A complete set of addition laws\\for incomplete Edwards curves

Daniel J. Bernstein and Tanja Lange

Abstract: Edwards curves were the first curves shown to have a complete addition law. However, the completeness of the addition law depends on the curve parameters and even a complete Edwards curve becomes incomplete over a quadratic field extension. This paper covers arbitrary Edwards curves and gives a set of two addition laws that for any pair of input points P1, P2 produce the sum P1+P2.

Category / Keywords: public-key cryptography / Elliptic curves, Edwards curves, complete addition law, points at infinity.

Publication Info: to appear in J. Number Theory

Date: received 29 Nov 2009, last revised 6 Oct 2010

Contact author: tanja at hyperelliptic org

Note: Fixed 2 typos.

Version: 20101006:142753 (All versions of this report)

