Cryptology ePrint Archive: Report 2015/673

Decaf: Eliminating cofactors through point compression

Mike Hamburg

Abstract: We propose a new unified point compression format for Edwards, Twisted Edwards and Montgomery curves over large-characteristic fields, which effectively divides the curve's cofactor by 4 at very little cost to performance. This allows cofactor-4 curves to efficiently implement prime-order groups.

Category / Keywords: public-key cryptography / Elliptic curves, Edwards curves, Montgomery curves, isogenies, quotient groups

Original Publication (with minor differences): IACR-CRYPTO-2015

Date: received 3 Jul 2015

Contact author: mike at shiftleft org

Version: 20150705:180509 (All versions of this report)

