Hashing to elliptic curves of j-invariant 1728

被引:2
|
作者
Koshelev, Dmitrii [1 ,2 ,3 ]
机构
[1] Versailles St Quentin Yvelines Univ, Versailles Lab Math, Versailles, France
[2] Inst Informat Transmiss Problems, Algebra & Number Theory Lab, Moscow, Russia
[3] Moscow Inst Phys & Technol, Dept Discrete Math, Dolgoprudnyi, Russia
关键词
Finite fields; Pairing-based cryptography; Elliptic curves of j -invariant 1728; Kummer surfaces; Rational curves; Weil restriction; Isogenies; POINTS;
D O I
10.1007/s12095-021-00478-y
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This article generalizes the simplified Shallue-van de Woestijne-Ulas (SWU) method of a deterministic finite field mapping h : F-q -> E-a(F-q) to the case of any elliptic F-q-curve E-a : y(2) = x(3) - ax of j-invariant 1728. In comparison with the (classical) SWU method the simplified SWU method allows to avoid one quadratic residuosity test in the field Fq, which is a quite painful operation in cryptography with regard to timing attacks. More precisely, in order to derive h we obtain a rational Fq -curve C (and its explicit quite simple proper F-q -parametrization) on the Kummer surface K' associated with the direct product E-a x E'(a), where E'(a) is the quadratic F-q-twist of E-a. Our approach of finding C is based on the fact that every curve E-a has a vertical F-q2-isogeny of degree 2.
引用
收藏
页码:479 / 494
页数:16
相关论文
共 50 条