You are looking at a specific version 20190208:134518 of this paper. See the latest version.

Paper 2019/110

Optimized Method for Computing Odd-Degree Isogenies on Edwards Curves

Suhri Kim and Kisoon Yoon and Young-Ho Park and Seokhie Hong

Abstract

In this paper, we present an efficient method to compute arbitrary odd-degree isogenies on Edwards curves. By using the $w$-coordinate, we optimized the isogeny formula on Edwards curves by Moody \textit{et al}.. The state-of-the-art implementation of isogeny-based cryptosystems works entirely with Montgomery curves since they provide efficient isogeny computation and elliptic curve arithmetic. However, we demonstrated that the same computational costs of elliptic curve arithmetic and isogeny evaluation could be achieved by using the $w$-coordinate on Edwards curves, with additional benefit when computing isogenous curves. For $\ell$-degree isogeny where $\ell=2s+1$, our isogeny formula on Edwards curves outperforms Montgomery curves when $s \geq 2$. The result of our work opens the door for the usage of Edwards curves in isogeny-based cryptography, especially in CSIDH which requires higher degree isogenies.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint. MINOR revision.
Keywords
IsogenyPost-quantum cryptographyMontgomery curvesEdwards curvesSIDHCSIDH
Contact author(s)
suhrikim @ gmail com
History
2019-12-07: last of 2 revisions
2019-02-05: received
See all versions
Short URL
https://ia.cr/2019/110
License
Creative Commons Attribution
CC BY
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.