Paper 2009/580

A complete set of addition laws\\for incomplete Edwards curves

Daniel J. Bernstein and Tanja Lange

Abstract

Edwards curves were the first curves shown to have a complete addition law. However, the completeness of the addition law depends on the curve parameters and even a complete Edwards curve becomes incomplete over a quadratic field extension. This paper covers arbitrary Edwards curves and gives a set of two addition laws that for any pair of input points P1, P2 produce the sum P1+P2.

Note: Fixed 2 typos.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. to appear in J. Number Theory
Keywords
Elliptic curvesEdwards curvescomplete addition lawpoints at infinity.
Contact author(s)
tanja @ hyperelliptic org
History
2010-10-06: revised
2009-12-01: received
See all versions
Short URL
https://ia.cr/2009/580
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2009/580,
      author = {Daniel J.  Bernstein and Tanja Lange},
      title = {A complete set of addition laws\\for incomplete Edwards curves},
      howpublished = {Cryptology ePrint Archive, Paper 2009/580},
      year = {2009},
      note = {\url{https://eprint.iacr.org/2009/580}},
      url = {https://eprint.iacr.org/2009/580}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.