**Double-Base Chains for Scalar Multiplications on Elliptic Curves**

*Wei Yu and Saud Al Musa and Bao Li*

**Abstract: **Double-base chains (DBCs) are widely used to speed up scalar multiplications on elliptic curves. We present three results of DBCs. First, we display a structure of the set containing all DBCs and propose an iterative algorithm to compute the number of DBCs for a positive integer. This is the first polynomial time algorithm to compute the number of DBCs for positive integers. Secondly, we present an asymptotic lower bound on average Hamming weights of DBCs $\frac{\log n}{8.25}$ for a positive integer $n$. This result answers an open question about the Hamming weights of DBCs. Thirdly, we propose a new algorithm to generate an optimal DBC for any positive integer. The time complexity of this algorithm is $\mathcal{O}\left(\left(\log n\right)^2 \log\log n\right)$ bit operations and the space complexity is $\mathcal{O}\left(\left(\log n\right)^{2}\right)$ bits of memory. This algorithm accelerates the recoding procedure by more than $6$ times compared to the state-of-the-art Bernstein, Chuengsatiansup, and Lange's work. The Hamming weights of optimal DBCs are over $60$\% smaller than those of NAFs. Scalar multiplication using our optimal DBC is about $13$\% faster than that using non-adjacent form on elliptic curves over large prime fields.

**Category / Keywords: **implementation / Elliptic curve cryptography, Scalar multiplication, Double-base chain, Hamming weight

**Original Publication**** (with minor differences): **IACR-EUROCRYPT-2020

**Date: **received 10 Feb 2020, last revised 13 May 2020

**Contact author: **yuwei_1_yw at 163 com,yuwei@iie ac cn

**Available format(s): **PDF | BibTeX Citation

**Version: **20200514:042239 (All versions of this report)

**Short URL: **ia.cr/2020/144

[ Cryptology ePrint archive ]