Differential addition in generalized Edwards coordinates

  • Authors:
  • Benjamin Justus;Daniel Loebenberger

  • Affiliations:
  • Bonn-Aachen International Center for Information Technology, Universität Bonn, Bonn, Germany;Bonn-Aachen International Center for Information Technology, Universität Bonn, Bonn, Germany

  • Venue:
  • IWSEC'10 Proceedings of the 5th international conference on Advances in information and computer security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

We use two parametrizations of points on elliptic curves in generalized Edwards form x2 + y2 = c2(1 + dx2y2) that omit the x- coordinate. The first parametrization leads to a differential addition formula that can be computed using 6M + 4S, a doubling formula using 1M+ 4S and a tripling formula using 4M+ 7S. The second one yields a differential addition formula that can be computed using 5M + 2S and a doubling formula using 5S. All formulas apply also for the case c ≠ 1 and arbitrary curve parameter d. This generalizes formulas from the literature for the special case c = 1 or d being a square in the ground field. For both parametrizations the formula for recovering the missing X- coordinate is also provided.