Efficient Isogeny Computations on Twisted Edwards Curves

The isogeny-based cryptosystem is the most recent category in the field of postquantum cryptography. However, it is widely studied due to short key sizes and compatibility with the current elliptic curve primitives. The main building blocks when implementing the isogeny-based cryptosystem are isogen...

Full description

Bibliographic Details
Main Authors: Suhri Kim, Kisoon Yoon, Jihoon Kwon, Seokhie Hong, Young-Ho Park
Format: Article
Language:English
Published: Hindawi-Wiley 2018-01-01
Series:Security and Communication Networks
Online Access:http://dx.doi.org/10.1155/2018/5747642
id doaj-fb803fdd6b354a1fb4e565d578ec67e2
record_format Article
spelling doaj-fb803fdd6b354a1fb4e565d578ec67e22020-11-25T01:14:47ZengHindawi-WileySecurity and Communication Networks1939-01141939-01222018-01-01201810.1155/2018/57476425747642Efficient Isogeny Computations on Twisted Edwards CurvesSuhri Kim0Kisoon Yoon1Jihoon Kwon2Seokhie Hong3Young-Ho Park4Center for Information Security Technologies (CIST), Korea University, Seoul, Republic of KoreaNSHC Inc., Uiwang, Republic of KoreaCenter for Information Security Technologies (CIST), Korea University, Seoul, Republic of KoreaCenter for Information Security Technologies (CIST), Korea University, Seoul, Republic of KoreaSejong Cyber University, Seoul, Republic of KoreaThe isogeny-based cryptosystem is the most recent category in the field of postquantum cryptography. However, it is widely studied due to short key sizes and compatibility with the current elliptic curve primitives. The main building blocks when implementing the isogeny-based cryptosystem are isogeny computations and point operations. From isogeny construction perspective, since the cryptosystem moves along the isogeny graph, isogeny formula cannot be optimized for specific coefficients of elliptic curves. Therefore, Montgomery curves are used in the literature, due to the efficient point operation on an arbitrary elliptic curve. In this paper, we propose formulas for computing 3 and 4 isogenies on twisted Edwards curves. Additionally, we further optimize our isogeny formulas on Edwards curves and compare the computational cost of Montgomery curves. We also present the implementation results of our isogeny computations and demonstrate that isogenies on Edwards curves are as efficient as those on Montgomery curves.http://dx.doi.org/10.1155/2018/5747642
collection DOAJ
language English
format Article
sources DOAJ
author Suhri Kim
Kisoon Yoon
Jihoon Kwon
Seokhie Hong
Young-Ho Park
spellingShingle Suhri Kim
Kisoon Yoon
Jihoon Kwon
Seokhie Hong
Young-Ho Park
Efficient Isogeny Computations on Twisted Edwards Curves
Security and Communication Networks
author_facet Suhri Kim
Kisoon Yoon
Jihoon Kwon
Seokhie Hong
Young-Ho Park
author_sort Suhri Kim
title Efficient Isogeny Computations on Twisted Edwards Curves
title_short Efficient Isogeny Computations on Twisted Edwards Curves
title_full Efficient Isogeny Computations on Twisted Edwards Curves
title_fullStr Efficient Isogeny Computations on Twisted Edwards Curves
title_full_unstemmed Efficient Isogeny Computations on Twisted Edwards Curves
title_sort efficient isogeny computations on twisted edwards curves
publisher Hindawi-Wiley
series Security and Communication Networks
issn 1939-0114
1939-0122
publishDate 2018-01-01
description The isogeny-based cryptosystem is the most recent category in the field of postquantum cryptography. However, it is widely studied due to short key sizes and compatibility with the current elliptic curve primitives. The main building blocks when implementing the isogeny-based cryptosystem are isogeny computations and point operations. From isogeny construction perspective, since the cryptosystem moves along the isogeny graph, isogeny formula cannot be optimized for specific coefficients of elliptic curves. Therefore, Montgomery curves are used in the literature, due to the efficient point operation on an arbitrary elliptic curve. In this paper, we propose formulas for computing 3 and 4 isogenies on twisted Edwards curves. Additionally, we further optimize our isogeny formulas on Edwards curves and compare the computational cost of Montgomery curves. We also present the implementation results of our isogeny computations and demonstrate that isogenies on Edwards curves are as efficient as those on Montgomery curves.
url http://dx.doi.org/10.1155/2018/5747642
work_keys_str_mv AT suhrikim efficientisogenycomputationsontwistededwardscurves
AT kisoonyoon efficientisogenycomputationsontwistededwardscurves
AT jihoonkwon efficientisogenycomputationsontwistededwardscurves
AT seokhiehong efficientisogenycomputationsontwistededwardscurves
AT younghopark efficientisogenycomputationsontwistededwardscurves
_version_ 1725156513728692224