Cryptology ePrint Archive: Report 2018/839

On Kummer Lines With Full Rational 2-torsion and Their Usage in Cryptography

Huseyin Hisil and Joost Renes

Abstract: A paper by Karati and Sarkar at Asiacrypt'17 has pointed out the potential for Kummer lines in genus one, by observing that its SIMD-friendly arithmetic is competitive with the status quo. A more recent preprint explores the connection with (twisted) Edwards curves. In this paper we extend this work and significantly simplify their treatment. We show that their Kummer line is the x-line of a Montgomery curve translated by a point of order two, and exhibit a natural isomorphism to a twisted Edwards curve. Moreover, we show that the Kummer line presented by Gaudry and Lubicz can be obtained via the action of a point of order two on the y-line of an Edwards curve. The maps connecting these curves and lines are all very simple. As an example, we present the first implementation of the qDSA signature scheme based on the squared Kummer line. Finally we present close estimates on the number of isomorphism classes of Kummer lines.

Category / Keywords: public-key cryptography / Montgomery curves, Edwards curves, Kummer lines, Montgomery ladder, Digital signatures

Date: received 6 Sep 2018

Contact author: j renes at cs ru nl

Available format(s): PDF | BibTeX Citation

Version: 20180906:205612 (All versions of this report)

Short URL:

[ Cryptology ePrint archive ]