Paper 2019/1048

New point compression method for elliptic Fq2-curves of j-invariant 0

Dmitrii Koshelev

Abstract

In the article we propose a new compression method (to 2log2(q)+3 bits) for the Fq2-points of an elliptic curve Eb:y2=x3+b (for bFq2) of j-invariant 0. It is based on Fq-rationality of some generalized Kummer surface GKb. This is the geometric quotient of the Weil restriction Rb:=RFq2/Fq(Eb) under the order 3 automorphism restricted from Eb. More precisely, we apply the theory of conic bundles (i.e., conics over the function field Fq(t)) to obtain explicit and quite simple formulas of a birational Fq-isomorphism between GKb and A2. Our point compression method consists in computation of these formulas. To recover (in the decompression stage) the original point from Eb(Fq2)=Rb(Fq) we find an inverse image of the natural map RbGKb of degree 3, i.e., we extract a cubic root in Fq. For q1(mod 27) this is just a single exponentiation in Fq, hence the new method seems to be much faster than the classical one with coordinate, which requires two exponentiations in .

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint. MINOR revision.
Keywords
pairing-based cryptographyelliptic curves of point compressionWeil restrictiongeneralized Kummer surfacesrationality problemsconic bundlescubic rootssingular cubic surfaces
Contact author(s)
dishport @ ya ru
History
2020-12-02: last of 5 revisions
2019-09-18: received
See all versions
Short URL
https://ia.cr/2019/1048
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2019/1048,
      author = {Dmitrii Koshelev},
      title = {New point compression method for elliptic $\mathbb{F}_{\!q^2}$-curves of $j$-invariant $0$},
      howpublished = {Cryptology {ePrint} Archive, Paper 2019/1048},
      year = {2019},
      url = {https://eprint.iacr.org/2019/1048}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.