New point compression method for elliptic F_q^2-curves of j-invariant 0
conic bundleselliptic curves with \(j=0\)generalized Kummer surfacespairing-based cryptographypoint compressionrationality problemssingular cubic surfacesWeil restriction
Rationality questions in algebraic geometry (14E08) Applications to coding theory and cryptography of arithmetic geometry (14G50) Elliptic curves (14H52) Vector bundles on curves and their moduli (14H60) Coding and information theory (compaction, compression, models of communication, encoding schemes, etc.) (aspects in computer science) (68P30)
In Elliptic Curve Cryptography an usual tool is a compression representation of a point \((x,y)\)\, of the underlying elliptic curve defined over a finite field \(\mathbb{F}_q\). Usually this is done taking the \(x\)-coordinate plus a single bit. The present paper proposes a new method for ordinary elliptic curves \(E_b: y^2=x^3+b\),\, defined over \(\mathbb{F}_{q^2}\),\,field of characteristic \(p\equiv 1 \bmod 3\),\, method that \lq \lq seem to be much faster than the classical one with \(x\)-coordinate, which requires two exponentiations in \(\mathbb{F}_q\). (for the decompression stage).\par The proposed method uses the Weil restriction \(R_b= R_{\mathbb{F}_{q^2}/\mathbb{F}_q}(E_b)\)\, and the generalized Kummer surface \(GK_b=R_b/[\omega]_2\), with \([\omega]_2\) the automorphism induced by a cubic root of 1, \(\omega \in \mathbb{F}_p\).\par \(GK_b\)\, is proved to be \(\mathbb{F}_{q^2}\)-rational and the paper, applying the theory of conic bundles, find a birational \(\mathbb{F}_q\)-isomorphism \(GK_b\approx \mathbb{A}^2\),\, which gives the looked compression. \par To recover the original point of the curve one need to compute one cubic root in \(\mathbb{F}_q\)\, which, for \(q\not \equiv 1 \bmod 27\),\, requires one exponentiation in \(\mathbb{F}_q\).\par Sections 1 and 2 gather the necessary mathematical background and some auxiliary results. The proposed compression is showed in Section 3. Theorem 12 proves (for \(q=p)\)\, that \(GK_b\)\, is \(\mathbb{F}_p\)-rational and gives the birational isomorphism \(GK_b\approx \mathbb{A}^2\).\par Section 3.1 instantiates the compression method to a family of curves, family including the pairing-friendly curve BLS12-381, [\url{https://z.cash/blog/new-snark-curve/}], and studies the complexity of the compression and decompression stages, see Table 1.
- Faster point compression for elliptic curves of \(j\)-invariant 0
- Public Key Cryptography – PKC 2004
- Determining formulas related to point compression on alternative models of elliptic curves
- Multiple point compression on elliptic curves
- Point compression for the trace zero subgroup over a small degree extension field
- A computational introduction to number theory and algebra
- A taxonomy of pairing-friendly elliptic curves
- Arithmetic on Singular Del Pezzo Surfaces
- Endomorphisms for faster elliptic curve cryptography on a large class of curves
- Finite automorphism groups of complex tori of dimension two
- Four-dimensional Gallant-Lambert-Vanstone scalar multiplication
- Four\(\mathbb {Q}\): four-dimensional decompositions on a \(\mathbb {Q}\)-curve over the Mersenne prime
- Guide to pairing-based cryptography
- scientific article; zbMATH DE number 1594291 (Why is no real title available?)
- scientific article; zbMATH DE number 4085811 (Why is no real title available?)
- scientific article; zbMATH DE number 3638024 (Why is no real title available?)
- scientific article; zbMATH DE number 1952905 (Why is no real title available?)
- scientific article; zbMATH DE number 1504543 (Why is no real title available?)
- scientific article; zbMATH DE number 3445393 (Why is no real title available?)
- scientific article; zbMATH DE number 1842492 (Why is no real title available?)
- scientific article; zbMATH DE number 3288410 (Why is no real title available?)
- Identity-based cryptosystems and signature schemes
- Implementing the 4-dimensional GLV method on GLS elliptic curves with j-invariant 0
- New cube root algorithm based on the third order linear recurrence relations in finite fields
- On Castelnuovo's criterion of rationality P\(_a\)=P\(_2\)=0 of an algebraic surface
- Optimal Eta Pairing on Supersingular Genus-2 Binary Hyperelliptic Curves
- Pairing-Friendly Elliptic Curves of Prime Order
- Point compression for Koblitz elliptic curves
- Quotients of abelian surfaces
- RATIONAL SURFACES WITH A PENCIL OF RATIONAL CURVES
- RATIONAL SURFACES WITH A PENCIL OF RATIONAL CURVES AND WITH POSITIVE SQUARE OF THE CANONICAL CLASS
- Solving conics over functions fields
- Square Root Computation over Even Extension Fields
- The Arithmetic of Elliptic Curves
- The Eta Pairing Revisited
- Zariski K3 surfaces
- A classification of the automorphism groups of polarized abelian threefolds over finite fields
- Hashing to elliptic curves of j=0 and Mordell-Weil groups
- Faster point compression for elliptic curves of \(j\)-invariant 0
- An optimal representation for the trace zero subgroup
- Multiple point compression on elliptic curves
- High-degree compression functions on alternative models of elliptic curves and their applications
- Public Key Cryptography – PKC 2004
- Hashing to elliptic curves through Cipolla-Lehmer-Müller's square root algorithm
- Batch point compression in the context of advanced pairing-based protocols
- Point (de)compression for elliptic curves over highly 2-adic finite fields
This page was built for publication: New point compression method for elliptic \(\mathbb{F}_{q^2}\)-curves of \(j\)-invariant 0
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q1995209)