## Efficient Doubling for Genus Two Curves over Binary Field

Venue: | Selected Areas in Cryptography SAC 2004, Lecture Notes in Computer Science |

Citations: | 18 - 1 self |

### BibTeX

@INPROCEEDINGS{Lange_efficientdoubling,

author = {Tanja Lange and Marc Stevens},

title = {Efficient Doubling for Genus Two Curves over Binary Field},

booktitle = {Selected Areas in Cryptography SAC 2004, Lecture Notes in Computer Science},

year = {},

pages = {170--181}

}

### Years of Citing Articles

### OpenURL

### Abstract

Abstract. In most algorithms involving elliptic and hyperelliptic curves, the costliest part consists in computing multiples of ideal classes. This paper investigates how to compute faster doubling over fields of characteristic two. We derive explicit doubling formulae making strong use of the defining equation of the curve. We analyze how many field operations are needed depending on the curve making clear how much generality one loses by the respective choices. Note, that none of the proposed types is known to be weak – one only could be suspicious because of the more special types. Our results allow to choose curves from a large enough variety which have extremely fast doubling needing only half the time of an addition. Combined with a sliding window method this leads to fast computation of scalar multiples. We also speed up the general case.

### Citations

338 | Algebraic Function Fields and Codes - Stichtenoth - 1993 |

189 | A remark concerning m-divisibility and the discrete logarithm in the divisor class group of curves - Frey, Rück - 1994 |

155 | Computing in Jacobian of a Hyperelliptic Curve,” in - Cantor - 1987 |

145 | Hyperelliptic cryptosystems - Koblitz - 1989 |

107 | Handbook of elliptic and hyperelliptic curve cryptography. Discrete mathematics and its applications - Cohen, Frey, et al. - 2006 |

87 | Supersingular Curves in Cryptography - Galbraith - 2001 |

78 | An algorithm for solving the discrete log problem on hyperelliptic curves - Gaudry |

58 | An Elementary Introduction to Hyperelliptic Curves - Menezes, Wu, et al. - 1998 |

52 | A double large prime variation for small genus Hyper Elliptic index calculus”, Cryptology ePrint Archive, Report 2004/153, 2004. Available at http://eprint.iacr.org/ AUTHORS P. Vijayakumar is currently working as Assistant Professor (Sr.) in School Electr - Gaudry, Thome |

49 | Formulae for Arithmetic on Genus 2 Hyperelliptic Curves,” September 2003. http://www.ruhr-uni-bochum.de/itsc/ tanja/preprints/expl sub.pdf
- Lange
(Show Context)
Citation Context ... on the properties of the input – to derive explicit formulae one needs to study additions independently from doublings. For a complete study of all possible inputs together with formulae we refer to =-=[Lan04a]-=-. In this paper we concentrate on doublings for genus 2 curves in the most frequent case where the input [u, v] has full degree and u and h do not have a root in common. Accordingly, we assume from no... |

44 | Index calculus attack for hyperelliptic curves of small genus - Thériault - 2003 |

36 | Aspects of Hyperelliptic Curves over Large Prime Fields in Software Implementations - Avanzi - 2004 |

24 | Securing Elliptic Curve Point Multiplication against Side-Channel Attacks - Möller - 2001 |

13 | Speeding up the Arithmetic on Koblitz Curves of Genus Two - Günther, Lange, et al. - 2000 |

11 |
Countermeasures Against Differential Power Analysis for Hyperelliptic Curve Cryptosystems
- Avanzi
- 2003
(Show Context)
Citation Context ...e, the lower operation count obtained here for the special choices applies also to other coordinate systems. Projective and new coordinates bear the additional advantage that randomization techniques =-=[Ava04]-=- can be applied to avoid DPA, e. g. all coordinates can be multiplied by (powers of) a random integer leading to a different representation of the same ideal class. For affine coordinates one can rand... |

7 |
Special Hyperelliptic Curve Cryptosystems of Genus Two: Efficient Arithmetic and Fast Implementation, chapter
- Pelzl, Wollinger, et al.
- 2004
(Show Context)
Citation Context ...m in the Koblitz curve setting. Clearly, this again is a special choice but the number of non-isomorphic curves has grown considerably. So far only one very special type of curves has been considered =-=[PWP04]-=- and shown to lead to efficient doubling formulae. Our results improve their formulae and provide clear tables with all types of defining equations together with the number of operations and also give... |

6 |
Classification of genus 2 curves over F2n and optimization of their arithmetic. Cryptology ePrint Archive: Report 2004/107
- Byramjee, Duquesne
(Show Context)
Citation Context ... with all types of defining equations together with the number of operations and also give the doubling formulae. After the submission of this paper the authors found a further work in special curves =-=[BD04]-=-. They obtain less efficient doublings, but also do a complete study of all kinds of curves. Even more recently, Duquesne (see [ACD+ 04]) made improvements for the case where deg h = 2 and h0 ̸= 0. We... |

6 | Mathematical Background of Public Key Cryptography - Frey, Lange |

6 | An Invitation to Arithmetic Geometry, volume 9 of Graduate studies in mathematics. AMS - Lorenzini - 1996 |

3 | Koblitz Curve Cryptosystems. Finite Fields and Their Applications - Lange - 2004 |

1 | Improvement of Thériault Algorithm of Index Calculus for Jacobian of Hyperelliptic Curves of Small Genus. Cryptology ePrint Archive, Report 2004/161 - Springer - 2004 |