the basic step in a Montgomery ladder, uses 5
M
+ 4
S
+ 2
D
when the known difference is given in affine form.