Faster cofactorization with ECM using mixed representations

Cyril Bouvier and Laurent Imbert

Abstract: This paper introduces a novel implementation of the elliptic curve factoring method specifically designed for medium-size integers such as those arising by billions in the cofactorization step of the number field sieve. In this context, our algorithm requires fewer modular multiplications than any other publicly available implementation. The main ingredients are: the use of batches of primes, fast point tripling, optimal double-base decompositions and Lucas chains, and a good mix of Edwards and Montgomery representations.

Category / Keywords: public-key cryptography / factoring, Elliptic Curve Method, cofactorization, double-base representation, twisted Edwards curve, Montgomery curve, CADO-NFS

