Cryptology ePrint Archive: Report 2014/333

An optimal representation for the trace zero subgroup

Elisa Gorla and Maike Massierer

Abstract: We give an optimal-size representation for the elements of the trace zero subgroup of the Picard group of an elliptic or hyperelliptic curve of any genus, with respect to a fi eld extension of any prime degree. The representation is via the coefficients of a rational function, and it is compatible with scalar multiplication of points. We provide efficient compression and decompression algorithms, and complement them with implementation results. We discuss in detail the practically relevant cases of small genus and extension degree, and compare with the other known compression methods.

Category / Keywords: public-key cryptography / elliptic curve cryptosystem

Date: received 12 May 2014, last revised 15 Jun 2016

Contact author: maike at unsw edu au

Available format(s): PDF | BibTeX Citation

Version: 20160615:123618 (All versions of this report)

Short URL:

Discussion forum: Show discussion | Start new discussion

[ Cryptology ePrint archive ]