Efficient arithmetic on elliptic curves using a mixed Edwards-Montgomery representation

Wouter Castryck and Steven Galbraith and Reza Rezaeian Farashahi

Abstract: From the viewpoint of x-coordinate-only arithmetic on elliptic curves, switching between the Edwards model and the Montgomery model is quasi cost-free. We use this observation to speed up Montgomery's algorithm, reducing the complexity of a doubling step from 2M + 2S to 1M + 3S for suitably chosen curve parameters.

Category / Keywords: public-key cryptography /

Date: received 14 May 2008, last revised 3 Jun 2008

Contact author: wouter castryck at gmail com

