Analysis of the Gallant-Lambert-Vanstone method based on efficient endomorphisms: Elliptic and hyperelliptic curves

Sica, F;Quisquater, Jean-Jacques;Ciet, M.
(2003) 9th Annual International Workshop on Selected Areas in Cryptography — Location: ST JOHNS(Canada) (15.August.2002)

Files

pdfdocument.pdf
  • Restricted Access
  • Adobe PDF
  • 331.73 KB

Details

Authors
Abstract
In this work we analyse the GLV method of Gallant, Lambert and Vanstone (CRYPTO 2001) which uses a fast endomorphism Phi with minimal polynomial X-2 + rX + s to compute any multiple kP of a point P of order n lying on an elliptic curve. First we fill in a gap in the proof of the bound of the kernel K vectors of the reduction map f : (i, j) --> i + gimelj (mod n). In particular, we prove the GLV decomposition with explicit constant kP = k(1)P + k(2)Phi(P), with max {k(1), k(2)} less than or equal to root1 + + srootn. Next we improve on this bound and give the best constant in the given examples for the quantity sup(k,n) max {k(1), k(2)}/rootn. Independently Park, Jeong, Kim, and Lim (PKC 2002) have given similar but slightly weaker bounds. Finally we provide the first explicit bounds for the GLV method generalised to hyperelliptic curves as described in Park, Jeong and Lim (EUROCRYPT 2002).
Affiliations

Citations

Sica, F., Quisquater, J.-J., & Ciet, M. (2003). Analysis of the Gallant-Lambert-Vanstone method based on efficient endomorphisms: Elliptic and hyperelliptic curves. Lecture Notes in Computer Science, 2595, 21-36. https://doi.org/10.1007/3-540-36492-7_3 (Original work published 2003)