In this work, we use elementary facts about quadratic rings to immediately write down a short basis of the lattice for the GLV, GLS, GLV+GLS, and Q-curve constructions on elliptic curves, and for genus 2 real multiplication constructions. We do not pretend that this represents a significant optimization in scalar multiplication, since the lattice reduction step is always an offline precomputation---but it does give a better insight into the structure of scalar decompositions. In any case, it is always more convenient to use a ready-made short basis than it is to compute a new one.
Category / Keywords: implementation / Elliptic curve cryptography, number theory, endomorphisms, GLV Date: received 19 Oct 2013 Contact author: smith at lix polytechnique fr Available format(s): PDF | BibTeX Citation Note: Submitted to the proceedings of AGCT 2013. Version: 20131024:083914 (All versions of this report) Short URL: ia.cr/2013/672 Discussion forum: Show discussion | Start new discussion